Legal
Privacy & Terms
The Privacy Notice and Terms of Use for VisitPlus, provided by Fortified Security LLC.
Privacy Notice
What this covers
This notice explains how VisitPlus (“the Platform”) collects, uses and protects personal data when you sign in as a host, administrator or staff user, and, separately, how it handles visitor data captured at client sites. VisitPlus is provided to your employer or the company you are visiting (“the Company”) as a visitor management and access-control tool.
Information we collect
- Account data — name, work email and role, provided by your organization’s identity provider (Microsoft Entra) when you sign in.
- Visit records — visitor name, contact details, host, company and site, purpose of visit, and check-in and check-out timestamps.
- Contact records vs. verified identity — information a host or admin types in about a visitor (a typed email or phone number, for example) is stored as that Company’s contact record. It is treated differently from information a visitor personally enters or confirms — such as an email they type at the kiosk, or an emailed invitation they respond to — which is stored as a verified identity, and is the only kind of record used to send verification codes or match returning visitors.
- Biometric data, if enabled by the Company — see Biometric data below.
- Device and log data — IP address, browser and device information, and access timestamps, for security and audit purposes.
How we use this information
- To operate visitor check-in, host notification and site access control.
- To maintain a security audit trail as required by the Company’s security program.
- To detect and prevent fraud, impersonation and unauthorized access.
- To comply with legal, regulatory or contractual obligations.
We do not sell personal data. We do not share it with third parties for their own marketing purposes.
Who can see your information
Access is restricted to the Company you are visiting or working for, and to authorized personnel at Fortified Security who operate and support the Platform. A person’s identity information — email, phone, biometric data — is only visible to a Company after that person has actually interacted with that Company by confirming a visit. A Company cannot gain access to your verified identity simply by typing your name or email into the system.
Your rights
You can:
- View which companies have access to which of your verified identities.
- Revoke a company’s access to a specific identity — turning off shared Face ID, for example — at any time.
- Request correction or deletion of your data, subject to the Company’s legal retention obligations, such as visitor logs required for security compliance.
To exercise these rights, contact [email protected] or use the privacy settings in your account.
Data retention
Visit records are retained per the Company’s configured retention policy. Biometric data, where enabled, is retained per the Company’s biometric retention setting — 90 days by default — and is deleted automatically after that period unless re-enrolled.
Security
Data is encrypted in transit and at rest. Biometric data is stored as a non-reversible mathematical representation (a template), not as photographs, via Microsoft Azure’s Face API.
Biometric data
If enabled by the Company you are visiting, VisitPlus offers optional facial recognition check-in. Facial recognition data is collected only with your explicit consent at the check-in kiosk, is stored as a biometric template rather than a photograph via Microsoft Azure Face API, and is retained for up to 90 days or until you revoke consent, whichever is sooner, in accordance with the Company’s published biometric data retention policy. You may decline facial recognition and check in using another method at any time.
Changes to this notice
We may update this notice from time to time. Material changes will be communicated to Company administrators before they take effect.
Contact
Fortified Security LLC221 Remington Way, Hickory, KY 42051
[email protected]
Terms of Use
Acceptance
By signing in to VisitPlus, you agree to these Terms of Use. If you do not agree, do not sign in.
Who this applies to
These Terms apply to hosts, administrators and other staff users signing in through your organization’s identity provider. Visitors checking in at a site kiosk are subject to the separate terms and consent presented at check-in.
Acceptable use
You agree to:
- Use the Platform only for legitimate visitor management, host and access-control purposes authorized by your organization.
- Not attempt to access data, sites or visitor records outside your assigned role or permissions.
- Not use the Platform to collect, store or process information about any individual without a legitimate business purpose.
- Keep your credentials confidential, and report any suspected unauthorized access immediately to [email protected].
Accuracy of data you enter
Information you enter about a visitor — name, phone, email — is stored as your organization’s own record of that person. VisitPlus does not treat information you enter on someone else’s behalf as verified until that person confirms it themselves, by responding to an invitation or checking in. You are responsible for the accuracy of information you enter.
Availability
The Platform is provided on an “as available” basis. Fortified Security LLC is not liable for interruptions in service, including third-party outages — Microsoft Entra or Azure Face API, for example — that are outside our control.
Ownership
Visit and access-control data belongs to the Company operating the site. Fortified Security processes it on the Company’s behalf as a service provider.
Termination
Access may be suspended or terminated if these Terms are violated, or if your relationship with the Company ends.
Governing law
Kentucky law governs these Terms, without regard to conflict-of-law principles.
Contact
Fortified Security LLC221 Remington Way, Hickory, KY 42051
[email protected]