What EvTrack holds about a visitor, how consent is recorded, how long data is kept, and how to answer a person who asks about their data. To change the periods, see Privacy.

What EvTrack holds about a visitor

Visitor profile tab What it holds
Overview, Profile Name, contact details, company, identity numbers and the photo
Credentials QR codes, cards, faces and number plates issued to the visitor
Visit Pass Their visits: dates, host, location, status
Vehicles Registered vehicles
Events What happened: check-ins, check-outs, doors opened
Declarations The agreements they answered, with any signature
Documents Uploaded files, such as the Copy of ID

Which personal fields are collected in the first place is set under Required Fields: collect only what you need.

Consent is recorded with agreements: a privacy notice, site rules or a consent form your administrator writes. Each agreement asks for Yes or No, Agree or Disagree, or a signature, and the answers are kept in Declaration Records - see Agreements.

At a kiosk, Show Privacy Consent Before Check-in (on by default) shows a consent screen before a visitor registers; Decline returns the kiosk to its idle screen. For what happens when a document is scanned first, see Privacy Consent.

How long it is kept

EvTrack deletes old data automatically, every 30 minutes, using three periods:

Period What it deletes Default (single server) Default (EvTrack cloud)
Events (Days) Access and movement events, visit records, statistics and expired credentials 1095 days 365 days
Audit Logs (Days) The record of who changed what 90 days 31 days
Visitor Data (Days) Signed agreements, and visitors with no events left 1095 days 365 days

Data is deleted, not anonymised, and cannot be recovered except from your own backups. A visitor is deleted only once none of their events remain, so a visitor never goes sooner than their events: to remove visitors after 90 days, set both Events (Days) and Visitor Data (Days) to 90.

Deleting a visitor

Deleting a visitor (Visitor Management: Delete) removes their profile, photos, signature and documents at once, and cancels their visit passes. Their signed declarations and their movement events remain until the periods above remove them.

A request about personal data

There is no one-click export or “forget” button. To answer a request:

  1. Open the visitor’s profile and go through its tabs.
  2. Check Declaration Records for their agreements.
  3. Search the Logbook for their entries and exits; it can be exported to Excel.
  4. To erase, delete the visitor, and note that declarations and events follow under the retention periods.

Route every request through your organisation’s own data protection process, and keep a record of what you did.

Laws

Which laws apply depends on where you operate and whom you serve: for example POPIA in South Africa, the GDPR in the European Union and the UAE’s personal data protection law. EvTrack gives you the controls on this page; your organisation decides how to use them. This page is not legal advice.

Good habits

  • Collect only the fields you need, and keep the periods no longer than your policy requires.
  • Keep Visitor Management Admin Privilege : View All Visitors to the people who need it.
  • Do not leave exported reports on shared drives or desks: they hold personal data too.
  • Keep Show Visitor ID Numbers on Report off unless a report must identify people.

Back to top

Copyright EvTrack. All rights reserved.

Page last modified: 2026-10-11 18:21.