Legal
Privacy Policy
How SynTifika collects, uses and protects personal information, and the rights you have. We keep a deliberately small data footprint, and we are precise about who is responsible for what.
Last updated: 28 August 2026
1. Who we are, and our two roles
SynTifika is a product of Celagenix Holdings (Pty) Ltd (registration number 2014/073666/07) ("Celagenix", "we", "us"), a company incorporated in the Republic of South Africa, with its registered office at 4th Floor West Wing, Nelson Mandela Square, Sandton City, Johannesburg, South Africa. SynTifika is a white-label learning platform with an automated content-production pipeline.
We handle personal information in two distinct roles, and the distinction matters:
- As a Responsible Party (Controller under the GDPR), for the personal information of website visitors and the people who contact us, and for our client account and billing contacts. This policy governs that data.
- As an Operator (Processor under the GDPR), for the client and learner personal information processed through the platform on a client's behalf. There, the client is the Responsible Party and decides how that data is used; we act on the client's documented instructions under a separate Data Processing Agreement. That agreement, not this policy, governs the client's learner data.
2. Information we collect
From website visitors and enquiries
When you use the enquiry form, we collect the name, organisation, work email, area of interest and message you provide. We do not run analytics, advertising or tracking scripts, so we do not build a profile of your browsing.
From clients (account data)
To provide the service we hold account and billing contact details for the organisations we work with, and the source material a client uploads to produce their courses.
Learner data (as Operator)
The platform processes learner records (such as names, work email addresses, course progress and completion) on a client's behalf. We process this only to run the client's academy, under the client's instructions and the Data Processing Agreement.
3. How we use it
We use personal information only to:
- respond to your enquiry and arrange a walkthrough or pilot;
- provide, operate and support the platform, including producing and validating course content from a client's own sources;
- meet our legal and contractual obligations, and keep the service secure.
We do not sell personal information, use it for advertising, or use client content or learner data to train any AI model. Our lawful bases are your consent (for enquiries), the performance of a contract (to deliver the service), and our legitimate interests in operating and securing the platform, balanced against your rights.
4. Sub-processors
We keep a deliberately small set of third parties, each bound by contract to protect the data they handle. We use no payment processor, no analytics provider and no advertising or tracking services. In summary:
- Cloud hosting and database for all personal data, located in the European Union (Frankfurt).
- AI and media services that render course scripts into video, audio and other formats. These receive course content only, never the learner personal-data store, and are engaged on terms that prohibit training on that content.
- Website and request infrastructure that serves the site.
A current, named sub-processor register, showing each provider, what it handles and where it runs, is available to clients and prospective clients on request. Request it here.
5. Where your data lives, and transfers
All learner and client personal data is hosted in the European Union (Frankfurt) and isolated to each client's own tenant. The only information that ever leaves that store is request metadata needed to serve the site and course content sent to the media services that produce video and audio; never the personal-data store.
Because Celagenix is South African, any transfer of personal information across borders is made under a lawful transfer mechanism: for South African data subjects, on a ground recognised by section 72 of POPIA (including binding agreements with adequate safeguards); and for data subjects in the EU or UK, under appropriate safeguards such as Standard Contractual Clauses.
6. How long we keep it
We keep enquiry information only as long as needed to deal with your enquiry and any resulting relationship. Client and learner data is retained for the term of the client engagement and then handled per the Data Processing Agreement, which provides for return or deletion. We aim to minimise how long raw source material persists, using it to produce a client's course and then retaining the finished content rather than the raw upload wherever we can.
7. Security
We protect personal information with measures appropriate to its sensitivity, including tenant isolation enforced at the database and continuously verified by an automated security suite, encryption in transit and at rest, access controls, and the principle of collecting and keeping as little as possible. No system is perfectly secure, but a small footprint and strong isolation are the strongest controls we can offer.
8. Cookies
The marketing site uses no advertising or tracking cookies. It sets only what is strictly necessary to function, and it loads fonts from Google Fonts, whose use is governed by Google's own terms. The learner platform may use a strictly necessary session cookie to keep you signed in; it is not used for tracking.
9. Your rights
Subject to the applicable law, you have the right to access the personal information we hold about you, to have it corrected or deleted, to object to or restrict its processing, and, where processing is based on consent, to withdraw that consent. EU and UK data subjects also have the right to data portability.
If your personal information is held by us as an Operator on a client's behalf (for example, as a learner on a client's academy), please contact that organisation, which is the Responsible Party; we will support them in meeting your request.
To exercise a right, or to reach our Information Officer, use our contact form.
10. Children
SynTifika is a workplace training platform intended for organisations and their staff. It is not directed at children, and we do not knowingly collect the personal information of children.
11. Changes
We may update this policy as the product and the law evolve. We will change the "last updated" date above, and, for material changes affecting clients, give notice through the service.
12. Contact and complaints
For any privacy question or request, please use our contact form, addressed to the Information Officer. Martin Louw is the appointed Information Officer, with Johann Koen as Deputy Information Officer.
You also have the right to complain to a supervisory authority. In South Africa that is the Information Regulator (inforegulator.org.za). EU and UK data subjects may complain to their local data-protection authority. Our PAIA manual sets out how to request access to information.