GreensafeIT collect visitor information for security, health and safety, and business continuity purposes. Personal data is processed lawfully under UK GDPR Article 6(1)(f) — Legitimate Interests and, where health and safety obligations apply, Article 6(1)(c) — Legal Obligation.
Your information is retained only for as long as necessary in accordance with the storage limitation principle (UK GDPR Article 5(1)(e)) and our documented retention schedule. Visitor records are normally retained for 3 months and are then securely deleted unless a longer retention period is required for legal, regulatory, insurance, security, or incident investigation purposes.
All visitor data is protected through our ISO/IEC 27001:2022 Information Security Management System, with access restricted to authorised personnel and records disposed of securely at the end of their retention period.
For information about your personal data rights, including access, rectification, restriction or complaint rights, please request a copy of our Privacy Notice or contact our Data Protection Representative.