Secogate ApproVault LogMeGo!
  • Sign In

Privacy Policy

Last updated 2026-08-19

Legal
On this page
Introduction 1. Our Collection of Information 2. Our Use of Information 3. Cookies & Tracking Technologies 4. Role-Based Access Disclosures 5. Multi-Tiered Compliance Obligations 6. Automated Decision-Making 7. Anonymising Information 8. How Long We Keep Information 9. Disclosure of Information 10. Security & Multi-Tenant Isolation 11. International Data Transfers 12. Your Rights 13. Breach Notification 14. Children's Information 15. Changes to This Policy 16. Contact Us

Introduction

Secogate ("we", "our", or "us") provides membership-based access management, workforce onboarding, and digital check-in solutions (collectively, our "Services"). This Privacy Policy explains how we collect, use, and protect personal information when you interact with our platforms.

Secogate is available to organisations and individuals worldwide. This policy is written to apply broadly across jurisdictions; where a specific regional law grants additional rights, we honour those rights for individuals located in that region as described in Section 12.

This policy does not apply when we process personal information on behalf of our corporate clients or resellers as a Data Processor. In those scenarios, our clients or resellers control the data, and their respective corporate privacy policies apply.

1. Our Collection of Information

Information You Provide Voluntarily

  • Account & Identity Data: Name, corporate or personal email, phone number, job title, company name, and encrypted credentials when registering as an administrator, reseller, group manager, or user.
  • Customer Support: Information provided when you contact us for technical help, system configuration, or inquiries.

Membership, Onboarding & Access Data (Provided by System Administrators)

To facilitate membership onboarding and system access workflows, authorised administrators or resellers submit personal details regarding data subjects — including employees, contractors, and organisation members. This data includes full names, corporate contact details, department/team assignments, membership types, structural access permissions, and encrypted passkey data.

Group Check-In Data

Group check-in is available to platform users who hold a valid Secogate account (identified by an "EID"). A company may configure its own EID format for its accounts (for example, an employee ID or member ID), and an EID can be changed. Each EID is unique across the entire Secogate platform — once an EID value is in use by one company, it cannot be used by another company. An EID is bound to the company that issued it and can only be used to check in at that company's sites, even if the account holder also holds a separate EID with a different company on Secogate. To use group check-in, an account holder (the "primary person") must be 18 or older and must verify their identity by entering the EID associated with the company they wish to check in with, together with their last name. Once verified, the primary person may check in themselves together with up to four accompanying persons aged 15 or older. This feature involves the following data:

  • Primary Person Verification Data: The primary person's EID and last name, used solely to verify their identity for the purposes of check-in.
  • Accompanying Person Data: The first and last name of each accompanying person. We do not collect or verify the age of accompanying persons; the primary person represents that each accompanying person meets the applicable minimum age requirement. Accompanying persons do not register for, and are not issued, their own Secogate account or EID. Their information is recorded solely against that specific check-in event and is linked to the primary person's attendance history.
  • Digital Pass Data: A digital pass is generated for the primary person only, covering the primary person and their accompanying persons for the duration of the check-in.
  • Joint Check-Out: All accompanying persons must check out together with the primary person at the same time. This occurs when the primary person taps the check-out button on their digital pass, checking out their entire group, or when an authorised administrator of the company operating that check-in point performs a force check-out on the primary person's record, which likewise checks out the entire group.

Information Collected Automatically

  • Technical Logs: IP addresses, browser types, operating systems, and device identifiers.
  • Usage Data: Timestamps, pages viewed within our dashboard, audit trail logs (including "Modified By" and "Title" markers), and system interaction metrics to optimise performance.
  • Location Data: General location information (such as that derived from IP address or device settings) collected as part of your use of the Services.

2. Our Use of Information

We use your data strictly to maintain, secure, and operate our services:

  • Service Delivery: Managing multi-tenant accounts, routing access requests to the correct authorised reviewers, validating secure back-channel API authentication, and maintaining system uptime.
  • System Protection: Troubleshooting logs, monitoring database performance, preventing unauthorised cross-tenant access, and defending against security threats.
  • Audit Compliance: Tracking historical permission changes, access requests, approvals, and denials to ensure transparent, compliant access reviews.

3. Cookies & Tracking Technologies

Secogate uses cookies and similar technologies (such as local storage) to operate the platform securely and reliably. We categorise these as follows:

  • Strictly Necessary Cookies: Required to keep you signed in, maintain your session across pages, and protect against cross-site request forgery. The platform cannot function without these.
  • Preference Cookies: Remember settings such as your selected organisation, dashboard layout, or display preferences.
  • Analytics Cookies: Help us understand aggregate usage patterns (e.g., which dashboard features are used most) so we can improve performance and reliability. Where used, this data is aggregated and not used to build advertising profiles.

We do not use cookies for third-party advertising or behavioural ad targeting. Most browsers allow you to control or disable cookies through their settings; please note that disabling strictly necessary cookies will prevent you from logging in or using core features of the Service.

4. Multi-Tiered Governance & Role-Based Access Disclosures

Secogate is a multi-tenant, membership-based application that operates using defined administrative, management, and reseller tiers. By using the platform, clients acknowledge that personal information (of employees, contractors, and members) is visible to different users based on assigned roles:

  • Resellers: Have administrative access only to the specific corporate accounts assigned to them. Within those assigned companies, they can view all personal information and manage all access requests.
  • Account Owners, HR, and Admins: Have global visibility across their entire company instance. They can view all personal information and manage access requests for all employees, contractors, and members within their organisation.
  • Group Managers: Have visibility restricted to their specific team or group. A Group Manager can view personal information and manage access requests only for individuals belonging to their designated group or team.
  • Hosts: Have visibility into the complete check-in and check-out (attendance) history of all individuals checked in within their company instance, and may validate the current status (valid or invalid) of any individual's digital pass. This visibility is in addition to any other role-based permissions the individual may hold.
  • System Admins: Have administrative oversight over specific downstream systems or applications. They receive and take action on access requests for the systems under their direct management and have access to the personal information required to review and fulfil those requests.

5. Multi-Tiered Compliance Obligations (Your Privacy Shield)

A. Reseller Obligations

If you are a Secogate Reseller:

  • Cross-Tenant Responsibility: You are explicitly responsible for ensuring you have the appropriate legal agreements or mandates to view and manage data across different downstream corporate accounts.
  • Access Misuse: Secogate disclaims liability for data exposure arising from mismanaged reseller-level administrative privileges or unauthorised visibility assignments.

B. Account Owner, HR, and Company Administrator Obligations

If you are an Account Owner, HR Professional, or Admin:

  • Lawful Basis for Onboarding: You assume sole legal responsibility for ensuring you possess a valid lawful basis (e.g., employment contract, service agreement, or explicit consent) to upload, onboard, and process your personnel's personal information within Secogate.
  • RBAC Alignment: You are solely responsible for accurately configuring and maintaining user roles (Group Managers, System Admins, HR) within your organisation. You must ensure that internal access to personal information strictly aligns with your internal data privacy policies and the principle of least privilege.
  • Rights Requests: You are responsible for receiving, evaluating, and honouring any data-deletion or access rights requests submitted by your employees, contractors, or members.

C. Host Obligations

If you are a Host:

  • Scope of Authority: You must exercise your ability to view company-wide attendance history and digital pass status solely for legitimate operational purposes and in accordance with your organisation's internal policies.
  • Confidentiality: Personal information accessed through the attendance history or pass validation functions must not be disclosed, copied, or used for any purpose beyond verifying attendance or pass validity.

6. Automated Decision-Making

Secogate uses automated logic to execute security workflows defined by administrators (such as matching encrypted passkeys, processing visitor check-in/out timestamps, or validating time-restricted access windows). These automated actions are carried out solely to fulfil the operational parameters set by our clients.

7. Anonymising Information

We reserve the right to anonymise and aggregate technical metadata so that it can no longer be traced back to an identifiable individual. Anonymised data is utilised for industry benchmarking, infrastructure scaling, and security analytics.

8. How Long We Keep Information

We retain Account & Identity Data that we control directly (such as administrator login credentials and billing contact details) for as long as your account remains active, and for a reasonable period afterward to comply with legal, statutory, or accounting obligations.

Processor Retention: Data managed on behalf of corporate clients or resellers (onboarding records, access histories, group logs) is retained, archived, or purged strictly according to the controlling client's subscription agreement and instruction.

Check-In History Retention: Check-in and check-out records — including visitor, staff, contractor, member, and group check-in history (and any accompanying persons' data linked to a primary account holder's attendance history) — are retained on an ongoing basis for the period specified under the controlling client company's subscription plan. Retention periods for this data may therefore differ between client companies depending on their plan. Clients should refer to their subscription agreement or contact their administrator for the applicable retention period.

Cancellation & Grace Period: When an Account Owner submits a cancellation request, all company data is retained in full for a 30-day grace period following approval of the cancellation. During this period the account remains accessible and the Account Owner may reactivate the subscription at any time to cancel the deletion. After the 30-day grace period expires, all company data — including user accounts, access records, check-in history, organisational settings, and associated personal data — is permanently and irreversibly deleted from Secogate servers and cannot be recovered. Consent records (records of Terms and Privacy Policy acceptance) are retained after deletion as required for legal compliance.

Secogate Stand Program — Complimentary Basic Plan: Where a customer participates in the Secogate Stand Program and receives a complimentary Basic plan, their data is retained in the same manner as any other Basic plan subscriber for the duration of their participation. Upon termination of the complimentary arrangement — whether by Secogate (with 30 days prior written notice) or by the customer — the standard cancellation and data retention terms apply, including the 30-day grace period prior to permanent deletion. Data collected during the complimentary period is not treated differently from data collected during any other subscription period and is subject to the same deletion obligations upon account closure.

Data Export & Backup: Secogate does not provide an automated data export, download, or backup facility for Basic, Standard, or Business plan subscribers. This limitation applies at all times during the subscription, not only upon cancellation. Enterprise plan subscribers may request a data export by contacting Secogate support; availability, format, and turnaround time are subject to Secogate's then-current technical capabilities and are not guaranteed within any specific timeframe. Upon permanent deletion following the expiry of the 30-day cancellation grace period, no data can be recovered regardless of plan type. Secogate accepts no liability for data loss arising from the absence of an export facility or from a customer's failure to retain records prior to cancellation.

9. Disclosure of Information

We do not sell, rent, or trade personal data. We only share data with trusted entities under strict confidentiality constraints:

  • Infrastructure Service Providers: Essential third-party vendors providing technical infrastructure, such as secure cloud database hosting or encrypted communication routing.
  • Payment Processing: Where you elect to pay by direct debit, we use GoCardless, a third-party payment processor, to set up and process your direct debit mandate and payments. You are redirected to GoCardless to provide your bank account details directly to them; Secogate does not collect, view, or store your bank account or BSB details. GoCardless processes this information under its own privacy policy, and Secogate receives only limited billing metadata from GoCardless, such as mandate status, payment status, amounts, and dates, in order to reconcile your account.
  • Legal Compliance: When compelled by law, subpoena, or government authority to protect the physical safety, property, or systemic security of our platform and users.

10. Security & Multi-Tenant Isolation

We implement comprehensive technical and organisational measures to safeguard data:

  • Data Isolation: Our platform uses rigorous multi-tenant data isolation to guarantee that unauthorised users, client companies, or unassigned resellers cannot view or intercept data from another instance.
  • Cryptographic Protocols: All sensitive credentials, authorisation mechanisms, and back-channel communications utilise industry-standard encryption protocols during transit and at rest.

11. International Data Transfers

Because Secogate is used by organisations around the world, your information may be processed and stored on servers located in a different country than your own. Where required by applicable law, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) to protect personal information transferred across borders.

12. Your Rights

Depending on your location, individuals (employees, contractors, members, managers, or admins) may have the right to access, correct, update, or request the deletion of their personal data.

If your inquiry concerns data controlled directly by Secogate, contact us via the channel in Section 16. If your request relates to onboarding, group membership, or access records managed by an employer, an organisation you belong to, or a managing reseller, please direct your request directly to that organisation, as they control that data.

Accompanying Persons: Individuals checked in as accompanying persons under a primary account holder's group check-in do not hold a Secogate account. Any request to access, correct, or delete an accompanying person's data should be directed to the client company that operates the relevant check-in point, as they control that data; the primary account holder who performed the check-in is responsible for the accuracy of the information they submit on the accompanying person's behalf.

13. Breach Notification

In the event of a security incident affecting personal information under our direct control, we will take prompt action to investigate and remediate the issue and will notify affected clients without undue delay, consistent with our contractual and applicable legal obligations.

14. Children's Information

Our Services are strictly business-to-business (B2B) utility platforms intended for use by adults acting in a professional or organisational capacity. We do not permit individuals under the age of 18 to register for or hold a Secogate account, and we do not knowingly collect or process personal information from individuals under 18, except as described below in connection with group check-in.

Group Check-In Exception: A verified adult (18+) account holder may use the group check-in feature to check in up to four accompanying persons aged 15 or older. In this limited circumstance, we collect basic identifying information (the accompanying person's first and last name) for the purposes of that check-in only; we do not collect or independently verify the age of accompanying persons, and the primary account holder is responsible for representing and ensuring that each accompanying person meets the applicable minimum age requirement. Accompanying persons are not issued a Secogate account or EID, and their data is not used for any purpose beyond the relevant check-in and check-out record. The primary account holder is responsible for ensuring they have the necessary authority or consent (including, where applicable, parental or guardian consent) to check in each accompanying person. Outside of this exception, if we become aware that we have inadvertently collected personal information from an individual under 18, we will take steps to delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated policy on this page with a revised "Last Updated" date. We encourage you to review this page periodically.

16. Contact Us

For privacy inquiries, security compliance questions, or to assert your data rights, reach our data compliance office at:

Email: privacy@secogate.com




Secogate

Smart check-in, digital passes, and automated access request workflows, and audit-ready reviews — all in one platform for every organisation type.

Follow on LinkedIn
Product
Features ApproVault LogMeGo! Who It's For Pricing
Connect
About Secogate Contact Sales Contact Support Become a Reseller
Legal
Privacy Policy Terms of Use
© 2026 Secogate. All rights reserved.
Privacy Policy Terms of Use