Déclaration de confidentialité
Safe-In - SaaS Visitor Registration System
Effective date: 13 September 2026 - Version: 1.0 - Last updated: 13 September 2026
Safe-In provides a cloud-based visitor registration and visitor management system for organisations in Europe. We respect the privacy of visitors, customers, users and other individuals whose personal data is processed through our services.
1. Introduction
This Privacy Statement explains how personal data is collected, used, disclosed, stored and protected in connection with the Safe-In platform, website and related services.
Safe-In processes personal data in accordance with applicable European data protection legislation, including Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), and applicable national data protection laws.
2. Who We Are
Safe-In operates the Safe-In visitor registration and visitor management service.
- Website: https://www.safe-in.com
- Privacy contact: support@safe-in.com or the Safe-In contact form
3. Our Role Under the GDPR
Customer Visitor Data
When an organisation uses Safe-In to register and manage its visitors, that organisation generally determines why visitor information is collected, which information is requested and how long it is retained.
In this situation, the customer organisation normally acts as the data controller, and Safe-In acts as a data processor on behalf of that customer.
Safe-In processes this personal data according to the customer's documented instructions, the applicable Data Processing Agreement ("DPA"), and applicable data protection law.
Visitors who have questions about why an organisation collects their information, the legal basis for the processing, or how long their information is retained should normally contact the organisation they are visiting.
Safe-In's Own Business Activities
Safe-In acts as a data controller when it determines the purposes and means of processing personal data for its own activities. This may include customer account administration, billing, sales, website operation, security, support, contractual administration and business communications.
4. Personal Data Processed Through Safe-In
Depending on how a customer configures Safe-In, the platform may process information such as:
- first and last name;
- company or organisation;
- email address;
- telephone number;
- date and time of arrival and departure;
- person or department being visited;
- location or site being visited;
- purpose of the visit;
- vehicle registration details, where enabled;
- visitor photograph, where enabled;
- badge or visitor identification information;
- acknowledgement of site rules, safety instructions or confidentiality requirements;
- visitor responses to questions configured by the customer;
- pre-registration and invitation information;
- access, check-in and check-out records;
- technical information necessary to operate and secure the Service; and
- other information that a customer chooses to collect through configured visitor-registration fields.
Customers are responsible for ensuring that the personal information they choose to collect is necessary, proportionate and lawful.
5. Special Categories of Personal Data
Safe-In is not intended by default for the collection of special categories of personal data under Article 9 GDPR, criminal-conviction information under Article 10 GDPR, biometric identification information, or similarly sensitive information.
Customers should not configure Safe-In to request such information unless the relevant functionality expressly supports it and the customer has established an appropriate legal basis and implemented all safeguards required by applicable law.
6. Why Visitor Data Is Processed
When Safe-In processes visitor information on behalf of a customer, the purposes are determined primarily by that customer.
Depending on the customer's configuration, these purposes may include:
- registering and identifying visitors;
- managing visitor invitations and pre-registration;
- notifying employees or hosts of a visitor's arrival;
- managing reception and check-in/check-out processes;
- printing visitor badges;
- maintaining visitor records;
- supporting building and site security;
- managing emergency or evacuation procedures;
- communicating relevant safety or site information;
- administering confidentiality or visitor policies;
- producing authorised visitor reports; and
- complying with applicable legal or organisational requirements.
The customer is responsible for establishing the appropriate legal basis under the GDPR for these activities.
7. Personal Data Safe-In Processes as Controller
Safe-In may process personal data relating to customer administrators, authorised users, prospective customers, suppliers and other business contacts.
This may include:
- name and business contact information;
- employer and job title;
- account and authentication information;
- subscription and contract information;
- billing and transaction information;
- communications with Safe-In;
- support requests;
- Service usage and security information; and
- technical information such as IP address, device, browser and log information.
8. Purposes and Legal Bases
Where Safe-In acts as controller, we may process personal data for the following purposes:
- Providing and administering the Service - where processing is necessary to perform a contract or take requested pre-contractual steps.
- Customer support and communications - to provide support, respond to requests and manage our relationship with customers. Processing may be necessary for performance of a contract or based on our legitimate interests in operating our business.
- Security and fraud prevention - based on our legitimate interests in protecting Safe-In, our customers, users and systems and, where applicable, compliance with legal obligations.
- Billing and financial administration - where necessary for performance of a contract and compliance with accounting, tax and other legal obligations.
- Service improvement - where based on our legitimate interests in maintaining and improving our Service, provided those interests are not overridden by the rights and freedoms of affected individuals.
- Marketing communications - where permitted by applicable law, based on consent or legitimate interests as appropriate. Individuals may opt out of direct marketing communications at any time.
- Legal and regulatory compliance - where processing is necessary to comply with a legal obligation or establish, exercise or defend legal claims.
9. Data Minimisation
Safe-In is designed to allow customers to configure their visitor-registration processes according to their needs.
Customers should collect only personal data that is adequate, relevant and necessary for their visitor-management purposes.
Safe-In encourages customers to avoid unnecessary visitor questions and to establish appropriate retention periods for visitor information.
10. Data Retention
Where Safe-In acts as a processor, visitor data is retained according to the customer's configuration, documented instructions, contractual arrangements and the applicable DPA.
Customers may configure retention periods where this functionality is available.
Following termination of a customer's Safe-In subscription, Customer Data will be returned, deleted or anonymised in accordance with the applicable agreement, DPA and documented deletion procedures, subject to legitimate backup cycles and legal retention obligations.
Where Safe-In acts as controller, we retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, accounting, contractual and security requirements.
11. Data Hosting
Safe-In uses hosting infrastructure and service providers appropriate for delivering the Service.
Details concerning hosting locations and relevant subprocessors are available from Safe-In on request.
Where Safe-In makes a specific commitment concerning European or regional data hosting, that commitment is subject to the applicable contract and DPA.
12. Subprocessors and Service Providers
Safe-In may engage carefully selected service providers and subprocessors to provide infrastructure, hosting, communications, security, technical support and other functions necessary to operate the Service.
Where a subprocessor processes personal data on behalf of Safe-In's customers, Safe-In enters into appropriate contractual arrangements as required by Article 28 GDPR.
Safe-In remains responsible for managing its subprocessors in accordance with its obligations under applicable data protection law and the applicable DPA.
An up-to-date list of relevant subprocessors is available from Safe-In on request.
13. International Data Transfers
Safe-In seeks to process personal data within the European Economic Area ("EEA") where this forms part of its contractual or hosting commitments.
Where personal data is transferred to a country outside the EEA and that country has not been recognised as providing an adequate level of protection, Safe-In will use an appropriate transfer mechanism where required.
This may include the European Commission's Standard Contractual Clauses ("SCCs"), together with supplementary technical, organisational or contractual safeguards where appropriate.
14. Security
Safe-In maintains technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the Service and risk, these measures may include:
- access and authorisation controls;
- authentication controls;
- encryption in transit and, where appropriate, at rest;
- system and security logging;
- backup and recovery procedures;
- vulnerability and patch management;
- security monitoring;
- incident-management procedures;
- employee confidentiality requirements; and
- restrictions on access to production systems and personal data.
No online system can guarantee absolute security. Safe-In continually evaluates its safeguards in light of relevant risks and technological developments.
15. Personal Data Breaches
Safe-In maintains procedures for identifying, investigating and responding to security incidents.
Where Safe-In acts as a processor and becomes aware of a personal data breach affecting Customer Data, Safe-In will notify the relevant customer without undue delay in accordance with Article 33(2) GDPR and the applicable DPA.
The customer, as controller, is generally responsible for determining whether notification to a supervisory authority or affected individuals is required.
16. Sharing Personal Data
Safe-In does not sell visitor personal data.
Personal data may be disclosed only where appropriate, including to:
- the customer organisation responsible for the visitor registration;
- authorised users of that customer;
- Safe-In personnel who require access for legitimate operational purposes;
- approved subprocessors and service providers;
- professional advisers where necessary; and
- public authorities, courts or law-enforcement bodies where disclosure is required by applicable law.
Safe-In may also disclose information where necessary to establish, exercise or defend legal claims or protect the rights, security and integrity of Safe-In, its customers or other persons, subject to applicable law.
17. Visitor Photographs and Badges
Where a customer enables visitor photography or badge functionality, photographs and related visitor information may be processed to identify visitors and support site-security or visitor-management procedures.
The customer is responsible for determining whether this processing is necessary and lawful and for providing appropriate information to visitors.
A standard visitor photograph used for visual identification is not necessarily biometric data under the GDPR. If technical processing is used for the purpose of uniquely identifying an individual through biometric characteristics, additional GDPR requirements may apply.
18. Emergency and Evacuation Information
Customers may use Safe-In visitor information to determine who is present at a location during an emergency or evacuation.
Access to emergency visitor lists should be limited to authorised personnel and used only for legitimate safety and emergency-management purposes.
19. Cookies and Website Technologies
Safe-In's public website and web applications may use cookies or similar technologies necessary for operation, authentication, security and user preferences.
Where analytics, advertising or other non-essential technologies are used and applicable law requires consent, Safe-In will request consent before placing or accessing those technologies.
Further details are provided in Safe-In's Cookie Statement.
20. Children's Personal Data
Safe-In is primarily intended for business and organisational visitor management and is not directed at children.
A customer may nevertheless register a minor as a visitor where appropriate. The customer is responsible for determining the applicable legal basis and implementing any additional safeguards or parental/guardian requirements required under applicable law.
21. Automated Decision-Making
Safe-In does not, by default, use visitor information for automated decision-making that produces legal effects or similarly significantly affects individuals within the meaning of Article 22 GDPR.
If a customer configures Safe-In or an integrated third-party service to conduct such processing, the customer is responsible for ensuring that the processing complies with applicable law and that affected individuals receive required information.
22. Your GDPR Rights
Subject to the circumstances and applicable law, individuals may have the right to:
- obtain information about the processing of their personal data;
- access their personal data;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict processing;
- object to certain processing;
- receive certain personal data in a portable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data protection supervisory authority.
These rights are subject to conditions and exceptions under the GDPR and applicable national law.
23. Exercising Rights Concerning Visitor Data
If you registered as a visitor at an organisation using Safe-In, that organisation normally acts as the controller of your visitor information.
You should therefore first direct requests to access, correct, delete or otherwise exercise your rights concerning visitor information to the organisation you visited.
Where Safe-In receives such a request directly and acts as processor, we may refer the request to the relevant customer and provide reasonable assistance to that customer as required by the GDPR and our DPA.
24. Exercising Rights Where Safe-In Is Controller
Where Safe-In acts as controller of your personal data, you may submit a privacy request through the Safe-In contact form or by email to support@safe-in.com.
We may need to verify your identity before processing a request. We will respond within the time periods required by applicable data protection law.
25. Complaints
If you believe your personal data has been processed unlawfully, you may contact Safe-In or, where your request concerns visitor information, the organisation you visited.
You also have the right to lodge a complaint with the competent data protection supervisory authority. Your right to approach another competent supervisory authority under the GDPR is not affected.
26. Government and Law-Enforcement Requests
Safe-In will disclose personal data to governmental or law-enforcement authorities only where required or permitted by applicable law.
Where legally permitted and appropriate, Safe-In will assess requests for validity, scope and legal authority and seek to limit disclosure to information lawfully required.
27. Export of Personal Data
Authorised customer users may export visitor and other Customer Data from Safe-In where export functionality is available.
The customer is responsible for controlling which users have export permissions and for ensuring exported personal data is subsequently stored, transferred, accessed, retained and deleted securely and lawfully.
Once an export has been successfully transferred to an environment controlled or selected by the customer, the customer is responsible for protecting that copy, except where an incident is attributable to Safe-In's breach of its applicable legal or contractual obligations.
Export functionality does not limit any applicable right to data portability or access under the GDPR.
28. Data Deletion and Account Termination
Upon termination or expiry of a customer's subscription, Safe-In will provide for the return or retrieval of Customer Data in accordance with the applicable agreement and DPA.
Following the applicable retrieval and retention period, Safe-In will delete or anonymise Customer Data in accordance with its documented procedures, except where retention is required by law or data remains temporarily within protected backup systems pending normal deletion cycles.
29. Changes to this Privacy Statement
Safe-In may update this Privacy Statement to reflect changes to the Service, our processing activities, applicable law or regulatory guidance.
Where changes are material, Safe-In will take reasonable steps to notify affected customers or users where required.
The latest version will identify its effective date and last revision date.
30. Contact Safe-In
Questions about this Privacy Statement or Safe-In's privacy practices may be submitted through the Safe-In contact form or by email to support@safe-in.com.
