Private by design. Ready for any audit.
Consent before anything is collected, every look logged, erasure on schedule. The record is there whenever someone asks.
Locked down from the lobby to the database.
Stored in your region
Visitor records are stored in the region named in your agreement.
Encrypted all the way
Visitor data is encrypted on the move and where it is stored.
Walled off from other customers
Your data is kept separate from every other company's, and tested with every update.
Each role sees only its job
Guards see only today's visitors: name, photo, host and status. Never staff phone numbers or emails.
Every look is logged
Who opened a visitor's details, and when, is always on record.
Support only when you invite it
Our team opens visitor details only in a time-limited window you grant, or in a logged security emergency. Every read is logged.
Records kept as written
Consent, approval and erasure records are append-only in Orb. Mistakes are fixed with a logged correction.
Less to lose
Five typed details and a photo by default, and extra fields only where you add them. ID images are deleted soon after the check.
ID checked. Only the result is kept.
Turn on ID verification for the visitor types that need it, such as contractors, or for every visitor.
Shown to their own phone
The visitor holds their ID up to their phone camera. No scanner, no photocopy.
Checked, then deleted
Our service checks the ID and deletes the images soon after, usually within minutes.
The result stays
The visit record keeps the outcome, the document type and when it was checked.
A person, never a dead end
If anything doesn't match, the desk checks the visitor instead. Children are never asked for ID.
Everyone says audit-ready. Orb shows the record.
Every visit writes its own record. Here is one, line by line: what is kept, who can see it, how long it stays, and why.
| When | What is kept | Who can see it | How long | Why it's kept |
|---|---|---|---|---|
| 10:58 | Notice shownVersion and language | Admins, data protection officer | With the visit record | Shows the visitor was told firstDPDP Act |
| 10:58 | Name, company, host, purpose | Admins; the guard sees name and host | With the visit record | Shows who came in, and whyISO 27001, PCI DSS |
| 10:58 | Photo | The host once; the guard at the gate | 7 daysYou set this clock | Lets the guard match the face at entry |
| 10:59 | Mobile numberConfirmed in WhatsApp or by SMS | Admins | 7 daysYou set this clock | Reaches the visitor about this visit |
| 10:58 | ConsentItem by item, nothing pre-ticked | Admins, data protection officer | With the visit record | Shows the visitor agreed to each itemDPDP Act |
| 11:00 | ApprovalPriya Sharma, in WhatsApp | Admins, guard | With the visit record | Shows who allowed the visitPCI DSS |
| 11:03 to 12:10 | Entry and exitGate 2, guard's own PIN | Admins, guard | With the visit record | Shows when they came and leftISO 27001 |
| 13 Oct 2027 | Visit record erasedSigned proof of what was erased that night | Data protection officer | Only a count remains | Shows nothing was kept longer than promisedDPDP Act |
Built for the rules your lobby answers to.
Most duties under the DPDP Act apply from 13 May 2027. Orb is built for them today.
Kept while it's needed. Then erased.
Erasure on every plan
Every plan erases on schedule, including the free trial.
A signed erasure report every night Assurance plan
A signed record of each nightly erasure run: what was erased, and when, ready for your reviewers.
The visitor stays in control.
Your organisation decides what is collected and for how long. Orb handles visitor data only the way you instruct, as your data processor.
Sees it before sharing it
The notice comes before any question.
Can say no
The desk signs them in instead. Nothing from their phone is saved.
Withdraws any time
From their pass or their verified WhatsApp.
Keeps a receipt
In and out times, and the date each detail is erased.
Everything your reviewers will ask for.
Whoever checks your building, from an auditor to a client's security team, gets a straight answer and a document to keep.
Evidence Pack
A sample visit record, consent record, erasure report and drill report, a DPDP lobby checklist, a sample visitor notice and a one-page security overview.
Data processing terms
The contract for how Orb handles your visitors' data, on every plan. A signed agreement on the Assurance plan.
List of providers
Every service that touches visitor data, named in your agreement.
Your security questionnaire
Send it over. We answer it.
Questions your reviewers will ask.
Why does our visitor register need to change now?
Visitor details kept in an app, a spreadsheet or a scanned register fall under India's DPDP Act 2023, and most of its duties apply from 13 May 2027 under the DPDP Rules 2025. Your organisation will need to account for each visitor's details: why they were taken, who saw them, and when they were erased. Orb is built for the DPDP Act and records each step, visit by visit.
Where is visitor data stored?
In the region you choose, named in your agreement. WhatsApp messages pass through WhatsApp's own servers, and your agreement names every provider that touches visitor data.
Who can see a visitor's details?
The host, the guard at the gate, your admins and data protection officer, and the providers named in your agreement. Our support team only in a window you open. Every look is logged.
Who do visitors contact with a question?
The contact named in your notice, usually your admin or data protection officer.
How long is visitor data kept?
Photo and mobile on a short clock you set, the visit record for the period you choose. Then both are erased, and only an anonymous count stays.
What if a visitor says no?
The desk checks them in instead. Nothing from their phone is saved.
Can a visitor take back consent?
Yes, from their pass or their verified WhatsApp. Orb erases their photo and phone number, keeps the register entry for the period your organisation must hold it, and records each step.
Do you keep ID cards?
No copies. The ID images are deleted soon after the check. The visit keeps the result and the document type.
Can our admins sign in with single sign-on?
Yes, on request. We connect it to your identity provider when we set you up.
Can a record be changed later?
Mistakes are fixed with a logged correction. Consent, approval and erasure records stay as written.
How does Orb help with the DPDP Act?
Orb is built for the DPDP Act 2023 and Rules 2025. It gives you the tools and records for notice, consent and erasure. Your organisation stays in charge of visitor data, and Orb acts on your instructions.
Is visitor data used for anything else?
Orb uses visitor data only to run your lobby and keep the service secure, on your instructions.
Can we take our records with us?
Yes. Paid plans export the visitor log, and you can take a full copy of your records for 30 days after you cancel.
What happens if a guard's phone is lost?
Your admin unpairs it in one step. Each guard signs in with their own PIN. The phone holds only the current shift's list, encrypted, and clears it at the end of the shift or when it next connects after unpairing.
Walk your reviewers through a real record.
Book a demo and bring whoever checks your records. We open a visit and show every line.