Docs
Privacy and data

Data subject requests

How visitors and staff ask to see or delete their data, and how your admins find, export and erase it.

Early access· P9For admins and data protection leads

Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.

Under the Data Protection Act, 2012 (Act 843), people can ask what personal data you hold about them, ask you to correct it, and ask you to delete it. These are data subject requests. Your organisation, as controller, answers them; Agoo gives you the tools to do it quickly and keeps a record that you did.

How someone makes a request

A visitor, contractor or employee can ask in two ways:

  1. Through your organisation, by email, letter, phone or at the front desk, using the contact details in your privacy notice.
  2. Online, from the privacy link on your visitor pages. They enter their phone number, confirm it with a one-time code sent by SMS, and choose See my data or Delete my data. The request then appears in your console.

If someone contacts Ardent about data your organisation holds, we refer them to you and help you answer.

Fulfil a request

Open Console → Settings → Data & privacy → Requests

Online requests appear here automatically. For a request made another way, choose New request and record who asked, how and when.

Confirm who is asking

Online requests are verified by a one-time code to the phone number. For other requests, check the person's identity before you share or delete anything, for example by calling back the phone number on their visits.

Find their data

Agoo gathers every visit, booking, delivery, form answer, photo and signed document linked to that phone number or person, across all your sites. Check the list: people with the same name may be different people.

Act on it

  • Access: download a copy of their data as a PDF or CSV and send it to them.
  • Correction: edit the details that are wrong.
  • Erasure: choose Erase. Agoo deletes their personal data across your organisation.

Close the request

Mark it done. The request, the steps taken and who took them are recorded in the audit trail.

What erasure does and doesn't remove

  • Removed: their name, phone number, email, photos, ID details, form answers and signed documents.
  • Kept as a record: the audit trail notes that an erasure took place and who carried it out.
  • Not removed while a legal hold applies (Enterprise). Records under a hold stay until it's lifted.

If you have a lawful reason to keep some data, such as a signed contractor agreement or a watchlist entry after a serious incident, record that reason before you erase anything, and take advice if you're unsure.

How quickly to respond

Record the date each request arrived and answer without undue delay. Act 843 sets out people's rights and your obligations as controller; if you're unsure about a deadline or an exemption, check with your data protection supervisor or legal adviser.

For developers

If you handle requests in your own systems, on Pro and Enterprise you can erase a visitor through the API with DELETE /visitors/{visitor_id}, which needs the visitors:delete scope, and listen for the visitor.erased webhook event to update other systems. See the developer platform and webhooks.

On this page