SnapStak (Pty) Ltd ("SnapStak", "we", "us", or "our") is a South African company that licenses proprietary AI governance and verification technology, including the CON10X platform, the ConteX Law framework, the CLARA governance layer, and the AXIOM certified truth layer. We license this technology to customers on a per-seat subscription basis. We do not host customer workloads and we do not operate the third-party AI services that our software connects to.
This Privacy Policy explains what personal information we collect when you visit our website, purchase and activate a licence, or contact us, how we use that information, and the rights you have over it. It is written for an organisation that holds very little personal data by design. We process personal information in line with South Africa's Protection of Personal Information Act, 2013 (POPIA), and, where it applies to you, the EU and UK General Data Protection Regulation (GDPR).
If you do not agree with this Policy, please stop using our website and our licensed software.
1. What this Policy covers
This Policy covers three things only:
- your use of the SnapStak website at snapstak.ai and related subdomains;
- the purchase, activation, and renewal of a SnapStak software licence; and
- any direct contact you have with us, for example a sales enquiry, a support request, or a research or press enquiry.
It does not cover the content you create inside our licensed software, the AI providers you choose to use with it, or any third-party website we link to. Those are addressed in Section 5.
2. Information we collect
Information you give us directly
When you complete a form on our website, buy a licence, or email us, you may provide your name, your business email address, your company name, the nature of your enquiry, and the message you choose to send. If you purchase a subscription, our payment processor collects the payment details needed to complete the transaction. We do not see or store your full card number.
Licence activation data
When you activate a licensed copy of our software, the CLARA activation system contacts our server at contexlaw.snapstak.ai to validate the licence. This exchange involves an activation token, a domain or device fingerprint generated for licence integrity, and the time of activation. We use this data only to confirm that a valid licence is in use and to prevent unauthorised copying. It is not used to profile you or to track what you do inside the software.
Information collected automatically on the website
When you visit the website we collect standard technical data such as your IP address, browser type, operating system, the pages you view, and the time of your visit. This is used for security, to keep the site working, and to understand traffic at an aggregate level.
3. How we use your information
We use the limited personal information we hold to:
- respond to your enquiries and provide customer and technical support;
- issue, activate, validate, and renew your software licence;
- process the payments you authorise;
- protect our software and our customers against unauthorised use, fraud, and security incidents;
- send you service messages about your licence, such as renewal or activation notices; and
- meet our legal, accounting, and record-keeping obligations.
We do not sell your personal information. We do not use it for automated decision-making that produces a legal or similarly significant effect on you. We do not send marketing email unless you have asked to receive it, and you can opt out at any time.
4. Legal basis for processing
Where POPIA applies, we process personal information on the basis that it is necessary to conclude or perform a contract with you, to comply with a legal obligation, or because we have a legitimate interest in operating and protecting our business that is not overridden by your rights. Where the GDPR applies to you, the equivalent bases are contract, legal obligation, legitimate interests, and, for optional activities such as marketing, your consent.
5. What happens inside the software, and the AI providers you use
This is the most important section for understanding how little of your data reaches us. Our software is a per-seat licensed application that runs on your own computer. When you use it to work with an AI provider such as Anthropic Claude, OpenAI ChatGPT, xAI Grok, DeepSeek, Kimi, or Qwen, it operates inside your own authenticated session with that provider, with a human in the loop. You sign in to the provider with your own account.
Because of this design, we do not receive, store, or process the prompts you write, the responses the AI returns, or the documents you author. Where the software keeps a local working history, that data is stored in databases on your own device and stays there. We never receive a copy.
Your relationship with each AI provider is governed by that provider's own terms and privacy policy. We are not a party to it and we are not responsible for how those providers handle the data you send them. You should read their policies before using their services through our software.
7. International transfers
We are based in South Africa. Some of our service providers may process data in other countries. Where personal information is transferred outside South Africa or the European Economic Area, we rely on the recipient being subject to a law or agreement that upholds principles of protection substantially similar to POPIA or the GDPR, or on appropriate contractual safeguards.
8. How long we keep it
We keep personal information only for as long as we need it for the purpose we collected it, and then for any further period required by law. Enquiry and support correspondence is kept while it remains useful and then deleted. Licence, billing, and tax records are kept for the period required by South African law.
9. Your rights
Subject to the applicable law, you have the right to:
- ask what personal information we hold about you and request a copy;
- ask us to correct information that is inaccurate or incomplete;
- ask us to delete information we no longer have a lawful reason to keep;
- object to or restrict certain processing; and
- withdraw any consent you have given, without affecting processing already carried out.
To exercise any of these rights, email us at the address in Section 13. If you are in South Africa and you believe we have not handled your information properly, you may complain to the Information Regulator (South Africa). If the GDPR applies to you, you may complain to your local supervisory authority.
10. Security
We apply reasonable technical and organisational measures to protect the personal information we hold, including access control, encryption in transit, and keeping the amount of data we hold to a minimum. No system is perfectly secure, but holding very little data is itself a deliberate safeguard.
11. Children
Our website and software are intended for business use by adults. They are not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the date at the top of the page. If the change is significant, we will take reasonable steps to bring it to your attention. Your continued use of our website and software after an update means you accept the revised Policy.
13. Contact us
If you have a question about this Policy or wish to exercise a right, please contact us:
- SnapStak (Pty) Ltd
- Email: info@snapstak.ai