Privacy notice
How Immersion X handles personal information in Synergi — for the people whose conversations we analyse, and for the clients who send them.
Who we are
Synergi is a product of Immersion X, part of the Immersion Group. Where a client uploads customer conversations for analysis, that client is the Responsible Party under the Protection of Personal Information Act (POPIA) and we act as its Operator, processing personal information only on the client's documented instruction.
Where we collect information directly — a request for access, an enquiry, a sign-in — we are the Responsible Party for that information.
What we process
Client content: batches of call transcripts, chat and conversational data, reviews and related exports supplied by a client, together with the findings derived from them. These records may contain names, contact details, account or policy references and other identifiers spoken by customers.
Account data: the name, work email, role and organisation of each invited user, plus sign-in and audit events.
Enquiry data: what you send us through the access request form — name, work email, job title, company, optional phone number and your message.
Website data: automated bot protection runs on public forms to block abuse. We do not run advertising or cross-site tracking on this site.
Redaction before analysis
South African identifiers — ID numbers, phone numbers, bank accounts, policy numbers, names — are masked server-side before any model reads a record. A record dominated by personal identifiers is quarantined rather than analysed. Quotes shown under a finding come from the redacted text.
Where information is held
Application compute, the database, object storage, cache and task queues run in Johannesburg, South Africa, and backups stay in the region. One flow crosses the border: analytical inference by our language-model provider in the United States, over TLS, under a zero data retention agreement, on text that has already been redacted. We maintain a written lawful-basis analysis for that transfer and give prior written notice before any change to region or residency posture.
Sub-processors
The security page sets out every third-party function we rely on, its region and whether it sees client content; the named list is provided to clients under NDA. We give clients prior written notice of any new sub-processor or material change, with the right to object. Client data is never used to train, fine-tune or benchmark any model — by us or by any provider.
Retention and deletion
Retention is set per engagement rather than by a platform default. Deletion is a hard delete. On termination a client chooses export-then-destroy or immediate destruction, and receives a signed certificate of destruction. Enquiry data is kept only as long as needed to answer the enquiry and record the decision.
Your rights
If your personal information sits inside a client's workspace, that client decides how it is used and is your first point of contact; we support their response as Operator. For information we hold as Responsible Party you may ask for access, correction or deletion, and object to processing, by writing to us.
You may also complain to the Information Regulator of South Africa.
Security
Access is invitation-only with role-based permissions and mandatory two-step verification. Traffic runs over TLS 1.2+ with HSTS; internal traffic runs on a private encrypted network; data is encrypted at rest. Incident commitments, including notice within 24 hours of becoming aware of a suspected compromise, are set out on the security page.
Contact
Write to our Information Officer at Immersion X for any privacy request or question about this notice. Contact details to be confirmed before publication.
Changes to this notice
We update this notice when the service or our processing changes, and record the date of the current version above. Material changes are notified to clients in writing.
The security page sets out hosting, sub-processors and incident commitments in full.