This Data Processing Addendum (“Addendum”) forms part of the agreement between the customer (“Controller” or “Data Fiduciary”) and Entrifie (“Processor”) for the provision of the Entrifie platform (the “Service”). It governs the processing of personal data Entrifie carries out on the customer’s behalf.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in applicable data protection law, including the EU/UK GDPR, India’s Digital Personal Data Protection Act, 2023 (“DPDP”), and the California Consumer Privacy Act (“CCPA”). “Data Fiduciary” and “Data Processor” carry their DPDP meanings.
2. Scope and roles of the parties
For visitor data the customer collects through the Service, the customer is the Controller / Data Fiduciary and Entrifie is the Processor / Data Processor, acting only on the customer’s documented instructions. For data Entrifie collects about the customer’s own account and website use, Entrifie is the Controller, governed by its Privacy Policy.
3. Details of processing
- Subject matter: provision of the visitor-management Service.
- Duration: the term of the agreement, plus the retention period the customer configures.
- Nature and purpose: registering visitors, issuing passes, notifying hosts, and maintaining an access audit log.
- Categories of data subject: the customer’s visitors, hosts, and authorised personnel.
- Categories of personal data: names, contact details, company, host, visit purpose, timestamps, vehicle number (where enabled), and visitor photos (where enabled and consented).
4. Processor obligations and controller instructions
Entrifie will process personal data only on the customer’s documented instructions (including as set out in the agreement and this Addendum), unless required otherwise by law, in which case Entrifie will inform the customer first where legally permitted. Entrifie will promptly notify the customer if, in its opinion, an instruction infringes applicable data protection law.
5. Confidentiality
Entrifie ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis.
6. Security measures
Entrifie maintains technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS) and at rest (AES-256).
- Data residency in India (asia-south1, Mumbai) for the primary datastore.
- Role-based access control and tenant isolation enforced at the database-rule layer.
- Authentication via managed identity providers; no plaintext passwords.
- Automated, retention-bound deletion of visitor records and photos.
- Audit logging of administrative and data-subject-request actions.
7. Sub-processors
The customer authorises Entrifie to engage the sub-processors below. Entrifie imposes data protection obligations on each that are no less protective than this Addendum, and remains responsible for their performance. Entrifie will give notice of any intended addition or replacement, allowing the customer a reasonable period to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase (Firestore, Auth) | Primary database and authentication | India (asia-south1, Mumbai) |
| Google Cloud Run | Website and application hosting | India (asia-south1, Mumbai) |
| Google Firebase Storage | Uploaded photos and documents | Google Asia multi-region (not India-only) |
| Google Cloud Logging | Administrative activity and system event records | Global (400-day retention, locked by the platform) |
| Resend | Transactional email delivery (OTP, notifications, DSR correspondence) | United States |
| Sentry | Backend error diagnostics from Cloud Functions only: stack traces, the callable name and a 1% trace sample. Visitor email, phone and IP are removed before sending, and the browser sends nothing | United States |
The current list is also maintained at entrifie.com/legal/sub-processors.
8. Data subject rights cooperation
Taking into account the nature of the processing, Entrifie assists the customer with appropriate technical and organisational measures to respond to data-subject requests (access, correction, erasure, and consent withdrawal), including through the in-product Data Requests tools. If Entrifie receives a request directly from a data subject, it will refer them to the relevant customer or to entrifie.com/privacy/dsr where appropriate.
9. Personal data breach notification
Entrifie will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer’s data, and will provide information reasonably required for the customer to meet its own notification obligations (e.g. to the Data Protection Board of India or a supervisory authority).
10. Data protection impact assessments
Entrifie provides reasonable assistance to the customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Entrifie.
11. International data transfers
The primary datastore is located in India. Where a sub-processor processes personal data outside the customer’s jurisdiction, such transfers are made under an appropriate transfer mechanism (for example, Standard Contractual Clauses or an adequacy decision) as required by applicable law.
12. Audit rights
Entrifie makes available information reasonably necessary to demonstrate compliance with this Addendum and allows for and contributes to audits, including inspections, conducted by the customer or an auditor it mandates, on reasonable prior notice, subject to confidentiality and without compromising other customers’ data.
13. Return and deletion of data
On termination of the Service, and at the customer’s choice, Entrifie deletes or returns the personal data it processes on the customer’s behalf and deletes existing copies, unless retention is required by law. Routine retention-bound deletion continues to apply throughout the term.
14. Liability
Each party’s liability under this Addendum is subject to the limitations and exclusions of liability set out in the agreement.
15. Term and termination
This Addendum takes effect on the customer’s acceptance and remains in force for as long as Entrifie processes personal data on the customer’s behalf under the agreement.
16. Governing law
This Addendum is governed by the law specified in the agreement and, in the absence of such a choice, by the laws of India.