Go back

Privacy Notice

Last updated: September 2026


Introduction

This Privacy Notice explains how NetNodes Limited (“NetNodes”, “we”, “our”, “us”), trading as DoorFlow, collects, uses and protects personal information when you use our websites, applications and access control services (collectively, the “Services”).

This notice applies globally to users in the UK, EU/EEA, the United States and other regions.

DoorFlow is used by organisations to control access to their buildings. When an organisation stores or manages information about its own people in DoorFlow, NetNodes acts as a Data Processor and that organisation is the Data Controller.


1. Who We Are

NetNodes Limited is the Data Controller for data we collect directly - for example website usage, account registration and support enquiries.

DoorFlow customers are Data Controllers for the information they hold about their own cardholders, staff and visitors within DoorFlow.

Our Data Processing Agreement governs our role as Processor, and our sub-processors are published on the corporate site.


2. Information We Collect

A. Information You Provide

Account information

Payment information

Communications

Data entered by DoorFlow customers

DoorFlow allows a customer to store basic personal information about an individual so that security events can be correlated to the right person. This may include:

This information is controlled by the customer, not by us.

B. Information We Collect Automatically

C. Measurement of our websites

We measure how our public websites are used, so that we can see what is working and improve them.

We treat this at the level of the organisation, not the individual. In particular, we may use the IP address a request came from, on its own or matched against a list of address ranges we associate with customers and prospective customers, to record that an organisation visited - never to identify a person. Any such match is treated as an indication rather than a fact, because shared offices, mobile networks and VPNs all place many people behind one address.

Where we use analytics cookies for this, they are set only after you have consented, and are described in our Use of Cookies notice.

We rely on legitimate interests for this measurement. You can object at any time using the contact details in section 13, and you can decline analytics cookies without affecting your use of the Services.

D. Information from Third Parties


3. How We Use Information

To:

Marketing communications are optional and require consent where the law requires it.

Our staff may access customer data only in order to provide and support the Services, to prevent or address a service or technical problem, or where the law requires it.


4. How We Share Information

We may share personal data with:

We do not, and never will, sell personal data.


May include:

DoorFlow customers determine the lawful basis for their own use of cardholder data.


6. Your Rights (UK/EU/EEA)

You may have rights to access, correct, delete, object to, restrict or port your data.

Requests about information held by a DoorFlow customer must be made to that customer, who is the Data Controller.

Requests about data we collect directly can be made to privacy@netnodes.net.

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint. We would ask you to raise it with us first, so that we have the chance to put it right.

Automated decision-making. We do not make decisions about you by automated means that produce legal effects or similarly significant effects, and we do not carry out profiling of that kind.


7. Rights for California / US Users

We comply with relevant state-level privacy laws, including the CCPA and CPRA.

You may have rights to access or delete your data, to request information about the categories of data we hold, and to opt out of its sale or sharing.

We do not and never will sell your data.


8. International Transfers

Transfers outside the UK and EEA are protected by:


9. Security

Security measures include:


10. Data Retention

We retain personal data only for as long as it is needed.

Activity data. Each time a credential is presented at a reader, DoorFlow records the reader, the date and time, the location, and the person the credential belongs to. We call this Activity data. A DoorFlow account holds Activity data for two years by default, across every location on the account.

That period is not fixed. As the account owner you can ask us to change it at any time, to keep data for longer or to clear it sooner. At the end of the retention period, Activity data is deleted automatically and permanently. That deletion cannot be undone: if you shorten your retention period, data falling outside the new window is deleted and cannot be recovered.

Account data. The account data you hold in DoorFlow - people, credentials, roles, groups, locations and permissions - belongs to you. You can view, correct, export and delete it in the DoorFlow interface or through the API at any time.

When you delete a person’s record it is marked as deleted rather than removed immediately, and is permanently deleted 60 days later. During those 60 days the record can be restored through the API.

Deleting a person does not delete their Activity data. Activity records are kept for your account’s retention period, described above, and are removed when that period expires.

Administrator audit logs. We keep a record of administrative actions taken on your account. These are kept for the life of the account, and deleted when the account is permanently deleted - 90 days after termination, or sooner at your request.

Limited exceptions. In a few cases we keep data beyond your retention period:

These are exceptions to deletion from active systems, not an extension of your retention period. We do not use data held under them for any other purpose.

After your contract ends. The periods above apply while your account is active. When your agreement with us ends, Customer Data is deleted in line with our Data Processing Agreement.

For more detail, see How long DoorFlow keeps Activity data.


11. Children’s Privacy

DoorFlow is not intended for children under 16, or under the local minimum age where that is higher. We do not knowingly collect such information.


12. Changes to This Notice

We may update this notice from time to time. When we do, we will revise the “Last updated” date, and material changes will be communicated appropriately.


13. Contact Us

If you have questions about this notice or about your personal data, please contact us at privacy@netnodes.net.

Cookies

You can find out about cookies and how we use them here.

Specifically, we monitor how people use our site to find out how well it's doing, and to look for ways to improve it. We would like your permission to do that, but we understand if you'd prefer not.