Safe-In visitor check-in
EN
ENEnglishNLNederlandsDEDeutschFRFrançaisESEspañol
Menu
HomeWhy Safe-InHow it worksWhere it worksPricingContact

Declaración de privacidad

Safe-In - SaaS Visitor Registration System

Effective date: 13 September 2026 - Version: 1.0 - Last updated: 13 September 2026

Safe-In provides a cloud-based visitor registration and visitor management system for organisations in Europe. We respect the privacy of visitors, customers, users and other individuals whose personal data is processed through our services.

1. Introduction

This Privacy Statement explains how personal data is collected, used, disclosed, stored and protected in connection with the Safe-In platform, website and related services.

Safe-In processes personal data in accordance with applicable European data protection legislation, including Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), and applicable national data protection laws.

2. Who We Are

Safe-In operates the Safe-In visitor registration and visitor management service.

3. Our Role Under the GDPR

Customer Visitor Data

When an organisation uses Safe-In to register and manage its visitors, that organisation generally determines why visitor information is collected, which information is requested and how long it is retained.

In this situation, the customer organisation normally acts as the data controller, and Safe-In acts as a data processor on behalf of that customer.

Safe-In processes this personal data according to the customer's documented instructions, the applicable Data Processing Agreement ("DPA"), and applicable data protection law.

Visitors who have questions about why an organisation collects their information, the legal basis for the processing, or how long their information is retained should normally contact the organisation they are visiting.

Safe-In's Own Business Activities

Safe-In acts as a data controller when it determines the purposes and means of processing personal data for its own activities. This may include customer account administration, billing, sales, website operation, security, support, contractual administration and business communications.

4. Personal Data Processed Through Safe-In

Depending on how a customer configures Safe-In, the platform may process information such as:

Customers are responsible for ensuring that the personal information they choose to collect is necessary, proportionate and lawful.

5. Special Categories of Personal Data

Safe-In is not intended by default for the collection of special categories of personal data under Article 9 GDPR, criminal-conviction information under Article 10 GDPR, biometric identification information, or similarly sensitive information.

Customers should not configure Safe-In to request such information unless the relevant functionality expressly supports it and the customer has established an appropriate legal basis and implemented all safeguards required by applicable law.

6. Why Visitor Data Is Processed

When Safe-In processes visitor information on behalf of a customer, the purposes are determined primarily by that customer.

Depending on the customer's configuration, these purposes may include:

The customer is responsible for establishing the appropriate legal basis under the GDPR for these activities.

7. Personal Data Safe-In Processes as Controller

Safe-In may process personal data relating to customer administrators, authorised users, prospective customers, suppliers and other business contacts.

This may include:

8. Purposes and Legal Bases

Where Safe-In acts as controller, we may process personal data for the following purposes:

9. Data Minimisation

Safe-In is designed to allow customers to configure their visitor-registration processes according to their needs.

Customers should collect only personal data that is adequate, relevant and necessary for their visitor-management purposes.

Safe-In encourages customers to avoid unnecessary visitor questions and to establish appropriate retention periods for visitor information.

10. Data Retention

Where Safe-In acts as a processor, visitor data is retained according to the customer's configuration, documented instructions, contractual arrangements and the applicable DPA.

Customers may configure retention periods where this functionality is available.

Following termination of a customer's Safe-In subscription, Customer Data will be returned, deleted or anonymised in accordance with the applicable agreement, DPA and documented deletion procedures, subject to legitimate backup cycles and legal retention obligations.

Where Safe-In acts as controller, we retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, accounting, contractual and security requirements.

11. Data Hosting

Safe-In uses hosting infrastructure and service providers appropriate for delivering the Service.

Details concerning hosting locations and relevant subprocessors are available from Safe-In on request.

Where Safe-In makes a specific commitment concerning European or regional data hosting, that commitment is subject to the applicable contract and DPA.

12. Subprocessors and Service Providers

Safe-In may engage carefully selected service providers and subprocessors to provide infrastructure, hosting, communications, security, technical support and other functions necessary to operate the Service.

Where a subprocessor processes personal data on behalf of Safe-In's customers, Safe-In enters into appropriate contractual arrangements as required by Article 28 GDPR.

Safe-In remains responsible for managing its subprocessors in accordance with its obligations under applicable data protection law and the applicable DPA.

An up-to-date list of relevant subprocessors is available from Safe-In on request.

13. International Data Transfers

Safe-In seeks to process personal data within the European Economic Area ("EEA") where this forms part of its contractual or hosting commitments.

Where personal data is transferred to a country outside the EEA and that country has not been recognised as providing an adequate level of protection, Safe-In will use an appropriate transfer mechanism where required.

This may include the European Commission's Standard Contractual Clauses ("SCCs"), together with supplementary technical, organisational or contractual safeguards where appropriate.

14. Security

Safe-In maintains technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Depending on the Service and risk, these measures may include:

No online system can guarantee absolute security. Safe-In continually evaluates its safeguards in light of relevant risks and technological developments.

15. Personal Data Breaches

Safe-In maintains procedures for identifying, investigating and responding to security incidents.

Where Safe-In acts as a processor and becomes aware of a personal data breach affecting Customer Data, Safe-In will notify the relevant customer without undue delay in accordance with Article 33(2) GDPR and the applicable DPA.

The customer, as controller, is generally responsible for determining whether notification to a supervisory authority or affected individuals is required.

16. Sharing Personal Data

Safe-In does not sell visitor personal data.

Personal data may be disclosed only where appropriate, including to:

Safe-In may also disclose information where necessary to establish, exercise or defend legal claims or protect the rights, security and integrity of Safe-In, its customers or other persons, subject to applicable law.

17. Visitor Photographs and Badges

Where a customer enables visitor photography or badge functionality, photographs and related visitor information may be processed to identify visitors and support site-security or visitor-management procedures.

The customer is responsible for determining whether this processing is necessary and lawful and for providing appropriate information to visitors.

A standard visitor photograph used for visual identification is not necessarily biometric data under the GDPR. If technical processing is used for the purpose of uniquely identifying an individual through biometric characteristics, additional GDPR requirements may apply.

18. Emergency and Evacuation Information

Customers may use Safe-In visitor information to determine who is present at a location during an emergency or evacuation.

Access to emergency visitor lists should be limited to authorised personnel and used only for legitimate safety and emergency-management purposes.

19. Cookies and Website Technologies

Safe-In's public website and web applications may use cookies or similar technologies necessary for operation, authentication, security and user preferences.

Where analytics, advertising or other non-essential technologies are used and applicable law requires consent, Safe-In will request consent before placing or accessing those technologies.

Further details are provided in Safe-In's Cookie Statement.

20. Children's Personal Data

Safe-In is primarily intended for business and organisational visitor management and is not directed at children.

A customer may nevertheless register a minor as a visitor where appropriate. The customer is responsible for determining the applicable legal basis and implementing any additional safeguards or parental/guardian requirements required under applicable law.

21. Automated Decision-Making

Safe-In does not, by default, use visitor information for automated decision-making that produces legal effects or similarly significantly affects individuals within the meaning of Article 22 GDPR.

If a customer configures Safe-In or an integrated third-party service to conduct such processing, the customer is responsible for ensuring that the processing complies with applicable law and that affected individuals receive required information.

22. Your GDPR Rights

Subject to the circumstances and applicable law, individuals may have the right to:

These rights are subject to conditions and exceptions under the GDPR and applicable national law.

23. Exercising Rights Concerning Visitor Data

If you registered as a visitor at an organisation using Safe-In, that organisation normally acts as the controller of your visitor information.

You should therefore first direct requests to access, correct, delete or otherwise exercise your rights concerning visitor information to the organisation you visited.

Where Safe-In receives such a request directly and acts as processor, we may refer the request to the relevant customer and provide reasonable assistance to that customer as required by the GDPR and our DPA.

24. Exercising Rights Where Safe-In Is Controller

Where Safe-In acts as controller of your personal data, you may submit a privacy request through the Safe-In contact form or by email to support@safe-in.com.

We may need to verify your identity before processing a request. We will respond within the time periods required by applicable data protection law.

25. Complaints

If you believe your personal data has been processed unlawfully, you may contact Safe-In or, where your request concerns visitor information, the organisation you visited.

You also have the right to lodge a complaint with the competent data protection supervisory authority. Your right to approach another competent supervisory authority under the GDPR is not affected.

26. Government and Law-Enforcement Requests

Safe-In will disclose personal data to governmental or law-enforcement authorities only where required or permitted by applicable law.

Where legally permitted and appropriate, Safe-In will assess requests for validity, scope and legal authority and seek to limit disclosure to information lawfully required.

27. Export of Personal Data

Authorised customer users may export visitor and other Customer Data from Safe-In where export functionality is available.

The customer is responsible for controlling which users have export permissions and for ensuring exported personal data is subsequently stored, transferred, accessed, retained and deleted securely and lawfully.

Once an export has been successfully transferred to an environment controlled or selected by the customer, the customer is responsible for protecting that copy, except where an incident is attributable to Safe-In's breach of its applicable legal or contractual obligations.

Export functionality does not limit any applicable right to data portability or access under the GDPR.

28. Data Deletion and Account Termination

Upon termination or expiry of a customer's subscription, Safe-In will provide for the return or retrieval of Customer Data in accordance with the applicable agreement and DPA.

Following the applicable retrieval and retention period, Safe-In will delete or anonymise Customer Data in accordance with its documented procedures, except where retention is required by law or data remains temporarily within protected backup systems pending normal deletion cycles.

29. Changes to this Privacy Statement

Safe-In may update this Privacy Statement to reflect changes to the Service, our processing activities, applicable law or regulatory guidance.

Where changes are material, Safe-In will take reasonable steps to notify affected customers or users where required.

The latest version will identify its effective date and last revision date.

30. Contact Safe-In

Questions about this Privacy Statement or Safe-In's privacy practices may be submitted through the Safe-In contact form or by email to support@safe-in.com.

Declaración de privacidad | Safe-In