Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Envoy is a workplace visitor management, desk booking and room booking platform. Sign-in kiosks capture visitor name, photo, signature, NDA acceptance and host details. It is a US-hosted service (DPF) processing sensitive personal data including visitor photographs and signatures. It is classified as high risk and requires explicit consent for photo capture, clear signage and a DPIA.
Envoy is a US-based workplace experience platform specialising in visitor management, desk booking and room booking. Its visitor management product replaces paper sign-in books with iPad kiosks or browser-based sign-in flows. When a visitor arrives at a workplace, the Envoy kiosk collects their name, email address, phone number, employer, the name of their host employee, and optionally a photograph and a handwritten or digital signature for NDA acceptance. The system notifies the host, logs the visit and stores all captured data on Envoy''s US-based cloud infrastructure. The desk and room booking modules allow employees to reserve workspaces and meeting rooms, with the system processing employee identity and booking preference data.
Envoy''s data collection is unusually broad for a workplace system. Visitor photographs are facial images that, depending on deployment, may be linked to identity records and used for building access purposes, bringing them close to biometric data under Article 4(14) GDPR. Digital signatures are handwriting samples that can uniquely identify individuals. Visitor logs record who entered a building, when and with whom, creating a detailed record of physical presence. NDA acceptance records create a legally sensitive document trail. All of this data belongs to visitors who are not employees of the operator and who may have limited awareness of how their data will be processed or how long it will be retained. This combination of factors places Envoy in the high-risk category.
The GDPR requires a specific legal basis for each category of data processed. For basic sign-in data (name, company, host, timestamp), the operator''s legal basis is typically legitimate interest in building security and visitor management (Article 6(1)(f)), supported by a Legitimate Interest Assessment documenting the proportionality of the processing. For visitor photographs, the legal basis is more contested. Where photos are used solely for a time-limited security badge and deleted on departure, legitimate interest may be defensible. Where photos are retained in a searchable database or used for identification beyond the visit, consent (Article 6(1)(a)) is the appropriate basis, and that consent must be freely given (photos cannot be made a condition of entry). NDA acceptance is covered by contract (Article 6(1)(b)) as between the visitor and the organisation. Employee desk and room booking data is typically processed under contract or legitimate interest.
Visitor data subjects have rights under Articles 15 to 22 GDPR including the right to access, rectification, erasure and restriction of processing. The Article 13 or Article 14 privacy notice obligation applies to visitor data collected at the kiosk. A concise, layered notice at the kiosk is essential. The notice must disclose the controller identity, the data collected, the legal basis, the retention period, the US transfer, and how to exercise rights.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For visitor photograph capture, EU DPA guidance generally requires that the consent obtained is genuinely free: the visitor must be able to sign in and access the premises without providing a photo. Making the photo mandatory or presenting it as the only option violates the freely-given consent requirement. The Envoy kiosk should be configured to allow visitors to skip the photo step, and the privacy notice presented at the kiosk must clearly state that the photo is optional. Physical signage at the reception area, in addition to the on-screen notice, is required in most EU jurisdictions to satisfy the transparency obligations of Article 13 for data collected at the point of entry.
All data processed by Envoy is stored on US infrastructure. Envoy participates in the EU-US Data Privacy Framework (DPF), which provides a transfer mechanism for personal data from the EU to certified US organisations. Operators should verify Envoy''s current DPF certification at the US Department of Commerce DPF list and ensure that the Data Processing Agreement includes Standard Contractual Clauses as a fallback in the event the DPF is invalidated. Given that the DPF has faced legal challenges historically (Schrems I and Schrems II), maintaining SCCs in parallel is prudent. The visitor privacy notice must disclose the US transfer and the mechanism used.
Conduct a DPIA before or at deployment covering the photograph capture, signature collection, visitor log retention and US transfer risks. Execute an Article 28 Data Processing Agreement with Envoy, including Standard Contractual Clauses for US transfers. Configure the kiosk to make photograph capture optional and present a clear Article 13 layered notice at sign-in. Display physical privacy signage at the reception area. Define and configure a data retention period in Envoy that matches your documented retention policy. Maintain a Record of Processing Activities (ROPA) entry for the visitor management processing activity. Implement a process for receiving and responding to visitor data subject access requests. Review Envoy''s DPF certification and SCC compliance annually. For employee desk booking, ensure employee notice satisfies Article 13 and document the retention and deletion policy for booking records.
Websites using Envoy must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is mandatory or strongly recommended for Envoy deployments in the EU. Risk factors triggering a DPIA include: systematic collection of visitor photographs (which constitute biometric-adjacent data and may be special-category data if used for identification), collection of handwritten or digital signatures, processing of personal data of a large number of data subjects who are visitors (non-employees) who may be unaware of the full extent of data collection, transfers of all collected data to the United States without an EU adequacy decision for the US (relying on DPF or SCCs), retention of visitor logs beyond the immediate security purpose, and integration with building access control systems. The DPIA must address the proportionality of photo capture, the adequacy of notice given to visitors at the kiosk, the retention period, sub-processor arrangements with Envoy under Article 28, and the adequacy of the DPF or SCC transfer mechanism. Operators in sectors with heightened sensitivity (healthcare, legal, financial) face additional risk.
Sample consent text
Welcome. Before you sign in, please read this important information. [Organisation Name] uses Envoy, a visitor management system provided by Envoy Inc. (USA), to manage access to our premises. We will collect your name, company, the name of your host, and the date and time of your visit. We would also like to take your photograph for security and identification purposes. Your photograph and visit record will be stored on Envoy's servers in the United States and transferred under the EU-US Data Privacy Framework or Standard Contractual Clauses. Your visit data will be retained for [X months/years] and then deleted. You have the right to access, correct and request deletion of your personal data. To exercise these rights, contact [[email protected]]. Your photograph is optional: you may sign in without providing a photo by asking a member of our reception team. By proceeding to sign in, you acknowledge that you have read this notice.
Third-party domains contacted
envoy.comdashboard.envoy.comapi.envoy.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| envoy_session | Strictly Necessary | Session | Session authentication cookie for the Envoy web dashboard and kiosk interface. Maintains the authenticated session for workspace administrators managing visitor logs, desk bookings and room reservations. |
| __envoy_csrf | Strictly Necessary | Session | CSRF protection token for the Envoy web dashboard. Prevents cross-site request forgery attacks on authenticated admin sessions. |
| envoy_preferences | Preferences | 1 year | Stores user interface preferences for the Envoy dashboard including language settings, timezone and notification preferences for workspace administrators. |
| _envoy_analytics | Analytics | 2 years | Analytics cookie on the Envoy dashboard and marketing site used to measure product usage and improve the platform. Requires consent where deployed on marketing-facing pages. |
| envoy_visitor_token | Strictly Necessary | Session | Short-lived token set during the visitor kiosk sign-in flow to maintain the sign-in session state. Cleared after sign-in is completed or the session expires. Contains no personal data beyond the session identifier. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
Envoy collects visitor name, email address, phone number, company, the name of their host employee, and the date and time of the visit. Optionally, and subject to consent, it also captures a facial photograph and a handwritten or digital signature for NDA acceptance. All data is transmitted to and stored on Envoy's US-based cloud servers. Visitor logs may be retained for months or years depending on the operator's configured retention policy.
Yes. Under GDPR and EU DPA guidance, visitor photograph capture requires freely given consent because facial images are biometric-adjacent data. The photograph must be optional: visitors must be able to sign in and access the premises without providing a photo. Envoy should be configured to allow the photo step to be skipped, and the on-screen and physical privacy notices at the kiosk must clearly state that the photo is voluntary.
Basic visit data (name, company, host, timestamp) is typically processed under legitimate interest (Article 6(1)(f)) in building security. Visitor photographs, where retained beyond the visit, require consent (Article 6(1)(a)) that is freely given and not a condition of entry. NDA acceptance is a contractual basis (Article 6(1)(b)). Employee desk and room booking data may rely on contract (Article 6(1)(b)) or legitimate interest. A Legitimate Interest Assessment should be documented for each processing activity.
Yes. All Envoy data is stored on US servers. Envoy participates in the EU-US Data Privacy Framework (DPF) which provides a GDPR-compliant transfer mechanism. Operators should verify Envoy's current DPF certification on the US Department of Commerce list and ensure that the Data Processing Agreement includes Standard Contractual Clauses as a fallback in case the DPF is invalidated. The visitor privacy notice must disclose the US transfer and identify the mechanism used.
Yes, a DPIA is strongly recommended and in many cases mandatory under Article 35 GDPR. Envoy combines systematic large-scale collection of visitor personal data including photographs and signatures, processing of data belonging to non-employee data subjects who have not been pre-informed, transfers to the United States, and potential integration with building access systems. These factors collectively meet the criteria for a high-risk processing activity requiring a DPIA.
Conduct a DPIA before deployment. Sign an Article 28 Data Processing Agreement with Envoy including Standard Contractual Clauses. Configure the kiosk to make photographs optional and to display an Article 13 privacy notice. Install physical privacy signage at reception. Set a retention period in Envoy aligned to your documented policy. Build a process for responding to visitor data subject rights requests. Verify DPF certification annually. For employee booking modules, ensure Article 13 notice is provided and booking data retention is limited to what is necessary.
Alternatives include Proxyclick (Belgian company, EU-hosted, GDPR-first design), Sign In App (UK company) and Traction Guest. EU-hosted visitor management solutions avoid the US transfer concern entirely. If Envoy is retained, the DPIA should document why US-hosted alternatives are necessary or preferable for operational reasons. Consider whether photo capture is genuinely required or whether it can be disabled to reduce the risk level.
Update your visitor-facing privacy notice (displayed on the kiosk and in physical form at reception) whenever Envoy changes its data processing practices or sub-processors, when you add new data categories to the sign-in flow, when retention periods change, or at least annually. The notice must always include: data collected, legal basis, retention period, US transfer mechanism, data subject rights and contact details for rights requests. Update your website privacy notice to list Envoy as a sub-processor under your visitor management processing activity.