Legal at Harness

Visitors Privacy Notice

Version

October 7, 2026

Status

Current

At Harness, we care about your privacy. This privacy notice explains what personal data (information about you) we collect when you visit a Harness office, why and how we use it, and what rights you have. We aim to be open with you and to use your data fairly, lawfully, and securely.

If you have any questions about how we use your data, please contact us using the details below.

1. Who We Are

The Harness company that runs the office you visit is the “data controller” for your visitor data.

Role Details
Data Controller For US offices: Harness Inc., 55 Stockton St, 8th Floor, San Francisco, CA 94108, USA
For Indian offices: Harness R&D Labs India Private Limited, Urban Vault, Garden Layout, Sector 2, HSR Layout, Bengaluru, Karnataka 560102For UK offices: Harness Group UK Limited, 9 Old Broad St., Liverpool St., London EC2M 1QS,
Contract: privacy@harness.io
EU Representative Harness France SAS, 92 Av. des Champs-Élysées, 75008 Paris, France.
privacy@harness.io
Independent Controllers Building management and co-working space providers act as independent controllers because they operate building reception, security, and shared facilities independently under their own privacy policies and terms.

2. Scope of This Notice

This notice applies to you if you visit a Harness office as an external visitor, for example:

  • Customers and prospective customers
  • Suppliers and vendors, including regular service vendors (for example, cleaning or kitchen supplies delivery)
  • Job applicants attending interviews
  • Business partners
  • Auditors, legal advisors and consultants
  • Event attendees
  • Family members of Harness employees (visitors under 18 are registered by, and must be accompanied by, their parent or guardian or the Harness employee hosting them)

How your visit is managed depends on the type of office:

  • Offices rented directly by Harness (“direct lease offices”): Harness manages visitor check-in on its own floor, as explained in Section 3.
  • Co-working spaces (for example, WeWork): your Harness host registers you on the co-working provider’s members website using only your name. Harness does not collect any other information about you and does not ask you to sign a non-disclosure agreement (NDA). The co-working provider runs reception and building security as an independent controller. It may collect more information about you under its own privacy notice, so we recommend you read it.

3. What Personal Data We Collect

3.1 Before Your Visit

Your Harness host registers you in advance with building reception, using your name and expected arrival time. Building reception then gives you a QR code that works for the length of your visit. Building reception and QR codes are run by building management, not by Harness.

3.2 When You Check In on the Harness Floor

When you arrive on the Harness floor, you check in on our Envoy iPad system, which collects:

  • The type of visitor you are (for example, customer or supplier), chosen from the check-in menu
  • Full name
  • Email address
  • Name of your Harness host
  • Your signature on our visitor non-disclosure agreement (NDA)
  • Date and time of arrival

You will get a paper badge. It does not open any restricted areas, and someone from Harness will stay with you throughout your visit. You need to provide the information listed above and sign the visitor NDA to enter our office. If you do not, we may not be able to let you in.

3.3 Regular Vendors 

If you are a regular vendor, you will get a badge through our Brivo access system. The system records the date and time each time you use the badge. 

3.4 CCTV

Some of our offices use CCTV. To find out how we use CCTV footage and what your rights are, please see our CCTV Notice: https://www.harness.io/legal/cctv-privacy-notice.

3.5 Accessibility Information

We do not intentionally collect “special categories of personal data” (sensitive information, such as health data). If you tell us about an accessibility need (for example, wheelchair access), we use that information only to help with your visit and do not keep a record of it.

4. Why We Use Your Personal Data and Our Legal Basis

We only use your personal data as data protection laws allow. The table below shows why we use it and the “legal basis” (the legal reason under the GDPR) for each use:

Purpose Legal basis
Confirm who you are when you arrive Legitimate interests (Art. 6(1)(f)) of the GDPR
Meet our health and safety duties, such as knowing who is in the building, keeping emergency evacuation lists, and recording incidents Legal obligation (Art. 6(1)(c)) of the GDPR
Keep a record of visitors so we can look into security incidents Legitimate interests (Art. 6(1)(f)) of the GDPR
Protect confidential information by asking you to sign a visitor NDA Legitimate interests (Art. 6(1)(f)) of the GDPR
Give regular vendors access so they can provide their services Legitimate interests (Art. 6(1)(f)) of the GDPR

When we rely on “legitimate interests”, we have checked that our interests do not override your rights and freedoms. In particular: visitors expect to identify themselves and be recorded when entering business premises; we collect only a small amount of business-related information; we tell you about it when you check in; we keep it for a limited time; and we do not use it to make decisions that negatively affect you. You can object to this use of your data at any time (see Section 9).

5. Who We Share Your Data With

To protect your privacy, we only share your data when it is necessary and when appropriate security safeguards are in place. The following people and organizations may see or receive your data.

Internal access to your personal data is provided to our personnel strictly on a need-to-know and case-by-case basis.

External service providers and other recipients:

  • Envoy: our visitor check-in system at direct lease offices
  • Brivo: our badge access system for regular vendors
  • Building management / landlord: runs building reception, QR codes, and shared building access systems as an independent controller (not covered by this Privacy Notice)
  • Co-working space providers (for example, WeWork): run visitor reception and security at co-working spaces as independent controllers (not covered by this Privacy Notice)

Legal authorities:

  • Public authorities, such as regulators or the police, when the law requires us to share it.

For any international data transfers, we implement appropriate safeguards and mechanisms, including EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework that any recipient may hold, or relevant adequacy decisions. 

6. Security measures 

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, protecting personal data against unauthorized or unlawful processing, accidental loss, destruction, alteration, or disclosure. For more information on our security practices, please visit our Trust Center at trust.harness.io.

7. How Long We Keep Your Data

We keep your personal data only as long as we need it for the purposes described in this notice, in line with our internal retention rules:

  • Visitor records: 2 years from the date of your visit.
  • Regular vendor badges: switched off when the vendor stops providing services to us. 
  • CCTV footage: see our CCTV Notice.  

We may keep data for longer if the law requires it or if we need it to deal with legal claims.

8. Automated Decision-Making

We do not use automated decision-making, including profiling (decisions made only by computer, without a person involved), that has legal or similarly significant effects on you in connection with your visit.

9. Your Rights

9.1 General Rights under the GDPR

Under the GDPR, you have the following rights in relation to your personal data:

  • Access your personal data and receive a copy of it
  • Correct personal data that is inaccurate or incomplete
  • Ask us to delete your personal data in certain situations, unless the law requires us to keep it
  • Ask us to limit how we use your personal data in certain cases
  • Object to our use of your personal data where we rely on legitimate interests

The right to data portability (getting your data in a format you can move elsewhere) does not apply, because we do not rely on your consent or on a contract to use visitor data. These rights have limits, and in some situations a right may not apply. You can use your rights through our privacy portal at harness-privacy.relyance.ai.

9.2 European Economic Area and United Kingdom

If you are in the EEA or the UK, you can contact our EU Representative using the details in Section 1. You also have the right to complain to your local data protection authority (called a “supervisory authority”).

9.3 United States

If you live in a US state with a consumer privacy law (such as California, Colorado, Connecticut, Oregon, Utah, Virginia, Texas, or other applicable states), you may have the right to access, correct, and delete your personal data. We do not sell or share visitor personal information, and we do not collect sensitive personal information (as defined under applicable US state privacy laws) about visitors. We will not treat you unfairly for using your privacy rights. To make a request, use our privacy portal at harness-privacy.relyance.ai. If your state law lets you appeal our decision, you can do so through the same portal.

9.4 India

If you are in India, the Digital Personal Data Protection Act, 2023 gives you the right to get a summary of your personal data and how we use it, to ask us to correct or delete it, and to name another person to use your rights for you. You can also complain to the Data Protection Board of India. You can use these rights through our privacy portal at harness-privacy.relyance.ai.

10. Complaints

If you think we have not respected your data protection rights, you can complain to your local data protection authority, for example:

  • Your national supervisory authority in the EEA
  • The Information Commissioner’s Office (ICO) in the UK
  • The relevant state attorney general or agency in the United States
  • The Data Protection Board of India

11. Changes to This Notice

We may update this privacy notice from time to time. When we do, we will change the “Last updated” date at the top of this page. If we make important changes to how we use your personal data, we will tell you clearly [at our office reception points and on our website] before the change takes effect.