Privacy Policy
Entrada Privacy Policy
Visitor Management, Streamlined. Clear records, controlled access, and practical data protection.
Last updated: 25 July 2026
This Policy is a notice describing our data practices. It does not create contractual obligations beyond those required by applicable law or set out in our Terms of Use.
1. Who We Are
Entrada is a visitor management, reception, alerting, and reporting system provided by Henrix Automations Ltd ("we," "us"), a company registered in Kenya.
Entrada replaces paper visitor books with controlled digital visitor records, host notifications, timestamped check-ins and checkouts, dashboard visibility, CSV exports, billing records, and analysed PDF reports.
Our role under the Data Protection Act, 2019:
If you are a visitor whose details were captured through Entrada, your primary point of contact for data rights requests is the organization that hosted your visit (the client using Entrada), not Henrix Automations Ltd directly, though we will assist and route requests appropriately.
2. Data We Process
We process only the information reasonably needed to operate visitor management, reception workflows, account administration, reporting, billing, security, and support:
Entrada requires a valid ID or passport number to log a visit. Since minors in Kenya do not typically hold a national ID or passport, this has the practical effect of excluding minors from being logged as visitors in the ordinary check-in flow. We do not knowingly collect personal data from children through Entrada.
3. Lawful Basis for Processing
We (and our client organizations, as controllers) rely on the following lawful bases under Section 30 of the Data Protection Act:
Visitors are informed of this processing through signage, verbal notice, or check-in screens provided by the client organization at the point of data capture. Client organizations are responsible for giving this notice.
4. Why We Use The Data
We use data to register visitors, notify hosts, support reception workflows, show management reports, generate exports, deliver invoices and receipts, secure accounts, prevent misuse, and maintain service reliability.
We do not sell visitor records, use visitor records for advertising, or send visitor personal data to third-party analytics or advertising services.
5. Data Ownership And Control
Visitor records entered into Entrada belong to the client organization using the system. The client controls who may access records, how long records are retained, and when records are exported or deleted.
For self-hosted deployments, the client controls the server environment, database, backups, staff access, storage encryption, and infrastructure security settings, and bears responsibility for its own compliance in that configuration.
6. Your Rights
Under the Data Protection Act, 2019, data subjects have the following rights: to be informed of processing, to access their data, to rectification of inaccurate data, to erasure, to restrict processing, to object to processing, to data portability where technically feasible, and to withdraw consent at any time.
Who to contact depends on whose data is involved:
If you have a concern about how your data has been handled, contact us at info@henrixautomations.com so we can look into it directly.
7. Data Processors and Third Parties
We use the following categories of third-party service providers to operate Entrada, each bound by confidentiality and, where applicable, data processing terms:
These providers are engaged to process data only as instructed and only to the extent needed to deliver their service to us; they are not authorized to use visitor personal data for their own independent purposes.
8. Cross-Border Data Transfers
Where any data processing occurs outside Kenya (for example, through a hosting or messaging provider with servers abroad), our practice is to rely on the safeguards recognized under Section 48 of the Data Protection Act, such as an applicable adequacy finding, appropriate contractual safeguards with the provider, or the data subject's consent, appropriate to that specific transfer. Client organizations using self-hosted deployments control their own hosting location and are responsible for their own transfer compliance.
9. Security Measures
Entrada separates management and reception access, uses authenticated sessions, supports OTP verification, applies rate limiting, stores passwords with one-way hashing, and keeps provider credentials in server-side environment configuration rather than frontend code.
Entrada uses HTTPS for data in transit, protected database storage, encrypted storage volumes, and encrypted backups where supported by the hosting environment. Backups may be stored with trusted third-party object storage providers; where this is the case, backups are encrypted before storage.
Entrada uses database-level tenant isolation, including PostgreSQL Row-Level Security where applicable, so each organization's visitor records, accounts, destinations, billing records, and settings are separated at the database layer as well as in the application.
Analysed reports are generated using an AI model that runs locally on our own infrastructure. Visitor and organization data used to generate reports is not sent to third-party AI providers.
For self-hosted deployments, the client is responsible for enabling and maintaining encryption at rest on the database, disk, backup, or hosting environment under its control.
10. Data Breach Notification
If a personal data breach occurs that is likely to result in risk to data subjects, we will notify affected client organizations without undue delay so they can take appropriate steps. Where Henrix Automations Ltd is itself the controller of account or billing data, we will notify affected individuals directly where required.
11. Analytics
We may use product analytics to understand feature usage, organization type, sessions, growth, plan activity, and system health.
Analytics events do not include visitor names, ID numbers, phone numbers, or other visitor personal identifiers.
12. Notifications And Reports
Entrada may send SMS or email alerts when visitors check in or check out. Delivery depends on external network and email providers, so Entrada records whether alerts were sent, failed, skipped, or pending where available.
Scheduled analysed PDF reports and manual CSV exports are sent only to authorized recipients selected by the client organization.
13. Retention And Deletion
Client organizations may configure retention periods for visitor records. Where no retention period is configured, visitor records are retained for a default period of 1 year, after which eligible records are automatically and permanently deleted, unless a longer period is required by law.
When an authorized admin deletes an organization account, we permanently delete the organization workspace, reception accounts, management accounts, visitor history, expected visitors, destination records, billing records, settings, and related operational data. This action is not recoverable after the undo window ends.
14. Support Access
Henrix Automations Ltd may access a deployment only when required for setup, maintenance, troubleshooting, migration, backup verification, or support, and only to the extent reasonably needed for that work.
Where support access is granted, it is limited to the relevant task and governed by confidentiality obligations under our Terms of Use.
15. Changes To This Policy
We may update this policy from time to time. Material changes will be communicated to client organizations by email, and the "last updated" date at the top of this page will be revised. Continued use of Entrada after changes take effect constitutes acceptance of the revised policy.
16. Contact
For any enquiry, support, billing, general questions, or complaints, contact Henrix Automations Ltd at info@henrixautomations.com.