Legal · Data Processing Addendum

Data Processing Addendum

The terms on which Entrifie processes personal data on behalf of our customers, as a Data Processor under India’s DPDP Act 2023.

Version 1.0Applies from: 27 August 2026

These are the terms that will apply, not an agreement already in place

This Addendum is the standard text that becomes part of your agreement with Entrifie when you subscribe and accept it. Publishing it here does not create an agreement with anyone, and nothing on this page has been signed. Version 1.0, applying from 27 August 2026.

This Data Processing Addendum (“Addendum”) forms part of the agreement between the customer (“Controller” or “Data Fiduciary”) and Entrifie (“Processor”) for the provision of the Entrifie platform (the “Service”). It governs the processing of personal data Entrifie carries out on the customer’s behalf.

1. Definitions

Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in applicable data protection law, including the EU/UK GDPR, India’s Digital Personal Data Protection Act, 2023 (“DPDP”), and the California Consumer Privacy Act (“CCPA”). “Data Fiduciary” and “Data Processor” carry their DPDP meanings.

2. Scope and roles of the parties

For visitor data the customer collects through the Service, the customer is the Controller / Data Fiduciary and Entrifie is the Processor / Data Processor, acting only on the customer’s documented instructions. For data Entrifie collects about the customer’s own account and website use, Entrifie is the Controller, governed by its Privacy Policy.

3. Details of processing

  • Subject matter: provision of the visitor-management Service.
  • Duration: the term of the agreement, plus the retention period the customer configures.
  • Nature and purpose: registering visitors, issuing passes, notifying hosts, and maintaining an access audit log.
  • Categories of data subject: the customer’s visitors, hosts, and authorised personnel.
  • Categories of personal data: names, contact details, company, host, visit purpose, timestamps, vehicle number (where enabled), and visitor photos (where enabled and consented).

4. Processor obligations and controller instructions

Entrifie will process personal data only on the customer’s documented instructions (including as set out in the agreement and this Addendum), unless required otherwise by law, in which case Entrifie will inform the customer first where legally permitted. Entrifie will promptly notify the customer if, in its opinion, an instruction infringes applicable data protection law.

5. Confidentiality

Entrifie ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis.

6. Security measures

Entrifie maintains technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS) and at rest (AES-256).
  • Data residency in India (asia-south1, Mumbai) for the primary datastore.
  • Role-based access control and tenant isolation enforced at the database-rule layer.
  • Authentication via managed identity providers; no plaintext passwords.
  • Automated, retention-bound deletion of visitor records and photos.
  • Audit logging of administrative and data-subject-request actions.

7. Sub-processors

The customer authorises Entrifie to engage the sub-processors below. Entrifie imposes data protection obligations on each that are no less protective than this Addendum, and remains responsible for their performance. Entrifie will give notice of any intended addition or replacement, allowing the customer a reasonable period to object.

Sub-processorPurposeLocation
Google Cloud / Firebase (Firestore, Auth)Primary database and authenticationIndia (asia-south1, Mumbai)
Google Cloud RunWebsite and application hostingIndia (asia-south1, Mumbai)
Google Firebase StorageUploaded photos and documentsGoogle Asia multi-region (not India-only)
Google Cloud LoggingAdministrative activity and system event recordsGlobal (400-day retention, locked by the platform)
ResendTransactional email delivery (OTP, notifications, DSR correspondence)United States
SentryBackend error diagnostics from Cloud Functions only: stack traces, the callable name and a 1% trace sample. Visitor email, phone and IP are removed before sending, and the browser sends nothingUnited States

The current list is also maintained at entrifie.com/legal/sub-processors.

8. Data subject rights cooperation

Taking into account the nature of the processing, Entrifie assists the customer with appropriate technical and organisational measures to respond to data-subject requests (access, correction, erasure, and consent withdrawal), including through the in-product Data Requests tools. If Entrifie receives a request directly from a data subject, it will refer them to the relevant customer or to entrifie.com/privacy/dsr where appropriate.

9. Personal data breach notification

Entrifie will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer’s data, and will provide information reasonably required for the customer to meet its own notification obligations (e.g. to the Data Protection Board of India or a supervisory authority).

10. Data protection impact assessments

Entrifie provides reasonable assistance to the customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Entrifie.

11. International data transfers

The primary datastore is located in India. Where a sub-processor processes personal data outside the customer’s jurisdiction, such transfers are made under an appropriate transfer mechanism (for example, Standard Contractual Clauses or an adequacy decision) as required by applicable law.

12. Audit rights

Entrifie makes available information reasonably necessary to demonstrate compliance with this Addendum and allows for and contributes to audits, including inspections, conducted by the customer or an auditor it mandates, on reasonable prior notice, subject to confidentiality and without compromising other customers’ data.

13. Return and deletion of data

On termination of the Service, and at the customer’s choice, Entrifie deletes or returns the personal data it processes on the customer’s behalf and deletes existing copies, unless retention is required by law. Routine retention-bound deletion continues to apply throughout the term.

14. Liability

Each party’s liability under this Addendum is subject to the limitations and exclusions of liability set out in the agreement.

15. Term and termination

This Addendum takes effect on the customer’s acceptance and remains in force for as long as Entrifie processes personal data on the customer’s behalf under the agreement.

16. Governing law

This Addendum is governed by the law specified in the agreement and, in the absence of such a choice, by the laws of India.

Version 1.0 · Related: DPIA · SCCs · Sub-processors. Questions about this addendum? Write to support@entrifie.com.