Privacy & Policy

Privacy Policy

SynrgiseLearn (Pty) Ltd Registration No. 2010/016796/07 | VAT Registration No. 4180257794

 Last updated: 29 July 2026


1. Who we are

SynrgiseLearn (Pty) Ltd (“Synrgise”, “we”, “us”) provides cloud-based learning management, eLearning content, and AI content authoring services. This Privacy Policy explains how we collect, use, share, and protect personal information when you use our websites (including [www.synrgise.com] and helpdesk.synrgise.com) and our platform and services (the “Services”), and it sets out your rights under the Protection of Personal Information Act, 2013 (“POPIA”).

Responsible party: SynrgiseLearn (Pty) Ltd, [PHYSICAL ADDRESS], South Africa Information Officer: [NAME], [io@synrgise.com], [PHONE] Our Information Officer is registered with the Information Regulator (South Africa). Our PAIA Manual is available at [LINK].

2. Two roles: responsible party and operator

We process personal information in two distinct capacities. Your rights and who you should contact depend on which applies.

2.1 As responsible party. For personal information of our prospective, current, and former business clients and their representatives, website visitors, helpdesk users, and billing contacts, Synrgise determines the purpose and means of processing and is the responsible party under POPIA.

2.2 As operator (learner data). When a client organisation loads its employees’ or learners’ personal information onto the platform, that client is the responsible party and Synrgise acts as its operator under section 20 and 21 of POPIA. We process learner data only to provide the Services, on the client’s instructions, and under a written agreement. If you are a learner on a client’s LMS instance, please direct privacy requests to your employer or training provider in the first instance; we will assist them in responding.

3. What we collect

From clients and their representatives: - Identity and contact details: name, job title, organisation, email, phone, postal and physical address - Company details: registration and VAT numbers, billing contacts - Billing and transaction data: subscription plan, invoices, payment history, and payment confirmation data returned by our payment processor (we do not collect or store full card numbers; see clause 6.1) - Support and communication records: helpdesk tickets, emails, call notes, training attendance - Contractual records: proposals, agreements, signatures

From platform users (as operator, on our clients’ instructions): - Account data: name, surname, email, and any additional fields the client configures (for example employee number, department, or fields required for statutory reporting such as SETA/SAQA/NLRD submissions) - Learning records: enrolments, progress, assessment results, certificates, attendance, forum and messaging activity within the LMS - Content submitted by learners, including portfolios of evidence and file uploads

Automatically, from all users: - Technical data: IP address, browser and device type, operating system, log-in timestamps, pages viewed, and system logs - Cookies and similar technologies (see clause 10)

We do not intentionally collect special personal information (such as race or health data) unless a client configures such fields for a lawful purpose (for example employment equity or SETA reporting), in which case the client is responsible for the lawful basis of that collection and we process it solely as operator.

4. Why we process personal information and on what basis

Purpose

POPIA justification

Creating and administering accounts, providing the LMS, KreateAI, content, hosting, and support

Performance of a contract

Billing, collecting subscription fees via Paystack, issuing invoices, debt collection

Performance of a contract; legal obligation

Onboarding, implementation, and training

Performance of a contract

Responding to enquiries and helpdesk tickets

Legitimate interests; performance of a contract

Sending service notices (maintenance, changes to terms, billing notifications)

Performance of a contract; legitimate interests

Direct marketing of our own similar services to existing clients, with opt-out

Section 69 of POPIA; consent where required

Security, fraud prevention, and abuse monitoring

Legitimate interests; legal obligation

Complying with tax, company, and other laws, and responding to lawful requests

Legal obligation

Aggregated, de-identified analytics to improve the Services

Legitimate interests (data is de-identified)

We will not use learner data loaded by clients for our own marketing.

5. AI features

KreateAI is a content authoring tool. Prompts and materials submitted to KreateAI are processed to generate the requested content. We do not use client content or learner personal information to train our own or third-party foundation models without the client’s prior written agreement. Clients remain responsible for reviewing AI-assisted content before publishing it.

6. Who we share personal information with

We do not sell personal information. We share it only with:

6.1 Payment processing — Paystack. Online payments are processed by Paystack Payments Limited and its affiliates. When you pay or authorise a recurring subscription, your card details are collected, tokenised, and stored by Paystack, not by us. We receive confirmation data (such as masked card number, transaction status, and reference). Paystack processes your data under its own privacy policy: [https://paystack.com/privacy].

6.2 Service providers (operators) who help us run the Services: cloud hosting and infrastructure providers, email and SMS delivery providers, our CRM and ticketing systems, accounting and auditing services. All operators are bound by written agreements requiring confidentiality and appropriate security safeguards.

6.3 Professional advisers, regulators, and authorities where disclosure is required by law, court order, or to protect our rights.

6.4 Statutory education bodies (for example SETAs, SAQA/NLRD) where a client instructs us to submit compliance reports on its behalf.

6.5 Business transfers. If we undergo a merger, acquisition, or asset sale, personal information may be transferred to the successor, subject to this policy.

7. Cross-border transfers

Our primary hosting is in [South Africa / REGION]. Some service providers (for example cloud infrastructure, email delivery, or AI processing) may store or process data outside South Africa. Where personal information is transferred across borders, we do so in accordance with section 72 of POPIA: the recipient is subject to laws or binding agreements providing substantially similar protection, or the transfer is necessary for the performance of the contract, or we have the data subject’s consent.

8. Security

We maintain appropriate, reasonable technical and organisational measures under section 19 of POPIA, including encryption of data in transit, access controls and role-based permissions, network and infrastructure security, logging and monitoring, backup and disaster recovery procedures, and staff confidentiality undertakings. Our Information and Security Policy and Disaster Recovery Plan are available to clients on request or as annexures to their agreements.

If we become aware of a security compromise affecting personal information, we will notify the Information Regulator and affected responsible parties or data subjects as required by section 22 of POPIA.

9. Retention

We keep personal information only as long as necessary for the purposes above or as required by law:

             Client account and contract records: duration of the relationship plus 5 years (tax and companies legislation may require longer for financial records)

             Invoices and transaction records: at least 5 years under the Value-Added Tax Act and Tax Administration Act

             Learner data processed as operator: retained per the client’s instructions; on termination of a client agreement, data is available for export for 30 (thirty) calendar days, after which it is deleted or de-identified within [60] days, except where law requires retention

             Helpdesk and support records: [3] years after closure

             Website logs: [12] months

10. Cookies

Our websites use cookies and similar technologies for: essential functions (authentication, session management, security), preferences, and analytics. You can control cookies through your browser settings; disabling essential cookies may break platform functionality. [If you use non-essential analytics/marketing cookies, list them and provide a consent banner.]

11. Your rights under POPIA

Subject to the two-role structure in clause 2, you have the right to:

             Access — request confirmation that we hold your personal information and a copy of it (also see our PAIA Manual)

             Correction — request correction or updating of inaccurate or incomplete information (section 24)

             Deletion or destruction — request deletion of information that is inaccurate, irrelevant, excessive, outdated, or unlawfully obtained (section 24)

             Objection — object to processing based on legitimate interests, on reasonable grounds (section 11(3))

             Opt out of direct marketing at any time (section 69); every marketing message we send includes an unsubscribe option

             Not to be subject to automated decision-making with legal or similarly significant effect (section 71)

             Complain to the Information Regulator (details below)

             Withdraw consent where processing is based on consent, without affecting prior lawful processing

To exercise these rights, contact our Information Officer at [io@synrgise.com]. We will respond within a reasonable time and in any event within the periods prescribed by POPIA and PAIA. We may need to verify your identity before acting on a request.

12. Children

The Services are provided to business clients. Where a client enrols learners under 18, the client is responsible for obtaining the consent of a competent person (parent or guardian) as required by section 35 of POPIA.

13. Information Regulator

You may lodge a complaint with the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 Email: complaints.IR@justice.gov.za | enquiries@inforegulator.org.za Website: https://inforegulator.org.za

14. Changes to this policy

We may update this policy from time to time. The current version is always available at [www.synrgise.com/privacy]. Material changes will be notified to client administrators by email.

15. Contact

 

Information Officer: Chris Asals Email: chris@synrgise.com Address: Level 3, 17 Thora Cres, Wynberg, Johannesburg, 2090