Privacy Terms
Version 1.3
1. What we collect
- Identity and contact data — name, email, telephone, nationality, and passport details.
- Application documents — passport scans, photographs, bank statements, employment contracts, and any supporting evidence you upload.
- Financial data — the fact and amount of payment. Card details are handled entirely by our payment processor and never reach our servers.
- Technical and audit data — IP address, browser user-agent, and timestamps for security-relevant actions.
2. Why we collect it
To assess eligibility, prepare and file your application, communicate with you about your case, take payment, comply with our legal obligations, and maintain a tamper-evident record of consent and account activity.
3. The audit log
Certain actions — registration, acceptance of terms, document upload, payment, administrative decisions on your file — are written to an append-only log alongside your IP address and a timestamp. Each entry is cryptographically chained to its predecessor so that any later alteration is detectable.
We keep this record so that both parties can establish what was agreed and when. It protects you as much as us. You may request a copy of the entries relating to you at any time.
4. Who we share it with
- The diplomatic mission handling your application — this is the purpose of the engagement.
- Our payment processor, for taking payment and issuing refunds.
- Our hosting and storage providers, under contractual confidentiality obligations.
- Authorities, where we are legally compelled to disclose.
We do not sell your data, and we do not share it with advertisers or data brokers. Ever.
5. How long we keep it
Application documents are retained for 24 months after your case closes, then deleted. Audit log entries and financial records are retained for [7] years to meet statutory record-keeping requirements. You may request earlier erasure of your documents; we will comply unless a legal obligation requires us to retain them.
6. How we protect it
- Documents are encrypted at rest and served only over authenticated, logged requests.
- Passwords are stored as salted bcrypt hashes and are never recoverable in plaintext.
- Sessions use signed, HTTP-only cookies that JavaScript cannot read.
- Access to client files is restricted to assigned staff and is itself logged.
7. Your rights
You may request access to your data, correction of inaccuracies, erasure, a portable copy, or restriction of processing. Write to [privacy contact email] and we will respond within 30 days. If you are unsatisfied you may complain to your local data protection authority.
8. Cookies
We set one strictly necessary cookie to keep you signed in. We do not use advertising or third-party tracking cookies, so there is no consent banner to dismiss.
9. Contact
Data controller: [legal entity name] · [privacy contact email] · [registered address]