Gfacility

Questionnaire

Visitor policy

Who do you let in, which data do you record, which notifications do you send and which compliance requirements apply? Visitors touch safety, privacy and first impression at once.

Updated May 18, 2026

Questionnaire · 4.5

Why this now

Visitors are where marketing (first impression), security (access) and privacy (GDPR) meet. A badly designed kiosk flow means a messy lobby, complaining reception or a data breach with reporting obligation. The policy here directly determines which screens you later activate in the Visitor module.

What do you deliver?

Visitor types

Standard, supplier, contractor, candidate, VIP, event — with separate rules.

Pre-registration policy

Mandatory/optional, which data, which invitation template.

Kiosk flow

Walk-in vs scheduled arrival, ID check, photo, badge print.

Compliance & retention

Which data, how long, on which legal basis — aligned with DPO.

Key questions

  1. 1Which visitor types do you distinguish? Does handling differ between customer, supplier, contractor, candidate?
  2. 2Pre-registration — mandatory or optional? Who can invite someone (any employee, only managers, only reception)?
  3. 3Which data do you collect at pre-registration? Name, email, company, phone — and the sensitive: licence plate, clothing size (event badges), allergies?
  4. 4Invitation — which template, which language (host's or visitor's?), with which instructions (parking, directions, dress code)?
  5. 5Arrival — registration via kiosk, via reception, or both? Walk-ins allowed?
  6. 6Identification — ID check required, take a photo, print badge with photo, anonymous badge? Does it differ per location or visitor type?
  7. 7NDA / house rules — must the visitor sign or accept something? Once or every time?
  8. 8Notifications — who gets notified on arrival? Only the host, or also reception/security? Which channel (Teams, email, SMS, app push)?
  9. 9Departure & check-out — active check-out on leaving? Important for evacuation lists?
  10. 10Retention & GDPR — how long do you keep visitor data? Legal basis, right to be forgotten, export requests — who handles them?
  11. 11Special scenarios — large events (>50 guests), VIP visits, journalists, audits, supplier inspections — need their own flow?

Template — Visitor type matrix

Type Pre-registration ID check Badge NDA Notification Retention
Standard customerOptionalNoName badgeNoHost (Teams)90 days
SupplierMandatoryYesPhoto + colour codeOnceHost + reception12 months
CandidateMandatory (via HR)NoAnonymous badgeNoHR recruiter30 days
Event guestMandatoryNoPre-printed setVia event T&CEvent organiser60 days