What happens to your documents, in plain terms.
Kre8AI processes internal policy material, so how we handle it matters more than any feature we could describe. This page is written for the people who have to approve us: IT, security, risk and legal.
- ISO 27001
SynrgiseLearn is certified. Kre8AI runs under that ISMS.
- POPIA-aligned
Information security policy and incident process designed for personal information.
- Customer content
Processed only to provide the service. Isolation, retention and our POPIA position are on this page.
Operated under SynrgiseLearn's ISMS
Kre8AI is a SynrgiseLearn product. Security governance, business continuity and incident handling sit in the parent company's Information Security Management System.
SynrgiseLearn is ISO 27001 certified. The Information Security Policy defines access control on a need-to-know basis, leavers and privilege reviews, password standards, security awareness for staff, and formal handling of security incidents. The ISMS Policy Owner is Xenothan Hojem, Group CTO.
We align that programme with the Protection of Personal Information Act. Certificate details, statement of applicability and deeper control evidence are available on request for a security assessment.
Business continuity plan
Covers site, systems and people unavailability, with defined escalation and recovery procedures for critical services.
Backups and failover
Off-site backups, secondary data-centre switchover procedures, and periodic recovery testing. Exact product recovery targets are confirmed in writing for procurement reviews.
Testing cadence
Scenario-based continuity drills twice a year, an annual full BCP review, and monthly checks of backup integrity and failover capability.
Your content is used to run the feature you asked for
Authoring and media features process the material you submit so the product can generate, retrieve and render a course. That processing is limited to providing the service.
Customer content is not used to train foundation models. Hosting, residency and processing detail for your environment are confirmed in writing for a procurement review — we will not invent those details here.
Tenant separation
Kre8AI is multi-tenant by design, but not shared-workspace by accident. There is no cross-tenant content.
- Every record that belongs to a customer carries an organisation identifier, and every authenticated request is scoped to the caller’s organisation.
- Uploaded documents and generated media are stored under per-organisation object storage namespaces.
- Access within an organisation is role-based, and external reviewers reach only the single course they were invited to.
The product surface is served over HTTPS. Hosting provider, data residency region, encryption-at-rest mechanisms and backup retention for your environment are confirmed in writing for security questionnaires — we will not invent those details here.
How long we keep things, and how you get them removed
Source documents, generated courses, exported packages and related product records are retained for the life of your organisation's account and contract, unless you ask us to delete them earlier or your agreement sets a shorter period.
On contract termination, or when you request deletion, we remove customer content from the live systems under our deletion process. Backup copies fall out of the retention cycle according to that process; exact timeframes and any lag are stated in the customer agreement or confirmed in writing for a procurement review.
Data subject requests under POPIA are handled through our incident and compliance process. Contact us and we will action the request; turnaround commitments for your programme are confirmed in the operator agreement.
The audit trail
Kre8AI records AI-assisted and human actions against each course, which is the record you produce when someone asks who wrote the content.
Generation events, review decisions, comments and approvals are all recorded with the actor and timestamp. See how governance works.
Incident response
Security incidents are reported, recorded and evaluated under the Information Security Policy. Where a personal-data security breach must be notified to the supervisory authority, we aim to do so without delay and no later than 72 hours after becoming aware of it. Material incidents that affect customers are communicated to the affected parties so they can take protective steps.
Staff access
SynrgiseLearn personnel access systems on a need-to-know basis under the ISMS. Access is granted for job function, reviewed periodically, and removed when roles change or people leave. Customer content is not treated as a shared browsing surface.
Our position under the Protection of Personal Information Act
For the marketing website, SynrgiseLearn is the responsible party for personal information collected through forms and consented analytics. That processing is described in our privacy policy, including the Information Officer.
For documents and media you upload into Kre8AI, we act as an operator processing that content on your instruction to provide the service. You remain responsible for having a lawful basis to put the material into the product. A standard operator agreement is available for customers who need it in their procurement pack.
