Privacy Policy

Entrada Privacy Policy

Visitor Management, Streamlined. Clear records, controlled access, and practical data protection.

Last updated: 25 July 2026

This Policy is a notice describing our data practices. It does not create contractual obligations beyond those required by applicable law or set out in our Terms of Use.

1. Who We Are

Entrada is a visitor management, reception, alerting, and reporting system provided by Henrix Automations Ltd ("we," "us"), a company registered in Kenya.

Entrada replaces paper visitor books with controlled digital visitor records, host notifications, timestamped check-ins and checkouts, dashboard visibility, CSV exports, billing records, and analysed PDF reports.

Our role under the Data Protection Act, 2019:

  • For visitor records (names, ID/passport numbers, phone numbers, visit details), the client organization using Entrada is the data controller. Henrix Automations Ltd acts as the data processor, operating the system on the controller's instructions in accordance with our Terms of Use.
  • For management/reception account data and billing data, Henrix Automations Ltd is the data controller.
  • If you are a visitor whose details were captured through Entrada, your primary point of contact for data rights requests is the organization that hosted your visit (the client using Entrada), not Henrix Automations Ltd directly, though we will assist and route requests appropriately.

    2. Data We Process

    We process only the information reasonably needed to operate visitor management, reception workflows, account administration, reporting, billing, security, and support:

  • Visitor data: name, phone number, ID or passport number, visit purpose, destination, check-in time, checkout time, and notification delivery status.
  • Destination/host data: destination, unit, department, office, venue, resident, staff, or host contact information configured by the organization.
  • Account data: name, email, phone number, role, login activity, and assigned permissions for management and reception users.
  • Billing data: invoice, receipt, subscription, and payment reference information for paid plans.
  • Security/operational logs: OTP attempts, session activity, rate-limit events, and audit timestamps.
  • Entrada requires a valid ID or passport number to log a visit. Since minors in Kenya do not typically hold a national ID or passport, this has the practical effect of excluding minors from being logged as visitors in the ordinary check-in flow. We do not knowingly collect personal data from children through Entrada.

    3. Lawful Basis for Processing

    We (and our client organizations, as controllers) rely on the following lawful bases under Section 30 of the Data Protection Act:

  • Legitimate interests of the client organization in maintaining accurate, secure records of who enters its premises, for safety, security, and access-control purposes.
  • Contractual necessity for account, billing, and subscription data tied to a client's use of Entrada.
  • Legal obligation, where a client organization is required by law or regulation to keep visitor or security records.
  • Consent, where a client organization chooses to collect it as an additional basis (e.g. for optional marketing communications, which Entrada does not itself send to visitors).
  • Visitors are informed of this processing through signage, verbal notice, or check-in screens provided by the client organization at the point of data capture. Client organizations are responsible for giving this notice.

    4. Why We Use The Data

    We use data to register visitors, notify hosts, support reception workflows, show management reports, generate exports, deliver invoices and receipts, secure accounts, prevent misuse, and maintain service reliability.

    We do not sell visitor records, use visitor records for advertising, or send visitor personal data to third-party analytics or advertising services.

    5. Data Ownership And Control

    Visitor records entered into Entrada belong to the client organization using the system. The client controls who may access records, how long records are retained, and when records are exported or deleted.

    For self-hosted deployments, the client controls the server environment, database, backups, staff access, storage encryption, and infrastructure security settings, and bears responsibility for its own compliance in that configuration.

    6. Your Rights

    Under the Data Protection Act, 2019, data subjects have the following rights: to be informed of processing, to access their data, to rectification of inaccurate data, to erasure, to restrict processing, to object to processing, to data portability where technically feasible, and to withdraw consent at any time.

    Who to contact depends on whose data is involved:

  • Visitor data belongs to, and is controlled by, the organization you visited, Henrix Automations Ltd processes it only on that organization's instructions and has no independent authority to access, edit, delete, or export it. Direct any request about your visitor record to the organization you visited; they are responsible for fulfilling it.
  • Account, billing, or other Henrix Automations Ltd-controlled data, contact us directly at info@henrixautomations.com and we will respond as promptly as possible.
  • If you have a concern about how your data has been handled, contact us at info@henrixautomations.com so we can look into it directly.

    7. Data Processors and Third Parties

    We use the following categories of third-party service providers to operate Entrada, each bound by confidentiality and, where applicable, data processing terms:

  • Hosting and infrastructure providers (server hosting, backups, storage).
  • SMS and email delivery providers, for host notifications and reports.
  • Payment and billing infrastructure providers.
  • These providers are engaged to process data only as instructed and only to the extent needed to deliver their service to us; they are not authorized to use visitor personal data for their own independent purposes.

    8. Cross-Border Data Transfers

    Where any data processing occurs outside Kenya (for example, through a hosting or messaging provider with servers abroad), our practice is to rely on the safeguards recognized under Section 48 of the Data Protection Act, such as an applicable adequacy finding, appropriate contractual safeguards with the provider, or the data subject's consent, appropriate to that specific transfer. Client organizations using self-hosted deployments control their own hosting location and are responsible for their own transfer compliance.

    9. Security Measures

    Entrada separates management and reception access, uses authenticated sessions, supports OTP verification, applies rate limiting, stores passwords with one-way hashing, and keeps provider credentials in server-side environment configuration rather than frontend code.

    Entrada uses HTTPS for data in transit, protected database storage, encrypted storage volumes, and encrypted backups where supported by the hosting environment. Backups may be stored with trusted third-party object storage providers; where this is the case, backups are encrypted before storage.

    Entrada uses database-level tenant isolation, including PostgreSQL Row-Level Security where applicable, so each organization's visitor records, accounts, destinations, billing records, and settings are separated at the database layer as well as in the application.

    Analysed reports are generated using an AI model that runs locally on our own infrastructure. Visitor and organization data used to generate reports is not sent to third-party AI providers.

    For self-hosted deployments, the client is responsible for enabling and maintaining encryption at rest on the database, disk, backup, or hosting environment under its control.

    10. Data Breach Notification

    If a personal data breach occurs that is likely to result in risk to data subjects, we will notify affected client organizations without undue delay so they can take appropriate steps. Where Henrix Automations Ltd is itself the controller of account or billing data, we will notify affected individuals directly where required.

    11. Analytics

    We may use product analytics to understand feature usage, organization type, sessions, growth, plan activity, and system health.

    Analytics events do not include visitor names, ID numbers, phone numbers, or other visitor personal identifiers.

    12. Notifications And Reports

    Entrada may send SMS or email alerts when visitors check in or check out. Delivery depends on external network and email providers, so Entrada records whether alerts were sent, failed, skipped, or pending where available.

    Scheduled analysed PDF reports and manual CSV exports are sent only to authorized recipients selected by the client organization.

    13. Retention And Deletion

    Client organizations may configure retention periods for visitor records. Where no retention period is configured, visitor records are retained for a default period of 1 year, after which eligible records are automatically and permanently deleted, unless a longer period is required by law.

    When an authorized admin deletes an organization account, we permanently delete the organization workspace, reception accounts, management accounts, visitor history, expected visitors, destination records, billing records, settings, and related operational data. This action is not recoverable after the undo window ends.

    14. Support Access

    Henrix Automations Ltd may access a deployment only when required for setup, maintenance, troubleshooting, migration, backup verification, or support, and only to the extent reasonably needed for that work.

    Where support access is granted, it is limited to the relevant task and governed by confidentiality obligations under our Terms of Use.

    15. Changes To This Policy

    We may update this policy from time to time. Material changes will be communicated to client organizations by email, and the "last updated" date at the top of this page will be revised. Continued use of Entrada after changes take effect constitutes acceptance of the revised policy.

    16. Contact

    For any enquiry, support, billing, general questions, or complaints, contact Henrix Automations Ltd at info@henrixautomations.com.