Privacy Policy
Last updated: 3 June 2026 · Effective date: 3 June 2026
1. Who We Are and How to Contact Us
VisaScan AI ("VisaScan AI", "we", "us", or "our") operates the platform at visascan.ai, which helps individuals prepare document packs for Schengen visa applications across all 29 Schengen member states.
For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection law, VisaScan AI is the data controller of personal data collected through this platform.
Data Controller contact details
- Company: VisaScan AI
- Email: support@visascan.ai
- Website: https://visascan.ai
For all privacy queries, data access requests, or complaints, please email support@visascan.ai. We will respond within one month of receiving your request.
2. What This Policy Covers
This Privacy Policy applies to:
- All visitors to visascan.ai, whether or not they hold an account;
- All registered users who use the checklist, document upload, AI review, or form auto-fill features;
- Any person whose personal data appears in a document uploaded to the platform, such as a co-traveller included in a Family Pack application;
- Anyone who contacts us by email or any other channel.
3. What Personal Data We Collect
3.1 Account Data
When you register, we collect:
- Your full name;
- Your email address;
- Your password — stored in a hashed, non-reversible format. We never store passwords in plaintext;
- Account creation date and timestamp;
- Whether you registered via email/password or Google OAuth;
- Your IP address at registration.
3.2 Profile and Trip Data
When you complete the visa profile questionnaire, we collect:
- Your nationality and passport-issuing country;
- Your Schengen destination country (from all 29 countries supported);
- Purpose of travel (tourism or business);
- Employment status and funding source;
- Accommodation arrangements and trip dates;
- Number and details of co-travellers, where applicable;
- Any information you voluntarily enter in free-text fields.
3.3 Uploaded Document Data — Special Category Notice
When you choose to upload documents for AI review, we process the contents of those documents to generate your readiness report. Documents you may upload include:
- Passports and national identity documents, which may contain biographic data, nationality, date of birth, full name, and document numbers;
- Bank statements and financial records;
- Employment letters, payslips, and income documentation;
- Travel insurance certificates;
- Hotel bookings, flight itineraries, and accommodation confirmations;
- Cover letters and personal statements;
- Any other document you choose to submit.
Important — special category data: Passports and identity documents contain data classified as special category personal data under GDPR Article 9 (including, where applicable, data relating to nationality and biometric identifiers). We do not collect this data automatically. It is collected only when you actively choose to upload such a document.
We will not process any special category data contained in your uploaded documents without your separate, explicit consent. At the point of upload, before processing begins, you will be presented with a clear, standalone consent confirmation asking whether you consent to the processing of any special category data in your documents for the purpose of generating your AI readiness report. You may decline this consent and the document will not be processed. This consent can be withdrawn at any time by emailing support@visascan.ai.
3.4 Payment Data
When you purchase a paid plan:
- All payments are handled entirely by Paddle.com Market Limited, our Merchant of Record;
- We do not store your card number, CVV, or full card details at any point;
- We receive and retain only a transaction reference, amount paid, currency, and payment confirmation status;
- Where applicable, your billing country is shared with Paddle for EU VAT purposes.
3.5 Technical and Usage Data
When you use the platform, we automatically collect:
- IP address and approximate geographic location (country or city level);
- Browser type, version, and operating system;
- Device type and screen dimensions;
- Pages visited and features used;
- Session duration and navigation path;
- Error logs and crash reports;
- Session tokens maintaining your logged-in state.
3.6 Support Communications
If you contact us at support@visascan.ai, we collect:
- Your email address and any contact details you provide;
- The content and timestamp of your message;
- Any files or attachments included in your communication.
4. Why We Use Your Data — Lawful Basis
We only process personal data where we have a valid lawful basis under GDPR. The table below sets out each processing activity and its applicable basis.
| Processing activity | Data used | Lawful basis |
|---|---|---|
| Creating and managing your account | Account data | Contract — Art. 6(1)(b) |
| Generating your personalised checklist | Profile and trip data | Contract — Art. 6(1)(b) |
| Running AI document review and producing your report | Document data, profile data | Contract — Art. 6(1)(b) |
| Processing special category data in uploaded documents | Identity / biometric document data | Explicit consent — Art. 9(2)(a) — obtained via separate tick-box at point of upload |
| Processing your payment and issuing a receipt | Payment data, account data | Contract — Art. 6(1)(b) |
| Platform security and fraud prevention | Technical data, account data | Legitimate interests — Art. 6(1)(f) |
| Improving the platform using anonymised, aggregated usage data | Aggregated, anonymised usage data | Legitimate interests — Art. 6(1)(f) |
| Responding to support requests | Communications data, account data | Contract / Legitimate interests |
| Complying with legal and tax obligations | Relevant data categories | Legal obligation — Art. 6(1)(c) |
| Sending transactional emails (account verification, password reset, receipts) | Email address, account event | Contract — Art. 6(1)(b) |
5. How Long We Keep Your Data
We retain personal data only for as long as is necessary for the purpose for which it was collected, and in any case only for as long as required or permitted by law.
| Data category | Retention period | Reason |
|---|---|---|
| Uploaded documents | Automatically deleted within 30 days of upload | Document sensitivity — no longer required after report generation |
| AI-generated reports, readiness scores, recommendations | Retained in your account until you delete them, or until account closure + 30 days | Required for you to access and re-use your report |
| Financial transaction records (payment amounts, dates, receipts) | 7 years from transaction date | Legal obligation — standard tax and accounting record-keeping requirements |
| Account data (name, email) | Retained for account lifetime + 30 days after account closure | Required to fulfil account closure and confirm deletion |
| Profile and trip data | Retained for account lifetime + 30 days after account closure | Deleted promptly on closure |
| Technical logs and server data | Maximum 90 days, then deleted or anonymised | Security monitoring and debugging |
| Support communications | 3 years from date of communication | Legitimate interests — record of support interactions |
You may request early deletion of any data category at any time, subject to any overriding legal retention obligation.
6. How We Protect Your Data
TLS in transit
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
AES-256 at rest
All stored documents are encrypted at rest using AES-256 encryption, with encryption keys stored separately from the encrypted data.
Short-lived signed upload URLs
Document upload links are single-use, time-limited, and cryptographically signed. They expire immediately after use and cannot be reused or shared.
No document data in logs or emails
Our infrastructure is specifically configured to prevent the contents of uploaded documents from appearing in application logs, error-tracking tools, or email notifications.
Strict sessions and rate limiting
Authentication flows include session controls, rate limiting, and audit trails to mitigate brute-force and credential-stuffing attacks.
Audit logs for every action
Authentication events, administrative access, and data interactions are recorded in tamper-resistant audit logs.
Access controls
Internal access to personal data is restricted on a strict need-to-know basis. All personnel with access to user data are bound by confidentiality obligations.
7. Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms — which, given the nature of the data we process (passports, financial records), we treat as the standard assumption — we will:
- Notify the competent supervisory authority without undue delay and where feasible within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33;
- Notify you at your registered email address without undue delay, describing the nature of the breach, the likely consequences, the measures taken or proposed to address it, and the contact point where you can obtain further information, in accordance with GDPR Article 34.
We maintain an internal data breach register and incident response procedures for this purpose.
9. Your Rights
If you are located in the EEA, United Kingdom, or any jurisdiction with applicable data protection rights, you have the following rights. To exercise any of them, email support@visascan.ai. We will respond within one month of receiving your request.
Right of access (GDPR Art. 15)
Request a copy of the personal data we hold about you and information about how it is processed.
Right to rectification (Art. 16)
Ask us to correct inaccurate or incomplete personal data.
Right to erasure (Art. 17)
Ask us to delete your personal data. We will comply unless we are required to retain it by a legal obligation (such as tax record retention). Data we are legally required to retain will be kept for the minimum required period and not otherwise used.
Right to restriction of processing (Art. 18)
Ask us to suspend processing of your data in certain circumstances while a dispute is resolved.
Right to data portability (Art. 20)
Receive your personal data in a structured, machine-readable format and transfer it to another provider, where processing is based on consent or contract and carried out by automated means.
Right to object (Art. 21)
Object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right to withdraw consent (Art. 7(3))
Where processing is based on your consent — including explicit consent to process special category data in uploaded documents — you may withdraw that consent at any time by emailing support@visascan.ai. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Rights regarding automated decision-making (Art. 22)
The AI readiness report is advisory only and does not constitute an automated decision with legal or similarly significant effects. No decision affecting your legal rights is made solely by automated means on this platform. Visa decisions are made exclusively by human consular authorities.
If you are not satisfied with our response to any rights request, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence or establishment.
11. Children
The platform is not directed to anyone under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has created an account or uploaded data without appropriate parental or guardian consent, please email support@visascan.ai and we will delete the data without delay.
12. Changes to This Policy
We may update this Policy when our services or applicable law change. We distinguish between two types of changes:
Non-material changes (corrections, clarifications, new contact details): We will update the "Last updated" date and post a notice on the platform. Continued use of the platform after 14 days' notice constitutes acknowledgement of non-material changes.
Material changes (changes to what data we collect, how we use it, who we share it with, or the legal basis for processing): We will email you at your registered address at least 14 days before the change takes effect. We will also require an active in-app confirmation the next time you log in, before you can continue using the platform.
13. Contact and Supervisory Authority
For any privacy-related question, data request, or complaint:
You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence or where the alleged infringement occurred. A directory of EEA supervisory authorities is available at edpb.europa.eu.
This Privacy Policy is drafted to comply with the General Data Protection Regulation (EU) 2016/679, the UK Data Protection Act 2018, the EU ePrivacy Directive, and applicable international data transfer frameworks including Standard Contractual Clauses (Commission Decision 2021/914). It reflects the platform's operation as of the effective date above.
Questions about this policy?
Contact support