Privacy Policy

This Privacy Policy explains how personal data is processed in connection with the Entryward website (entryward.com) and the Entryward product (the browser extension and the admin dashboard at app.entryward.com). Entryward is operated by [Your full name], entrepreneur individuel (EI), registered in France (SIREN [SIREN — 9 digits]). You can reach us at hello@entryward.com.

1. Controller and processor roles

For the marketing website and for admin-account data, Entryward acts as the data controller.

For data processed through the product about an organisation’s employees or end-users (e.g. access-request data), the customer organisation (the employer) is the data controller and Entryward acts as a processor on its behalf and on its documented instructions, under a Data Processing Agreement (DPA). Employees should direct requests about that data to their employer.

2. What we process

Website visitors

The website sets no advertising or analytics cookies and runs no third-party tracking. If you email us (e.g. to request a demo), we process the contact details and content you choose to send.

Admin users

When an administrator signs in, we process their work email, the identity returned by their identity provider (Google or Microsoft via our authentication provider), and their organisation/role membership.

Product data (as processor, on behalf of the customer)

Entryward never reads, transmits or stores what a user types. The extension only evaluates the page’s origin locally to decide whether a password field may be used — it does not capture passwords or keystrokes.

3. Purposes and legal bases

4. Subprocessors and hosting

Entryward relies on the following providers, with processing located in the EU:

We maintain an up-to-date list of subprocessors and will inform customers of material changes. Where a provider’s corporate group is established outside the EU, transfers are framed by the European Commission’s Standard Contractual Clauses and appropriate supplementary measures.

5. International transfers

Personal data is processed in the European Union. Any transfer outside the EU/EEA is governed by an adequacy decision or Standard Contractual Clauses.

6. Retention

Account data is kept while the account is active. Product data (e.g. access requests) is retained according to the customer’s configuration and the DPA, and deleted or returned at the end of the contract. Website contact emails are kept only as long as needed to handle your request.

7. Security

We encrypt data in transit (TLS with a pinned database CA), store secrets only as salted hashes, scope every access to the relevant tenant, design the extension to fail closed, and host data in the EU.

8. Your rights

Subject to applicable law, you have rights of access, rectification, erasure, restriction, portability and objection. To exercise them for data for which Entryward is the controller, email hello@entryward.com. For product data processed on behalf of your employer, contact your employer (the controller). You also have the right to lodge a complaint with the French supervisory authority, the CNIL.

9. Cookies

The marketing website uses no tracking cookies. The admin dashboard uses only strictly-necessary session cookies to keep you signed in; these are exempt from consent.

10. Changes

We may update this policy; the “Last updated” date above reflects the latest version. Material changes will be communicated to customers.

11. Contact

[Your full name], entrepreneur individuel (EI), [Registered business address — consider a domiciliation to avoid your home address], France hello@entryward.com.