AVMS (Advanced Visitor Management System) is committed to protecting the privacy and personal
data of every individual who interacts with our platform — including visitors, hosts, operators, and
administrators. This Privacy Policy describes what data we collect, why we collect it, how it is used,
and the rights you have over your information.
1
Information We Collect
We collect the following categories of personal data in the course of providing visitor management services:
Visitor Identity Information: Full name, national ID or passport number, photograph, and any other identification document details submitted during the invitation or check-in process.
Invitation Details: Visit type, purpose of visit, host name, scheduled date and time, and the area or department being visited.
Access Transaction Data: Entry/exit timestamps, gate or door accessed, and the device used to process the transaction.
Biometric Data: Fingerprint templates or card credentials used for identity verification at access control points. This data is processed securely and never used beyond authentication purposes.
Photographs: Captured at kiosk or terminal check-in points for identity verification and archival purposes.
Device & System Data: Information about the devices (kiosks, terminals, readers) used, including device type, location within the facility, and operational logs.
Administrator Account Information: Username, role, and activity logs for system users managing the platform.
Note on Biometric Data: Fingerprint templates are stored in an encrypted format and are never shared with third parties. Processing occurs on-device or within secured infrastructure only.
2
How We Use Your Information
To register and process visitor invitations and pre-approvals.
To verify visitor identity at entry and exit points.
To control and log access to secured areas and facilities.
To enforce blacklist policies and prevent unauthorized access.
To generate attendance and transaction reports for facility management.
To maintain audit logs for security and compliance purposes.
To improve the reliability and performance of the AVMS platform.
To comply with applicable legal and regulatory obligations.
3
Sharing Your Information
With Facility Operators & Administrators: Visitor records, access logs, and invitation data are accessible to authorized personnel within the managing organization for operational and security purposes.
With Access Control Systems: When integrated with third-party access control hardware (e.g., Suprema BioStar 2, RBH systems), visitor credentials may be transmitted to those systems solely for the purpose of granting or denying physical access.
With Technology Service Providers: We may engage trusted infrastructure or hosting providers who process data on our behalf under strict data processing agreements and confidentiality obligations.
Legal Compliance: We may disclose personal data to governmental or regulatory authorities when required by applicable law, court order, or to protect the safety and security of individuals or property.
We do not sell, rent, or trade personal data to any third party for commercial purposes.
4
Data Retention
Visitor and transaction records are retained for as long as necessary to fulfill the purposes described in this policy, meet legal retention requirements, and support the security audit needs of the operating organization. Administrators may archive or delete records through the Data Archive module in accordance with their organization's data governance policies.
Active invitation and transaction data: retained for the duration of the operational period.
Archived records: accessible through the archive viewer and subject to the organization's retention schedule.
Biometric templates: deleted upon request or when a visitor's profile is removed from the system.
5
Data Security
We apply industry-standard technical and organizational measures to protect your data against unauthorized access, disclosure, alteration, or destruction. These include:
Encrypted transmission of all data between clients, servers, and access control integrations (HTTPS/TLS).
Encrypted storage of sensitive data, including biometric templates and identification documents.
Role-based access control (RBAC) limiting system access to authorized users only.
Comprehensive audit logging of all administrative actions within the platform.
Regular security reviews of infrastructure and integration components.
6
Your Rights
Depending on your jurisdiction and the applicable data protection regulations, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Rectification: Request correction of inaccurate or incomplete personal data.
Erasure: Request deletion of your personal data, subject to legal retention requirements and the policies of the operating organization.
Restriction: Request that we limit the processing of your data in certain circumstances.
Objection: Object to the processing of your data for specific purposes.
Data Portability: Request your data in a structured, machine-readable format where technically feasible.
To exercise any of these rights, please contact us using the details in Section 8. Requests will be processed in coordination with the operating organization in accordance with applicable law.
7
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the features of the AVMS platform. When we make significant changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the AVMS system following any updates constitutes acceptance of the revised policy.
8
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please reach out to us: