Legal
Privacy Policy
Last updated: March 3, 2026
1. Introduction
iENTR ("we" "our" or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect use disclose and safeguard your information when you use our facial recognition access control application and related services (the "Service"). We take the handling of biometric data with the utmost seriousness. iENTR is subject to the New Zealand Privacy Act 2020 and the Biometric Processing Privacy Code 2025 and processes personal information in accordance with them.
2. Biometric Data Collection
Our Service collects and processes biometric data specifically facial recognition data ("Biometric Data"). This includes:
- Facial geometry data: Mathematical representations (encodings) derived from photographs of your face used to identify you at access points.
- Enrollment photographs: Captured and retained only when your site enables ID cards as an entry and exit verification mode, for printing on the card. With ID cards disabled, no photograph is taken or kept.
Purpose: Biometric Data is collected solely for the purpose of identity verification and access control at enrolled sites. We do not use Biometric Data for advertising profiling or any purpose unrelated to access control.
Consent: We obtain explicit informed consent before collecting any Biometric Data. You may withdraw consent at any time by requesting deletion of your data.
3. Other Information We Collect
- Account information: Name email address phone number and company name provided during registration.
- Billing information: Payment details processed securely through Stripe. We do not store credit card numbers on our servers.
- Usage data: Sign-in/sign-out timestamps site access logs and device information for security and audit purposes.
- Technical data: IP addresses browser type and device identifiers collected automatically.
4. GDPR Compliance (European Users)
For users in the European Economic Area (EEA), we process personal data under the following legal bases:
- Explicit consent (Article 9(2)(a)) for Biometric Data processing.
- Contractual necessity (Article 6(1)(b)) for account and service management.
- Legitimate interests (Article 6(1)(f)) for security and fraud prevention.
You have the right to: access your data rectify inaccuracies erase your data restrict processing data portability and object to processing. To exercise these rights contact us at opensesame@ientr.com.
5. BIPA Compliance (Illinois, USA)
In compliance with the Illinois Biometric Information Privacy Act (BIPA):
- We provide written notice and obtain written consent before collecting Biometric Data.
- We publish this retention schedule and destruction guidelines.
- We do not sell lease trade or otherwise profit from Biometric Data.
- Biometric Data is stored with protections equal to or exceeding those used for other confidential information.
- Biometric Data is permanently destroyed when the initial purpose has been satisfied or within 3 years of the individual's last interaction whichever comes first.
6. CCPA Compliance (California, USA)
California residents have the right to: know what personal information is collected request deletion opt out of the sale of personal information (we do not sell personal information) and non-discrimination for exercising CCPA rights. To submit a request contact us at opensesame@ientr.com.
7. Data Retention & Deletion
- Biometric Data: Retained only as long as needed for access control purposes. Automatically deleted when a user is removed from a site or upon request.
- Visitor data: Retained according to per-site retention policies (default 24 hours configurable by site administrators).
- Account data: Retained while your account is active. Deleted within 30 days of account closure.
- Audit logs: Retained for up to 2 years for security and compliance purposes.
You may request complete deletion of all your data at any time through the app's Data Deletion Request feature or by contacting us directly.
8. Third-Party Sharing
We do not sell or share Biometric Data with any third party. Limited data sharing occurs with:
- Stripe: Payment processing (billing information only no biometric data).
- Cloud infrastructure providers: Data hosting with encryption at rest and in transit.
- Law enforcement: Only when required by valid legal process.
9. Data Security
We implement industry-standard security measures including: encryption at rest and in transit (TLS 1.3) row-level security policies on all database tables secure authentication with optional multi-factor authentication regular security audits and access controls limiting employee access to personal data.
10. Contact Us
For privacy inquiries data requests or concerns:
Email: opensesame@ientr.com
Data Protection Officer: opensesame@ientr.com