South Bank Central
Visitor Management

Data protection notice

How personal information is handled in the visitor-management system. Last reviewed 30 July 2026.

What this notice covers

This notice explains how personal information is handled in the visitor-management system used at South Bank Central — the system that pre-registers guests, tells a host their visitor has arrived, and keeps a record of who has been in the building.

It sits alongside, and does not replace, South Bank Central's general privacy policy and cookies policy, which cover the website and the wider business relationship. Building security systems that are separate from this one — CCTV and the physical access-control platform — are covered by their own notices; this system records only the access-card number issued for a visit, not door-by-door movement or camera footage.

The data controller is South Bank Central, 30 Stamford Street, South Bank, London SE1 9LS. Questions or requests about this notice: dataprotection@southbankcentral.london.

Information the system holds

Who What is recorded
Visitors Name; email address and company where given; the date and time of the visit; who you are visiting and which tenant company they work for; the reason for the visit if one was recorded; the access-card number issued to you; and the times you checked in and out. If a badge is printed, the badge reference and when it was printed.
Hosts and staff
tenant employees, reception, administrators
Name, work email address, telephone number where given, job title, the tenant company and floor, account status and role. For a one-off host who has no account, the name, email and telephone number supplied for that visit only.
System records An audit log of actions taken in the system — who booked, checked in, checked out, edited or exported a record, and when. Sign-in session details including IP address, browser type and last activity time. Access tokens where the mobile application is used.

The system does not ask for or store identity-document images, vehicle registrations, photographs, health information, or any other special category data.

Where visitor information comes from

If you are a visitor, your details are usually entered by the person you are coming to see, or by reception on their behalf — not by you. That means information about you may reach this system before you have had any contact with the building.

The system sends arrival and booking notifications to your host only; it does not email or text visitors. So if you were pre-registered, you are being told about this processing at reception and through this page rather than by a message from us. You can ask for a copy of what is held about you at any time using the contact address above.

Why the information is used, and the legal basis

Under the UK GDPR the building relies on the following bases:

  • Legitimate interests — to control and record access to a multi-tenant building, to confirm that expected visitors are who they say they are, to let a host know their guest has arrived, and to keep an accurate record of who is on site. The building has a clear interest in knowing who is in it; the information used is limited to what reception needs to do that.
  • Legal obligation — health-and-safety and fire-safety duties require the building to be able to account for everyone present in an evacuation. The "on site now" record exists for that purpose.
  • Contract — for tenant staff who hold an account, to provide the service agreed with their employer.

Visitor information is not used for marketing, and is not sold or shared for anyone else's marketing.

Who can see it

Access is restricted by role, and the restriction is enforced by the system rather than by policy alone:

  • Tenant staff see only their own company's visitors and bookings. They cannot see other tenants' visitors.
  • Reception sees all visitors in the building, which is necessary to run the front desk and to produce an evacuation list.
  • Administrators can additionally manage accounts, tenant companies and settings.

Actions taken in the system are recorded in the audit log, so access can be reviewed.

Suppliers who process it on our behalf

The system is operated for the building by its technology supplier, and uses these providers:

Provider Purpose Where
DigitalOcean Hosts the system and its database United Kingdom (London)
Mailgun Sends host notification emails European Union endpoint
Twilio Sends host notification text messages, where SMS is enabled United States — transfer safeguards apply

Each acts only on instructions, under a written agreement. Information may also be disclosed where the building is legally required to do so — for example to the emergency services, or in response to a lawful request.

How long it is kept

Visit records are deleted automatically once they pass the retention window, which is 365 days by default and is configurable by the building. A scheduled job runs every day at 03:00 and permanently deletes visits dated before the cut-off, together with any printed-badge records attached to them. A visitor's own record is deleted once they have no remaining visits, so nobody is left on file after their last visit ages out. Each purge is itself recorded in the audit log so the deletion can be evidenced.

Staff accounts are kept while the account is active and for as long as the building's relationship with that tenant continues.

Keeping it secure

Access requires an individual account and password; passwords are stored only as a cryptographic hash and cannot be read back. Sign-in attempts are rate-limited. The system is served over an encrypted connection, separation between tenant companies is enforced in the application itself, and administrative actions are logged.

Your rights

You have the right to ask for a copy of the personal information held about you; to have inaccurate information corrected; to ask for information to be deleted; to object to or ask us to restrict how it is used; and, where it applies, to receive it in a portable form. Where processing relies on legitimate interests, you can object and we will consider whether those interests still outweigh your objection.

To exercise any of these, contact dataprotection@southbankcentral.london. There is normally no charge and we will respond within one month.

If you are unhappy with how your information has been handled you can complain to the UK Information Commissioner's Office at ico.org.uk, though we would rather you raised it with us first.

Changes to this notice

If this notice changes, the revised version will be published on this page and the review date above updated. This version was last reviewed on 30 July 2026.

← Back to sign in South Bank Central · London SE1