Skip to main content
CoReceptionist
Schedule a demo
Trust · Data protection

Your visitors' data, accounted for

Where your data lives, who can touch it, how long we keep it, and which credentials we do and don't hold. Written for the person who has to sign off on us.

Last reviewed September 2026

Today

What is true right now

HostingAmazon Web Services

The platform runs on AWS. We do not operate our own data centres or colocation hardware.

Data residencyUnited States

Customer and visitor data is stored in a US AWS region. We do not currently offer an EU or UK storage region — if that is a requirement for your organisation, tell us before you evaluate us.

Data in transitTLS encrypted

Traffic between visitors, kiosks, the dashboard and our servers travels over an encrypted TLS connection. This has been our stated practice since our first published privacy policy.

Data at restEncrypted storage

Visitor records, photos and signed documents are held in encrypted storage on AWS.

Payment dataNever touches our systems

Card details are processed by Stripe. We do not process, store or take custody of card numbers at any point.

RetentionYou set it, per site

Retention periods are configured per site, and visitor photos are deleted on your schedule rather than ours. Records can be exported before deletion.

Device controlOne-time activation, remote revoke

Every kiosk is enrolled with a single-use code issued from your dashboard, and any device can be revoked remotely without touching the hardware.

Use of your dataService delivery only

Visitor logs and data about your employees and guests are used only to provide and improve the service for you. We do not sell them, and we do not use them to train AI models.

Sub-processors

Everyone who touches your data

The complete list of third parties that process customer or visitor data on our behalf. We will give you 30 days' notice before adding a new one — email support@coreceptionist.co to be added to that notification list.

Sub-processorPurposeData processedRegion
Amazon Web ServicesApplication hosting and data storageAll customer and visitor dataUnited States
StripeSubscription billing and payment processingBilling contact and payment detailsUnited States
Freshworks (Freshchat)Website chat and customer supportSupport conversations and contact details you provideUnited States
Google AnalyticsWebsite analytics on coreceptionist.coWebsite usage data, subject to cookie consentUnited States
Web3FormsContact and demo form delivery on the websiteName, email, company and message you submit on our formsUnited States
Amazon SESHost notifications, visitor invitations and transactional emailHost and visitor names, email addresses, visit detailsUnited States
TwilioHost notification by text messageHost phone numbers and notification contentUnited States
In progress

What we are working toward

Dated commitments, not aspirations. Nothing below is claimed as complete anywhere else on this site.

Planned

SOC 2 Type II

We do not hold a SOC 2 report today. It is the credential most of our enterprise prospects ask for first, and it is the next compliance investment we intend to make. We will publish the auditor and the observation window when the engagement starts, rather than announcing an intention with no date behind it.

Planned

Independent penetration test

We have not yet commissioned a third-party penetration test, so there is no report to share and we make no claim otherwise. Establishing an annual external test, with a summary letter available under NDA, sits alongside SOC 2 in the same programme of work.

Under evaluation

EU data residency

All data is currently stored in a US AWS region. An EU storage region is under evaluation and will be driven by customer demand — if you need it, that demand is how it gets prioritised.

In progress

Standard Data Processing Agreement

A pre-signed DPA that you can review without a legal round-trip is in preparation. Until it is published, we will sign a DPA on request.

In progress

Refreshed privacy policy and terms

Our published privacy policy and terms predate the current platform and are being rewritten to describe the service as it exists today, including retention, sub-processors and data subject rights.

Documentation

What you can ask us for

Available today

Security Overview

A written summary of our architecture, hosting, access controls and data handling, suitable for attaching to a vendor review.

On request

Data Processing Agreement

Signed on request while the standard pre-signed version is being finalised.

On request

Completed security questionnaire

We will complete your own questionnaire — SIG Lite, CAIQ or an internal template. Most of the standard answers are already published in our security FAQ.

Not yet available

SOC 2 report

No report exists yet. We would rather tell you that plainly than let a badge imply otherwise.

Bring your compliance team

We would rather answer the hard questions early than discover them at contract stage.