About this policy
This policy forms part of our Terms of Service and applies to everyone who uses Entris: the organisation that subscribes, every user it invites, and every device signed in with its kiosk credentials.
As the subscribing organisation you are responsible for your users’ compliance with this policy, and for making sure the people who operate your kiosks understand it.
General conduct
You must not use Entris:
- to break the law, or to help anyone else break it;
- to store or transmit anything unlawful, defamatory, harassing, or abusive;
- to infringe anyone’s intellectual property or privacy rights;
- to impersonate another person or organisation, or misrepresent your affiliation with one;
- to upload anything containing malware or other harmful code;
- in a way that damages our reputation or that of the schools we serve.
Using the data in Entris
Entris tells you where people are. That is useful for safety, and misusable for other things. You must use the information in Entris only for the purposes it was collected for — running your site, safeguarding the people on it, and meeting your legal obligations.
In particular, you must not:
- use visit records, presence data or absence data to monitor individuals for purposes unrelated to site safety and management, such as covert performance monitoring;
- disclose visitor, staff or pupil data to third parties without a lawful basis for doing so;
- export data from Entris in order to sell it, market to the people in it, or add it to an unrelated database;
- use Entris to record information a person has not been told you are recording.
You are the controller
Photographs and pupil data
- Only enable visitor photography if you have told visitors it happens and have a lawful basis for it. Photo capture is optional and off unless you switch it on.
- Do not photograph children through the visitor kiosk flow.
- Do not use badge photographs for anything other than identifying the person on site.
- Do not attempt to use exported photographs for facial recognition or any other biometric processing. Entris performs none, and using its output that way is outside the purpose it was collected for.
- Keep pupil records limited to what your attendance and roll call processes actually need.
Security and access
You must:
- keep your sign-in credentials confidential, and not share a personal account between people;
- give each user the lowest role that lets them do their job;
- remove users promptly when they leave or change role;
- re-roll kiosk credentials if a device is lost or stolen, or if someone who knew them leaves;
- site kiosks so that the screen and any printed badges are not casually visible to people who should not see them.
You must not:
- attempt to gain access to another organisation’s data, or to any part of Entris you have not been granted access to;
- probe, scan or test the security of Entris, or attempt to bypass authentication, rate limiting or any other protection, without our prior written consent;
- reverse engineer, decompile or attempt to derive the source code of Entris, except to the extent the law expressly permits;
- copy, resell, sublicense or provide Entris as a service to a third party.
Security research
Email and webhooks
Entris sends email on your behalf and can post events to a webhook you configure. Both are for operational notifications only.
- Do not use Entris notifications to send marketing, newsletters or bulk unsolicited email.
- Only configure webhook destinations you control and are authorised to send data to.
- Do not point a webhook at an internal or private network address in an attempt to reach systems that are not publicly reachable — these are blocked, and attempting it is a breach of this policy.
- Make sure notification recipients — such as hosts receiving visitor arrival emails — expect to receive them.
Technical limits
You must not:
- place an unreasonable load on Entris, whether deliberately or through faulty automation;
- access Entris by automated means — scripts, scrapers or bots — other than through an interface we provide for the purpose;
- circumvent any usage limit, quota or rate limit;
- interfere with another customer’s use of the service.
Where your plan sets limits — on kiosks, users or API calls — they are stated in your order or invoice. We do not apply undisclosed limits, and we will contact you before restricting an account for usage.
Reporting a problem
If you become aware of a breach of this policy — a shared credential, a device left signed in somewhere it should not be, data sent somewhere it should not have gone — tell us at support@syntari.co.uk. Telling us early makes it easier to contain, and we would far rather help than find out later.
How we enforce this
Where we believe this policy has been breached, our response will be proportionate to what happened. Depending on the seriousness, we may:
- contact you to resolve it — our usual first step;
- remove or disable specific content or configuration, such as a webhook pointing somewhere it should not;
- suspend an individual user, a kiosk, or the account;
- terminate the agreement in accordance with our Terms of Service;
- report the matter to the police, the Information Commissioner’s Office or another authority where we are required to, or where there is a risk to a child.
Where a suspension is needed to protect people or the service, we may act first and explain immediately afterwards. We will always tell you what we did and why.
Questions about this policy — support@syntari.co.uk.