LEGAL & COMPLIANCE

Privacy Policy

How VeriGuest Systems manages personal information with transparency, security, and integrity.

Effective Date: June 15, 2026
Last Revised: June 15, 2026
Jurisdiction: Alberta & Canada (Federal)

1. Introduction

VeriGuest Systems ("VeriGuest", "we", "our", or "us"), a registered sole proprietorship in Alberta, Canada, respects your privacy and is committed to protecting it. This Privacy Policy explains how we collect, hold, process, disclose, and protect personal information when you visit our website (veriguest.ca), use our marketing channels, or interact with the VeriGuest Visitor Management System (VMS) software, including our Windows desktop client, Android tablet applications, and web dashboards.

We operate in strict accordance with the Alberta Personal Information Protection Act (PIPA), the Canadian federal Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable national and provincial privacy frameworks. As a provider of B2B enterprise software, we maintain high security standards to ensure our corporate clients and their end visitors remain safe and compliant.

2. Controller vs. Processor Roles

Depending on how you interact with our services, VeriGuest may act either as a Data Controller or a Data Processor. Under privacy laws like PIPA and GDPR, this distinction defines our legal duties:

The remainder of this policy applies differently depending on these roles. If you are a visitor registering at a client facility, requests to access, modify, or delete your registration data should be directed to the client organization who operates the facility.

3. Information We Collect

We collect and hold different types of information depending on whether you are a corporate customer, a website visitor, or a visitor registering at a client facility:

Category Data Elements Collected Collection Method
Account & Marketing Data
(We act as Controller)
Client name, professional email address, corporate phone number, company name, mailing address, billing details, subscriptions, and customer support communications. Provided directly by client representatives upon account registration, scheduling a demo, or initiating contact.
Website Traffic Data
(We act as Controller)
IP addresses, web browser type, operating system details, referral URLs, time spent on pages, and navigation patterns. Automatically collected via hosting logs and essential site session cookies when visiting veriguest.ca.
Visitor & Employee Logs
(We act as Processor)
Visitor names, host employee, phone/email, company name, arrival/departure timestamps, visitor badges, signed digital NDAs, health/safety declarations, and contractor certifications. Provided directly by visitors on the kiosk tablet or pre-registration web forms hosted by the Client.
Kiosk Media & Biometrics
(We act as Processor)
Optional photo capture on registration (if configured by client) and mathematical facial vectors (if facial recognition is enabled for rapid badge-less entry). Captured via the kiosk front camera during visitor check-in, subject to explicit user consent.

4. How We Use Data

We process personal information only under valid legal bases and for specified, legitimate purposes:

A. Account and Marketing Data

  • To establish, bill, and manage corporate customer accounts.
  • To deliver customer support, product training, and requested demonstrations.
  • To communicate administrative updates, security alerts, and periodic product newsletters (which you can opt out of at any time).
  • To analyze marketing site usage and improve the user experience.

B. Visitor and Employee Data (VMS Logs)

  • To verify visitor identities, notify hosts of arrival, print visitor badges, and record sign-ins for safety audits.
  • To administer digital NDAs, safety briefings, and ensure contractor compliance.
  • To execute emergency broadcasts and safety evacuations by providing real-time lists of personnel currently in the building.

We will never sell, lease, or distribute personal information to third-party brokers, nor will we use customer-managed VMS visitor logs for marketing or profiling purposes.

5. Biometrics and Photo Capture

Some client organizations configure photo badging or rapid check-in using facial verification. Because these methods require specialized attention, we enforce strict controls:

  • No Raw Photos Stored as Biometrics: If a client enables facial verification, the VeriGuest tablet analyzes the camera feed locally and converts facial features into a secure, mathematical vector representation (a hash). We do not store raw photos as biometrics; only this one-way, irreversible vector hash is saved.
  • Client-Bound Architecture: These biometric vectors are isolated within the Client's encrypted database tenant and are never shared across facilities operated by other organizations or consolidated into a global directory.
  • Explicit Consent Required: Kiosk software requires visitors to opt-in explicitly before any facial scan is processed. Visitors who decline can sign in manually without penalty or restriction.

6. Storage and Data Residency

For Canadian manufacturing, enterprise, and healthcare entities, maintaining local data residency is critical for regulatory compliance under PIPEDA, PIPA, and provincial frameworks:

  • Primary Storage Location: All client VMS databases, visitor logs, and account files are hosted in secure enterprise cloud centers located in **Montreal, Quebec, Canada** (AWS Canada Central Region).
  • No Unauthorized Transfers: Account data and visitor logs do not cross international borders without the explicit contractual authorization of the Client.
  • Local Server Options: For high-security facilities, we offer private dedicated cloud servers or hybrid deployments that keep all operational data localized behind the client's corporate firewall.

7. Data Security Protocols

VeriGuest employs a robust security program aligned with SOC 2 requirements to prevent unauthorized access, alteration, disclosure, or destruction of personal information:

  • Encryption in Transit: All data transmitted between VMS kiosk tablets, the cloud database, and administrator web dashboards is protected using TLS 1.3 encryption.
  • Encryption at Rest: All stored database tables, backup files, and system volumes are encrypted using hardware-accelerated AES-256 standard encryption.
  • Network Isolation: Client databases are hosted in isolated virtual networks (VPC) with restricted port access and strict firewall policies.
  • Role-Based Access (RBAC): Admin dashboards enforce strict user permissions. Activity logs track every access, addition, modification, or deletion of visitor logs for auditing purposes.

8. Data Retention

We hold personal data only for as long as necessary to fulfill the purposes for which it was gathered, or as mandated by statutory compliance timelines:

  • Marketing Site Submissions: Form entries and request metadata are archived or securely deleted after 36 months of inactivity.
  • VMS Visitor Logs (Client-Controlled): As Processor, VeriGuest retains check-in records at the pleasure of the Client organization. Clients can configure automatic retention rules ranging from 30 days to multiple years to meet legal audit mandates.
  • Post-Subscription Deletion: Upon the termination of a Client subscription, all database tables, visitor logs, signatures, and backups are permanently purged within 180 days.

9. Your Privacy Rights

Under Canadian federal and provincial laws (including PIPA Alberta and PIPEDA), individuals have the following legal rights regarding their personal data:

  • Right of Access: You can request a clear copy of the personal information we hold about you.
  • Right to Rectification: You have the right to correct inaccurate or incomplete details.
  • Right to Erasure: You can request that we delete your personal details, subject to active contracts, safety audits, or legal holds.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

To submit a request or raise questions, contact our Privacy Officer at info@veriguest.ca. We respond to all verified inquiries within 30 days without charge.

10. Cookie Policy

VeriGuest respects your browsing privacy. Our website utilizes **essential and functional cookies** only:

  • Essential Cookies: Required to authenticate users logging into dashboards, manage shopping carts, and block Cross-Site Request Forgery (CSRF) attacks.
  • No Tracking Pixels: We do not deploy cross-site tracking tags, Google Ads pixels, or social media remarketing beacons. Your browsing history outside veriguest.ca is never tracked.

You can adjust your browser settings to reject cookies, but doing so may impact your ability to log into administrative web portals.

11. GDPR & UK GDPR Addendum

If you reside in the European Economic Area (EEA) or the United Kingdom, we comply with the General Data Protection Regulation (GDPR). When dealing with Account and Marketing Data, VeriGuest acts as a Data Controller. For Visitor and Employee Data, our Client is the Data Controller, and we act as the Data Processor.

Legal Bases for Processing: We process your data based on your explicit consent, for the performance of a subscription contract, or under our legitimate business interests that do not override your privacy rights.

International Data Transfers: Data stored in Canada is protected under the European Commission's adequacy decisions which recognize Canada's PIPEDA framework as providing equivalent privacy protection. In instances where third-party subprocessors transfer data to other regions (such as the US), we enforce Standard Contractual Clauses (SCCs) to maintain safety standards.

12. Contact Information

Inquiries, access requests, or complaints concerning our privacy protocols should be addressed to our Privacy Officer:

  • Email Address: info@veriguest.ca
  • Mailing Address:
    VeriGuest Systems
    Attn: Privacy Officer
    Suite 200, 100 4th Ave S
    Lethbridge, Alberta, T1J 4E8
    Canada

If we are unable to resolve your concerns, you have the right to lodge a formal complaint with the **Office of the Information and Privacy Commissioner of Alberta** (at www.oipc.ab.ca) or the **Office of the Privacy Commissioner of Canada** (at www.priv.gc.ca).


© 2026 VeriGuest Systems. All rights reserved. This document constitutes a legally binding privacy notice under applicable Canadian legislation.