Sentritec Privacy Policy

Last updated: 23 July 2026

1. Introduction

Sentritec is a cloud-based access control platform that helps organisations manage who can open which doors, and when. It includes the Sentritec One web portal (for Subscriber administrators to set up sites, doors, users, schedules and access rights), the Sentritec Pass mobile app (which lets end users unlock doors using Bluetooth or remote unlock), our smart door readers (such as Access Core, Access Core Pro and Face Core), and related portals, applications and devices (collectively, the “Services”).

Sentritec is a product of the TimeTec group and is operated by TimeTec Computing Sdn. Bhd. (“TimeTec”, “we”, “us” or “our”). Sentritec is developed and operated by the same research and development team, on the same cloud infrastructure, and within the same certified information security management system as the TimeTec Cloud platform.

This Privacy Policy explains what personal data we collect through the Services, how and why we use it, who we share it with, how we protect it, how long we keep it, and the rights available to you. It should be read together with our Cookie Policy, Terms of Service and, for business customers, our Data Processing Addendum.

We handle personal data in accordance with the Malaysian Personal Data Protection Act 2010 and its Amendment Act 2024 (“PDPA 2024”), and, where applicable to individuals in the European Economic Area (EEA) and the United Kingdom, the EU/UK General Data Protection Regulation (“GDPR”).

2. Our Roles — When We Are a Controller and When We Are a Processor

Because Sentritec is an access control platform used by organisations to manage access on their premises, it is important to understand who decides how personal data is used.

  • We act as a data “controller” for the personal data of the account administrators and operators who register for and manage a Sentritec account, and for visitors to our website and marketing channels. For this data we determine the purposes and means of processing, and this Privacy Policy governs it directly.
  • We act as a data “processor” for the personal data that our business customers (“Subscribers” — typically the building owner, employer or operator) upload to or generate within the Services about their own people — for example cardholders, employees, tenants, members and visitors. For this data, the Subscriber is the controller and decides why and how it is processed; we process it only on the Subscriber’s documented instructions and in accordance with our Data Processing Addendum.

If you are a cardholder, employee, tenant, member or visitor whose access is managed through Sentritec, the organisation that operates your building or account is the controller of your data. Please direct requests about your personal data (including access, correction or deletion) to that organisation in the first instance. We will support them in responding to you.

3. Consent

By registering for, accessing or using the Services, you consent to the collection, use, disclosure and transfer of your personal data as described in this Privacy Policy. Where the law requires a higher standard of consent — in particular for biometric and other sensitive personal data — that consent is obtained as described in Section 5.

Where we act as a processor on behalf of a Subscriber, the Subscriber is responsible for establishing the lawful basis (including obtaining any necessary consent) for the personal data it uploads to or collects through the Services.

4. Personal Data We Collect

4.1 Data you provide as an administrator or account user

  • Identity and contact details: name, job title, organisation/company name, business address, email address and telephone number;
  • Account credentials: username and password (stored in hashed form) and account settings;
  • Billing and transaction information (payment card details are handled by our payment providers, not stored by us);
  • Support and communications: correspondence, support tickets, feedback, and survey responses.

4.2 Data we process on behalf of a Subscriber

  • Identity and directory details: name, email, user group/role and access validity (the period during which access is allowed); where the Subscriber uses SCIM or single sign-on (SSO), these details may be automatically synchronised from the Subscriber’s own identity provider, such as Microsoft Entra/Azure AD, Okta or Google;
  • Credential data: access card numbers, PIN codes, QR codes, mobile credentials and Bluetooth (BLE) keys used to unlock doors;
  • Biometric data: facial-recognition data used for face unlock at supported readers such as Face Core (see Section 5);
  • Access-activity data: records of who opened or attempted to open which door, the date and time, and whether access was granted or denied, together with door/zone identifiers, alarms and related audit logs;
  • Facial images captured at readers/terminals for the purpose of matching and, where the Subscriber enables it, verification records;
  • Visitor data: visitor name, host, purpose of visit, check-in/check-out times and temporary credentials.

4.3 Data collected through the Sentritec Pass mobile app

With your device permissions, and only where the Subscriber enables the relevant feature, the Sentritec Pass app may process the following on the Subscriber’s behalf:

  • Location (GPS): where geofencing is enabled, the app checks your device location at the moment you unlock, to confirm you are within a defined area (for example the building or site). This is used for the access decision at the time of unlocking — not for continuous tracking;
  • Network information: where enabled, whether your device is connected to an approved Wi-Fi network at the time of unlocking;
  • Bluetooth: used to communicate with nearby readers for tap, wave or hands-free unlocking.

4.4 Data we collect automatically

  • Device and technical data: IP address, device and operating system type, app version, browser type, and system logs;
  • Site and device data: buildings, doors, zones and schedules, reader/terminal identifiers and serial numbers, and whether a device is online;
  • Usage data: features used, dates and times of access, and diagnostic information;
  • Cookies and similar technologies on our website and web application (see Section 8).

5. Biometric Data

Sensitive personal data — Under PDPA 2024 and the GDPR, biometric data used to identify an individual is treated as sensitive (special-category) personal data and is given a higher level of protection. Sentritec processes biometric data only for identity verification and access control, and only where enabled by the Subscriber.

What we process. Where a Subscriber enables biometric access, the Services process facial-recognition data at supported readers such as Face Core in order to verify a person’s identity and grant or deny access.

How it is stored. Biometric data is converted into an encrypted mathematical representation (a “template”) used for matching. A template is not a stored image of your face and cannot be reverse-engineered into the original biometric by us. Templates and any associated images are encrypted in transit and at rest.

Consent and choice. Because biometric data is sensitive, it is processed on the basis of explicit consent or another lawful basis established by the Subscriber (the controller). The Subscriber is responsible for informing individuals and obtaining any required consent before enrolling them, and for offering a reasonable non-biometric alternative (such as a card, PIN or mobile credential) where required by law or requested by the individual.

Retention and deletion. Biometric templates are retained only for as long as the individual is enrolled and the Subscriber requires them for access control. They are deleted when the individual is removed from the system, when the Subscriber instructs deletion, or on termination of the Subscriber’s account, subject to the retention rules in Section 12.

6. How We Use Your Data

Where we act as a controller, we use personal data to:

  • Provide, operate, maintain and secure the Services;
  • Create and administer accounts, verify identity and authenticate users;
  • Process subscriptions, billing and payments, and manage the customer relationship;
  • Respond to enquiries, provide support, and send service and security notifications;
  • Monitor, troubleshoot and improve the Services, including through analysis of aggregated or de-identified usage data;
  • Detect, prevent and investigate security incidents, fraud and misuse;
  • Comply with legal, regulatory and audit obligations, and establish, exercise or defend legal claims;
  • Send you relevant product information and marketing where permitted, from which you may opt out at any time.

Where we act as a processor, we use Subscriber data only to provide the Services on the Subscriber’s documented instructions, as set out in our Data Processing Addendum, and not for our own independent purposes.

7. Automated Processing and Facial Recognition

The Services use automated matching — including facial-recognition matching — to verify identity and to grant or deny access at doors and terminals. This automated processing is configured and controlled by the Subscriber. Decisions that produce legal or similarly significant effects are subject to the safeguards required by applicable law, and a Subscriber-defined manual override or alternative (such as an operator or a card/PIN) is available. We do not use biometric data for profiling or for any purpose other than access control and security.

8. Cookies and Similar Technologies

Our website and web application use cookies and similar technologies for functionality, security, preferences and analytics. You can control non-essential cookies through our consent banner and your browser settings. Disabling some cookies may affect the functionality of the Services. For details of the cookies we use and your choices, please see our Cookie Policy.

9. How We Share and Disclose Data

We do not sell personal data, and we do not share it with third parties for their own marketing. We disclose personal data only as follows:

  • Service providers (sub-processors): trusted third parties who process data on our behalf to deliver the Services, under contract and appropriate safeguards — including cloud hosting on Amazon Web Services in Malaysia, email delivery, customer support tooling and analytics;
  • Within the Subscriber’s organisation: with administrators and operators the Subscriber has authorised to manage access;
  • Legal and regulatory: law enforcement, regulators, courts or government agencies where required by law or to protect rights, safety and security;
  • Corporate transactions: in connection with a merger, acquisition or reorganisation, subject to this Privacy Policy;
  • With your consent or on your instruction, or that of the relevant Subscriber.

A current list of our sub-processors is available on request and, where published, via our Trust/Security page.

10. International Transfers

We are based in Malaysia and use cloud infrastructure and service providers that may store or process personal data in Malaysia which we or our providers maintain facilities. Where personal data is transferred across borders, we take reasonable steps to ensure it receives an adequate level of protection, using appropriate safeguards such as contractual protections (including Standard Contractual Clauses where relevant) and the risk-based transfer requirements under PDPA 2024.

For personal data subject to EEA or UK data protection law, transfers outside the EEA/UK are made under an approved transfer mechanism with appropriate safeguards in place.

11. Data Security

We protect personal data using administrative, technical and physical safeguards. Sentritec runs on the same cloud infrastructure and is operated within TimeTec Cloud Sdn. Bhd.’s ISO/IEC 27001:2022-certified information security management system (ISMS), which is also operated in alignment with the cloud-security and personal-data-protection practices described in ISO/IEC 27017 and ISO/IEC 27018.

Our safeguards include: encryption of data in transit (TLS/SSL) and at rest; encryption of biometric templates; role-based access controls and authentication; network protection and monitoring; secure development practices; hosting in access-controlled, certified data centres; and regular review of our controls. Despite these measures, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Breach notification. If we become aware of a personal data breach, we will act in accordance with applicable law, including notifying the relevant authority and, where required, affected individuals or the relevant Subscriber, as required by PDPA 2024 and other applicable regulations.

12. Data Retention

Where we act as a processor, we retain personal data for as long as needed to provide the Services and in accordance with the Subscriber’s instructions and our Data Processing Addendum. On termination of a Subscriber’s account, we return or delete Subscriber data within the period stated in the applicable agreement, unless retention is required by law.

Where we act as a controller, we retain personal data only as long as necessary for the purposes described in this Policy, to comply with legal, tax and audit obligations, to resolve disputes and to enforce our agreements. Access-activity logs and biometric templates are retained only for the period configured by the Subscriber or required by law, after which they are deleted or de-identified.

13. Your Rights

Subject to applicable law, you have the right to: access a copy of your personal data; correct inaccurate or incomplete data; request deletion; request restriction of, or object to, certain processing; request data portability; and withdraw consent where processing is based on consent. You may also lodge a complaint with the relevant data protection authority.

Where we are the controller (administrators and website users), you may exercise these rights by contacting us using the details in Section 15. We will respond within the timeframe required by law (and in any event within 30 days for PDPA requests), and may need to verify your identity first.

Where we are the processor (cardholders, employees, tenants, members and visitors), please direct your request to the Subscriber that manages your access, as they are the controller of that data. If you contact us, we will forward your request to the relevant Subscriber and support their response.

14. Protection of Minors

The Services are intended for use by organisations and their authorised users. We do not knowingly collect personal data directly from children under 18 without the consent of a parent or guardian. Where a Subscriber manages access for minors (for example in a school or residential setting), the Subscriber is responsible for obtaining any necessary consents.

15. How to Contact Us

If you have questions about this Privacy Policy or how we handle personal data, or wish to exercise your rights, please contact us:

  • Operating entity: TimeTec Computing Sdn. Bhd. 201001038946 (922870-T)
  • Registered address: Lot No. 18F-1&2, Level 18, Tower 5 @ PFCC, Jalan Puteri 1/2, Bandar Puteri, 47100 Puchong, Selangor, Malaysia
  • Data Protection Officer (DPO): dpo@timeteccloud.com
  • General enquiries: info@timeteccloud.com
  • Telephone: +603 - 8070 9933

Our Data Protection Officer oversees our data protection programme and compliance with PDPA 2024 and, where applicable, the GDPR, across the TimeTec and Sentritec platforms.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Services or by other appropriate means before they take effect. The “Last updated” date at the top shows when this Policy was last revised. Your continued use of the Services after an update means you accept the revised Policy.