1. Introduction and Scope
1.1 Overview: This Cookie Policy explains how Synapser (Pty) Ltd uses cookies, local storage, and similar session technologies across all its websites, platforms, and hosted services, including synapser.com, entryidp.com (and its subdomains including idp.entryidp.com), entrymfa.com, thekeyplatform.co, gain4me.com, project-tide.org, secureus-fs.com, and utilityafrica-cp.com.
1.2 Complementary Policies: This Policy operates in conjunction with our Privacy Policy and Terms of Use.
2. Definition and Nature of Cookies
2.1 Cookies Defined: Cookies are small data files placed on your device to maintain session integrity, execute secure authentication handoffs, retain user settings, and monitor platform performance.
2.2 Personal Data Linkage: Where cookie identifiers can be linked to an identifiable user, processing conforms strictly to our Privacy Policy.
3. Categories of Cookies Utilized
3.1 Essential Technical Cookies: Strictly necessary for core platform operations, security routing, load balancing, and page navigation across all Synapser websites. These cannot be disabled in our systems.
3.2 Security and OIDC Session Cookies: Deployed across entryidp.com, entrymfa.com, and related subdomains to maintain OIDC session states, handle cryptographic nonce parameters, and pass anti-CSRF state tokens during hosted browser redirects. These cookies verify session origin and prevent cross-site request forgery and replay attacks.
3.3 Functional Cookies: Retain interface preferences, such as language selection, portal themes, and localized display configurations.
3.4 Analytics & Performance Cookies: Collect aggregated, non-identifying telemetry to measure platform stability, system latency, and interface usability across our products.
3.5 Third-Party Integration Cookies: Deployed strictly where external modules (such as documentation viewers or customer support components) are loaded.
4. Structured Classification Schedule
- OIDC State & Nonce Parameters — Technical Purpose: Secures OAuth 2.0 / OIDC redirects against CSRF and replay attacks across EntryIDP. Regulatory Necessity: Strictly Necessary (Exempt from consent).
- Authentication Session Tokens — Technical Purpose: Maintains authenticated state within hosted verification containers and customer portals. Regulatory Necessity: Strictly Necessary (Exempt from consent).
- User Interface Preferences — Technical Purpose: Retains localized display, dashboard filters, and accessibility configurations. Regulatory Necessity: Functional (Optional).
- Platform Telemetry — Technical Purpose: Collects anonymized platform performance and drop-off metrics across products. Regulatory Necessity: Analytics (Consent-Based).
5. Preference Management and Consent
5.1 Essential Security Cookies: Placed automatically upon initiating a session or authentication handoff as permitted by applicable law.
5.2 Non-Essential Cookies: Analytics and non-essential cookies require opt-in consent and can be adjusted or revoked at any time via on-site preference banners or browser settings.
6. Regulatory Compliance and Inquiries
6.1 Compliance: Synapser deploys cookie technologies in compliance with POPIA, the EU/UK ePrivacy Directive, and the GDPR.
6.2 Contact: Direct inquiries to the Information Officer at info@synapser.com.