What EvTrack holds about a visitor, how consent is recorded, how long data is kept, and how to answer a person who asks about their data. To change the periods, see Privacy.
What EvTrack holds about a visitor
| Visitor profile tab | What it holds |
|---|---|
| Overview, Profile | Name, contact details, company, identity numbers and the photo |
| Credentials | QR codes, cards, faces and number plates issued to the visitor |
| Visit Pass | Their visits: dates, host, location, status |
| Vehicles | Registered vehicles |
| Events | What happened: check-ins, check-outs, doors opened |
| Declarations | The agreements they answered, with any signature |
| Documents | Uploaded files, such as the Copy of ID |
Which personal fields are collected in the first place is set under Required Fields: collect only what you need.
Consent
Consent is recorded with agreements: a privacy notice, site rules or a consent form your administrator writes. Each agreement asks for Yes or No, Agree or Disagree, or a signature, and the answers are kept in Declaration Records - see Agreements.
At a kiosk, Show Privacy Consent Before Check-in (on by default) shows a consent screen before a visitor registers; Decline returns the kiosk to its idle screen. For what happens when a document is scanned first, see Privacy Consent.
How long it is kept
EvTrack deletes old data automatically, every 30 minutes, using three periods:
| Period | What it deletes | Default (single server) | Default (EvTrack cloud) |
|---|---|---|---|
| Events (Days) | Access and movement events, visit records, statistics and expired credentials | 1095 days | 365 days |
| Audit Logs (Days) | The record of who changed what | 90 days | 31 days |
| Visitor Data (Days) | Signed agreements, and visitors with no events left | 1095 days | 365 days |
Data is deleted, not anonymised, and cannot be recovered except from your own backups. A visitor is deleted only once none of their events remain, so a visitor never goes sooner than their events: to remove visitors after 90 days, set both Events (Days) and Visitor Data (Days) to 90.
Deleting a visitor
Deleting a visitor (Visitor Management: Delete) removes their profile, photos, signature and documents at once, and cancels their visit passes. Their signed declarations and their movement events remain until the periods above remove them.
A request about personal data
There is no one-click export or “forget” button. To answer a request:
- Open the visitor’s profile and go through its tabs.
- Check Declaration Records for their agreements.
- Search the Logbook for their entries and exits; it can be exported to Excel.
- To erase, delete the visitor, and note that declarations and events follow under the retention periods.
Route every request through your organisation’s own data protection process, and keep a record of what you did.
Laws
Which laws apply depends on where you operate and whom you serve: for example POPIA in South Africa, the GDPR in the European Union and the UAE’s personal data protection law. EvTrack gives you the controls on this page; your organisation decides how to use them. This page is not legal advice.
Good habits
- Collect only the fields you need, and keep the periods no longer than your policy requires.
- Keep Visitor Management Admin Privilege : View All Visitors to the people who need it.
- Do not leave exported reports on shared drives or desks: they hold personal data too.
- Keep Show Visitor ID Numbers on Report off unless a report must identify people.