Privacy Notice - EntryFilter
Last updated: June 25, 2026
Welcome to EntryFilter, a service provided by 821lab ("we", "us", or "the Controller"). We are committed to protecting your privacy and processing your personal data transparently, securely, and in compliance with the EU General Data Protection Regulation (GDPR) and applicable law.
This Privacy Notice describes how we collect, use, store, and protect your data when you use the EntryFilter application (the "Service").
---
1. Data Controller
The data controller is:
- Company Name: 821lab
- VAT: IT07559680488
- Website: https://entryfilter.com
- Contact Email: privacy@entryfilter.com
For questions, clarifications, or to exercise your legal rights, you may contact us directly at the dedicated email address provided in the section on your rights.
---
2. Categories of Data Processed
EntryFilter is a digital assistant and voice organizer designed mainly for field workers and tradespeople, for real-time data capture. To function correctly, the Service processes the following categories of data:
a) Data provided directly by the user
- Registration and account data: First name, last name, email address, a password hashed and protected using secure algorithms, and any contact or billing details needed to manage the subscription.
- User-entered content (voice and text data): Audio recordings, transcriptions, and text notes generated while using the application for real-time data capture.
- Support communications: Messages, support requests, and related content sent to our support service.
b) Data collected automatically
- Technical and usage data: IP address, device identifiers, browser type, operating system, system logs, and interface interaction data (e.g., access timestamps, features used) required to ensure security and operational continuity.
- File metadata: Technical information related to uploaded audio files or texts (e.g., file size, creation date).
c) AI processing and automatic transcription
EntryFilter may include AI-based automatic transcription features.
- AI providers used: OpenAI (API) and/or other third-party AI providers strictly necessary to deliver transcription functionality, appointed as Processors/Sub-processors as applicable.
- Data sent to AI providers: To generate transcriptions, audio fragments and the minimum technical metadata required for processing may be sent to the AI provider.
- Possible transcription errors: Automatic transcriptions may contain errors, omissions, or incorrect interpretations.
- User verification obligation: The user must always verify transcribed content before any operational, professional, or commercial use.
- Use for AI training: Customer data is not used by EntryFilter to train proprietary AI models. For third-party AI providers, we apply contractual/technical settings, where available, to exclude data use for model training; provider terms may still apply.
The updated list of Data Processors is available to the data subject upon request.
---
3. Purposes of Processing
We process your data exclusively for the following purposes: 1. Service delivery and maintenance: Enable registration, account management, voice command processing, note organization, and service synchronization. 2. Payment management: Process transactions and manage pricing plans through our payment provider (Stripe). 3. Customer support and security: Manage support requests, monitor infrastructure stability, and prevent fraud, abuse, or unauthorized access. 4. Legal compliance: Fulfill tax, accounting, and regulatory obligations under Italian and EU law.
---
4. Legal Bases for Processing
Processing is based on the following legal grounds under EU law:
- Performance of a contract: For delivery of the EntryFilter Service and management of your account and payments.
- Legitimate interest: For technical/diagnostic logging, cybersecurity, prevention of abuse/fraud/unlawful use, and protection of infrastructure stability and reliability.
- Legal obligation: For compliance with legal obligations (e.g., retention of invoices and accounting records).
- Data subject consent: Where required for specific optional features (e.g., device hardware permissions or specific integrations not strictly necessary for the core service).
---
5. Data Retention and Object Storage
Personal data is retained only for the period strictly necessary to achieve the purposes for which it was collected, or as required by law.
- Account data and user content: Retained while your account is active. In case of account deletion, associated data is deleted or permanently anonymized within standard technical timelines (except where tax retention obligations apply).
- Technical and security logs: Retained for different periods depending on purpose, typically from 30 to 180 days; logs relevant for security, audit, and abuse prevention may be retained for up to 12 months, unless longer retention is required by law or for the defense of legal claims.
- Storage infrastructure: EntryFilter media files, voice data, and documents are securely stored using Cloudflare R2 object storage, configured with strict isolation and access protection standards.
---
6. Data Sharing and Transfers
We do not sell, assign, or otherwise commercially trade your personal data with third parties. To provide the Service, we rely on trusted external providers acting as Data Processors:
- Cloud and storage providers: Cloudflare (Cloudflare R2) for secure file storage.
- Payment management: Stripe for secure and transparent transaction processing.
The updated list of Data Processors is available to the data subject upon request.
Extra-EU transfers: If data is transferred or stored outside the European Economic Area (EEA), the Controller ensures adoption of EU Standard Contractual Clauses or equivalent legal safeguards to ensure an EU-equivalent level of protection.
Where AI providers use extra-EU infrastructure, transfers are managed with the same safeguards (e.g., SCCs and supplementary measures where needed), in compliance with GDPR.
---
7. Security Measures
We apply appropriate technical and organizational security measures to prevent accidental loss, unlawful use, alteration, or unauthorized access to your data. These measures include encryption in transit (HTTPS/TLS) and at rest on storage systems, as well as strict access-control mechanisms.
---
8. Team Use and Data Confidentiality
You acknowledge that data and documents entered into the system are accessible to other authorized users within the same company. Each company's data is kept separate from that of other companies through appropriate security measures and in accordance with applicable security best practices.
Within the same company, authorized users may view and, according to their respective permissions, modify data and documents entered by other users. Changes are securely logged to ensure traceability and oversight.
---
9. Processing of Third-Party Data (EntryFilter Role)
Important note for professional users/tradespeople: When you use EntryFilter to collect field data (e.g., data relating to your end customers entered through voice notes or reminders), you act as Data Controller in relation to those third parties, while EntryFilter acts as Data Processor. You therefore undertake to collect such information in full compliance with applicable law and to ensure that you have an appropriate legal basis for recording such data.
---
10. Data Subject Rights
In accordance with data protection law, you may exercise the following rights at any time:
- Right of Access: Obtain confirmation of the data we process and receive a copy.
- Right to Rectification: Request correction of inaccurate data or completion of incomplete data.
- Right to Erasure (Right to be Forgotten): Request permanent deletion of your personal data, where applicable.
- Right to Restriction: Request temporary restriction of processing in specific cases.
- Right to Data Portability: Receive your data in a structured, machine-readable format to transfer it to another controller.
- Right to Object: Object to processing based on legitimate interest.
To exercise these rights, send a written request to: privacy@entryfilter.com.
You also have the right to lodge a complaint with your local Data Protection Authority (in Italy: https://www.garanteprivacy.it, or the supervisory authority in the EU country where you reside or work) if you believe processing violates applicable law.
---
11. Cookies and Tracking Technologies
We use technical cookies and, where present, tools to analyze site traffic and performance in order to understand its usage, improve its functioning, and monitor its security. We do not use profiling tools for advertising purposes, nor do we sell personal data to third parties.
---
12. Changes to this Notice
The Controller reserves the right to update this notice to reflect legal changes or technical developments of the Service. Each revision is marked by the "Last updated" date at the top of the document and is available directly in the application or on the website.
---
13. Service Not Intended for Minors
The Service is not intended for persons under 18 years of age. We do not knowingly collect personal data from minors under 18. If we become aware of such data, we will delete or anonymize it without undue delay, within technical limits.