Safety & data

Visitor data and GDPR.

How retention, automatic anonymization, export and deletion work — and where the data processing agreement lives.

Last updated 23 August 2026

All guides

For visitor data, your organization is the data controller and ReadyLive Technologies is the processor. The legal basis is set out in the data processing agreement; this article is the practical side.

Retention

Each office has its own retention window, set under Offices → Data retention (the default is 90 days). When a visit record passes that window it is automatically anonymized by a nightly job: name, company, email, phone and license plate are removed, and only non-identifying statistics remain. No manual step is required. Visitor photos and agreement signatures are deleted outright at the same moment — they are never anonymized, they are gone.

What is collected

The check-in flow is configurable per office: name is always collected; company, email, phone and license plate are optional per office — except that an email address is required where evacuation safety links are used, because it's the channel that reaches a visitor in an emergency. Check-in and check-out times and the host visited are always recorded.

Two further steps are available per office, both off by default. A visitor photo can be requested or required at check-in; it is stored in encrypted private storage, shown to the host and in the visitor log, and is never exposed on a public URL. A visitor agreement can require the visitor to read a document and accept it with a typed name and/or a drawn signature; each acceptance is stored against the exact version the visitor read, and versions are immutable once published.

Export and deletion

Organization owners can do both themselves, at any time, under Account → Billing → Data & privacy. Export builds a complete archive of your organization — every table as machine-readable JSON plus all stored images (visitor photos, agreement signatures, office covers and kiosk media) — and gives you a private download link that expires after 15 minutes. Delete removes the entire organization: every record and every stored file, immediately and permanently, and cancels any subscription. It asks you to type the organization name and confirm you understand it cannot be undone.

To remove one visitor's data before the retention window passes, open the visit in the visitor log and choose to erase the visitor. If you'd rather we handle an export or deletion for you, see Support. Where an organization ends without deleting its data, all personal data is deleted following a 30-day grace period.

Where data lives

The primary database and backend are hosted in the EU. The full list of subprocessors — who processes what, and where — is maintained on the subprocessor page. Chat platforms (Slack, Teams, Google Chat, Discord) only receive arrival notifications if your organization actively connects that channel.

Visitors exercising their GDPR rights (access, erasure, objection) should contact your organization directly — you are the controller for their visit record. We assist you with those requests without undue delay.

More in Safety & data