Safe-In visitor check-in
EN
ENEnglishNLNederlandsDEDeutschFRFrançaisESEspañol
Menu
HomeWhy Safe-InHow it worksWhere it worksPricingContact

Data Processing Agreement (DPA)

Safe-In - SaaS Visitor Registration System

Effective date: 13 September 2026 - Version: 1.0

This Data Processing Agreement ("DPA") forms part of the agreement governing use of the Safe-In visitor registration and visitor management service (the "Agreement").

Parties: the customer identified in the applicable Order Form or Agreement ("Customer" or "Controller") and Safe-In, the provider of the Safe-In visitor registration and visitor management service ("Safe-In" or "Processor"). The Customer and Safe-In are individually a "Party" and together the "Parties".

1. Purpose and Scope

This DPA governs Safe-In's Processing of Personal Data on behalf of the Customer in connection with the Safe-In SaaS visitor registration and visitor management system ("Service"). It is intended to satisfy Article 28 GDPR and applies whenever Safe-In acts as Processor. Where Safe-In independently determines purposes and means, its applicable Privacy Statement governs that controller Processing.

2. Definitions

Applicable Data Protection Law means the GDPR and applicable national data protection legislation. Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Supervisory Authority and Special Categories of Personal Data have their GDPR meanings. Customer Data means data submitted to, stored in, generated through or otherwise Processed by the Service for the Customer. Customer Personal Data means Personal Data within Customer Data. Subprocessor means a third party engaged by Safe-In to Process Customer Personal Data. SCCs means applicable European Commission Standard Contractual Clauses.

3. Roles of the Parties

The Customer generally acts as Controller and Safe-In as Processor. The Customer determines the purposes and essential means of Processing, including collected visitor information, purposes, legal basis, retention, access, optional questions and integrations. Safe-In shall Process Customer Personal Data only on documented Customer instructions except where EU or Member State law requires otherwise. Where legally permitted, Safe-In shall inform the Customer of such requirements and shall inform the Customer if an instruction, in Safe-In's reasonable opinion, infringes Applicable Data Protection Law.

4. Customer Instructions

The Agreement, this DPA, Customer configuration and use of the Service, and documented instructions through agreed channels constitute Customer instructions. Additional instructions outside normal Service operation must be agreed. Material additional work may be subject to reasonable agreed fees.

5. Customer Obligations

The Customer is responsible for lawful instructions and use, appropriate legal bases, required privacy information, data minimisation, retention periods, Data Subject requests, access permissions, lawful visitor questions and lawful integrations. The Customer shall not instruct unlawful Processing.

6. Details of Processing

The subject matter, duration, nature and purpose of Processing, categories of Data Subjects and categories of Personal Data are described in Annex I.

7. Confidentiality

Safe-In shall ensure authorised persons are subject to appropriate confidentiality obligations. Access shall be limited to personnel requiring it to provide, maintain, secure or support the Service. Confidentiality continues after employment or engagement ends.

8. Security of Processing

Safe-In shall maintain appropriate technical and organisational measures under Article 32 GDPR, taking account of state of the art, costs, context and risk. Measures may include access controls, authentication, encryption, logging, backup and recovery, vulnerability management, incident management, logical customer separation, personnel controls and resilience. Annex II provides further detail. Updates shall not materially decrease overall protection.

9. Personal Data Breaches

Safe-In shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent reasonably available, notification shall provide information necessary for Articles 33 and 34 GDPR, including nature, affected categories and approximate numbers, likely consequences, measures taken or proposed and relevant contact information. Information may be provided in phases. The Customer remains responsible for determining regulatory or Data Subject notification requirements.

10. Subprocessors

The Customer grants general written authorisation for Safe-In to engage Subprocessors. Safe-In shall maintain an up-to-date list available on request, provide reasonable advance notice of intended additions or replacements, and permit objections on reasonable data-protection grounds within 15 days. Safe-In shall impose appropriate written data-protection obligations on Subprocessors and remains responsible to the Customer to the extent required by Article 28 GDPR.

11. International Data Transfers

Safe-In shall not transfer Customer Personal Data outside the EEA unless compliant with Applicable Data Protection Law. Safe-In may rely on adequacy decisions or appropriate Chapter V safeguards, including SCCs, with supplementary measures where appropriate, and shall provide reasonably necessary transfer information.

12. European Data Hosting

The primary hosting location and provider are documented in the applicable Agreement, DPA documentation or Subprocessor list and are available from Safe-In on request. Any contractual EU/EEA residency commitment is subject to authorised support access, disclosed Subprocessors, backup and disaster recovery, legally required disclosures and lawful international transfers.

13. Data Subject Rights

Taking into account the nature of Processing, Safe-In shall reasonably assist the Customer with applicable access, rectification, erasure, restriction, portability, objection and automated-decision rights. If Safe-In directly receives a request concerning Customer Personal Data, it shall not substantively respond unless authorised or legally required and, where permitted, shall direct the requester to or inform the Customer.

14. Assistance with GDPR Compliance

Safe-In shall provide reasonable assistance, considering the nature of Processing and information available, with Articles 32 to 36 GDPR, including security, breach assessment, DPIAs and prior consultation.

15. Data Protection Impact Assessments

Where the Customer reasonably determines that use of Safe-In requires an Article 35 DPIA, Safe-In shall provide reasonably available information necessary to assist. The Customer remains responsible for conducting the DPIA and determining whether prior consultation is required.

16. Government and Law-Enforcement Requests

If Safe-In receives a legally binding public-authority request for Customer Personal Data, it shall, unless prohibited, notify the Customer, assess validity, appropriately challenge requests it reasonably considers unlawful where legally available, and disclose only the minimum legally required information.

17. Audit Rights

Safe-In shall make reasonably necessary compliance information available. Relevant independent reports, certifications, security documentation or questionnaires may satisfy reasonable requests. If insufficient, the Customer may request an audit on reasonable prior notice, normally no more than once per 12 months unless justified, during business hours, without unreasonable disruption and without access to other customers' information. The Customer bears its own costs; substantial assistance may be subject to reasonable agreed charges unless material Safe-In non-compliance is identified.

18. Return, Export and Deletion

During the Service term the Customer may access and export Customer Personal Data using available functionality. Unless otherwise agreed, the post-termination retrieval period is 30 days. Afterwards Safe-In shall delete or anonymise Customer Personal Data under documented procedures unless law requires retention. Protected backup copies may remain until normal overwrite or deletion and shall not be restored for ordinary business purposes. Safe-In shall provide reasonable deletion confirmation where required under Article 28 GDPR.

19. Customer Data Exports

The Customer determines authorised exporters and Safe-In shall maintain appropriate access controls. Once an export is successfully delivered to an environment, device or third-party system selected or controlled by the Customer, responsibility for securing that copy passes to the Customer except to the extent an incident results from Safe-In's breach.

20. Special Categories of Personal Data

Safe-In is not intended by default for Article 9 special-category data, Article 10 criminal-conviction data, biometric identification information, government identification documents or similarly sensitive information. The Customer shall not instruct such Processing unless expressly supported, a valid legal basis exists, additional legal requirements are satisfied and appropriate safeguards are agreed where necessary.

21. Visitor Photographs

Where enabled, Safe-In may Process visitor photographs according to Customer instructions for visitor identification and management. A photograph is not biometric data merely because it depicts an individual. If technical Processing is used to uniquely identify a person through biometric characteristics, applicable Article 9 requirements must be satisfied.

22. Automated Decision-Making

Safe-In does not, as part of standard visitor-registration functionality, make solely automated decisions producing legal or similarly significant effects within Article 22 GDPR. Customer-selected integrations or configurations enabling such Processing are the Customer's responsibility for compliance.

23. Records of Processing

Safe-In shall maintain records as required by Article 30(2) GDPR and make relevant information available to competent Supervisory Authorities as required by law.

24. Cooperation with Supervisory Authorities

Safe-In shall cooperate with competent Supervisory Authorities as required and reasonably assist the Customer with relevant enquiries concerning Safe-In's Processing.

25. Liability

Liability under this DPA is subject to the Agreement except where limitation is prohibited by Applicable Data Protection Law. Nothing restricts Data Subject rights or Supervisory Authority powers.

26. Term and Termination

This DPA is effective while Safe-In Processes Customer Personal Data for the Customer. Confidentiality, security, return, deletion and legal-compliance obligations survive while Safe-In retains such data.

27. Order of Precedence

For conflicts concerning Personal Data Processing: (1) mandatory data protection law; (2) applicable SCCs; (3) this DPA; (4) the Agreement; and (5) other contractual documentation, to the extent of conflict.

28. Governing Law

Unless mandatory data protection law or applicable SCCs require otherwise, this DPA is governed by the law and jurisdiction specified in the Agreement.

Annex I - Details of Processing

A. Subject Matter

Provision of the Safe-In cloud-based visitor registration and visitor management Service.

B. Duration

Processing takes place for the Customer subscription and any agreed post-termination retrieval period, subject to backup cycles and legal retention obligations.

C. Nature of Processing

Collection, receipt, recording, organisation, structuring, storage, retrieval, consultation, transmission, display, export, modification, restriction, backup, restoration, deletion, anonymisation and other Processing necessary to provide the Service.

D. Purposes

Visitor registration and pre-registration; arrival and departure recording; host notification; badges; visitor logs; reception; emergency and evacuation information; site and security requirements; authorised reports and exports; Customer-selected integrations; Service security and maintenance; and technical support.

E. Categories of Data Subjects

Visitors, prospective visitors, employees, visitor hosts, contractors, temporary personnel, customer administrators, authorised Service users and other persons registered for legitimate visitor-management purposes.

F. Categories of Personal Data

Depending on configuration: name; organisation; job title or affiliation; email; telephone; host details; visit date and time; arrival and departure timestamps; site or location; purpose; photograph where enabled; visitor or badge identifiers; badge data; vehicle registration where enabled; invitation or pre-registration data; acknowledgements of site, safety, confidentiality or visitor terms; signatures or electronic acknowledgements where enabled; Customer-configured question responses; emergency or evacuation status; integration-related access information; language or communication preferences; necessary IP or device data; system or audit logs; and other Personal Data submitted through Customer-configured fields.

G. Special Categories

Safe-In is not intended by default to Process Article 9 special-category or Article 10 criminal-conviction data. Such collection shall not be configured unless expressly supported, appropriate legal bases exist and required safeguards are implemented.

H. Frequency

Processing occurs continuously or recurrently during Customer use, including invitations, pre-registration, registration, check-in and check-out, host association, badge issue, emergency lists, reports and exports.

I. Purpose of Processing

Safe-In Processes Customer Personal Data solely to provide and support the Service according to documented Customer instructions, including visitor management, identification, host notification, reception, badges, access administration, records, emergency management, instructions, acknowledgements, reporting, integrations, security, troubleshooting, support, backup and recovery, deletion and anonymisation.

J. Processing Operations

Collection, receipt, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, display, transmission, notification, authorised integration synchronisation, reporting, export, restriction, backup, restoration, deletion and anonymisation.

K. Duration

Processing continues for the subscription and applicable post-termination retrieval period. Unless otherwise agreed, retrieval is available for 30 days after termination or expiry, after which data is deleted or anonymised subject to legal retention and backup cycles.

L. Retention Periods

Retention periods are determined by Customer configuration, the applicable Agreement or DPA, documented deletion procedures, the normal backup lifecycle and legal retention obligations. Post-termination retrieval is available for 30 days unless otherwise agreed.

M. Processing Locations

The primary hosting provider and region, storage countries, backup locations and technical-support access locations are documented in the applicable Agreement, DPA documentation or Subprocessor list and are available from Safe-In on request. Transfers outside the EEA must comply with Chapter V GDPR.

N. Customer Instructions

The Customer instructs Safe-In to Process Customer Personal Data as necessary to provide, configure, maintain, secure and support the Service; perform requested exports, integrations and administration; comply with the Agreement and DPA; and carry out additional documented instructions agreed between the Parties.

Annex II - Technical and Organisational Measures

1. Access Control

Role-based access, least privilege, controlled administrative access, authentication requirements, access lifecycle procedures, privileged-access review and production-access restrictions.

2. Authentication

Appropriate authentication for personnel and administrative systems. Where appropriate and available, multi-factor authentication should protect privileged or security-sensitive access.

3. Encryption

Customer Personal Data shall be protected using appropriate encryption in transit and, where appropriate to risk and environment, at rest.

4. Logging and Monitoring

Appropriate logging and monitoring may cover administrative access, authentication, security events, errors, relevant configuration changes and suspicious activity. Logs shall be protected against unauthorised modification.

5. Vulnerability Management

Processes appropriate to risk for vulnerability identification, security patching, dependency management, scanning, assessment and remediation.

6. Secure Development

Appropriate software-development security practices, which may include code review, dependency controls, testing, environment separation, change management and security review of material changes.

7. Backup and Recovery

Appropriate backup and recovery procedures are maintained. Specific backup frequency, retention, region and any contractually committed recovery objectives are documented in the applicable Agreement, DPA documentation or SLA.

8. Business Continuity

Reasonable business-continuity and disaster-recovery procedures appropriate to the Service, periodically reviewed or tested.

9. Incident Management

Procedures to identify, assess, contain, investigate and remediate security incidents. Personal Data Breaches are handled under Section 9.

10. Personnel Security

Personnel with Customer Personal Data access are subject to confidentiality, receive appropriate privacy and security awareness training, receive access only where required and have access revoked when no longer needed.

11. Physical Security

Physical security for hosting infrastructure is provided by Safe-In or authorised infrastructure providers using controls appropriate to the data-centre environment.

12. Customer Separation

Logical or other appropriate mechanisms designed to prevent one customer from obtaining unauthorised access to another customer's data.

13. Data Deletion

Documented procedures for secure deletion or anonymisation of Customer Personal Data following applicable retention periods, subject to protected backup cycles and legal retention requirements.

14. Review and Improvement

Safe-In may review and improve these measures as technology, threats and the Service evolve, provided the overall level of protection is not materially reduced.

Signatures (optional)

For Customer: __________________________ Date: ____________

For Safe-In: ____________________________ Date: ____________

Data Processing Agreement (DPA) | Safe-In