Private visa assistance platform. Not affiliated with the government. Service fees apply.
Jump to content
eVisa Immigration
Back to legal center

eVisa Immigration Legal

Privacy Policy

How Nova Group Sp. z o.o. collects, uses, stores, shares, transfers, and protects personal data.

Jurisdiction
Poland / European Union
Version
2026-07-03
Operator
Nova Group Sp. z o.o.

This Privacy Policy explains how Nova Group Sp. z o.o., operating eVisa Immigration at https://evisa-immigration.com, collects, uses, stores, shares, transfers, and protects personal data.

1. Controller details

The data controller is:

Nova Group Sp. z o.o.
Tax ID / VAT ID: PL7011215529
KRS: 0001117840
REGON: 529224431
Registered address: Żurawia 6/12 Lok. 745, 00-503 Warszawa, Poland

Website: https://evisa-immigration.com
Privacy contact: privacy@evisa-immigration.com
Customer support: support@evisa-immigration.com
Security contact: security@evisa-immigration.com

2. Scope of this Policy

This Policy applies to personal data processed through eVisa Immigration websites, online forms, customer accounts, payment flows, mobile applications, support channels, document-upload tools, analytics tools, marketing tools, and related services.

It applies to customers, travelers, account users, website visitors, app users, support contacts, business contacts, applicants, payment users, and persons whose information is submitted by another authorized person.

3. Categories of personal data we process

Depending on the service and order, we may process:

  • Identity data: name, date of birth, nationality, gender where required for a travel document, passport or identity-document details, photograph, signature, and identification information.
  • Contact data: email address, address, country, language preference, and customer-support details.
  • Travel data: travel dates, destination, purpose of travel, itinerary, accommodation details, flight information, transit information, prior travel information, and border-entry information.
  • Application data: answers to visa, authorization, arrival-card, health, customs, immigration, embassy, consular, airline, or authority questions.
  • Document data: passport scans, photographs, supporting documents, invitation letters, proof of accommodation, flight confirmations, proof of funds, employment documents, family documents, student documents, or other documents required for the chosen product.
  • Special-category or sensitive data where required for a specific application: biometric-style photographs, health declarations, criminal-history answers, immigration-history answers, religious or family information, or other sensitive data required by an authority.
  • Account data: login identifiers, authentication status, session information, account activity, order history, app activity, and preferences.
  • Payment and transaction data: amount, currency, billing details, payment status, payment method type, processor reference, refunds, disputes, fraud-screening signals, and tax information. Full card data is handled by payment processors and is not stored by us.
  • Technical data: IP address, device identifiers, browser type, operating system, log files, cookie identifiers, analytics events, consent choices, security logs, and fraud-prevention information.
  • Communication data: emails, support messages, attachments, notes, complaint records, customer instructions, consent records, and service-performance records.
  • Marketing data: newsletter preferences, advertising consent, campaign source, conversion events, and remarketing preferences where permitted.

4. How we collect data

We collect data when:

  • A customer visits the website or app.
  • A customer creates an account or signs in.
  • A customer starts, saves, or submits an application.
  • A customer uploads documents or photographs.
  • A customer pays, requests a refund, or opens a payment dispute.
  • A customer contacts support.
  • Another authorized person submits traveler information.
  • Service providers, payment processors, analytics providers, fraud-prevention providers, authorities, or technical systems generate data necessary for the service.

5. Purposes and legal bases

We process personal data for the following purposes and legal bases under GDPR / RODO:

PurposeExamplesLegal basis
Service performancePreparing applications, checking documents, delivering digital services, providing account access, supporting ordersContract performance or steps before entering into a contract
Government or authority process supportFormatting information, submitting where included, responding to authority requests, tracking statusContract performance; legal obligation where applicable; consent where required
Payment processingTaking payment, confirming payment, refunds, chargeback evidence, fraud checksContract performance; legitimate interests; legal obligation
Customer support and complaintsResponding to messages, resolving order issues, keeping complaint recordsContract performance; legitimate interests; legal obligation
Security and fraud preventionAccount protection, transaction monitoring, abuse detection, sanctions screening, loggingLegitimate interests; legal obligation
Legal and tax complianceAccounting records, tax records, compliance evidence, consumer-law recordsLegal obligation
Website and app analyticsMeasuring use, improving pages, detecting errors, understanding product performanceConsent where required; legitimate interests for strictly necessary or privacy-preserving analytics where permitted
Advertising and remarketingGoogle Ads conversion tracking, remarketing, campaign measurementConsent where required
Product improvementImproving forms, app flows, document checks, support tools, and customer experienceLegitimate interests; consent where required
AI-assisted operationsSummaries, classification, document extraction support, customer-support assistance, fraud detectionContract performance; legitimate interests; consent where required for specific data uses
CommunicationsOrder emails, service messages, account notices, consent confirmations, policy updatesContract performance; legal obligation; legitimate interests
Marketing communicationsNewsletters, promotions, offers, service updatesConsent or legitimate interests where permitted by law

Where consent is the legal basis, the customer may withdraw consent at any time. Withdrawal does not affect processing already performed lawfully before withdrawal.

6. Special-category and sensitive data

Some travel-document or immigration processes may require sensitive information, such as health declarations, biometric-style photographs, criminal-history answers, religious information, family information, or other sensitive details. We process such data only where needed for the selected service, where permitted by law, and where an appropriate legal basis applies, such as explicit consent, substantial public-interest requirements, legal claims, or another applicable basis.

If the customer submits sensitive data about another traveler, the customer confirms that they have authority to do so.

7. Payment processor role

Payments may be processed by Stripe, Worldline, card networks, banks, wallet providers, app stores, fraud-prevention providers, or other payment partners. These providers may act as independent controllers, processors, or both, depending on the processing activity.

We receive limited payment information such as payment status, processor reference, payment method type, billing details, fraud signals, dispute details, and refund status. We do not store full card numbers or card security codes on our own systems.

Payment providers may process data for fraud prevention, transaction security, authentication, payment processing, regulatory compliance, dispute handling, and their own legally required purposes.

8. Analytics, advertising, and tracking tools

The website may use Cookiebot CMP, Google Consent Mode v2, GA4 / Google Analytics 4, Google Ads conversion tracking and remarketing, Plausible Analytics, PostHog, Clerk, Stripe, Worldline, and related technologies.

Analytics and marketing tools are controlled through the cookie consent mechanism where required. Google Consent Mode v2 may send consent signals such as analytics storage, advertising storage, ad user data, and ad personalization settings to Google services according to the user’s choices.

More information is available in the Cookies Policy.

9. Customer support

When a customer contacts support, we process the content of the message, order reference, customer identity, attachments, prior communications, and related service records. Support records are used to respond to the customer, resolve complaints, prevent fraud, maintain service quality, and evidence service performance.

10. Processors and subprocessors

We may share personal data with service providers necessary for operating eVisa Immigration, including:

  • Hosting, cloud infrastructure, databases, storage, backup, logging, and security providers.
  • Authentication and account providers such as Clerk.
  • Payment processors such as Stripe and Worldline.
  • Fraud-prevention, identity-verification, sanctions-screening, and risk providers.
  • Analytics and product-improvement providers such as GA4, Plausible Analytics, and PostHog.
  • Advertising and measurement providers such as Google Ads.
  • Cookie-consent providers such as Cookiebot CMP.
  • Customer-support and communication providers.
  • Email, notification, and delivery providers.
  • Document-processing, OCR, translation, AI-assisted, and quality-control providers.
  • Government authorities, embassies, consulates, immigration authorities, border authorities, airlines, app stores, banks, card networks, regulators, courts, and professional advisers where necessary.

Processors are required to process data according to contractual obligations, confidentiality requirements, security obligations, and applicable data-protection law.

11. International transfers

Because travel-document services are international by nature, personal data may be transferred outside Poland, the European Economic Area, the United Kingdom, Switzerland, or the customer’s country. Transfers may occur when:

  • The destination government, embassy, consulate, airline, border authority, or related authority is located outside the EEA.
  • A service provider, payment provider, app-store provider, analytics provider, support provider, or technical provider processes data internationally.
  • The customer requests a service for a destination outside the EEA.

Where GDPR applies, we use appropriate transfer mechanisms where required, such as adequacy decisions, Standard Contractual Clauses, additional safeguards, necessity for contract performance, explicit consent where applicable, legal claims, or other lawful transfer bases.

12. Retention periods

We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.

Typical retention periods include:

Data categoryTypical retention
Account dataFor the life of the account and a reasonable period after closure
Order and service recordsUp to 6 years after completion, cancellation, or final customer contact, unless longer retention is needed for disputes, tax, fraud, or legal reasons
Tax and accounting recordsAs required by Polish tax and accounting law
Payment and refund recordsAs required for payment, accounting, fraud prevention, processor, and dispute purposes
Customer-support recordsUp to 6 years where connected with an order or complaint; shorter periods may apply for general enquiries
Application documentsFor the period needed to perform the service, support the customer, handle corrections, evidence performance, and comply with legal obligations
Consent recordsFor as long as needed to evidence consent and comply with legal obligations
Security logsUsually from several days to 24 months depending on risk and system needs
Analytics dataAccording to the analytics configuration and consent settings, typically up to 24 months where identifiers are used
Marketing dataUntil consent is withdrawn, objection is received, or the data is no longer needed

We may retain limited records for longer if necessary to establish, exercise, or defend legal claims, prevent fraud, respond to payment disputes, comply with sanctions or regulatory obligations, or protect the service.

13. Data subject rights

Where GDPR applies, data subjects have the right to:

  • Access personal data.
  • Rectify inaccurate personal data.
  • Erase personal data where the legal conditions are met.
  • Restrict processing.
  • Object to processing based on legitimate interests or direct marketing.
  • Data portability.
  • Withdraw consent where processing is based on consent.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.

Requests should be sent to privacy@evisa-immigration.com. We may need to verify the requester’s identity and authority. We will respond within the period required by GDPR, normally within one month, with extensions where permitted for complex requests.

14. Complaint to the Polish supervisory authority

A person who believes that their personal data has been processed in violation of data-protection law may contact us first at privacy@evisa-immigration.com. They also have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland:

Prezes Urzędu Ochrony Danych Osobowych
ul. Stawki 2
00-193 Warszawa
Poland

15. Automated decision-making

We may use automated tools to support fraud prevention, risk scoring, document classification, error detection, analytics, customer routing, and operational efficiency. These tools assist service performance and security. We do not use solely automated decisions that produce legal or similarly significant effects for customers unless permitted by law and accompanied by required safeguards.

16. Security

We use technical and organizational measures designed to protect personal data, including access controls, authentication controls, encryption in transit where appropriate, logging, restricted access, provider due diligence, backups, monitoring, and payment-security practices. No online service can be guaranteed to be completely secure.

Security concerns should be reported to security@evisa-immigration.com.

17. Children’s data

The service may process data of minors where a parent, guardian, or authorized adult orders a service for a minor traveler. The person submitting the data must have legal authority to do so.

18. Marketing choices

Customers may unsubscribe from marketing communications using the unsubscribe mechanism in the message or by contacting support@evisa-immigration.com. Service communications relating to orders, payments, security, legal notices, and account administration may still be sent where necessary.

19. Changes to this Policy

We may update this Policy to reflect service changes, legal changes, provider changes, technology changes, or operational improvements. The latest version will be available on the website.