Privacy Policy
Last updated: 23 July 2026
This page is published in English. Translations are provided for convenience only — if there is any discrepancy between a translation and the English text, the English version prevails.
This policy explains how personal data is processed on the Entrly platform — the entrly.com website, the Entrly web app (portal.entrly.com) and the Entrly mobile apps for iOS and Android (together, the “Service”). It is written to meet the requirements of Regulation (EU) 2016/679 (GDPR).
1. Who we are
Registered seat: 1158 Budapest, Bezsilla Nándor utca 24., Hungary
Company registration number: 01-09-357654 (Metropolitan Court of Budapest, acting as Court of Registration)
Tax number: 27930467-2-42 · EU VAT number: HU27930467
Email: hello@entrly.com
Bitcrafts Kft. (“we”, “us”) operates Entrly. For questions about this policy or your personal data, write to hello@entrly.com.
2. Our two roles: controller and processor
Entrly is a platform where organizations (sports clubs, event organizers, communities) run their spaces and events, and participants join them. Because of this, we act in two different roles:
- We are the data controller for your Entrly account, for data about visitors to entrly.com, and for the business data of the organizations that subscribe to Entrly (billing contacts, invoices).
- We are a data processor for the participant data an organization manages in its spaces — registrations, custom form answers, photos, attachments, wallet balances, access records and messages. For this data the organization is the data controller, and we process it on the organization's behalf and instructions. If you take part in a space and want to exercise your data protection rights over that data, the fastest route is to contact the organizer; we assist them in responding, and we forward any request we receive directly to them.
3. What data we process
- Account data — name, email address and sign-in credentials, managed through our authentication provider Clerk. Optional profile details you add (photo, phone number).
- Participant data — data entered when you register for a space or that an organizer records about your participation: answers to the space's registration and data forms, tags, photos, files shared with you, your personal QR credential, badge and PIN, access history at check points, wallet balances and transactions, and store purchases.
- Communications — announcements sent to you in-app, by email, SMS or push notification, together with your per-space notification preferences.
- Billing data — for organizations: subscription, invoicing and payment records. Card details are collected and stored by Stripe, not by us.
- Device and technical data — push notification tokens, app/device identifiers needed to deliver notifications, IP addresses and server logs used for security and troubleshooting.
4. Why we process it and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the Service — accounts, registrations, credentials, wallets, announcements | Art. 6(1)(b) — performance of a contract |
| Billing and accounting, including statutory invoice retention | Art. 6(1)(c) — legal obligation (Hungarian Accounting Act) |
| Service security, abuse prevention, troubleshooting, logging | Art. 6(1)(f) — legitimate interest in a secure, reliable service |
| Optional notification channels you enable (e.g. SMS) | Art. 6(1)(a) — consent, withdrawable at any time in your notification settings |
| Processing participant data inside a space | Carried out as processor — the organizer determines the purposes and legal basis |
5. Cookies and local storage
Entrly uses only strictly necessary cookies. Our authentication provider Clerk sets session cookies (such as __session and __client_uat) that keep you signed in; the Service cannot work without them. We also use your browser's local storage for functional preferences on your own device. We do not use advertising, tracking or third-party analytics cookies, which is why you don't see a cookie consent banner on Entrly.
6. Who we share data with
We never sell personal data. We share it only with the service providers (processors and sub-processors) needed to run Entrly:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, databases, file storage, email delivery | EU (and US for US-homed organizations — see section 7) |
| Clerk, Inc. | Authentication and account management | USA |
| Stripe | Subscription payments and invoicing | EU/USA |
| Twilio | SMS message delivery (when an organizer uses text announcements) | USA |
| Apple / Google | Push notification delivery and wallet passes on mobile devices | USA |
| OpenAI | AI features for organization staff (only the content needed for the request; organizations may instead configure their own AI provider or disable AI) | USA |
In addition, the data an organizer manages about your participation is, by design, available to that organization's authorized staff.
7. Where your data lives
When an organization is created, its owner chooses a home region — the European Union or the United States — and that organization's data is stored and served from that region. Account and sign-in data is managed globally by Clerk. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our providers.
8. How long we keep data
- Account data — kept while your account exists. When you delete your account, your sign-in account is destroyed and the name, email address and phone number on it are erased.
- After you delete your account — we keep a record that contains no personal data, so that records which refer to you remain intact, and we keep your text-messaging consent decisions as proof of consent. Participant data held by the organizations you registered with is not deleted with your account: deleting the account only unlinks you from it, and only that organization can erase it.
- Participant data — retained according to the controlling organization's instructions; deleted when the organization removes it or its space/organization is deleted.
- Invoices and accounting records — 8 years, as required by the Hungarian Accounting Act.
- Server logs — kept for a short, limited period for security and troubleshooting, then deleted or anonymized.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate data (Art. 16) — most account and profile data you can edit yourself in the Service;
- Erase your data (“right to be forgotten”, Art. 17);
- Restrict processing (Art. 18);
- Data portability — receive your data in a structured, machine-readable format (Art. 20);
- Object to processing based on legitimate interest (Art. 21);
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
Download your data yourself. Signed in, you can export a copy of your data at any time from your profile settings (and in the Entrly apps, under My profile). The download is a ZIP holding a readable page and a structured, machine-readable file — your account and saved profile, plus the registration answers, accepted documents, access and scan history, wallet activity and messages of every participant record you manage, in every space.
An organizer may additionally hold internal notes or files about your participation that are not shown to you in the Service. They are not part of the self-service download, because the organizer — not Entrly — decides what is disclosed from their own records. Ask the organizer for them; staff can export the complete record of a participant, internal content included, in one click.
To exercise any of these rights, email hello@entrly.com. We respond within one month. Where the request concerns data controlled by an organization, we forward it to the organizer and help them respond.
10. Complaints
If you believe we process your data unlawfully, please contact us first — we take every message seriously. You also have the right to lodge a complaint with the Hungarian supervisory authority:
1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf. 9.
naih.hu · ugyfelszolgalat@naih.hu
You may also turn to the supervisory authority of your own EU member state, or to court.
11. Security
We protect personal data with technical and organizational measures appropriate to the risk: encrypted connections (TLS) everywhere, encrypted storage, secrets kept in managed key vaults, role-based access control with fine-grained permissions inside the product, and separation between each organization's data. Access to production systems is restricted and logged.
12. Children
Entrly accounts are intended for people aged 16 or older. Children can take part in spaces (for example a kids' training group) without their own account: Entrly's delegated access lets a parent or guardian manage a child's participation from the parent's own account, under the organizer's responsibility as controller.
13. Changes to this policy
When we change this policy we update the date at the top of this page, and for significant changes we notify you in the Service or by email before they take effect.
14. Contact
Bitcrafts Kft. · 1158 Budapest, Bezsilla Nándor utca 24., Hungary · hello@entrly.com