Privacy Policy
What we collect, why we collect it, who else processes it, and what you can ask us to do with it.
Last updated 21 September 2026
Who is responsible for what
For your account data — the details of you and your organization — Synapta Technologies is the controller.
For customer content — the documents, records and conversations you put into the platform — you are the controller and we are your processor. We act on your instructions and do not use that content for our own purposes.
What we collect
- Account data — name, email, organization name, role, hashed password.
- Content you connect — knowledge sources, uploaded documents, your business profile, and chatbot configuration.
- Conversations — messages exchanged with your chatbots, including messages from your own website visitors, stored so conversations have continuity and so you can review them — together with details extracted from them (such as a visitor's stated requirements and any name, email or phone number they chose to share), which form your leads.
- Operational data — logs, error reports and IP addresses, used to keep the service running, secure and rate limited.
- Enquiries — what you send us through the contact form, so we can reply.
Why we process it
To provide the service you have asked for; to keep it secure and prevent abuse; to bill you; to support you; and to meet legal obligations. We do not sell personal data, and we do not use your content to train foundation models.
Who else processes it
We rely on these categories of subprocessor:
- Model providers. When a chatbot answers, the prompt and the retrieved passages relevant to that question are sent to a large language model provider to generate the response.
- Hosting. The application and database run on dedicated server infrastructure under our control.
- Email. Amazon Simple Email Service delivers transactional mail such as invitations and notifications.
Some of these process data outside Zimbabwe. Where that happens we rely on the provider's contractual data protection terms.
How long we keep it
Customer content is kept for as long as your workspace is active. When you delete a knowledge source, a record, or your organization, we delete the corresponding data and its derived indexes within a reasonable period.
Operational logs are kept for a limited period for security and debugging. Records we must keep for legal or accounting reasons are kept for the period the law requires.
Your rights
You can ask us to give you a copy of your personal data, correct it, delete it, or restrict how we use it. Account data is editable directly in Settings.
If you are an end user who spoke to a chatbot on someone else's website, that organization is the controller of the conversation — contact them first. We will support them in responding.
To make a request, contact us. We respond within 30 days.
Children
The service is for business use and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
We will post updates to this policy here and notify you of material changes before they take effect.