VMS Platform Privacy Policy

Applies to the VMS login and platform · Version VMS-PLATFORM-2026-06
Visitor Privacy Policy

Policy Version: DPDP-V1-2026-06
Effective Date: 01-JUNE-2026
Company: ShreeRaj App Developer

1. Purpose of This Policy

ShreeRaj App Developer respects the privacy of visitors, vendors, contractors, candidates, service providers, and other persons entering its premises.

This policy explains what personal data is collected through the Visitor Management System (VMS), why it is required, how it is protected, how long it is retained, and how visitors may exercise their privacy rights.

2. Personal Data We Collect

Depending on the nature of the visit, we may collect:

* First name and last name
* Optional mobile number
* Visitor photograph
* Visitor company or vendor name
* Government-issued or company-issued ID name
* ID card number and image
* Department and employee being visited
* Purpose of visit
* Visit request, approval, rejection, check-in, and check-out details
* Date, time, unit, and location of the visit
* Visitor consent records and written consent references
* Communications sent through WhatsApp, email, or other approved channels
* Security and activity records connected with the visit

Please avoid providing personal information that is not required for visitor verification or premises security.

3. Purpose of Processing

Visitor personal data may be processed for:

* Verifying visitor identity
* Protecting employees, visitors, assets, and premises
* Obtaining approval from the concerned host or department
* Managing visitor check-in and check-out
* Printing visitor passes
* Contacting visitors during emergencies or extended visits
* Maintaining visitor and security records
* Investigating security incidents
* Responding to privacy requests or grievances
* Meeting applicable legal, regulatory, audit, and security requirements
* Enabling faster check-in during future visits, where consent has been provided

Visitor data will not be used for unrelated advertising or marketing without separate consent.

4. Consent

Where consent is required, visitors may provide consent through:

* WhatsApp Consent / Pass ID verification; or
* Written consent signed by the visitor.

Consent must be freely given, specific, informed, and capable of being withdrawn.

Visitors who do not wish to create a reusable visitor profile may contact the security team or company Admin to understand available alternatives.

Withdrawal of consent will not affect processing already completed lawfully or records that must be retained for legitimate security, legal, or regulatory purposes.

5. Visitor Photographs and Identity Documents

Visitor photographs and ID details are collected only when required for identity verification and premises security.

ID information must not be copied, downloaded, shared, or used by authorised users for purposes unrelated to visitor management.

Photographs and uploaded ID images are protected using access controls and encryption. Access is limited to authorised personnel according to their assigned roles.

6. WhatsApp and Email Communications

Where configured, VMS may send messages concerning:

* Consent and Pass ID verification
* Visit approval or rejection
* Permission to enter
* Check-in and check-out confirmation
* Privacy requests and grievances
* Important security-related updates

Messages are sent using the selected company’s configured communication service. Visitors should not send unnecessary sensitive personal information through WhatsApp or email.

7. Data Sharing

Visitor personal data may be accessed by authorised personnel, including:

* Security personnel
* The employee or department being visited
* Authorised company administrators
* Personnel responsible for privacy requests, grievances, investigations, or legal compliance
* Approved service providers supporting VMS operations

Personal data will not be sold.

Data may be disclosed to government authorities, law-enforcement agencies, courts, or regulators where required by applicable law or a lawful order.

8. Data Security

Reasonable technical and organisational safeguards are used to protect visitor data, including:

* Role-based access controls
* Password security requirements
* Encryption of sensitive database fields
* Encryption of visitor photographs and ID images
* Masking of mobile numbers and ID details where full visibility is unnecessary
* Activity and security logging
* Limited-duration approval and photograph links
* Controlled privacy-erasure procedures
* Security incident recording and response processes
* Periodic backups and access reviews

Visitors should immediately report suspected misuse, unauthorised disclosure, or incorrect personal data.

9. Data Retention

Visitor data is retained only for the period necessary for security, legal, operational, or regulatory purposes.

The standard retention periods are:

* Visitor profile: 365 days
* Visitor photograph and ID images: 180 days
* Visit and premises-entry records: 1095 days
* Consent and privacy-request records: As required to demonstrate compliance
* Security incident records: As required for investigation and legal obligations

When personal data is no longer required, it will be erased or anonymised according to the approved company process.

After a visitor profile is erased, limited anonymised visit evidence may remain, such as visit date, time, duration, department, purpose, and an anonymous visitor reference. This helps maintain premises-security evidence without retaining the visitor’s identity.

10. Visitor Rights

Subject to applicable law, visitors may request:

* Information about their personal data
* Correction of inaccurate or incomplete data
* Erasure of personal data that is no longer required
* Withdrawal of consent
* Details concerning the handling of their privacy request
* Submission of a grievance

Visitors may initiate a request through the VMS Visitor Portal, by sending Remove Consent through the approved WhatsApp channel, or by contacting the company Admin.

Identity verification may be required before processing a privacy request.

11. Grievance Handling

Visitors may submit privacy-related concerns through the VMS Visitor Portal or contact company admin contact details provided:

A grievance reference number will be provided where applicable. The company will review and respond according to its approved grievance-handling process and applicable law.

12. Children and Persons Requiring a Lawful Guardian

Where a visitor is a child or requires assistance from a lawful guardian, the company may require verifiable consent from the parent or lawful guardian before processing personal data, except where processing is otherwise permitted by applicable law.

13. Responsibilities of Authorised Users

Authorised VMS users must:

* Access visitor data only when required for assigned duties
* Keep login credentials confidential
* Avoid copying or sharing visitor data outside approved processes
* Use masked data wherever full details are unnecessary
* Report suspected privacy or security incidents immediately
* Follow company retention, correction, and erasure procedures

Unauthorised access, disclosure, or misuse may result in disciplinary or legal action.

14. Policy Updates

This policy may be updated to reflect changes in legal requirements, security practices, or VMS operations.

The latest published version and effective date will be displayed in VMS. Significant changes may require a renewed visitor notice or consent where applicable.

15. Applicable Law

This policy is intended to support compliance with applicable Indian privacy and information-security requirements, including the Digital Personal Data Protection Act, 2023 and applicable rules.

Contact

For questions regarding this policy or the processing of visitor personal data, contact:

ShreeRaj App Developer
srcloudapps@gmail.com