Data Processing Addendum & GDPR Compliance
Last Updated: October 11, 2025
SecurePointUSA.com ("SecurePoint USA," "we," "us," or "our") provides an enterprise-grade Visitor Management System (VMS) with integrated trade compliance screening for ITAR, EAR, and international sanctions regulations.
Our Role:
We act as a data processor on behalf of our clients (the "data controllers"), handling personal data collected during visitor check-ins and compliance screening activities. Your organization remains the primary controller responsible for determining how visitor data is collected and used.
Compliance Commitment: We comply with:
For EU Residents: This policy outlines your rights under GDPR and how we process your personal data as a processor on behalf of our client organizations.
When you check in at a facility using our VMS, we process:
We collect only the minimum data necessary for visitor management, trade compliance screening, audit trail maintenance, and system security. We do not collect unnecessary personal data, and we do not sell visitor information to third parties.
Processing is based on:
Processing is based on:
Opt-Out Rights: EU visitors may object to processing via the VMS dashboard or by contacting the facility directly. Note: Objecting to screening may result in denied facility access per organizational security policies.
In the event of a data breach:
Data Retention:
For EU personal data transfers:
As a data processor, we enter into GDPR-compliant Data Processing Addendums with all controller organizations.
Our DPA includes:
We engage the following subprocessors:
We notify controllers 30 days before adding new subprocessors. Controllers may object to new subprocessors.
Email: privacy@securepointusa.com
Subject: "DPA Request - [Your Organization Name]"
Response Time: DPA provided within 14 business days
You have the right to:
Submit CCPA requests: privacy@securepointusa.com(subject: "CCPA Request")
We may update this policy to reflect changes in legal or regulatory requirements, new features, or industry best practices.
For privacy questions, data subject requests, or DPA requests:
Important: SecurePoint USA acts as a data processor. For questions about how your data is used, contact the organization that invited you to the facility (the data controller).
Trusted by Fortune 500 Companies • Defense Contractors • Global Enterprises
This Privacy Policy is provided for informational purposes and does not constitute legal advice. Organizations using SecurePoint USAmust implement their own privacy policies and obtain necessary consents from visitors. SecurePoint USA provides policy-neutral risk assessments—final access and compliance decisions remain the responsibility of the controlling organization.
For specific legal guidance on ITAR, EAR, OFAC, GDPR, or CCPA compliance, consult qualified legal counsel.
© 2025 SecurePoint USA. All rights reserved.