Legal

Privacy Policy

Entris records who is inside a school building. This explains what personal data that involves, who is responsible for it, and what rights people have over it.

On this page

Who we are

Entris is a visitor management system for schools, provided by Syntari Limited, a company registered in England and Wales (company number 17308205, registered office Office 19675, 182-184 High Street North, London, England, E6 2JA). In this policy “we”, “us” and “Syntari” mean Syntari Limited, and “Entris” means the Entris software and kiosk applications.

This policy covers personal data we handle through Entris and through our website at entris.syntari.co.uk. It does not cover how an individual school uses the information it collects — for that, ask the school.

Our two roles

Data protection law distinguishes between the organisation that decides why personal data is processed (the controller) and the organisation that processes it on their instructions (the processor). Entris involves both, and which one we are depends on whose data it is.

The short version

The school is the controller for everything about its visitors, staff and students. We are only its processor for that data. We are the controller for the accounts your staff use to sign in to the Entris dashboard.
DataControllerOur role
Visitor, staff and student records; visits; absences; emergency roll callsThe schoolProcessor — we act only on the school’s documented instructions
Dashboard user accounts (the people who sign in to manage Entris)Syntari LimitedController
Website usage, support enquiries, billing and business recordsSyntari LimitedController

Where we act as a processor, our obligations are set out in the data processing terms that form part of our agreement with the school. If you are a school and need a copy of those terms, contact us.

Information we handle

Visitors

When someone signs in at a kiosk or is pre-registered by school staff, Entris may record their name, email address, phone number, visitor type, the reason for their visit, who they are visiting, their arrival and departure times, and any notes staff add. Depending on how the school has configured its kiosks, it may also record a photograph, a vehicle registration, a DBS certificate expiry date, and acceptance of the school’s visitor terms.

Staff and students

For schools that use Entris to record attendance and roll calls, we hold staff and student names, school email addresses, and — where the school provides them — department, job title or year group. We record absences, including the reason chosen and when the absence was recorded or cleared. Where a school connects Microsoft Entra ID, these records are synchronised from the school’s own directory.

Dashboard users

For the staff who sign in to manage Entris, we hold a name, email address, a securely hashed password, an optional profile picture, two-factor authentication settings, and a record of active sessions including IP address, browser user agent and last activity time.

Operational records

We keep records that let a school account for what happened in its own system: a log of notification emails and webhooks sent, changes to member roles, and — for actions taken by Syntari staff through our internal administration tools — an audit log recording who did what and when.

Photographs

Visitor photographs are used for identification on badges and in the visitor record. They are an ordinary photograph, not biometric data: Entris does not perform facial recognition, matching or any other biometric processing. Whether photographs are captured at all is a setting each school controls.

How and why we use it

Where we act as a processor, we use school data only to provide Entris: recording sign-ins and sign-outs, producing the on-site register and emergency roll call, printing badges, sending arrival and absence notifications the school has switched on, and generating the reports the school asks for. We do not use school data for our own purposes, and we never use it to train machine learning models.

Where we are the controller

For dashboard accounts and our website, our legal bases under the UK GDPR are:

  • Contract — creating and running accounts, authenticating sign-ins, and providing support.
  • Legitimate interests — keeping the service secure, preventing abuse of sign-in, diagnosing faults, and understanding which features are used so we can improve them. We balance these against your interests and use the least identifying data that will do the job.
  • Consent — optional analytics cookies, which you can accept or decline, and change at any time.
  • Legal obligation — keeping business and accounting records where the law requires it.

We do not sell personal data, and we do not use it for advertising or automated decision-making that produces legal or similarly significant effects.

Children’s data

Schools decide; we process

Entris is sold to schools, not to children or parents. Where Entris holds information about pupils, the school is the controller and decides what is collected and why. We process it only on the school’s instructions.

We recognise that data about children deserves particular care. In practice that means we:

  • collect the minimum a school needs to run attendance and roll call — typically a name, school email address and year group;
  • never market to children, profile them, or use their data to build any form of behavioural model;
  • do not enrich pupil records with data from third parties;
  • apply the same access controls, encryption and audit logging to pupil data as to everything else, and restrict Syntari staff access to what is needed for support;
  • delete pupil data when the school instructs us to, or when its agreement with us ends.

Schools remain responsible for informing pupils and parents about their use of Entris, and for having a lawful basis for it — usually a public task under the UK GDPR. We are happy to help with the technical detail a school needs for its own privacy notice or data protection impact assessment.

Who we share it with

We do not sell or rent personal data. We share it only with the service providers below, who process it on our instructions under contract, and with authorities where the law requires it.

ProviderWhat it doesData involved
ResendSends transactional email — sign-in links, invitations, visitor arrival and absence notificationsRecipient name and email address, and the content of the notification
SentryError monitoring, so we can find and fix faultsTechnical diagnostics; may incidentally include an account identifier
PostHogProduct analytics — only where analytics cookies are acceptedPseudonymous usage events and an account identifier
Microsoft (Graph / Entra ID)Directory synchronisation — only where a school switches the integration onStaff and student names, email addresses and group membership
OVHcloud (UK)Hosts the server that runs Entris — the application, the database, the uploaded images and the backupsAll data held in Entris
Our current sub-processors. Schools are told before we add a new one. Uploaded images are stored on our own server rather than with a third-party storage provider, so no separate storage processor is involved.

A school may also send its own data out of Entris — for example by enabling an outbound webhook to another system it controls, or by exporting a report. Where it does, the school is responsible for that destination.

International transfers

Personal data in Entris is held in the UK. The server that runs the application, the database, the uploaded images and the backups are all in OVHcloud’s London region.

Our sub-processors are configured to store data in the UK or the European Economic Area: Resend, Sentry and PostHog each hold data in their EU region. Microsoft processes directory data in the tenancy the school itself controls, under the school’s own agreement with Microsoft.

Where a provider nonetheless transfers personal data outside the UK — for example for support or routing — we rely on UK adequacy regulations or the International Data Transfer Addendum to the European Commission’s standard contractual clauses, together with additional safeguards where appropriate.

How long we keep it

Where we are the processor, the school decides how long its records are kept, and can delete them at any time from within Entris. Our default behaviour is below.

RecordKept for
Visitor, visit, staff, student and absence recordsFor as long as the school keeps them, and until the school deletes them or its agreement with us ends
Deleted people (visitors, staff, pupils)30 days, then permanently erased — see below
Visitor photographsDeleted with the visitor record, at the end of the same 30 days
Expected visits (pre-registrations)6 months after the expected date, then the visitor’s details are erased and only the appointment remains
Notification delivery log90 days, then deleted automatically
Organisation activity log12 months, then deleted automatically
Emergency roll-call records3 years, then the notes and the list of who was accounted for are erased, leaving only that the roll call happened
Dashboard user accountsWhile the account is active; deleted on request or when the account is removed
Sign-in sessionsUntil they expire or are signed out, then deleted within 7 days
Unaccepted invitations, password reset and sign-in linksDeleted shortly after they expire
Internal administration audit log2 years, then deleted automatically
BackupsBackupsTaken daily and kept for no longer than 30 days, so a backup never outlives the erasure window above

What “deleted” actually means

When somebody is deleted in Entris they disappear from the register, the kiosks and the directory straight away, but the record is kept for 30 days so an accidental deletion can be undone. After that it is erased for good, automatically.

Erasure removes the person, not the history. Everything that identifies them — name, email address, phone number, photograph, vehicle registration, DBS expiry date — is permanently destroyed. The visits and absences themselves stay, with no name attached, because a school’s safeguarding record of who was in the building on a given day should not silently change months later. Where a deleted person has no visits or absences at all, the record is removed outright.

When a school’s agreement ends, we delete or return its data in accordance with our agreement with them. Records erased in Entris are removed from active systems at that point and fall out of backups within the backup retention period.

How we protect it

No system is perfectly secure, but these are the specific measures Entris uses rather than a general promise to take security seriously.
  • Traffic is encrypted in transit with TLS, with HSTS enforced. Stored third-party integration credentials are encrypted with AES-256-GCM.
  • Passwords are hashed with bcrypt; we never store them in a readable form and cannot recover them.
  • Two-factor authentication is required on every dashboard account. New accounts have a seven-day grace period to set it up, after which the account cannot be used until it is.
  • Access is role-based, and every request re-checks that the signed-in user is a member of the organisation whose data they are asking for.
  • Kiosks authenticate with their own credentials, and each kiosk password re-roll immediately invalidates every session on devices already signed in.
  • Badge QR codes carry a signed token rather than personal data, so scanning one reveals nothing on its own.
  • Third-party integration secrets are encrypted before they are stored.
  • Actions taken by Syntari staff in our internal tools are recorded in an audit log attributed to the individual.

If a personal data breach occurs, we will notify affected schools without undue delay and, where required, report it to the Information Commissioner’s Office within 72 hours of becoming aware of it.

Your rights

Under the UK GDPR you have the right to:

  • ask what personal data is held about you and get a copy of it;
  • have inaccurate data corrected;
  • have data erased in certain circumstances;
  • restrict or object to processing in certain circumstances;
  • receive data you provided in a portable format;
  • withdraw consent at any time, where we rely on consent.

Who to ask

If you are a visitor, member of staff or pupil at a school using Entris, the school is the controller — please contact the school directly. If they need our help to answer you, we will provide it. If you hold an Entris dashboard account, contact us directly using the details below.

We respond to requests within one month. You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, though we would appreciate the chance to put things right first.

Cookies

Entris uses a small number of cookies, most of which are strictly necessary to keep you signed in. Optional analytics cookies are only set if you accept them. Our Cookie Policy lists every cookie, what it does and how long it lasts.

Changes to this policy

We update this policy when our practices change. The version and date at the top of this page always reflect the current text. If a change materially affects how we handle personal data, we will tell account holders by email or in the dashboard before it takes effect, and schools will be notified in accordance with our agreement with them.

Contact us

For any privacy question, or to exercise a right over data we control, email support@syntari.co.uk or write to us at Office 19675, 182-184 High Street North, London, England, E6 2JA.

Our Data Protection Officer is Dylan Phillips, who can be reached at dylan@syntari.co.uk. For anything else, including a request about your own data, write to support@syntari.co.uk.