Privacy Policy
SynSight ERP ("SynSight", "the Service") is a cloud-based garment manufacturing platform developed and operated by Syntera Labs (Pty) Ltd ("Syntera Labs", "we", "us"), a private company registered in South Africa (registration number 2026/348010/07), with its registered office at 24 Cradock Avenue, Rosebank, Johannesburg, Gauteng, 2196.
This policy explains what personal information SynSight processes, why, who else handles it, how long we keep it, and the rights you have. It applies to the app at app.synsighterp.com, the website at synsighterp.com, and the emails the Service sends. It is written to meet the Protection of Personal Information Act, 2013 (POPIA) and, for users in the European Economic Area and the United Kingdom, the General Data Protection Regulation (GDPR and UK GDPR).
Our Information Officer under POPIA can be reached at [email protected].
For your own account (your name, email address, sign-in and security records) and for billing, Syntera Labs is the responsible party under POPIA and the controller under the GDPR.
For the business records your organisation enters into SynSight, including the names and details of your staff, operators, suppliers and buyers, your organisation is the responsible party (controller) and Syntera Labs is the operator (processor) under POPIA sections 20 and 21 and GDPR article 28. As operator we process that information only to provide SynSight as your organisation instructs, keep it confidential, secure it, and return or delete it when the service ends. A data processing agreement is available on request.
A person whose details are held by a SynSight customer should send requests about them to that customer first; we will help the customer answer them.
We do not collect payment card details. We do not use analytics, advertising or tracking tools, and we do not build profiles of you. The phone scanner reads barcodes on your device; camera images are not sent to us.
We do not sell personal information, use it for advertising, or send marketing email without your consent. No decision with legal or similarly significant effect on anyone is made by automated means alone (POPIA section 71, GDPR article 22).
SynScout answers questions and writes a daily briefing from your organisation’s own records. To do this we send Anthropic, PBC (United States), the provider of the Claude models, only what the request needs: the question, the page it was asked from, the person’s role, and the records SynScout reads to answer it, such as orders, steps, output, stock or shipments.
Anthropic processes this under its commercial terms, which do not allow it to train its models on this data, and it does not use it for any other purpose. SynScout reads only and changes nothing. Questions and answers are kept in your organisation’s SynScout log so administrators can see what was asked. Organisations that do not want this can simply not use SynScout; nothing else in SynSight depends on it.
We use a small number of providers, each bound by a written agreement to process data only for the service named:
We may also disclose information when the law, a court order or a regulator requires it, or to protect the rights and safety of people using the Service. If Syntera Labs or SynSight is sold or merged, personal information would pass to the new owner under this policy, and we would tell you first.
Cloudflare, Resend, Anthropic and GoDaddy process data in the United States and, for Cloudflare, in data centres around the world. Under POPIA section 72 and GDPR chapter V we transfer personal information outside South Africa or the European Economic Area only to providers bound by agreements that give it substantially the same protection, including the European Commission’s standard contractual clauses where the GDPR applies, and only what each service needs.
No system is perfectly secure. If personal information is accessed by someone without authority, we will tell the affected organisations and people, and the Information Regulator, as soon as reasonably possible, as POPIA section 22 requires, and the relevant supervisory authority within 72 hours where the GDPR applies.
You may ask for earlier deletion at [email protected], except where the law requires us to keep the record.
Under POPIA you may ask to know whether we hold your personal information and to see it, to have it corrected or deleted, and to object to its processing. You may also complain to the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, inforegulator.org.za, [email protected].
If the GDPR or UK GDPR applies to you, you also have the rights to restrict processing, to receive your data in a portable format, and to withdraw any consent you gave, and you may complain to your local data protection authority.
To use any of these rights, write to our Information Officer at [email protected]. We will answer within 30 days and will not charge for a reasonable request. We may need to confirm who you are first.
SynSight keeps your sign-in token in your browser’s local storage so you stay signed in; it is removed when you sign out. Cloudflare Turnstile, on the sign-in and registration pages, may set a strictly necessary cookie to tell people from bots. We use no advertising cookies, tracking pixels or third-party analytics, so no cookie banner is shown.
SynSight is a business service for people aged 18 and over. We do not knowingly collect personal information about children; if you believe we have, tell us and we will delete it. Organisations are responsible for any information about minors they enter as employer records, which must be lawful in their country.
We will post any change here with a new date. Where a change matters to you, we will email account holders at least 14 days before it takes effect.
Syntera Labs (Pty) Ltd, registration number 2026/348010/07
Registered office: 24 Cradock Avenue, Rosebank, Johannesburg, Gauteng, 2196, South Africa
Information Officer (registered with the Information Regulator, 2026-067698) and support: [email protected]
Website: synsighterp.com