Legal

Privacy Policy

Last updated: 3 June 2026  ·  Effective date: 3 June 2026

1. Who We Are and How to Contact Us

VisaScan AI ("VisaScan AI", "we", "us", or "our") operates the platform at visascan.ai, which helps individuals prepare document packs for Schengen visa applications across all 29 Schengen member states.

For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection law, VisaScan AI is the data controller of personal data collected through this platform.

Data Controller contact details

For all privacy queries, data access requests, or complaints, please email support@visascan.ai. We will respond within one month of receiving your request.

2. What This Policy Covers

This Privacy Policy applies to:

  • All visitors to visascan.ai, whether or not they hold an account;
  • All registered users who use the checklist, document upload, AI review, or form auto-fill features;
  • Any person whose personal data appears in a document uploaded to the platform, such as a co-traveller included in a Family Pack application;
  • Anyone who contacts us by email or any other channel.

3. What Personal Data We Collect

3.1 Account Data

When you register, we collect:

  • Your full name;
  • Your email address;
  • Your password — stored in a hashed, non-reversible format. We never store passwords in plaintext;
  • Account creation date and timestamp;
  • Whether you registered via email/password or Google OAuth;
  • Your IP address at registration.

3.2 Profile and Trip Data

When you complete the visa profile questionnaire, we collect:

  • Your nationality and passport-issuing country;
  • Your Schengen destination country (from all 29 countries supported);
  • Purpose of travel (tourism or business);
  • Employment status and funding source;
  • Accommodation arrangements and trip dates;
  • Number and details of co-travellers, where applicable;
  • Any information you voluntarily enter in free-text fields.

3.3 Uploaded Document Data — Special Category Notice

When you choose to upload documents for AI review, we process the contents of those documents to generate your readiness report. Documents you may upload include:

  • Passports and national identity documents, which may contain biographic data, nationality, date of birth, full name, and document numbers;
  • Bank statements and financial records;
  • Employment letters, payslips, and income documentation;
  • Travel insurance certificates;
  • Hotel bookings, flight itineraries, and accommodation confirmations;
  • Cover letters and personal statements;
  • Any other document you choose to submit.

Important — special category data: Passports and identity documents contain data classified as special category personal data under GDPR Article 9 (including, where applicable, data relating to nationality and biometric identifiers). We do not collect this data automatically. It is collected only when you actively choose to upload such a document.

We will not process any special category data contained in your uploaded documents without your separate, explicit consent. At the point of upload, before processing begins, you will be presented with a clear, standalone consent confirmation asking whether you consent to the processing of any special category data in your documents for the purpose of generating your AI readiness report. You may decline this consent and the document will not be processed. This consent can be withdrawn at any time by emailing support@visascan.ai.

3.4 Payment Data

When you purchase a paid plan:

  • All payments are handled entirely by Paddle.com Market Limited, our Merchant of Record;
  • We do not store your card number, CVV, or full card details at any point;
  • We receive and retain only a transaction reference, amount paid, currency, and payment confirmation status;
  • Where applicable, your billing country is shared with Paddle for EU VAT purposes.

3.5 Technical and Usage Data

When you use the platform, we automatically collect:

  • IP address and approximate geographic location (country or city level);
  • Browser type, version, and operating system;
  • Device type and screen dimensions;
  • Pages visited and features used;
  • Session duration and navigation path;
  • Error logs and crash reports;
  • Session tokens maintaining your logged-in state.

3.6 Support Communications

If you contact us at support@visascan.ai, we collect:

  • Your email address and any contact details you provide;
  • The content and timestamp of your message;
  • Any files or attachments included in your communication.

4. Why We Use Your Data — Lawful Basis

We only process personal data where we have a valid lawful basis under GDPR. The table below sets out each processing activity and its applicable basis.

Processing activityData usedLawful basis
Creating and managing your accountAccount dataContract — Art. 6(1)(b)
Generating your personalised checklistProfile and trip dataContract — Art. 6(1)(b)
Running AI document review and producing your reportDocument data, profile dataContract — Art. 6(1)(b)
Processing special category data in uploaded documentsIdentity / biometric document dataExplicit consent — Art. 9(2)(a) — obtained via separate tick-box at point of upload
Processing your payment and issuing a receiptPayment data, account dataContract — Art. 6(1)(b)
Platform security and fraud preventionTechnical data, account dataLegitimate interests — Art. 6(1)(f)
Improving the platform using anonymised, aggregated usage dataAggregated, anonymised usage dataLegitimate interests — Art. 6(1)(f)
Responding to support requestsCommunications data, account dataContract / Legitimate interests
Complying with legal and tax obligationsRelevant data categoriesLegal obligation — Art. 6(1)(c)
Sending transactional emails (account verification, password reset, receipts)Email address, account eventContract — Art. 6(1)(b)
We do not use the contents of your uploaded documents to train AI models. We do not share document content with any third party for marketing, advertising, profiling, or any purpose other than providing the review service described above.

5. How Long We Keep Your Data

We retain personal data only for as long as is necessary for the purpose for which it was collected, and in any case only for as long as required or permitted by law.

Data categoryRetention periodReason
Uploaded documentsAutomatically deleted within 30 days of uploadDocument sensitivity — no longer required after report generation
AI-generated reports, readiness scores, recommendationsRetained in your account until you delete them, or until account closure + 30 daysRequired for you to access and re-use your report
Financial transaction records (payment amounts, dates, receipts)7 years from transaction dateLegal obligation — standard tax and accounting record-keeping requirements
Account data (name, email)Retained for account lifetime + 30 days after account closureRequired to fulfil account closure and confirm deletion
Profile and trip dataRetained for account lifetime + 30 days after account closureDeleted promptly on closure
Technical logs and server dataMaximum 90 days, then deleted or anonymisedSecurity monitoring and debugging
Support communications3 years from date of communicationLegitimate interests — record of support interactions

You may request early deletion of any data category at any time, subject to any overriding legal retention obligation.

6. How We Protect Your Data

TLS in transit

All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.

AES-256 at rest

All stored documents are encrypted at rest using AES-256 encryption, with encryption keys stored separately from the encrypted data.

Short-lived signed upload URLs

Document upload links are single-use, time-limited, and cryptographically signed. They expire immediately after use and cannot be reused or shared.

No document data in logs or emails

Our infrastructure is specifically configured to prevent the contents of uploaded documents from appearing in application logs, error-tracking tools, or email notifications.

Strict sessions and rate limiting

Authentication flows include session controls, rate limiting, and audit trails to mitigate brute-force and credential-stuffing attacks.

Audit logs for every action

Authentication events, administrative access, and data interactions are recorded in tamper-resistant audit logs.

Access controls

Internal access to personal data is restricted on a strict need-to-know basis. All personnel with access to user data are bound by confidentiality obligations.

7. Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms — which, given the nature of the data we process (passports, financial records), we treat as the standard assumption — we will:

  • Notify the competent supervisory authority without undue delay and where feasible within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33;
  • Notify you at your registered email address without undue delay, describing the nature of the breach, the likely consequences, the measures taken or proposed to address it, and the contact point where you can obtain further information, in accordance with GDPR Article 34.

We maintain an internal data breach register and incident response procedures for this purpose.

8. Who We Share Your Data With

We do not sell your personal data. We do not share your data with advertisers, data brokers, or third parties for their own marketing or commercial purposes.

We share data only with the following named sub-processors, each bound to us by a Data Processing Agreement:

Sub-processorLegal entityPurposeData shared
Anthropic, PBCAnthropic, PBC, San Francisco, CA, USAAI-powered document analysis via the Claude APIDocument content and profile data submitted for AI review
Amazon Web ServicesAmazon Web Services, Inc., Seattle, WA, USACloud infrastructure and encrypted document storageAll data categories, depending on service layer
Cloudflare, Inc.Cloudflare, Inc., San Francisco, CA, USACDN, DDoS protection, and network securityTechnical / IP data
Paddle.com Market LimitedPaddle.com Market Limited, London, UKPayment processing and Merchant of RecordPayment data and billing country
Google LLCGoogle LLC, Mountain View, CA, USAOAuth sign-in only (if you choose "Continue with Google")Name and email as shared by Google at sign-in
Transactional email serviceThird-party email delivery providerSending account verification emails, password reset links, and receiptsYour email address and the specific event triggering the email

8.1 International Data Transfers

Several processors listed above are located in the United States, which does not currently hold a general EU adequacy decision. Where personal data is transferred to the United States or any other country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) as the legal transfer mechanism. We conduct Transfer Impact Assessments for all such transfers and maintain records of those assessments. You may request a copy of the relevant SCCs by emailing support@visascan.ai.

9. Your Rights

If you are located in the EEA, United Kingdom, or any jurisdiction with applicable data protection rights, you have the following rights. To exercise any of them, email support@visascan.ai. We will respond within one month of receiving your request.

Right of access (GDPR Art. 15)

Request a copy of the personal data we hold about you and information about how it is processed.

Right to rectification (Art. 16)

Ask us to correct inaccurate or incomplete personal data.

Right to erasure (Art. 17)

Ask us to delete your personal data. We will comply unless we are required to retain it by a legal obligation (such as tax record retention). Data we are legally required to retain will be kept for the minimum required period and not otherwise used.

Right to restriction of processing (Art. 18)

Ask us to suspend processing of your data in certain circumstances while a dispute is resolved.

Right to data portability (Art. 20)

Receive your personal data in a structured, machine-readable format and transfer it to another provider, where processing is based on consent or contract and carried out by automated means.

Right to object (Art. 21)

Object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to withdraw consent (Art. 7(3))

Where processing is based on your consent — including explicit consent to process special category data in uploaded documents — you may withdraw that consent at any time by emailing support@visascan.ai. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Rights regarding automated decision-making (Art. 22)

The AI readiness report is advisory only and does not constitute an automated decision with legal or similarly significant effects. No decision affecting your legal rights is made solely by automated means on this platform. Visa decisions are made exclusively by human consular authorities.

If you are not satisfied with our response to any rights request, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence or establishment.

10. Cookies

Essential cookies: We use session management and security cookies that are strictly necessary to keep you logged in and the platform operational. These cannot be disabled without impairing the service.

Analytics and non-essential cookies: We will only set non-essential cookies (including any analytics cookies) with your prior consent, obtained through a consent management banner displayed on your first visit to the platform. You may change your cookie preferences at any time through the consent banner or your browser settings.

We do not set any non-essential cookies before you have given consent.

11. Children

The platform is not directed to anyone under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has created an account or uploaded data without appropriate parental or guardian consent, please email support@visascan.ai and we will delete the data without delay.

12. Changes to This Policy

We may update this Policy when our services or applicable law change. We distinguish between two types of changes:

Non-material changes (corrections, clarifications, new contact details): We will update the "Last updated" date and post a notice on the platform. Continued use of the platform after 14 days' notice constitutes acknowledgement of non-material changes.

Material changes (changes to what data we collect, how we use it, who we share it with, or the legal basis for processing): We will email you at your registered address at least 14 days before the change takes effect. We will also require an active in-app confirmation the next time you log in, before you can continue using the platform.

13. Contact and Supervisory Authority

For any privacy-related question, data request, or complaint:

You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence or where the alleged infringement occurred. A directory of EEA supervisory authorities is available at edpb.europa.eu.

This Privacy Policy is drafted to comply with the General Data Protection Regulation (EU) 2016/679, the UK Data Protection Act 2018, the EU ePrivacy Directive, and applicable international data transfer frameworks including Standard Contractual Clauses (Commission Decision 2021/914). It reflects the platform's operation as of the effective date above.

Questions about this policy?

Contact support