GDPR-Shaped From The Schema Up
VARENTO handles competency and fitness data about real people. This page sets out what is collected, why, who can see it, how long it is kept and how workers exercise their rights.
Controller and processor
The employer or principal contractor is the controller of its workforce data and decides why records are held. VARENTO acts as processor and only processes data on documented instructions, under a Data Processing Agreement that includes the Art. 28 terms, sub-processor list and breach notification timelines.
This page is maintained by VARENTO to answer common privacy questions. It is a description of how the product is built — not a certification, legal advice, or a substitute for your own DPIA.
What we hold, and for how long
| Category | Examples | Lawful basis | Retention |
|---|---|---|---|
| Identity | Name, worker number, photo, nationality, preferred language | Contract / legitimate interests of the employer | Duration of employment + 6 years |
| Competency records | Scheme cards, certificates, assessments, authorisations | Legal obligation (health & safety) and contract | 6 years after expiry — accident-claim window |
| Health data (special category) | Medical fitness status and review dates only — never diagnoses | Art. 9(2)(b) — employment health & safety obligations | Status only, deleted 12 months after leaving |
| Site access events | Scan time, project, decision, reason code, scanning user | Legal obligation and legitimate interests (site safety) | 3 years, then aggregated |
Retention periods are defaults. Controllers can shorten them per company or project.
How the product protects it
Data minimisation on verification
A QR scan returns a decision — permitted, conditional or refused — plus the reason. It does not expose medical detail, home address, date of birth or documents to the verifying team.
Purpose limitation
Records are used to verify competency for site access. They are not used for performance monitoring, profiling or automated decisions with legal effects.
Role-based access
Workers see only their own record. Site managers see an access decision. Employer admins see their own workforce. Clients and auditors see project-level readiness, not personal files.
EU data residency
Personal data is stored and processed within the EU. Any sub-processor change is notified in advance.
Immutable audit trail
Every verification and record change is logged with actor, time and reason, so a controller can evidence lawful processing.
Worker data rights
Access, rectification, erasure, restriction and portability requests are raised from the worker's own record and routed to the employer as controller.
Privacy or DPA questions?
Ask for our Data Processing Agreement, sub-processor list or DPIA support pack.