VMS Platform Privacy Policy
Applies to the VMS login and platform · Version VMS-PLATFORM-2026-06
Visitor Privacy Policy
Policy Version: DPDP-V1-2026-06
Effective Date: 01-JUNE-2026
Company: ShreeRaj App Developer
1. Purpose of This Policy
ShreeRaj App Developer respects the privacy of visitors, vendors, contractors, candidates, service providers, and other persons entering its premises.
This policy explains what personal data is collected through the Visitor Management System (VMS), why it is required, how it is protected, how long it is retained, and how visitors may exercise their privacy rights.
2. Personal Data We Collect
Depending on the nature of the visit, we may collect:
* First name and last name
* Optional mobile number
* Visitor photograph
* Visitor company or vendor name
* Government-issued or company-issued ID name
* ID card number and image
* Department and employee being visited
* Purpose of visit
* Visit request, approval, rejection, check-in, and check-out details
* Date, time, unit, and location of the visit
* Visitor consent records and written consent references
* Communications sent through WhatsApp, email, or other approved channels
* Security and activity records connected with the visit
Please avoid providing personal information that is not required for visitor verification or premises security.
3. Purpose of Processing
Visitor personal data may be processed for:
* Verifying visitor identity
* Protecting employees, visitors, assets, and premises
* Obtaining approval from the concerned host or department
* Managing visitor check-in and check-out
* Printing visitor passes
* Contacting visitors during emergencies or extended visits
* Maintaining visitor and security records
* Investigating security incidents
* Responding to privacy requests or grievances
* Meeting applicable legal, regulatory, audit, and security requirements
* Enabling faster check-in during future visits, where consent has been provided
Visitor data will not be used for unrelated advertising or marketing without separate consent.
4. Consent
Where consent is required, visitors may provide consent through:
* WhatsApp Consent / Pass ID verification; or
* Written consent signed by the visitor.
Consent must be freely given, specific, informed, and capable of being withdrawn.
Visitors who do not wish to create a reusable visitor profile may contact the security team or company Admin to understand available alternatives.
Withdrawal of consent will not affect processing already completed lawfully or records that must be retained for legitimate security, legal, or regulatory purposes.
5. Visitor Photographs and Identity Documents
Visitor photographs and ID details are collected only when required for identity verification and premises security.
ID information must not be copied, downloaded, shared, or used by authorised users for purposes unrelated to visitor management.
Photographs and uploaded ID images are protected using access controls and encryption. Access is limited to authorised personnel according to their assigned roles.
6. WhatsApp and Email Communications
Where configured, VMS may send messages concerning:
* Consent and Pass ID verification
* Visit approval or rejection
* Permission to enter
* Check-in and check-out confirmation
* Privacy requests and grievances
* Important security-related updates
Messages are sent using the selected company’s configured communication service. Visitors should not send unnecessary sensitive personal information through WhatsApp or email.
7. Data Sharing
Visitor personal data may be accessed by authorised personnel, including:
* Security personnel
* The employee or department being visited
* Authorised company administrators
* Personnel responsible for privacy requests, grievances, investigations, or legal compliance
* Approved service providers supporting VMS operations
Personal data will not be sold.
Data may be disclosed to government authorities, law-enforcement agencies, courts, or regulators where required by applicable law or a lawful order.
8. Data Security
Reasonable technical and organisational safeguards are used to protect visitor data, including:
* Role-based access controls
* Password security requirements
* Encryption of sensitive database fields
* Encryption of visitor photographs and ID images
* Masking of mobile numbers and ID details where full visibility is unnecessary
* Activity and security logging
* Limited-duration approval and photograph links
* Controlled privacy-erasure procedures
* Security incident recording and response processes
* Periodic backups and access reviews
Visitors should immediately report suspected misuse, unauthorised disclosure, or incorrect personal data.
9. Data Retention
Visitor data is retained only for the period necessary for security, legal, operational, or regulatory purposes.
The standard retention periods are:
* Visitor profile: 365 days
* Visitor photograph and ID images: 180 days
* Visit and premises-entry records: 1095 days
* Consent and privacy-request records: As required to demonstrate compliance
* Security incident records: As required for investigation and legal obligations
When personal data is no longer required, it will be erased or anonymised according to the approved company process.
After a visitor profile is erased, limited anonymised visit evidence may remain, such as visit date, time, duration, department, purpose, and an anonymous visitor reference. This helps maintain premises-security evidence without retaining the visitor’s identity.
10. Visitor Rights
Subject to applicable law, visitors may request:
* Information about their personal data
* Correction of inaccurate or incomplete data
* Erasure of personal data that is no longer required
* Withdrawal of consent
* Details concerning the handling of their privacy request
* Submission of a grievance
Visitors may initiate a request through the VMS Visitor Portal, by sending Remove Consent through the approved WhatsApp channel, or by contacting the company Admin.
Identity verification may be required before processing a privacy request.
11. Grievance Handling
Visitors may submit privacy-related concerns through the VMS Visitor Portal or contact company admin contact details provided:
A grievance reference number will be provided where applicable. The company will review and respond according to its approved grievance-handling process and applicable law.
12. Children and Persons Requiring a Lawful Guardian
Where a visitor is a child or requires assistance from a lawful guardian, the company may require verifiable consent from the parent or lawful guardian before processing personal data, except where processing is otherwise permitted by applicable law.
13. Responsibilities of Authorised Users
Authorised VMS users must:
* Access visitor data only when required for assigned duties
* Keep login credentials confidential
* Avoid copying or sharing visitor data outside approved processes
* Use masked data wherever full details are unnecessary
* Report suspected privacy or security incidents immediately
* Follow company retention, correction, and erasure procedures
Unauthorised access, disclosure, or misuse may result in disciplinary or legal action.
14. Policy Updates
This policy may be updated to reflect changes in legal requirements, security practices, or VMS operations.
The latest published version and effective date will be displayed in VMS. Significant changes may require a renewed visitor notice or consent where applicable.
15. Applicable Law
This policy is intended to support compliance with applicable Indian privacy and information-security requirements, including the Digital Personal Data Protection Act, 2023 and applicable rules.
Contact
For questions regarding this policy or the processing of visitor personal data, contact:
ShreeRaj App Developer
srcloudapps@gmail.com
Policy Version: DPDP-V1-2026-06
Effective Date: 01-JUNE-2026
Company: ShreeRaj App Developer
1. Purpose of This Policy
ShreeRaj App Developer respects the privacy of visitors, vendors, contractors, candidates, service providers, and other persons entering its premises.
This policy explains what personal data is collected through the Visitor Management System (VMS), why it is required, how it is protected, how long it is retained, and how visitors may exercise their privacy rights.
2. Personal Data We Collect
Depending on the nature of the visit, we may collect:
* First name and last name
* Optional mobile number
* Visitor photograph
* Visitor company or vendor name
* Government-issued or company-issued ID name
* ID card number and image
* Department and employee being visited
* Purpose of visit
* Visit request, approval, rejection, check-in, and check-out details
* Date, time, unit, and location of the visit
* Visitor consent records and written consent references
* Communications sent through WhatsApp, email, or other approved channels
* Security and activity records connected with the visit
Please avoid providing personal information that is not required for visitor verification or premises security.
3. Purpose of Processing
Visitor personal data may be processed for:
* Verifying visitor identity
* Protecting employees, visitors, assets, and premises
* Obtaining approval from the concerned host or department
* Managing visitor check-in and check-out
* Printing visitor passes
* Contacting visitors during emergencies or extended visits
* Maintaining visitor and security records
* Investigating security incidents
* Responding to privacy requests or grievances
* Meeting applicable legal, regulatory, audit, and security requirements
* Enabling faster check-in during future visits, where consent has been provided
Visitor data will not be used for unrelated advertising or marketing without separate consent.
4. Consent
Where consent is required, visitors may provide consent through:
* WhatsApp Consent / Pass ID verification; or
* Written consent signed by the visitor.
Consent must be freely given, specific, informed, and capable of being withdrawn.
Visitors who do not wish to create a reusable visitor profile may contact the security team or company Admin to understand available alternatives.
Withdrawal of consent will not affect processing already completed lawfully or records that must be retained for legitimate security, legal, or regulatory purposes.
5. Visitor Photographs and Identity Documents
Visitor photographs and ID details are collected only when required for identity verification and premises security.
ID information must not be copied, downloaded, shared, or used by authorised users for purposes unrelated to visitor management.
Photographs and uploaded ID images are protected using access controls and encryption. Access is limited to authorised personnel according to their assigned roles.
6. WhatsApp and Email Communications
Where configured, VMS may send messages concerning:
* Consent and Pass ID verification
* Visit approval or rejection
* Permission to enter
* Check-in and check-out confirmation
* Privacy requests and grievances
* Important security-related updates
Messages are sent using the selected company’s configured communication service. Visitors should not send unnecessary sensitive personal information through WhatsApp or email.
7. Data Sharing
Visitor personal data may be accessed by authorised personnel, including:
* Security personnel
* The employee or department being visited
* Authorised company administrators
* Personnel responsible for privacy requests, grievances, investigations, or legal compliance
* Approved service providers supporting VMS operations
Personal data will not be sold.
Data may be disclosed to government authorities, law-enforcement agencies, courts, or regulators where required by applicable law or a lawful order.
8. Data Security
Reasonable technical and organisational safeguards are used to protect visitor data, including:
* Role-based access controls
* Password security requirements
* Encryption of sensitive database fields
* Encryption of visitor photographs and ID images
* Masking of mobile numbers and ID details where full visibility is unnecessary
* Activity and security logging
* Limited-duration approval and photograph links
* Controlled privacy-erasure procedures
* Security incident recording and response processes
* Periodic backups and access reviews
Visitors should immediately report suspected misuse, unauthorised disclosure, or incorrect personal data.
9. Data Retention
Visitor data is retained only for the period necessary for security, legal, operational, or regulatory purposes.
The standard retention periods are:
* Visitor profile: 365 days
* Visitor photograph and ID images: 180 days
* Visit and premises-entry records: 1095 days
* Consent and privacy-request records: As required to demonstrate compliance
* Security incident records: As required for investigation and legal obligations
When personal data is no longer required, it will be erased or anonymised according to the approved company process.
After a visitor profile is erased, limited anonymised visit evidence may remain, such as visit date, time, duration, department, purpose, and an anonymous visitor reference. This helps maintain premises-security evidence without retaining the visitor’s identity.
10. Visitor Rights
Subject to applicable law, visitors may request:
* Information about their personal data
* Correction of inaccurate or incomplete data
* Erasure of personal data that is no longer required
* Withdrawal of consent
* Details concerning the handling of their privacy request
* Submission of a grievance
Visitors may initiate a request through the VMS Visitor Portal, by sending Remove Consent through the approved WhatsApp channel, or by contacting the company Admin.
Identity verification may be required before processing a privacy request.
11. Grievance Handling
Visitors may submit privacy-related concerns through the VMS Visitor Portal or contact company admin contact details provided:
A grievance reference number will be provided where applicable. The company will review and respond according to its approved grievance-handling process and applicable law.
12. Children and Persons Requiring a Lawful Guardian
Where a visitor is a child or requires assistance from a lawful guardian, the company may require verifiable consent from the parent or lawful guardian before processing personal data, except where processing is otherwise permitted by applicable law.
13. Responsibilities of Authorised Users
Authorised VMS users must:
* Access visitor data only when required for assigned duties
* Keep login credentials confidential
* Avoid copying or sharing visitor data outside approved processes
* Use masked data wherever full details are unnecessary
* Report suspected privacy or security incidents immediately
* Follow company retention, correction, and erasure procedures
Unauthorised access, disclosure, or misuse may result in disciplinary or legal action.
14. Policy Updates
This policy may be updated to reflect changes in legal requirements, security practices, or VMS operations.
The latest published version and effective date will be displayed in VMS. Significant changes may require a renewed visitor notice or consent where applicable.
15. Applicable Law
This policy is intended to support compliance with applicable Indian privacy and information-security requirements, including the Digital Personal Data Protection Act, 2023 and applicable rules.
Contact
For questions regarding this policy or the processing of visitor personal data, contact:
ShreeRaj App Developer
srcloudapps@gmail.com