- Jurisdiction
- Poland / European Union
- Version
- 2026-07-03
- Operator
- Nova Group Sp. z o.o.
This Security page explains the general security practices used by eVisa Immigration, operated by Nova Group Sp. z o.o., at https://evisa-immigration.com.
Security contact: security@evisa-immigration.com
1. Security approach
eVisa Immigration processes travel-document, identity, payment, account, and customer-support information. We use technical and organizational measures designed to protect confidentiality, integrity, and availability of data and systems.
Security measures are risk-based and may include access controls, authentication controls, encryption in transit, logging, provider due diligence, secure payment flows, fraud-prevention checks, backups, monitoring, malware controls, operational procedures, and limited employee or contractor access based on role.
2. Payment security
Payments may be processed by Stripe, Worldline, banks, card networks, wallet providers, app stores, or other payment partners. These providers may perform payment authentication, fraud screening, risk scoring, sanctions checks, transaction monitoring, and dispute handling.
We do not store full card details on our own systems. Full card numbers, card security codes, and sensitive payment credentials are handled by payment processors according to their own security and compliance obligations.
3. Account security
Account and authentication features may use Clerk or other authentication providers. Account security may include session cookies, secure authentication flows, access controls, account activity signals, and abuse-prevention checks.
Customers are responsible for:
- Keeping account credentials confidential.
- Protecting access to their email account.
- Using secure devices and updated browsers.
- Signing out on shared devices.
- Not sharing account access with unauthorized persons.
- Contacting support promptly if they suspect account misuse.
4. Data protection measures
We may use the following general safeguards:
- HTTPS/TLS for website communication where supported.
- Access controls for systems that process customer data.
- Role-based access for operational users.
- Logging and monitoring for security and abuse-prevention purposes.
- Private storage or restricted access for sensitive documents where technically implemented.
- Provider due diligence for key service providers.
- Data minimization where possible.
- Retention controls according to operational and legal needs.
- Secure deletion or restriction where retention is no longer needed and deletion is legally permitted.
5. Document and identity security
Travel-document services may require passport scans, photographs, identity documents, supporting documents, and sensitive application answers. Customers should upload documents only through the website, account, app, or support channel indicated for the order.
Customers should avoid sending unnecessary sensitive information and should contact support@evisa-immigration.com if they are unsure which documents are needed.
6. Fraud prevention and abuse controls
We may use fraud-prevention and abuse-detection controls to protect customers, payment processors, card networks, government-service workflows, and the business. These controls may include payment-risk checks, velocity checks, device and session signals, IP-based checks, account monitoring, document consistency checks, sanctions screening, and manual escalation where appropriate.
Orders may be refused, suspended, cancelled, or restricted where we reasonably suspect fraud, unauthorized payment use, false documents, sanctions exposure, unlawful activity, platform-rule violations, or service misuse.
7. Responsible disclosure
Security concerns, suspected vulnerabilities, account-security issues, or payment-security concerns should be reported to:
security@evisa-immigration.com
A useful report includes:
- A clear description of the issue.
- The affected URL, endpoint, account area, or product flow.
- Steps to reproduce the issue.
- Screenshots or logs where safe to share.
- Contact details for follow-up.
Do not access, modify, delete, copy, download, disclose, or disrupt data that does not belong to you. Do not run destructive testing, social engineering, spam, denial-of-service testing, or tests that affect other users or service availability.
8. Incident communication
If we identify a security incident affecting personal data, payment data, account access, service availability, or customer documents, we will assess the incident and take appropriate steps according to applicable law, processor requirements, and operational risk. Where notification is required, we will communicate through appropriate channels such as email, account notices, website notices, or direct customer support.
9. Third-party services
The service may rely on third-party providers for hosting, authentication, payments, analytics, customer support, fraud prevention, document handling, AI assistance, app distribution, and communications. Third-party providers maintain their own infrastructure, terms, privacy policies, and security practices.
10. No absolute security guarantee
No website, app, email system, payment flow, account system, third-party system, or internet transmission can be guaranteed to be completely secure. Customers should use the service carefully, protect their devices, avoid public or untrusted networks for sensitive transactions, and contact security@evisa-immigration.com if they suspect a security issue.