Visitor data protection settings

Choose how long visitor data is kept and how much of an identity number is shown — every field on the Data protection card: the mask length, the two purge schedules and their 1 to 2555 day range, what each purge actually removes, and what Purge now does before it does it.

Updated 12 Sept 2026

Data protection is the last card on the visiting settings screen. It holds one masking rule and two scheduled deletions — and the two deletions are not variations of one setting. One erases visits, the other only hides a number.

Open Visitor management
The Data protection card: the mask length, then each purge with its own day count, time of day and Purge now.

The Data protection card: the mask length, then each purge with its own day count, time of day and Purge now.

The card

SettingWhat it doesWhen to change it
The number of visitor’s identity number digits will displayHow many digits of a recorded identity number stay readable on screen; the rest are masked from the visitor’s first day. 1 to 100, 4 until you change itLower it where reception should be able to confirm a document without reading the whole number
Purge visitor identity informationMasks the identity numbers of visitors whose last visit is older than the window. It deletes nothing else, and the visitor, their visits and their badges all stayTurn it on where identity numbers are collected at the door but are of no use once the visitor has gone
Purge visitor record informationDeletes visitor badges and visiting appointments whose period ended before the window, then the visitors nobody still refers to. Off until you turn it onTurn it on where a retention policy says visit history must not outlive a stated period
…day(s) at…Both schedules take a number of days since the visitor’s last visit, and a time of day to run at. 1 to 2555 days — seven years — and 90 days when you first switch one onMatch the days to your own retention policy; move the time to a quiet hour
Purge nowRuns that schedule immediately. It counts first and tells you what it will remove, and asks before it doesUse it once after setting a window, so the backlog goes in a run you are watching rather than overnight

What each purge leaves behind

The record purge is not reversible and does not use the recycle bin. It removes, in this order:

  • visitor badges whose period ended before the cutoff;
  • visiting appointments whose period ended before it — a recurring series’ master is never taken while its occurrences remain;
  • visitors with no surviving appointment, no live long-term badge, and no activity since the cutoff.

A visitor who still has a future visit, or a long-term badge that has not expired, survives however old their first visit was. A purged record reads This visitor data has been permanently deleted.

One run does not always finish the job. A visitor still counts as in use until the link between them and their last visit has been cleared, which happens shortly after the visit itself is removed — so the badges and the visits go on one run and the visitors on the next. Purge now is honest about this: run it again and it will tell you there is more to remove.

The identity purge only rewrites the identity number, so the visit history stays readable and attributable. Every purge that removed anything leaves one line in the audit trail saying what it took.

What this does not control