- Jurisdiction
- Poland / European Union
- Version
- 2026-07-03
- Operator
- Nova Group Sp. z o.o.
This Privacy Policy explains how Nova Group Sp. z o.o., operating eVisa Immigration at https://evisa-immigration.com, collects, uses, stores, shares, transfers, and protects personal data.
1. Controller details
The data controller is:
Nova Group Sp. z o.o.
Tax ID / VAT ID: PL7011215529
KRS: 0001117840
REGON: 529224431
Registered address: Żurawia 6/12 Lok. 745, 00-503 Warszawa, Poland
Website: https://evisa-immigration.com
Privacy contact: privacy@evisa-immigration.com
Customer support: support@evisa-immigration.com
Security contact: security@evisa-immigration.com
2. Scope of this Policy
This Policy applies to personal data processed through eVisa Immigration websites, online forms, customer accounts, payment flows, mobile applications, support channels, document-upload tools, analytics tools, marketing tools, and related services.
It applies to customers, travelers, account users, website visitors, app users, support contacts, business contacts, applicants, payment users, and persons whose information is submitted by another authorized person.
3. Categories of personal data we process
Depending on the service and order, we may process:
- Identity data: name, date of birth, nationality, gender where required for a travel document, passport or identity-document details, photograph, signature, and identification information.
- Contact data: email address, address, country, language preference, and customer-support details.
- Travel data: travel dates, destination, purpose of travel, itinerary, accommodation details, flight information, transit information, prior travel information, and border-entry information.
- Application data: answers to visa, authorization, arrival-card, health, customs, immigration, embassy, consular, airline, or authority questions.
- Document data: passport scans, photographs, supporting documents, invitation letters, proof of accommodation, flight confirmations, proof of funds, employment documents, family documents, student documents, or other documents required for the chosen product.
- Special-category or sensitive data where required for a specific application: biometric-style photographs, health declarations, criminal-history answers, immigration-history answers, religious or family information, or other sensitive data required by an authority.
- Account data: login identifiers, authentication status, session information, account activity, order history, app activity, and preferences.
- Payment and transaction data: amount, currency, billing details, payment status, payment method type, processor reference, refunds, disputes, fraud-screening signals, and tax information. Full card data is handled by payment processors and is not stored by us.
- Technical data: IP address, device identifiers, browser type, operating system, log files, cookie identifiers, analytics events, consent choices, security logs, and fraud-prevention information.
- Communication data: emails, support messages, attachments, notes, complaint records, customer instructions, consent records, and service-performance records.
- Marketing data: newsletter preferences, advertising consent, campaign source, conversion events, and remarketing preferences where permitted.
4. How we collect data
We collect data when:
- A customer visits the website or app.
- A customer creates an account or signs in.
- A customer starts, saves, or submits an application.
- A customer uploads documents or photographs.
- A customer pays, requests a refund, or opens a payment dispute.
- A customer contacts support.
- Another authorized person submits traveler information.
- Service providers, payment processors, analytics providers, fraud-prevention providers, authorities, or technical systems generate data necessary for the service.
5. Purposes and legal bases
We process personal data for the following purposes and legal bases under GDPR / RODO:
| Purpose | Examples | Legal basis |
|---|---|---|
| Service performance | Preparing applications, checking documents, delivering digital services, providing account access, supporting orders | Contract performance or steps before entering into a contract |
| Government or authority process support | Formatting information, submitting where included, responding to authority requests, tracking status | Contract performance; legal obligation where applicable; consent where required |
| Payment processing | Taking payment, confirming payment, refunds, chargeback evidence, fraud checks | Contract performance; legitimate interests; legal obligation |
| Customer support and complaints | Responding to messages, resolving order issues, keeping complaint records | Contract performance; legitimate interests; legal obligation |
| Security and fraud prevention | Account protection, transaction monitoring, abuse detection, sanctions screening, logging | Legitimate interests; legal obligation |
| Legal and tax compliance | Accounting records, tax records, compliance evidence, consumer-law records | Legal obligation |
| Website and app analytics | Measuring use, improving pages, detecting errors, understanding product performance | Consent where required; legitimate interests for strictly necessary or privacy-preserving analytics where permitted |
| Advertising and remarketing | Google Ads conversion tracking, remarketing, campaign measurement | Consent where required |
| Product improvement | Improving forms, app flows, document checks, support tools, and customer experience | Legitimate interests; consent where required |
| AI-assisted operations | Summaries, classification, document extraction support, customer-support assistance, fraud detection | Contract performance; legitimate interests; consent where required for specific data uses |
| Communications | Order emails, service messages, account notices, consent confirmations, policy updates | Contract performance; legal obligation; legitimate interests |
| Marketing communications | Newsletters, promotions, offers, service updates | Consent or legitimate interests where permitted by law |
Where consent is the legal basis, the customer may withdraw consent at any time. Withdrawal does not affect processing already performed lawfully before withdrawal.
6. Special-category and sensitive data
Some travel-document or immigration processes may require sensitive information, such as health declarations, biometric-style photographs, criminal-history answers, religious information, family information, or other sensitive details. We process such data only where needed for the selected service, where permitted by law, and where an appropriate legal basis applies, such as explicit consent, substantial public-interest requirements, legal claims, or another applicable basis.
If the customer submits sensitive data about another traveler, the customer confirms that they have authority to do so.
7. Payment processor role
Payments may be processed by Stripe, Worldline, card networks, banks, wallet providers, app stores, fraud-prevention providers, or other payment partners. These providers may act as independent controllers, processors, or both, depending on the processing activity.
We receive limited payment information such as payment status, processor reference, payment method type, billing details, fraud signals, dispute details, and refund status. We do not store full card numbers or card security codes on our own systems.
Payment providers may process data for fraud prevention, transaction security, authentication, payment processing, regulatory compliance, dispute handling, and their own legally required purposes.
8. Analytics, advertising, and tracking tools
The website may use Cookiebot CMP, Google Consent Mode v2, GA4 / Google Analytics 4, Google Ads conversion tracking and remarketing, Plausible Analytics, PostHog, Clerk, Stripe, Worldline, and related technologies.
Analytics and marketing tools are controlled through the cookie consent mechanism where required. Google Consent Mode v2 may send consent signals such as analytics storage, advertising storage, ad user data, and ad personalization settings to Google services according to the user’s choices.
More information is available in the Cookies Policy.
9. Customer support
When a customer contacts support, we process the content of the message, order reference, customer identity, attachments, prior communications, and related service records. Support records are used to respond to the customer, resolve complaints, prevent fraud, maintain service quality, and evidence service performance.
10. Processors and subprocessors
We may share personal data with service providers necessary for operating eVisa Immigration, including:
- Hosting, cloud infrastructure, databases, storage, backup, logging, and security providers.
- Authentication and account providers such as Clerk.
- Payment processors such as Stripe and Worldline.
- Fraud-prevention, identity-verification, sanctions-screening, and risk providers.
- Analytics and product-improvement providers such as GA4, Plausible Analytics, and PostHog.
- Advertising and measurement providers such as Google Ads.
- Cookie-consent providers such as Cookiebot CMP.
- Customer-support and communication providers.
- Email, notification, and delivery providers.
- Document-processing, OCR, translation, AI-assisted, and quality-control providers.
- Government authorities, embassies, consulates, immigration authorities, border authorities, airlines, app stores, banks, card networks, regulators, courts, and professional advisers where necessary.
Processors are required to process data according to contractual obligations, confidentiality requirements, security obligations, and applicable data-protection law.
11. International transfers
Because travel-document services are international by nature, personal data may be transferred outside Poland, the European Economic Area, the United Kingdom, Switzerland, or the customer’s country. Transfers may occur when:
- The destination government, embassy, consulate, airline, border authority, or related authority is located outside the EEA.
- A service provider, payment provider, app-store provider, analytics provider, support provider, or technical provider processes data internationally.
- The customer requests a service for a destination outside the EEA.
Where GDPR applies, we use appropriate transfer mechanisms where required, such as adequacy decisions, Standard Contractual Clauses, additional safeguards, necessity for contract performance, explicit consent where applicable, legal claims, or other lawful transfer bases.
12. Retention periods
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
Typical retention periods include:
| Data category | Typical retention |
|---|---|
| Account data | For the life of the account and a reasonable period after closure |
| Order and service records | Up to 6 years after completion, cancellation, or final customer contact, unless longer retention is needed for disputes, tax, fraud, or legal reasons |
| Tax and accounting records | As required by Polish tax and accounting law |
| Payment and refund records | As required for payment, accounting, fraud prevention, processor, and dispute purposes |
| Customer-support records | Up to 6 years where connected with an order or complaint; shorter periods may apply for general enquiries |
| Application documents | For the period needed to perform the service, support the customer, handle corrections, evidence performance, and comply with legal obligations |
| Consent records | For as long as needed to evidence consent and comply with legal obligations |
| Security logs | Usually from several days to 24 months depending on risk and system needs |
| Analytics data | According to the analytics configuration and consent settings, typically up to 24 months where identifiers are used |
| Marketing data | Until consent is withdrawn, objection is received, or the data is no longer needed |
We may retain limited records for longer if necessary to establish, exercise, or defend legal claims, prevent fraud, respond to payment disputes, comply with sanctions or regulatory obligations, or protect the service.
13. Data subject rights
Where GDPR applies, data subjects have the right to:
- Access personal data.
- Rectify inaccurate personal data.
- Erase personal data where the legal conditions are met.
- Restrict processing.
- Object to processing based on legitimate interests or direct marketing.
- Data portability.
- Withdraw consent where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.
Requests should be sent to privacy@evisa-immigration.com. We may need to verify the requester’s identity and authority. We will respond within the period required by GDPR, normally within one month, with extensions where permitted for complex requests.
14. Complaint to the Polish supervisory authority
A person who believes that their personal data has been processed in violation of data-protection law may contact us first at privacy@evisa-immigration.com. They also have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland:
Prezes Urzędu Ochrony Danych Osobowych
ul. Stawki 2
00-193 Warszawa
Poland
15. Automated decision-making
We may use automated tools to support fraud prevention, risk scoring, document classification, error detection, analytics, customer routing, and operational efficiency. These tools assist service performance and security. We do not use solely automated decisions that produce legal or similarly significant effects for customers unless permitted by law and accompanied by required safeguards.
16. Security
We use technical and organizational measures designed to protect personal data, including access controls, authentication controls, encryption in transit where appropriate, logging, restricted access, provider due diligence, backups, monitoring, and payment-security practices. No online service can be guaranteed to be completely secure.
Security concerns should be reported to security@evisa-immigration.com.
17. Children’s data
The service may process data of minors where a parent, guardian, or authorized adult orders a service for a minor traveler. The person submitting the data must have legal authority to do so.
18. Marketing choices
Customers may unsubscribe from marketing communications using the unsubscribe mechanism in the message or by contacting support@evisa-immigration.com. Service communications relating to orders, payments, security, legal notices, and account administration may still be sent where necessary.
19. Changes to this Policy
We may update this Policy to reflect service changes, legal changes, provider changes, technology changes, or operational improvements. The latest version will be available on the website.