GDPR Compliant by design — not by retrofit
100% EU-hosted · EU law only · No US CLOUD Act
All 24 EU Languages + 4 
Art. 17 erasure · Art. 20 portability · DPA included
Proudly European — Built, Hosted & Governed in the EU

Europe's Privacy-First Visitor Management Platform

Built in Europe, hosted in Europe, and governed solely by European law. GDPR compliance is baked into the architecture — not bolted on. From Article 5 data minimisation to Article 17 erasure, every visit record is protected by the strongest privacy framework in the world.

28
Languages supported
100%
EU-hosted data
0
Third-country transfers
Europe's Privacy-First Visitor Management Platform
EU-hosted · EU law only 🔒 GDPR (EU) 2016/679 🌍 All 24 EU Languages + 4  📜 Art. 17 Right to Erasure 🛡️ Art. 5 Data Minimisation 📦 Art. 20 Data Portability ⚖️ No US CLOUD Act exposure ✅ Schrems II safe 📋 DPA included 🚫 No third-party resources, no tracking cookies
Data Sovereignty & Legal Certainty

Why a European platform is not optional

US-based SaaS platforms are subject to the US CLOUD Act — which allows US authorities to compel any US company to hand over data stored anywhere in the world, regardless of EU data protection law. VisitorPass is incorporated, operated, and hosted entirely within the European Union. Only European law applies.

Data sovereignty question VisitorPass US-incorporated provider
Data stored within the EU?✓ AlwaysVaries
Subject to US CLOUD Act?✗ Never✓ Yes
Art. 44–49: no transfers needed?✓ None required✗ Required
1

The US CLOUD Act is a real, live risk

The Clarifying Lawful Overseas Use of Data Act (2018) allows US authorities to demand data from any US-incorporated company — regardless of where the data physically sits. A warrant in Washington can expose your visitors' personal data even if the servers are in Frankfurt. VisitorPass has no US legal presence. No CLOUD Act applies.

2

Schrems II invalidated most US transfer safeguards

The Court of Justice of the EU's landmark Schrems II ruling (C-311/18) invalidated the EU-US Privacy Shield and placed significant restrictions on Standard Contractual Clauses where US surveillance law still applies. Using an entirely EU-based platform means no transfer safeguards are needed at all.

3

Articles 44–49 GDPR: no exceptions required

When personal data never leaves the EU, your organisation needs no adequacy decision, no Standard Contractual Clauses, no Binding Corporate Rules, and no Transfer Impact Assessment. Compliance is structural and permanent — not a contractual arrangement that can be challenged or withdrawn.

4

NIS2 supply-chain due diligence simplified

Essential and important entities under the NIS2 Directive must ensure their entire supply chain — including every SaaS tool — meets EU cybersecurity standards. VisitorPass is built, hosted, and supported entirely within the EU, with a fully documented security architecture ready for your NIS2 risk assessment.

Platform capabilities

Everything you need, nothing you don't

From a single reception desk to a multi-site enterprise — VisitorPass covers every scenario without compromising on privacy.

Pre-registration & Invitations

Reception or an administrator pre-registers an expected visitor, or the visitor registers themselves from any device. Either way the visitor receives a pass e-mail with a QR code for a fast, contactless arrival.

Web Kiosk & Self Check-in

Deploy any browser-based tablet as a fully branded self-service kiosk. Visitors type their name to check in and receive a printed or digital badge — no app download needed.

Face-to-Face Video (WebRTC)

When no receptionist is physically present, the kiosk connects visitors directly to a live operator via encrypted peer-to-peer WebRTC video. The human is always in the loop — just remotely.

Human in the Middle

Every check-in can be reviewed by a receptionist or operator, whether on-site or remote. Operators receive instant notifications and decide whether to check the visitor in — keeping a person in control of every arrival.

Custom Domain, Logo & Brand Colours

Every tenant gets their own subdomain, uploaded logo, and full colour palette. Registration pages, digital passes, email notifications, and the kiosk all carry your identity — not ours.

Access Cards & Identity Checks

Record the physical access card issued to each visitor and confirm its return at sign-out. Where your site requires it, capture a photo and a picture of the visitor's ID document at check-in. Every sign-in, sign-out and card handover is written to the visit record.

Digital Visitor Passes

Every visit generates a pass e-mail with a QR code, host details and visit times. A signed Apple Wallet pass is attached automatically. At reception a 62 × 100 mm badge can be printed from the browser or from a connected Zebra or Brother label printer.

Multi-site & Multi-tenant

Manage multiple buildings and campuses (multi-site), or a shared building used by several separate companies (multi-tenant), from a single administration console. Each site and tenant has isolated data, independent branding, and its own operator team.

Host Notifications & Daily Reports

Hosts are alerted the moment their visitor arrives. Managers receive automated daily visitor summaries by email. Administrators can export sign-in logs as Excel spreadsheets for compliance audits.

Real screenshots — no mock-ups

See it in action

Every image on this page was captured directly from a live VisitorPass instance. The interface you see is exactly what you and your visitors experience.

Admin panel — today's visitors
Admin panel — today's visitors
Gatehouse kiosk — self check-in on any tablet
Gatehouse kiosk — self check-in on any tablet
Pre-registration — new visit modal
Pre-registration — new visit modal
Visitor self-registration on mobile
Visitor self-registration on mobile
Visitor self check-in (mobile)
Visitor self check-in (mobile)
Digital visitor pass — Apple Wallet compatible
Digital visitor pass — Apple Wallet compatible
GDPR (EU) 2016/679 — Article by Article

Compliance isn't a feature. It's the foundation.

Most visitor management systems treat GDPR as a box to tick. We treat it as the specification. Every data field, every retention rule, every access log, and every deletion mechanism was designed from first principles around the Regulation's requirements — not bolted on afterwards.

Configurable Retention & Auto-Purge

Each organisation sets its own data retention period. A nightly cron job automatically anonymises identifying fields and deletes photos for checked-in visits once that window passes — no manual intervention required.

Right to Erasure (Article 17)

Erasure requests are recorded in the built-in request register with the statutory one-month deadline. An administrator can locate every record held on a data subject and remove the identifying fields; the erasure is written to the GDPR audit log with timestamp and operator.

Data Portability (Article 20)

Any visitor can request a complete export of their personal data. The system generates a structured, machine-readable JSON export that can be handed to the data subject or a third party within minutes.

Immutable GDPR Audit Log

Every data access, export, anonymisation, and modification event is written to a tamper-evident audit log. Entries include the acting user, their IP address, the affected record, and a precise UTC timestamp — ready for a supervisory authority inspection.

Consent Capture & EULA Acceptance

Visitors are presented with your organisation's Privacy Notice and EULA at registration. Acceptance is timestamped and stored alongside the visit record, providing a clear lawful basis under Article 6(1)(a).

Data Minimisation by Default (Article 5(1)(c))

Only the fields genuinely needed for each visit are collected. Photo capture, document scanning, and contact fields are individually toggleable per-site so you never collect more than your lawful basis permits — satisfying the principle of data minimisation enshrined in Article 5(1)(c).

No Third-Country Data Transfers (Articles 44–49)

All visitor data is stored and processed exclusively on EU-based servers. Personal data never crosses EU borders. There is no adequacy decision to monitor, no Standard Contractual Clauses to maintain, and no Transfer Impact Assessment to commission — because no transfer ever takes place.

Data Processing Agreement Provided (Article 28)

VisitorPass acts as your data processor under Article 28 GDPR. A signed, legally compliant Data Processing Agreement — covering sub-processors, security obligations, and breach notification timescales — is included with every subscription, not offered as a paid extra.

GDPR at a Glance

Art. 5 — Lawful basis recorded for every collection
Art. 5(1)(e) — Retention limited to the period you define
Art. 5(1)(e) — Automated nightly hard purge of expired records
Art. 5(1)(c) — Data minimisation toggles per site
Art. 6(1)(a) — Consent captured and timestamped
Art. 13/14 — Privacy notice presented at registration
Art. 17 — Right to Erasure: request register with statutory deadline
Art. 20 — Data Portability: JSON export on demand
Art. 25 — Privacy by design and by default
Art. 28 — Signed DPA included with every subscription
Art. 30 — Records of processing activities maintained
Art. 32 — bcrypt password hashing, TLS 1.3 in transit, access-controlled photo storage
Art. 44–49 — No third-country transfers, ever
No US CLOUD Act exposure — EU company, EU servers
Schrems II safe — no transfer safeguards needed
Immutable audit log with actor, IP, and UTC timestamp
Visitor photos purged independently on schedule
Sessions: SameSite=Strict, HttpOnly, Secure cookies
Applicable EU Legal Framework
GDPR (EU) 2016/679 ePrivacy 2002/58/EC NIS2 (EU) 2022/2555
GDPR admin panel — data search, erasure, and audit log
GDPR admin panel — data search, erasure, and audit log
White-label & Multi-tenant

Your brand. Your domain. Your colours.

Every aspect of the visitor journey carries your identity. Guests never see "VisitorPass" — they see you.

Branding settings — custom logo and colour configuration
Branding settings — custom logo and colour configuration

Your brand. Your domain. Your colours.

Custom domains, Apple Wallet passes, printed visitor badges, and notification emails all carry your logo and colours — configured in minutes from the admin panel.

Custom domainvisitors.acme.com
Brand colour■ #2563EB
Logo on passes✓ Enabled
Email sender nameAcme Visitor
Beyond visitor management

Modules for your whole team

VisitorPass includes built-in modules for room and desk bookings — all GDPR-compliant and available in all 28 languages.

Operator station — live reception management

Operator Station

A three-column live reception view showing visitors in the queue, expected arrivals, and everyone currently on-site — with one-click check-in and sign-out.

Space bookings — browse and reserve resources

Space Bookings

Browse rooms and desks, view live availability, and reserve resources in one click. Week view, day view, and list mode included.

WebRTC · Peer-to-peer encrypted

Face to face, wherever you are

A visitor arrives at an unstaffed reception. The kiosk connects them instantly, face to face, with a real person — your operator, wherever they happen to be working that day.

1
Visitor presses "Call Reception"

On the kiosk screen, one tap initiates a WebRTC session. No app, no account, no friction.

2
Operator receives a live video alert

The operator's browser rings. They see the visitor's face and the visit record side-by-side.

3
Entry approved, pass issued

The operator clicks to sign the visitor in. The kiosk prints or sends a digital badge. All encrypted end-to-end.

Operator station — three-column visitor management view
Operator station — three-column visitor management view
Safety & Security

Security first — not an afterthought

VisitorPass follows a defence-in-depth approach. Each layer is hardened so that even a partial breach yields nothing of value.

Passwords & Sessions

Passwords are hashed with bcrypt. Sessions use HttpOnly, Secure, SameSite=Strict cookies with per-IP rate limiting to prevent brute-force. A fresh session is issued on every login.

Access Control & Roles

Role-based access control across six levels, from organisation administration down to individual employees. Every account is scoped to its own organisation, site or gatehouse, and cross-organisation access is re-checked on every request.

Audit Trails & Logging

Every sensitive action — login, data export, erasure, badge issuance — is written to an immutable, tamper-evident log with actor, timestamp, and source IP. Exportable for compliance reporting.

Transport & Storage Encryption

All traffic is TLS 1.3. Visitor photos are stored outside the web root. Upload directories block PHP execution at the server level. Sensitive config values are kept outside the repository.

Hardened HTTP Headers

Responses include X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, a strict Referrer-Policy, Permissions-Policy, and HSTS to prevent downgrade attacks.

Identity Verification

Operators can request photo capture at check-in for visual identity verification. Photos are linked to the visit record for the configured retention window and then auto-purged alongside all other personal data.

Simple, transparent pricing

Pay per gatehouse. No hidden fees.

All prices are net, per calendar month, and exclude VAT. This offer is directed exclusively at businesses within the meaning of § 14 BGB and not at consumers. Monthly term, cancellable to the end of any calendar month.

Starter
Essential visitor logging for a single reception. Community branding, no white-labelling.
€19 / month base
+ €39 / gatehouse / month
Visitor sign-in & sign-out
Host email notifications
GDPR-compliant data retention
28 languages supported
No custom logo & colours
No custom domain
No WebRTC video reception
No Apple Wallet passes
Get started or talk to sales
Enterprise
Large corporations, government, and regulated industries with bespoke requirements and SLA obligations.
€1,499 / month base
Gatehouse pricing quoted individually
Everything in Business
Negotiated contract & SLA
On-premises deployment on request
Integration projects scoped individually
Dedicated account manager
Custom data processing agreement
Volume discounts
Talk to sales or get started yourself

All plans include GDPR tooling, support for all 28 languages, and are hosted within the European Union.

Every visitor, in their own language.

The EU has 24 official languages and VisitorPass supports every one of them, plus Turkish, Russian, Arabic and Hebrew. Registration forms, kiosk screens, invitations, digital passes and host arrival notifications are localised throughout. Language is detected from the visitor's browser and can be switched at any time. Administrative e-mails and scheduled reports are currently English only.

English
en
Deutsch
de
Français
fr
Italiano
it
Español
es
Nederlands
nl
Polski
pl
Čeština
cs
Slovenčina
sk
Magyar
hu
Română
ro
Български
bg
Ελληνικά
el
Hrvatski
hr
Slovenščina
sl
Svenska
sv
Dansk
da
Suomi
fi
Eesti
et
Latviešu
lv
Lietuvių
lt
Português
pt
Gaeilge
ga
Malti
mt
GDPR is the law. Make compliance the easy part.

European organisations deserve a European platform.

VisitorPass was built in Europe, runs in Europe, and operates under European law — so your visitors' data is protected by the strongest privacy framework in the world, by default. Set up your first gatehouse in under 10 minutes.

Get started Talk to sales