← Privacy policies — all our apps Privacy policy

Entera Klíč

pro.itenterprise.klic · Android + iOS · last updated 2026-08-12 · Čeština · Русский

Entera Klíč is a small app that uses the camera to read a sign-in QR code (FIDO/passkey, the so-called hybrid transport) off your computer screen, asks you „Sign in on the computer?“ YES/NO, and hands the code to the phone's operating system, which completes the sign-in. The app has no registration, no login and no user accounts of its own.

This text describes what the app actually does and matches what is in its source code. It covers version 1.0.5 (Android versionCode 6, iOS build 6) as well as the forthcoming version 1.0.6 (versionCode/build 7). Wherever the two differ, this is stated explicitly at that point — version 1.0.6 adds push notifications via Google Firebase, version 1.0.5 has no notifications at all.

Who is the data controller

CompanyIT Enterprise Solution s.r.o.
Company ID28389701
VAT IDCZ28389701
DirectorJiří Hozda
Registered seatDomanovická 2480, Újezd nad Lesy, 190 16 Praha 9, Czech Republic
Contactdev@it-enterprise.cz

What data we process and why

DataWhy
No account, no profileThe app has no registration, no sign-in and no accounts of its own. No record about you is created on our side.
CameraUsed solely to read the sign-in QR code off your computer screen. Nothing is photographed or stored; the image is processed entirely on your device.
Bluetooth stateThe app only checks whether Bluetooth is switched on, because the sign-in protocol requires it. The connection itself is made by the operating system, not by the app; the app sends no data over Bluetooth.
Update checkOn start-up the app asks our server (sysadmin.it-enterprise.pro) whether a newer version exists. It sends only its own version number and the platform (Android/iOS) — no identifier of you or of your device.
Push notifications
from version 1.0.6 onwards
The app registers with Google Firebase Cloud Messaging so it can deliver a „someone is requesting a sign-in“ alert to you. In doing so Google issues it an identifier of this device (an FCM token) — it is therefore created at Google, not at our end. The app also requests notification permission and, on Android, offers a one-off battery-optimisation exemption. We do not send this token to our server and we do not link it to any person. This feature does not exist at all in version 1.0.5.
Note: for notifications the processor is Google (Firebase Cloud Messaging). Processing on their side is governed by the Firebase privacy terms and the Google Privacy Policy.

The app never sends the contents of the scanned QR code over the network — it verifies that it really is a sign-in code and hands it to the operating system on the device (on Android, to Google Play services), which completes the sign-in. The private sign-in keys are held by the operating system; the app has no access to them and signs nothing.

What the app does not collect

Who we share data with

The app has no user database that could be handed to anyone, and we neither sell nor share anything for advertising.

RecipientWhat reaches them
IT Enterprise Solution s.r.o.
our server
During the update check, the version number and the platform. As with any internet connection the server technically sees the IP address; it serves only to deliver the reply, is subject to ordinary short-term server operational logs, and we do not link it to any person.
Google Ireland Ltd. / Google LLC
Firebase Cloud Messaging, from version 1.0.6 onwards
The device identifier (FCM token) and the technical data needed to deliver notifications. It arises directly between your device and Google. Google acts here as a processor for notification delivery. This may involve a transfer outside the EU on the basis of Google's standard contractual clauses.

In version 1.0.5 the only network connection is the update check with our server — no third party is involved.

How long we keep data

We keep no personal data — the app sends us none. On your device the app stores only technical details about a downloaded update (file path, version number, checksum) and, from version 1.0.6, a flag that it has already asked once about the battery exemption. Uninstalling the app removes these. The language is not stored anywhere — the app follows the phone's language and has no setting of its own. The FCM token is managed by the operating system and the Google service; it ceases to exist when the app is uninstalled.

Deleting your account and data

The app creates no account and sends us no personal data, so on our side there is nothing to delete. Everything the app stored on your device (technical update details, the battery-prompt flag) is removed by uninstalling the app; this also ends any FCM token used for notifications.

If you nevertheless wish to check anything or exercise your rights, write to dev@it-enterprise.cz; the subject line Entera Klíč — data is enough. We reply within 30 days at the latest.

Security

The update check is encrypted (HTTPS/TLS). On Android a downloaded update is verified by its SHA-256 checksum before installation is offered; without a valid checksum it is not installed. On iOS updates are installed exclusively through the App Store / TestFlight.

Your rights under the GDPR

In relation to your personal data you have the right to:

Because the app sends us no personal data, the answer to most requests will be that we hold no data about you — but we are glad to confirm that in writing.

Children

The app is a technical tool for signing in to a company system and is not directed at children. It builds no profile of any user — child or adult — and collects no data about their identity or behaviour.

How this maps to the store declarations

Data typeGoogle Play — Data safetyApple — App Privacy
Version 1.0.5 — all categoriesNot collected, not sharedData Not Collected
From version 1.0.6 — Device ID
FCM token for notifications
Device or other IDs — collected, not shared; purpose: App functionality; not linked to the user's identity; not used for trackingDevice IDData Not Linked to You; purpose: App Functionality; not used for tracking
From version 1.0.6 — other categoriesNot collected, not sharedData Not Collected

The app version number sent during the update check is not personal data and we do not associate it with any person or device.

For filling in the stores: while version 1.0.5 is the released one, the first row applies („Data Not Collected“ / „not collected“). As soon as version 1.0.6 with notifications is released, the device identifier must be declared in both Google Play Data Safety and Apple App Privacy according to the second row — otherwise the declaration would be untrue.

Contact

Please direct any privacy questions about this app to dev@it-enterprise.cz.

This page applies to the Entera Klíč app (pro.itenterprise.klic · Android + iOS). An overview of all our apps is at it-enterprise.pro/privacy-policy. In case of any discrepancy, the Czech version prevails.