Find a card scheme, qualification or competence

Data protection

GDPR-Shaped From The Schema Up

VARENTO handles competency and fitness data about real people. This page sets out what is collected, why, who can see it, how long it is kept and how workers exercise their rights.

Controller and processor

The employer or principal contractor is the controller of its workforce data and decides why records are held. VARENTO acts as processor and only processes data on documented instructions, under a Data Processing Agreement that includes the Art. 28 terms, sub-processor list and breach notification timelines.

This page is maintained by VARENTO to answer common privacy questions. It is a description of how the product is built — not a certification, legal advice, or a substitute for your own DPIA.

What we hold, and for how long

CategoryExamplesLawful basisRetention
IdentityName, worker number, photo, nationality, preferred languageContract / legitimate interests of the employerDuration of employment + 6 years
Competency recordsScheme cards, certificates, assessments, authorisationsLegal obligation (health & safety) and contract6 years after expiry — accident-claim window
Health data (special category)Medical fitness status and review dates only — never diagnosesArt. 9(2)(b) — employment health & safety obligationsStatus only, deleted 12 months after leaving
Site access eventsScan time, project, decision, reason code, scanning userLegal obligation and legitimate interests (site safety)3 years, then aggregated

Retention periods are defaults. Controllers can shorten them per company or project.

How the product protects it

Data minimisation on verification

A QR scan returns a decision — permitted, conditional or refused — plus the reason. It does not expose medical detail, home address, date of birth or documents to the verifying team.

Purpose limitation

Records are used to verify competency for site access. They are not used for performance monitoring, profiling or automated decisions with legal effects.

Role-based access

Workers see only their own record. Site managers see an access decision. Employer admins see their own workforce. Clients and auditors see project-level readiness, not personal files.

EU data residency

Personal data is stored and processed within the EU. Any sub-processor change is notified in advance.

Immutable audit trail

Every verification and record change is logged with actor, time and reason, so a controller can evidence lawful processing.

Worker data rights

Access, rectification, erasure, restriction and portability requests are raised from the worker's own record and routed to the employer as controller.

Cookies and similar technologies

Under the ePrivacy Directive and the GDPR, anything beyond strictly necessary storage needs prior, informed, opt-in consent — per category, never bundled. Nothing non-essential is set before you choose, and withdrawing is one click, exactly like giving it.

Strictly necessary

Always on

Needed for sign-in, session security, load balancing and remembering this cookie choice. These cannot be switched off.

Auth session, CSRF protection, consent record

Preferences

Opt-in

Remembers your language, market and interface settings so the site behaves the same on your next visit.

Language, country, saved filters

Analytics

Opt-in

Aggregated, pseudonymised usage measurement so we can see which pages help buyers and which do not.

Page views, referrers, feature usage

Marketing

Opt-in

Measures campaign performance and lets us show relevant content on other platforms. Off unless you opt in.

Campaign attribution, remarketing pixels

Privacy or DPA questions?

Ask for our Data Processing Agreement, sub-processor list or DPIA support pack.