Safe-In visitor check-in
EN
ENEnglishNLNederlandsDEDeutschFRFrançaisESEspañol
Menu
HomeWhy Safe-InHow it worksWhere it worksPricingContact

Allgemeine Geschäftsbedingungen

SaaS Visitor Registration System - Europe

Effective date: 13 September 2026 - Version: 1.0

These Terms and Conditions ("Terms") govern access to and use of the Safe-In cloud-based visitor registration and visitor management service (the "Service") provided by Safe-In ("Provider"). The business or organisation purchasing or using the Service is the "Customer".

1. Scope and Acceptance

By entering into an Order Form, activating an account, or using the Service, the Customer agrees to these Terms. An Order Form, Data Processing Agreement ("DPA") or Service Level Agreement ("SLA") prevails over these Terms to the extent it expressly addresses and conflicts with the same subject matter.

2. Service

The Service is a SaaS visitor management platform that may provide visitor pre-registration, check-in/check-out, host notifications, badges, reception workflows, visitor logs, evacuation lists, reporting, integrations and related functions, depending on the subscription. The Provider may update the Service, but will not materially reduce purchased core functionality during a paid term without reasonable justification or an appropriate replacement, except where required for security, legal compliance or third-party dependency changes.

3. Accounts and Users

The Customer is responsible for accurate account information, appropriate user roles and permissions, protection of credentials, and promptly disabling access that is no longer required. The Customer is responsible for activity through its accounts to the extent within its control and shall notify the Provider without undue delay of known unauthorised access or compromised credentials.

4. Customer Responsibilities

The Customer shall use the Service in accordance with applicable law. The Customer is responsible for determining whether its visitor-registration processes are lawful and appropriate, including information requested from visitors, notices, retention settings, host workflows and integrations. The Customer shall not use the Service for unlawful surveillance, discrimination, profiling or other prohibited activities.

5. Acceptable Use

Users shall not attempt unauthorised access, interfere with security or performance, introduce malicious code, infringe third-party rights, reverse engineer except where mandatory law permits it, unlawfully resell the Service, or use it for illegal purposes. The Provider may take proportionate protective measures, including temporary restrictions, where reasonably necessary to address security threats, unlawful use or material breach.

6. Subscription Term and Renewal

Subscription scope, locations, modules, usage metrics, fees and term are stated in the Order Form. Unless otherwise agreed, subscriptions renew for successive periods equal to the initial term unless either party gives at least 30 days' notice of non-renewal before the current term ends.

7. Fees and Taxes

The Customer shall pay fees stated in the Order Form. Unless otherwise agreed, invoices are due within 30 days. Fees exclude VAT and similar taxes. For overdue undisputed amounts, the Provider may charge legally permitted interest and, after reasonable notice, proportionately suspend affected paid functionality.

8. Trials and Beta Features

Trials, proofs of concept, previews and beta functions may have additional limitations and may be changed or withdrawn. Unless mandatory law requires otherwise, they are provided without service-level commitments and should not be relied upon for critical operations.

9. Availability and Support

The Provider will use commercially reasonable efforts to maintain the Service. Planned maintenance may affect availability. Where an SLA applies, availability targets and remedies are governed by that SLA. Internet connectivity, Customer equipment and third-party services may affect operation.

10. Intellectual Property

The Provider and its licensors retain intellectual property rights in the Service, software, documentation, APIs, designs, templates and technology. Subject to payment and compliance, the Customer receives a limited, non-exclusive, non-transferable right to use the Service internally during the subscription term. The Customer retains its rights in Customer Data.

11. Feedback

The Provider may use voluntarily supplied feedback to improve its products and services without payment, provided it does not disclose Customer Confidential Information or publicly identify the Customer without permission.

12. Customer Data

"Customer Data" means information submitted to, stored in or generated through the Service on behalf of the Customer, including visitor, host, employee, contractor and location-related information. The Provider processes Customer Data to provide, secure and support the Service in accordance with the agreement, documented instructions and applicable law.

13. GDPR and Data Protection

Where the Provider processes personal data on the Customer's behalf, the Customer generally acts as controller and the Provider as processor under Regulation (EU) 2016/679 (GDPR), unless the circumstances require another allocation of roles. The parties shall be bound by a DPA meeting Article 28 GDPR requirements. The Customer is responsible for legal bases, privacy information, data-subject rights, proportional retention and data minimisation. The Provider shall maintain appropriate technical and organisational measures and provide processor assistance as required by the GDPR and DPA.

14. Sensitive Data

The Customer shall not use the Service to process special-category data under Article 9 GDPR, criminal-conviction data, biometric identification data, government identification documents or similarly sensitive information unless the relevant functionality is expressly supported, appropriate safeguards are agreed, and the Customer has established all necessary legal grounds.

15. Subprocessors

The Provider may use subprocessors for hosting, infrastructure, communications, support, security and related functions. It shall impose GDPR-compliant contractual protections. The DPA will govern notification of new or replacement subprocessors and any applicable objection mechanism.

16. International Transfers

Where personal data is transferred outside the EEA or another jurisdiction requiring transfer safeguards, the parties will use an applicable lawful mechanism, such as an adequacy decision, European Commission Standard Contractual Clauses or another valid mechanism, together with supplementary measures where appropriate.

17. Data Hosting

Hosting regions and relevant subprocessors are identified in the Provider's documentation, DPA or subprocessor list. Any expressly purchased regional-hosting commitment is subject to the terms of the DPA, including permitted support access, subprocessors, backups and lawful international transfers.

18. Security

The Provider shall maintain technical and organisational measures appropriate to risk, which may include access controls, encryption where appropriate, logging, vulnerability management, backups, incident management and personnel security. No internet-based service can be guaranteed completely secure, and each party remains responsible for controls within its own environment.

19. Confidentiality

Each party shall protect non-public information received from the other that is identified as confidential or reasonably should be understood to be confidential. Such information may be used only for the agreement and disclosed only to persons who need it and are subject to suitable confidentiality obligations. Standard exclusions apply for public, previously known, independently developed or lawfully received information, and disclosures required by law.

20. Third-Party Services

The Service may integrate with identity providers, access-control systems, calendars, messaging platforms, printers or other third-party products. Third-party services are governed by their own terms. The Provider is not responsible for services outside its control. The Customer authorises necessary data exchange with integrations it enables.

21. Visitor Notices and Customer Content

The Customer is responsible for visitor notices, questionnaires, safety instructions, NDA acknowledgements and other materials it configures or uploads. Standard templates and configuration options do not constitute legal advice. The Customer must ensure electronic acknowledgements or signatures are suitable for its intended purpose.

22. Retention and Deletion

Where supported, the Customer may configure retention periods and is responsible for selecting periods appropriate to its purposes and legal obligations. Following termination and the applicable retrieval period, Customer Data will be deleted or anonymised according to the Provider's documented deletion schedule, subject to backups, legal retention duties and irreversibly anonymised information.

23. Data Subject Requests

Where the Provider acts as processor and receives a request concerning Customer Data directly from a data subject, it will, where legally permitted, direct the requester to the relevant Customer. The Provider will provide reasonable assistance with data-subject requests as required by Article 28 GDPR and the DPA.

24. Suspension

The Provider may proportionately suspend affected access where reasonably necessary because of a material security risk, unlawful use, uncured material breach or overdue undisputed fees. Where practicable, the Provider will give notice and restore access when the reason for suspension is resolved.

25. Termination

Either party may terminate for material breach not cured within 30 days after written notice, where cure is possible. Termination may also occur where continued performance is unlawful or in specified insolvency circumstances. Accrued rights survive termination, together with provisions intended by their nature to survive.

26. Data Return on Termination

During the subscription and, unless otherwise agreed, for 30 days after termination or expiry, the Customer may retrieve Customer Data using available export tools or another agreed method. The Customer is responsible for completing necessary retrieval before deletion.

27. Export

The Customer may export Customer Data using functionality made available within the Service. Export formats and categories may depend on subscription, configuration, permissions and available functionality. Only authorised users should initiate or access exports. After exported data has been successfully transferred to a system, device, storage location or third-party service controlled or selected by the Customer, the Customer is responsible for its lawful and secure handling, except to the extent an incident results from the Provider's breach. The Provider may apply reasonable file-size, frequency, security or performance restrictions that do not unreasonably prevent retrieval. Mandatory statutory access, retrieval and portability rights remain unaffected.

28. Warranties

Each party warrants it has authority to enter into the agreement. During a paid term, the Provider warrants that the Service will materially conform to applicable documentation when used as instructed. The Provider's primary remedy is to correct material non-conformity; if it cannot do so within a reasonable period, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused fees. Other warranties are excluded only to the extent permitted by law.

29. Limitation of Liability

Nothing excludes or limits liability where prohibited by law, including liability for fraud or fraudulent misrepresentation and other non-excludable liability. Subject to mandatory law, neither party is liable for indirect or consequential loss or loss of profits, revenue, anticipated savings, goodwill or business opportunity. Unless a different cap is agreed, each party's aggregate liability arising from the Service in a 12-month period shall not exceed fees paid or payable for the Service during the 12 months preceding the event giving rise to the claim. The parties may agree separate caps for data protection, confidentiality, intellectual property or other risks.

30. Intellectual Property Claims

The Provider will defend the Customer against qualifying third-party claims that authorised use of the Service infringes intellectual property rights in the EEA, subject to prompt notice, reasonable cooperation and Provider control of defence and settlement. The obligation excludes claims caused by Customer Data, unauthorised modifications, unapproved combinations or use contrary to documentation. The Provider may procure continued use, modify or replace affected functionality, or terminate it with a pro-rata refund.

31. Force Majeure

Neither party is liable for delay or failure caused by events beyond its reasonable control, including widespread telecommunications or cloud failures, natural disasters, war, civil disorder, labour disruption, governmental action or similar events, provided the affected party takes reasonable steps to mitigate the impact. Payment obligations for Services already provided are not excused.

32. Changes to Terms

For an active paid subscription, material changes to these Terms will normally take effect at renewal unless required earlier by law, security needs or changes necessary to continue providing the Service. The Provider will give reasonable notice of material changes. Continued use after the effective date constitutes acceptance where legally permitted.

33. Notices

Contractual notices shall be sent using the contact details stated in the Order Form or account. Notices of material breach or termination should be in writing and delivered by a method that provides reasonable evidence of delivery. Operational and Service notices may be delivered electronically.

34. Assignment

Neither party may assign the agreement without the other's prior written consent, not to be unreasonably withheld, except that either party may assign it in connection with a merger, reorganisation, sale of substantially all relevant assets, or transfer to an affiliate, provided the assignee can perform the obligations. Assignment remains subject to applicable data-protection requirements.

35. Governing Law and Jurisdiction

The agreement is governed by the laws applicable to the Provider's establishment, excluding conflict-of-law rules. The competent courts in that jurisdiction shall have exclusive jurisdiction, unless mandatory law requires otherwise.

36. General

If a provision is invalid or unenforceable, it shall be modified to the minimum extent necessary or severed without affecting the remaining provisions. Failure to enforce a right is not a waiver. The agreement, including the Order Form, DPA and any applicable SLA, constitutes the entire agreement concerning the Service and supersedes prior proposals or understandings on the same subject. Headings are for convenience only.

37. Contact Information

Provider: Safe-In. Contract, legal and privacy enquiries can be submitted through the Safe-In contact form. Support is available at support@safe-in.com or through the support portal.

Allgemeine Geschäftsbedingungen | Safe-In