Last updated: September 2026
This Privacy Notice explains how NetNodes Limited (“NetNodes”, “we”, “our”, “us”), trading as DoorFlow, collects, uses and protects personal information when you use our websites, applications and access control services (collectively, the “Services”).
This notice applies globally to users in the UK, EU/EEA, the United States and other regions.
DoorFlow is used by organisations to control access to their buildings. When an organisation stores or manages information about its own people in DoorFlow, NetNodes acts as a Data Processor and that organisation is the Data Controller.
NetNodes Limited is the Data Controller for data we collect directly - for example website usage, account registration and support enquiries.
DoorFlow customers are Data Controllers for the information they hold about their own cardholders, staff and visitors within DoorFlow.
Our Data Processing Agreement governs our role as Processor, and our sub-processors are published on the corporate site.
Account information
Payment information
Communications
Data entered by DoorFlow customers
DoorFlow allows a customer to store basic personal information about an individual so that security events can be correlated to the right person. This may include:
This information is controlled by the customer, not by us.
We measure how our public websites are used, so that we can see what is working and improve them.
We treat this at the level of the organisation, not the individual. In particular, we may use the IP address a request came from, on its own or matched against a list of address ranges we associate with customers and prospective customers, to record that an organisation visited - never to identify a person. Any such match is treated as an indication rather than a fact, because shared offices, mobile networks and VPNs all place many people behind one address.
Where we use analytics cookies for this, they are set only after you have consented, and are described in our Use of Cookies notice.
We rely on legitimate interests for this measurement. You can object at any time using the contact details in section 13, and you can decline analytics cookies without affecting your use of the Services.
To:
Marketing communications are optional and require consent where the law requires it.
Our staff may access customer data only in order to provide and support the Services, to prevent or address a service or technical problem, or where the law requires it.
We may share personal data with:
We do not, and never will, sell personal data.
May include:
DoorFlow customers determine the lawful basis for their own use of cardholder data.
You may have rights to access, correct, delete, object to, restrict or port your data.
Requests about information held by a DoorFlow customer must be made to that customer, who is the Data Controller.
Requests about data we collect directly can be made to privacy@netnodes.net.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint. We would ask you to raise it with us first, so that we have the chance to put it right.
Automated decision-making. We do not make decisions about you by automated means that produce legal effects or similarly significant effects, and we do not carry out profiling of that kind.
We comply with relevant state-level privacy laws, including the CCPA and CPRA.
You may have rights to access or delete your data, to request information about the categories of data we hold, and to opt out of its sale or sharing.
We do not and never will sell your data.
Transfers outside the UK and EEA are protected by:
Security measures include:
We retain personal data only for as long as it is needed.
Activity data. Each time a credential is presented at a reader, DoorFlow records the reader, the date and time, the location, and the person the credential belongs to. We call this Activity data. A DoorFlow account holds Activity data for two years by default, across every location on the account.
That period is not fixed. As the account owner you can ask us to change it at any time, to keep data for longer or to clear it sooner. At the end of the retention period, Activity data is deleted automatically and permanently. That deletion cannot be undone: if you shorten your retention period, data falling outside the new window is deleted and cannot be recovered.
Account data. The account data you hold in DoorFlow - people, credentials, roles, groups, locations and permissions - belongs to you. You can view, correct, export and delete it in the DoorFlow interface or through the API at any time.
When you delete a person’s record it is marked as deleted rather than removed immediately, and is permanently deleted 60 days later. During those 60 days the record can be restored through the API.
Deleting a person does not delete their Activity data. Activity records are kept for your account’s retention period, described above, and are removed when that period expires.
Administrator audit logs. We keep a record of administrative actions taken on your account. These are kept for the life of the account, and deleted when the account is permanently deleted - 90 days after termination, or sooner at your request.
Limited exceptions. In a few cases we keep data beyond your retention period:
These are exceptions to deletion from active systems, not an extension of your retention period. We do not use data held under them for any other purpose.
After your contract ends. The periods above apply while your account is active. When your agreement with us ends, Customer Data is deleted in line with our Data Processing Agreement.
For more detail, see How long DoorFlow keeps Activity data.
DoorFlow is not intended for children under 16, or under the local minimum age where that is higher. We do not knowingly collect such information.
We may update this notice from time to time. When we do, we will revise the “Last updated” date, and material changes will be communicated appropriately.
If you have questions about this notice or about your personal data, please contact us at privacy@netnodes.net.