2. Description of the Processing
2.1 User account creation/managing
Categories of personal data
When you are invited to a meeting (regardless of whether you have a confirmed BmyGuest account):
- Name, email address, telephone number
- System ID number
- Company name
- Photo
- Creation and confirmation date
- Host name and hosting company
- Meeting information (subject, room, meeting owner, other attendees)
When you confirm your BmyGuest account, we may further collect:
- Workplace and job title
- Photo and LinkedIn URL
- Account password
When you are created as a host for your company, the following may be processed about you:
- Name, email address, telephone number
- System ID number
- Photo, LinkedIn URL
When you confirm and complete your account, we process data so you can log in, view your check‑in/visitor history, and share your data with other attendees:
- Password
- Workplace and job title
- Company ID and name
- Primary location and physical office
- Creation and confirmation date
- Meeting information (subject, owner, room, attendees)
Source of personal data
- Directly from you
- Your employer or colleague
- A company you are invited to visit
- Online/public sources (e.g., LinkedIn if you connect it)
Legal basis
Article 6(1)(f) GDPR (our legitimate interest in facilitating, easing, and documenting meetings).
Recipients
- Your employer or colleague
- Suppliers and vendors assisting our company/service (service providers, technical support, logistics, financial institutions, etc.)
- The company you are invited to visit (meeting owner, service personnel, other attendees)
Data retention
Up to 5 years plus the current year from your last visit or last hosted meeting (depending on your role). Retained to establish, exercise, or defend legal claims.
2.2 Meeting creation/managing and visitor registration
Categories of personal data
When you create a meeting:
- Name, email address, telephone number
- Workplace
- Photo
- Car license plate number
- Meeting subject and location
- Start/end date and time
- Email addresses and other data for the meeting owner and attendees
- The host you are visiting
- Expected arrival and check‑out time
- LinkedIn profile link
When attending a meeting, you must check in at the location (via QR code, link sent by email/SMS, or receptionist registration). We may process the location and real time of check‑in/check‑out.
Source of personal data
- Directly from you
- Your employer or colleague
- The company you are visiting
- Online/public sources (e.g., LinkedIn if connected)
Legal basis
Article 6(1)(f) GDPR (legitimate interest in facilitating, easing, and documenting meetings and visitor registration).
Recipients
- Your employer or colleague
- Suppliers and vendors assisting our company/service
- The company you are visiting (meeting owner, service personnel, other attendees)
Data retention
Up to 5 years plus the current year from your last visit or last hosted meeting. Retained to establish, exercise, or defend legal claims.
2.3 Notifications
We process personal data to notify you (as a host) when a visitor checks in; to inform visitors during evacuations; and to send informative messages during visits. Notifications are sent by SMS or email.
Categories of personal data
- Name
- Phone number
- Company name
- Location of check‑in
- Confirmation that you left the premises in case of evacuation
Source of personal data
- Directly from you
- Your employer or colleague
- The company you are visiting
Legal basis
Article 6(1)(f) GDPR (legitimate interest in facilitating/documenting meetings and optimizing evacuation procedures).
Recipients
- The company you are visiting
- The host you are visiting
- Suppliers and vendors assisting our company/service
Data retention
Up to 5 years plus the current year from your last visit or last hosted meeting. Retained to establish, exercise, or defend legal claims.
2.4 Marketing and user optimization
Personal data is used for marketing purposes, including to market our service directly to you by email, SMS, or phone. We also collect usage data (e.g., pages visited, features used, errors) to optimize the user experience and keep you signed in. See also our cookie policy at www.bmyguest.eu. We may collect data if you consent to receiving marketing (e.g., newsletters) from a company you visited.
Categories of personal data
- Name, email address, telephone number
- Workplace and job title
- Companies and hosts you have visited
- Date and time of meetings
- Your use of the application/service (pages visited, features used/activated, system errors)
Source of personal data
Legal basis
- Article 6(1)(a) GDPR (consent)
- Article 6(1)(f) GDPR (legitimate interest in providing an optimally working service)
Recipients
- Suppliers and vendors assisting our company, marketing activities, and service
- Companies you visited where you have consented to receive marketing
Data retention
Generally up to 5 years plus the current year (depending on your role) for the purposes described and for legal claims. Usage data about how you use the application/service is retained for up to 1 year.
2.5 Support
We process personal data when you send a support request or when the application/service malfunctions, to identify issues, handle the problem, and contact you.
Categories of personal data
- Name, email address, telephone number
- Workplace
- Screenshots showing the malfunction
Source of personal data
- Directly from you
- Your employer
Legal basis
- Article 6(1)(b) GDPR (performance of a contract)
- Article 6(1)(f) GDPR (legitimate interest in providing an optimally working service)
Recipients
- Suppliers and vendors assisting our company/service
Data retention
Up to 5 years plus the current year from your support request or the malfunction. Retained to establish, exercise, or defend legal claims.
2.6 Managing customers
We process data about you if you are employed by, or otherwise related to, one of our customers (e.g., entering contracts, general contact). We also process data for customer management (e.g., invoicing and communication).
Categories of personal data
- Name, email address, telephone number
- Workplace and job title
- Company name, address and VAT number
- Signature
- Invoicing details (invoice email address, contact person, P.O. number)
Source of personal data
- Directly from you
- Your employer or colleague
Legal basis
- Article 6(1)(b) GDPR (performance of a contract)
- Article 6(1)(f) GDPR (legitimate interest in communicating with you and delivering our services)
Recipients
- Suppliers and vendors assisting our company/service
Data retention
Up to 5 years plus the current year from termination of the business relationship with your company. Retained to establish, exercise, or defend legal claims.
2.7 Registration for contact tracing
We process personal data if you choose to register when visiting e.g., restaurants, cinemas, conference centers, sports facilities, hotels, nursing homes, hospitals, etc., to enable contact tracing related to COVID‑19.
Categories of personal data
- Name, email address, telephone number
- Companies visited
- Date and time of visit (check‑in and check‑out)
Source of personal data
- Directly from you
- An employer at the company you have visited
- A third‑party software application used at the company you have visited
Legal basis
Article 6(1)(f) GDPR (legitimate interest in facilitating/easing/documenting visitor registration and optimizing COVID‑19 contact tracing procedures).
Recipients
- Relevant authorities
- The company you have visited
- Suppliers and vendors assisting our company/service
Data retention
Up to 4 weeks from your last visit at a company using BmyGuest for contact tracing.