The Visa Orchestrator ("we", "us", or "our") is committed to protecting the privacy and security of the personal data processed through our platform. This Privacy Policy explains how we collect, use, and safeguard personal information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Our Role: Data Processor vs. Data Controller
Under the UK GDPR, our Enterprise Clients (such as visa agencies and corporate employers) who use our platform to manage visa applications for their end-users are the Data Controllers. The Visa Orchestrator acts solely as the Data Processor on behalf of our Enterprise Clients. We only process personal data according to the documented instructions of the Data Controller.
2. Data We Process
As a Data Processor, we securely store and orchestrate the following types of data on behalf of our clients:
- Identity Data: Names, dates of birth, nationality, and passport details.
- Contact Data: Email addresses, phone numbers, and physical addresses.
- Sensitive Documents: Scanned copies of passports, ID cards, visas, and supporting travel documentation.
- Application Data: Travel itineraries, employment history, and other data required by specific government visa portals.
3. Sub-Processors
To provide our orchestration platform, we utilize trusted third-party sub-processors who meet strict security and compliance standards:
- Supabase: Provides our encrypted database and secure digital document vault. All data is encrypted at rest and in transit.
- Stripe: Acts as our secure payment processing gateway. We do not store full credit card details on our servers.
4. Data Retention and Automated Deletion
We employ strict automated data retention protocols to minimize risk. Specifically:
- Passports and Sensitive IDs: Automatically purged from our digital vaults after a predefined period following the completion of the visa lifecycle, unless the user explicitly opts into a "Reusable Traveler Profile" for future applications.
- Account Data: Retained for as long as the Enterprise Client maintains an active subscription, or until the Data Controller explicitly requests deletion.
5. Security Measures
We implement bank-grade encryption (AES-256), secure TLS protocols, and strict access controls. Access to the document vault is restricted to authorized personnel of the Data Controller and specific automated orchestration workflows.
6. Your Rights (End-Users)
If you are an individual traveler whose data was submitted to our platform by an Enterprise Client (e.g., your employer or travel agency), please direct any requests to exercise your data protection rights (such as access, rectification, or deletion) directly to the Enterprise Client (the Data Controller). We will assist the Data Controller in fulfilling these requests.
