This page explains how Vizito handles personal data under the GDPR. It is written to help you complete a privacy or vendor review. It does not serve as legal advice.
What is the GDPR?
The General Data Protection Regulation (GDPR) is the European regulation that governs how personal data about people in the EU is collected, stored and used. It applies to organizations established in the EU, and to organizations anywhere in the world that process personal data of people in the EU.
A Visitor Management System (VMS) is squarely in scope. Every sign-in records personal data about a real person standing at your front desk: their name, who they are visiting, when they arrived, and sometimes a signature or a photo. That is exactly the kind of processing the GDPR is written for, which is why we treat it as a core requirement rather than a feature.
Is Vizito GDPR compliant?
Yes. In concrete terms:
- Your data stays in Europe. All visitor data is hosted in the European Union, on servers in Amsterdam (Netherlands) and Frankfurt (Germany).
- It is encrypted. In transit over TLS, and at rest through disk encryption.
- It is independently audited. Vizito is ISO 27001 certified. You can download our ISO 27001 certificate.
- You control what is collected. Every field in the sign-in flow is configurable, so you can collect only what you actually need.
- You control how long it is kept. Retention policies delete visitor records automatically after a period you define.
- There is a contract for it. You can download our Data Processing Agreement, which lists every sub-processor we use.
Do you have a Data Processing Agreement?
Yes. You can download our Data Processing Agreement (DPA) directly, without contacting us first.
The DPA is drafted to meet the requirements of Article 28 GDPR. It sets out the roles of controller and processor, the categories of personal data and data subjects involved, the technical and organizational security measures we apply, the sub-processors we work with, and our breach notification obligations. We commit to notifying you of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it.
If your organization needs a countersigned copy for its records, or wants to negotiate bespoke terms, contact dpo@vizito.eu.
Who is the controller and who is the processor?
This distinction matters for a visitor management system, because two different sets of data are involved.
For visitor data, you are the controller and Vizito is the processor. You decide which fields your visitors fill in, which agreements they sign, how long records are kept, and who in your organization can see them. We process that data only to deliver the service and only on your documented instructions. We never use visitor data for our own purposes, we do not sell it, and we do not use it for advertising or profiling.
For your account data, Vizito is the controller. This covers the details of the people who sign up for and administer a Vizito account: name, email address, company details, billing information, and support correspondence. How we handle that is described in our privacy policy.
What happens to visitor data?
You set the retention period, and Vizito enforces it automatically. When a visitor record passes the period you configured, it is deleted without anyone needing to remember to do it. This is how the data minimization principle of Article 5 is applied in practice, and it is the main thing a paper logbook cannot do.
Beyond automatic retention:
- Right of access. You can export a visitor’s records from the dashboard to answer a Subject Access Request.
- Right to erasure. You can locate and delete an individual visitor record at any time.
- Right to rectification. Administrators can correct entries directly in the dashboard.
- End of contract. When your agreement with Vizito ends, personal data is deleted. Our standard retention after termination is zero months. A certificate of deletion is available on request.
If you are a visitor rather than a customer and you want to know what was recorded about you, contact the organization you visited. They are the controller of that data, and we will support them in answering you.
Do you transfer data outside the EEA?
No. Vizito does not transfer personal data outside the European Economic Area unless you instruct us to do so in writing, or we are legally required to.
Every sub-processor we use contracts through an entity established in the EU or the EEA, and all visitor data is stored in Dutch and German data centres. Where a provider belongs to a wider international group and a transfer could occur, that transfer is covered by the European Commission’s standard contractual clauses and, where applicable, the EU-U.S. Data Privacy Framework.
Sub-processors
We keep the list of sub-processors deliberately short. The table below shows every third party involved in delivering Vizito, and whether it may process visitor data submitted through your sign-in flow.
| Sub-processor | Purpose | Location | May process visitor data |
|---|---|---|---|
| Leaseweb Global B.V. | Hosting of servers and data | 🇳🇱 🇩🇪 | Yes |
| BudgetSMS B.V. | SMS notifications to employees and visitors | 🇳🇱 | Yes |
| Spryng | SMS notifications to employees and visitors | 🇳🇱 | Yes |
| Vonage B.V. | SMS notifications to employees and visitors | 🇳🇱 | Yes |
| Microsoft Corporation | Email notifications | 🇮🇪 | Yes |
| Crisp IM SAS | Chat widget on our website and support tool for support@vizito.eu | 🇫🇷 | No - support conversations only |
Crisp is the only sub-processor that never receives visitor data. Its scope is limited to chat and email support, which means contact details of Vizito users and the content of the questions or bug reports they send us. No visitor registration data is transmitted to Crisp.
We inform customers in advance of any intended addition or replacement of a sub-processor, and you have 30 days to object.
Where can I find more?
- Data Processing Agreement - download the full DPA, including all schedules.
- ISO 27001 certificate - our certification, downloadable.
- Privacy policy - how Vizito handles data as a controller.
- Security policy - hosting, encryption, continuity and monitoring.
- Cookie policy - what this website stores in your browser.
- Visitor management and the GDPR - how the product supports compliance at the front desk.
Still have a question about privacy or data protection? Contact our Data Protection Officer at dpo@vizito.eu.
