Trust
What iENTR does with a face, in plain words.
Facial recognition has earned its scrutiny. In New Zealand a supermarket trial put it on the front page. In the UK a leisure operator was ordered to switch it off and delete the data. In Australia a hardware chain spent two years in a regulatory process. If you are being careful about this, you are right to be and this page is written for you rather than around you.
The architecture
On the iPad
Templates sync encrypted only between the terminals you have paired at your own sites, so every door recognises the same people.
When a person enrols, the iPad captures several images and converts them into a mathematical template. The template is created on the device and matched on the device. So that every door at your sites recognises the same people, templates sync encrypted through iENTR's Australian-region infrastructure to the terminals you have paired and to nowhere else. When someone steps up to the door, the comparison happens locally. The door releases locally. Alongside it, the entry record is written: who, which door, which direction, what time.
iENTR does not need a photograph to recognise anyone. Recognition runs on the template and the template stays on the device. The one case where a photograph exists is optional ID cards: if your site enables ID cards as an entry and exit verification mode, iENTR captures an enrolment photograph and holds it to print on the card. Turn ID cards off and no photograph is taken or retained.
What iENTR will never do
Identify strangers, or scan anyone who is not enrolled, against any list
Infer emotion, mood, attention, health, age, gender or ethnicity
Use your enrolments to train any model
Share biometric data between customers or between your own sites without your instruction
Require any individual to enrol a face
One distinction matters here. Through Restricted access, an administrator can mark a person who is enrolled at their site as Blocked, so they are refused, or Flagged, so they are admitted with staff alerted. That is an access decision about a known identity, the same decision a cancelled keycard makes. It is not surveillance: iENTR never scans strangers, passers-by or crowds against any list.
What you control
Retention, per site.
You set how long records are kept and the schedule runs without anyone remembering to run it.
Visitor expiry.
Visitor records purge automatically on the timetable you choose.
Deletion on request.
Biometric data is deleted automatically when a person is removed from a site or on request, exactly as the privacy policy commits, verifiable in the audit log.
Who can see records.
Role-based access, per site, logged.
Enrolment photographs.
Only taken if you enable ID cards, only used to print the card and never taken at all if you do not.
What iENTR is responsible for and what you are
iENTR provides the technical safeguards: on-device matching, verification-only architecture, configurable retention, access controls, audit logging and consent capture. The legal obligation to justify, notify and document the use of biometrics sits with your organisation, because that is how every one of these laws is written. iENTR ships a proportionality assessment template and a notification template so that obligation is a form to complete rather than a project to start.
Proportionality assessment template
The documented case the NZ Biometric Processing Privacy Code requires before biometric processing begins. Editable, with guidance notes.
Coming soonNotification template
The wording to tell your people what is collected, why, for how long and what their alternatives are.
Coming soonWhere you stand, by jurisdiction
New Zealand
The Privacy Act 2020 applies and since 3 November 2025 the Biometric Processing Privacy Code 2025 governs biometric processing specifically. It requires a documented proportionality assessment, notification with due particularity including whether alternatives are available and it restricts using biometrics to infer health, emotion or protected characteristics. Organisations already using biometrics had until 3 August 2026 to comply and that transition period has ended.
Australia
Biometric information used for automated verification or identification is sensitive information under the Privacy Act 1988, which generally requires consent to collect. The regulator's guidance calls for a precautionary approach, clear notice and a documented privacy impact assessment. The Bunnings facial recognition case turned substantially on notice, privacy policy documentation and the absence of a documented assessment.
United Kingdom
UK GDPR treats biometric data used to uniquely identify a person as special category data. In employment, the ICO has held that genuinely free consent requires a real alternative with no detriment: it ordered one operator to stop using biometric attendance across 38 sites where enrolment was effectively a condition of being paid. For schools, the Protection of Freedoms Act 2012 additionally requires written parental consent, gives the child a veto and requires an alternative.
European Union
GDPR Article 9 applies as in the UK. Under the EU AI Act, remote biometric identification is classified high risk, but verification-only systems, whose sole purpose is confirming a person is who they claim to be, are expressly excluded from that classification. iENTR is a verification-only system. Emotion inference in workplaces and education is prohibited outright; iENTR does not perform it anywhere.
United States
There is no federal biometric privacy law. Illinois BIPA requires informed written consent and a published retention and destruction policy and carries a private right of action. Texas, Washington and Colorado have their own regimes and most state comprehensive privacy laws treat biometric data as sensitive. iENTR's consent capture, retention controls and deletion support the requirements common to these laws; obligations rest with the deploying organisation.
None of the above is legal advice. It is the map iENTR is built against and your own advisers should confirm your position on it.
How iENTR governs itself
iENTR maintains an internal audit procedure covering data privacy and protection compliance: an independent audit function, an annual risk-based audit plan, review of access controls and monitoring, a maintained record of which staff have accessed personal data and defined incident response. It is published in full, because a vendor asking for trust should show its homework.
Read the internal audit policyTry it on one door.
Seven days free, cancel any time. Bring this page to your privacy officer first if you like. It was written to be read by them.