Private visa assistance platform. Not affiliated with the government. Service fees apply.
Jump to content
eVisa Immigration
Back to legal center

eVisa Immigration Legal

Security

General security practices, payment security, account security, data safeguards, and responsible disclosure.

Jurisdiction
Poland / European Union
Version
2026-07-03
Operator
Nova Group Sp. z o.o.

This Security page explains the general security practices used by eVisa Immigration, operated by Nova Group Sp. z o.o., at https://evisa-immigration.com.

Security contact: security@evisa-immigration.com

1. Security approach

eVisa Immigration processes travel-document, identity, payment, account, and customer-support information. We use technical and organizational measures designed to protect confidentiality, integrity, and availability of data and systems.

Security measures are risk-based and may include access controls, authentication controls, encryption in transit, logging, provider due diligence, secure payment flows, fraud-prevention checks, backups, monitoring, malware controls, operational procedures, and limited employee or contractor access based on role.

2. Payment security

Payments may be processed by Stripe, Worldline, banks, card networks, wallet providers, app stores, or other payment partners. These providers may perform payment authentication, fraud screening, risk scoring, sanctions checks, transaction monitoring, and dispute handling.

We do not store full card details on our own systems. Full card numbers, card security codes, and sensitive payment credentials are handled by payment processors according to their own security and compliance obligations.

3. Account security

Account and authentication features may use Clerk or other authentication providers. Account security may include session cookies, secure authentication flows, access controls, account activity signals, and abuse-prevention checks.

Customers are responsible for:

  • Keeping account credentials confidential.
  • Protecting access to their email account.
  • Using secure devices and updated browsers.
  • Signing out on shared devices.
  • Not sharing account access with unauthorized persons.
  • Contacting support promptly if they suspect account misuse.

4. Data protection measures

We may use the following general safeguards:

  • HTTPS/TLS for website communication where supported.
  • Access controls for systems that process customer data.
  • Role-based access for operational users.
  • Logging and monitoring for security and abuse-prevention purposes.
  • Private storage or restricted access for sensitive documents where technically implemented.
  • Provider due diligence for key service providers.
  • Data minimization where possible.
  • Retention controls according to operational and legal needs.
  • Secure deletion or restriction where retention is no longer needed and deletion is legally permitted.

5. Document and identity security

Travel-document services may require passport scans, photographs, identity documents, supporting documents, and sensitive application answers. Customers should upload documents only through the website, account, app, or support channel indicated for the order.

Customers should avoid sending unnecessary sensitive information and should contact support@evisa-immigration.com if they are unsure which documents are needed.

6. Fraud prevention and abuse controls

We may use fraud-prevention and abuse-detection controls to protect customers, payment processors, card networks, government-service workflows, and the business. These controls may include payment-risk checks, velocity checks, device and session signals, IP-based checks, account monitoring, document consistency checks, sanctions screening, and manual escalation where appropriate.

Orders may be refused, suspended, cancelled, or restricted where we reasonably suspect fraud, unauthorized payment use, false documents, sanctions exposure, unlawful activity, platform-rule violations, or service misuse.

7. Responsible disclosure

Security concerns, suspected vulnerabilities, account-security issues, or payment-security concerns should be reported to:

security@evisa-immigration.com

A useful report includes:

  • A clear description of the issue.
  • The affected URL, endpoint, account area, or product flow.
  • Steps to reproduce the issue.
  • Screenshots or logs where safe to share.
  • Contact details for follow-up.

Do not access, modify, delete, copy, download, disclose, or disrupt data that does not belong to you. Do not run destructive testing, social engineering, spam, denial-of-service testing, or tests that affect other users or service availability.

8. Incident communication

If we identify a security incident affecting personal data, payment data, account access, service availability, or customer documents, we will assess the incident and take appropriate steps according to applicable law, processor requirements, and operational risk. Where notification is required, we will communicate through appropriate channels such as email, account notices, website notices, or direct customer support.

9. Third-party services

The service may rely on third-party providers for hosting, authentication, payments, analytics, customer support, fraud prevention, document handling, AI assistance, app distribution, and communications. Third-party providers maintain their own infrastructure, terms, privacy policies, and security practices.

10. No absolute security guarantee

No website, app, email system, payment flow, account system, third-party system, or internet transmission can be guaranteed to be completely secure. Customers should use the service carefully, protect their devices, avoid public or untrusted networks for sensitive transactions, and contact security@evisa-immigration.com if they suspect a security issue.