GDPR Privacy Notice
Additional information for users in the European Economic Area, United Kingdom and Switzerland, under the GDPR and UK GDPR.
Draft placeholder text — not yet reviewed by a lawyer. Replace with the final wording (and company registration details) before this site goes live to real customers.
Who this applies to
This notice supplements our main Privacy Policy for users located in the EEA, the UK or Switzerland, whose personal data we process in connection with a visa or travel-authorisation application.
Legal basis for processing
We process your data to perform the contract formed when you place an order (Art. 6(1)(b) GDPR), to comply with legal obligations such as tax and accounting rules (Art. 6(1)(c)), for our legitimate interests in preventing fraud and improving the service (Art. 6(1)(f)), and, for marketing communications and non-essential cookies, your consent (Art. 6(1)(a)).
International transfers
Where we transfer your data outside the EEA — including to Türkiye, where our reviewers are based — we rely on the European Commission's standard contractual clauses or another lawful transfer mechanism, and take reasonable steps to keep it secure in transit and at rest.
Your rights
You have the right to access, rectify, erase or restrict the processing of your data, to data portability, to object to processing based on legitimate interests or for direct marketing, and to withdraw consent at any time without affecting past processing.
Complaints
You can lodge a complaint with your local supervisory authority. If you are unsure which one applies to you, you can start with the data protection authority of the EU member state where you live or work.
Contact
For any GDPR-related question, email info@expressvisa.app. Where an EU representative is required under Article 27 GDPR, their name and contact details will be added here.
