Built in Europe, hosted in Europe, and governed solely by European law. GDPR compliance is baked into the architecture — not bolted on. From Article 5 data minimisation to Article 17 erasure, every visit record is protected by the strongest privacy framework in the world.
US-based SaaS platforms are subject to the US CLOUD Act — which allows US authorities to compel any US company to hand over data stored anywhere in the world, regardless of EU data protection law. VisitorPass is incorporated, operated, and hosted entirely within the European Union. Only European law applies.
The Clarifying Lawful Overseas Use of Data Act (2018) allows US authorities to demand data from any US-incorporated company — regardless of where the data physically sits. A warrant in Washington can expose your visitors' personal data even if the servers are in Frankfurt. VisitorPass has no US legal presence. No CLOUD Act applies.
The Court of Justice of the EU's landmark Schrems II ruling (C-311/18) invalidated the EU-US Privacy Shield and placed significant restrictions on Standard Contractual Clauses where US surveillance law still applies. Using an entirely EU-based platform means no transfer safeguards are needed at all.
When personal data never leaves the EU, your organisation needs no adequacy decision, no Standard Contractual Clauses, no Binding Corporate Rules, and no Transfer Impact Assessment. Compliance is structural and permanent — not a contractual arrangement that can be challenged or withdrawn.
Essential and important entities under the NIS2 Directive must ensure their entire supply chain — including every SaaS tool — meets EU cybersecurity standards. VisitorPass is built, hosted, and supported entirely within the EU, with a fully documented security architecture ready for your NIS2 risk assessment.
From a single reception desk to a multi-site enterprise — VisitorPass covers every scenario without compromising on privacy.
Reception or an administrator pre-registers an expected visitor, or the visitor registers themselves from any device. Either way the visitor receives a pass e-mail with a QR code for a fast, contactless arrival.
Deploy any browser-based tablet as a fully branded self-service kiosk. Visitors type their name to check in and receive a printed or digital badge — no app download needed.
When no receptionist is physically present, the kiosk connects visitors directly to a live operator via encrypted peer-to-peer WebRTC video. The human is always in the loop — just remotely.
Every check-in can be reviewed by a receptionist or operator, whether on-site or remote. Operators receive instant notifications and decide whether to check the visitor in — keeping a person in control of every arrival.
Every tenant gets their own subdomain, uploaded logo, and full colour palette. Registration pages, digital passes, email notifications, and the kiosk all carry your identity — not ours.
Record the physical access card issued to each visitor and confirm its return at sign-out. Where your site requires it, capture a photo and a picture of the visitor's ID document at check-in. Every sign-in, sign-out and card handover is written to the visit record.
Every visit generates a pass e-mail with a QR code, host details and visit times. A signed Apple Wallet pass is attached automatically. At reception a 62 × 100 mm badge can be printed from the browser or from a connected Zebra or Brother label printer.
Manage multiple buildings and campuses (multi-site), or a shared building used by several separate companies (multi-tenant), from a single administration console. Each site and tenant has isolated data, independent branding, and its own operator team.
Hosts are alerted the moment their visitor arrives. Managers receive automated daily visitor summaries by email. Administrators can export sign-in logs as Excel spreadsheets for compliance audits.
Every image on this page was captured directly from a live VisitorPass instance. The interface you see is exactly what you and your visitors experience.
Most visitor management systems treat GDPR as a box to tick. We treat it as the specification. Every data field, every retention rule, every access log, and every deletion mechanism was designed from first principles around the Regulation's requirements — not bolted on afterwards.
Each organisation sets its own data retention period. A nightly cron job automatically anonymises identifying fields and deletes photos for checked-in visits once that window passes — no manual intervention required.
Erasure requests are recorded in the built-in request register with the statutory one-month deadline. An administrator can locate every record held on a data subject and remove the identifying fields; the erasure is written to the GDPR audit log with timestamp and operator.
Any visitor can request a complete export of their personal data. The system generates a structured, machine-readable JSON export that can be handed to the data subject or a third party within minutes.
Every data access, export, anonymisation, and modification event is written to a tamper-evident audit log. Entries include the acting user, their IP address, the affected record, and a precise UTC timestamp — ready for a supervisory authority inspection.
Visitors are presented with your organisation's Privacy Notice and EULA at registration. Acceptance is timestamped and stored alongside the visit record, providing a clear lawful basis under Article 6(1)(a).
Only the fields genuinely needed for each visit are collected. Photo capture, document scanning, and contact fields are individually toggleable per-site so you never collect more than your lawful basis permits — satisfying the principle of data minimisation enshrined in Article 5(1)(c).
All visitor data is stored and processed exclusively on EU-based servers. Personal data never crosses EU borders. There is no adequacy decision to monitor, no Standard Contractual Clauses to maintain, and no Transfer Impact Assessment to commission — because no transfer ever takes place.
VisitorPass acts as your data processor under Article 28 GDPR. A signed, legally compliant Data Processing Agreement — covering sub-processors, security obligations, and breach notification timescales — is included with every subscription, not offered as a paid extra.
Every aspect of the visitor journey carries your identity. Guests never see "VisitorPass" — they see you.
Custom domains, Apple Wallet passes, printed visitor badges, and notification emails all carry your logo and colours — configured in minutes from the admin panel.
VisitorPass includes built-in modules for room and desk bookings — all GDPR-compliant and available in all 24 EU languages.

A three-column live reception view showing visitors in the queue, expected arrivals, and everyone currently on-site — with one-click check-in and sign-out.

Browse rooms and desks, view live availability, and reserve resources in one click. Week view, day view, and list mode included.
A visitor arrives at an unstaffed reception. The kiosk connects them instantly, face to face, with a real person — your operator, wherever they happen to be working that day.
On the kiosk screen, one tap initiates a WebRTC session. No app, no account, no friction.
The operator's browser rings. They see the visitor's face and the visit record side-by-side.
The operator clicks to sign the visitor in. The kiosk prints or sends a digital badge. All encrypted end-to-end.
VisitorPass follows a defence-in-depth approach. Each layer is hardened so that even a partial breach yields nothing of value.
Passwords are hashed with bcrypt. Sessions use HttpOnly, Secure, SameSite=Strict cookies with per-IP rate limiting to prevent brute-force. A fresh session is issued on every login.
Role-based access control across six levels, from organisation administration down to individual employees. Every account is scoped to its own organisation, site or gatehouse, and cross-organisation access is re-checked on every request.
Every sensitive action — login, data export, erasure, badge issuance — is written to an immutable, tamper-evident log with actor, timestamp, and source IP. Exportable for compliance reporting.
All traffic is TLS 1.3. Visitor photos are stored outside the web root. Upload directories block PHP execution at the server level. Sensitive config values are kept outside the repository.
Responses include X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, a strict Referrer-Policy, Permissions-Policy, and HSTS to prevent downgrade attacks.
Operators can request photo capture at check-in for visual identity verification. Photos are linked to the visit record for the configured retention window and then auto-purged alongside all other personal data.
All prices are net, per calendar month, and exclude VAT. This offer is directed exclusively at businesses within the meaning of § 14 BGB and not at consumers. Monthly term, cancellable to the end of any calendar month.
All plans include GDPR tooling, 24 EU language support, and are hosted within the European Union.
The EU has 24 official languages and VisitorPass supports every one of them. Registration forms, kiosk screens, invitations, digital passes and host arrival notifications are localised throughout. Language is detected from the visitor's browser and can be switched at any time. Administrative e-mails and scheduled reports are currently English only.
VisitorPass was built in Europe, runs in Europe, and operates under European law — so your visitors' data is protected by the strongest privacy framework in the world, by default. Set up your first gatehouse in under 10 minutes.