1. Who this policy applies to
Entryo provides visitor-management technology to organizations, buildings, companies, hosts, reception teams and security teams. The organization operating Entryo for a location generally decides why visitor information is collected and who may access it. Entryo operates the platform and processes information to provide and secure the service.
For a request about a specific visit, contact the relevant building or inviting organization first. You may also use our Contact & Support page.
2. Information processed by Entryo
- Visitor and invitation information: name, mobile number, optional email, walk-in origin (company, organisation or city), destination company, host, purpose, invitation validity, pass status, check-in and checkout time.
- Gate information: the building, gate and barcode permanently associated with the scanned QR.
- Staff account information: name, email, role, active status, company/building/gate assignments and preferred language.
- Technical and security information: IP address, browser or device information, session/token details, an anonymous visitor-device cookie, scan outcomes, failure reasons, login and administrative audit activity.
- Organization information: customer, subscription, building, gate, barcode and company records required to operate the service.
3. Why the information is used
We process information to register and identify visitors, validate gate-mapped QR codes, verify time-bound invitations, maintain an entry and checkout record, provide role-scoped dashboards and reports, prevent misuse, investigate failures, secure accounts, maintain audit history and meet lawful operational obligations.
Entryo does not request device GPS for QR check-in or checkout. The scanned QR is validated against its permanently assigned customer, building and gate.
For walk-in visits, an anonymous HTTP-only browser cookie lets a repeat scan of the same gate QR close the active visit without asking for the registration form again. Only a one-way hash is stored with the active visit, it is not used for advertising, and the visit association is removed at checkout. A short-lived cache marker prevents accidental immediate rescans from reopening registration. IP addresses are not used to identify a returning visitor.
4. How information is obtained
Information may be provided directly by a visitor, entered by an authorized host or administrator, or generated during a gate scan or authorized account action.
5. Who may receive information
Information is available only within the authorized scope of the relevant customer, building, company, host, guard or administrator. It may also be processed by infrastructure and service providers needed to host, secure, back up or operate Entryo, and disclosed where required by law or necessary to protect people, rights or systems.
Entryo does not use visitor information for third-party advertising or sell it as a data product.
6. Retention and deletion
Visitor, scan and audit records are historical security records. The current platform preserves them until an authorized retention or deletion process is applied. Each production deployment must define a documented retention schedule based on the operating organization’s purpose, instructions and applicable legal obligations.
Requests for access, correction or deletion will be evaluated against security, audit, contractual and legal requirements. Some information may need to be retained where deletion is not permitted or would compromise a required security record.
7. Security
Entryo uses role-based authorization, server-side scope enforcement, secure sessions, expiring API tokens, opaque QR/pass tokens, password hashing, request validation, rate limits, audit logs, restrictive security headers and database constraints. No system can guarantee absolute security, so pass URLs, passwords and account credentials must not be shared.
8. Your choices and requests
Depending on the applicable relationship and law, individuals may request information about processing, access or correction, erasure where permitted, withdrawal of consent where consent is the basis, or grievance handling. Contact the relevant organization or use Entryo support and identify the relevant building without sending unnecessary personal data.
9. Children
Entryo is intended for managed workplace visitor access and is not designed for children to use independently. Organizations using Entryo are responsible for applying any consent or authorization required when processing a child’s information.
10. Hosting and international processing
The hosting location and service providers may vary by deployment. The organization deploying Entryo must document its production hosting, transfer arrangements and service providers before collecting live visitor data.
11. Changes and contact
We may update this policy when the product, deployment or legal requirements change. The effective date above will be revised when material updates are published.
Privacy and support requests: +91 77392 86549.