1. Who we are

The controller of your personal data is [COMPANY_NAME] ("we", "us"). The company is registered in the Republic of Armenia under registration number [COMPANY_REG_NO], with its address at [COMPANY_ADDRESS]. We operate the website [SITE_DOMAIN] (the "Site") and advise on Spanish visas: we check documents and help prepare the application package.

For any questions about personal data, write to [PRIVACY_EMAIL].

2. What data the Site collects

Requests. When you submit the "Contact us" form, the form in the discount pop-up or the form after the quiz, we receive your name, phone number and email address. We also receive the Site language and the address of the page the request was sent from.

Quiz answers. If you send a request after the quiz, your answers come with it. Depending on the quiz, these may cover the purpose of your trip or studies, whether you have an offer of admission, previous visa refusals, whether you’re formally employed, bookings, timing and how ready your documents are. Until you send a request, your answers go nowhere.

Technical data and cookies. IP address, browser and device details, the pages you view and your actions on them. Some of this is collected by cookies and analytics services, but only with your consent. See our Cookie policy.

The Site doesn’t collect documents, scans or photos of documents.

3. Why the Site collects data and on what basis

The consent you give when submitting a request is published separately: Consent to the processing of personal data.

We don’t send newsletters without your separate consent. The quiz result on the Site is a pointer, not a decision. We don’t make automated decisions with legal effects on you.

4. Who receives data from the Site

  • Hosting: Cloudflare, Inc. (USA), privacy policy. Form submissions pass through Cloudflare but aren’t stored there.
  • Receiving requests: the Telegram messenger, privacy policy. A request from the Site is forwarded straight to us on Telegram, where we see it in our work chat.
  • Analytics: Yandex Metrica and Google Analytics, if you consent.
  • Messengers. Links to WhatsApp, Telegram and WeChat are plain links. Until you follow one, those services receive nothing from the Site.

5. How we receive client data

Once we’ve agreed to work together, we communicate and exchange documents not through the Site but on messengers (Telegram, WhatsApp, WeChat) or by email. You decide what to send. We only ask for what’s needed for your visa and the service you’ve chosen.

In these conversations we also see your details on that service: username, phone number, profile photo. The conversation itself is governed by the rules of the messenger or email provider.

We don’t ask for separate consent to message you or exchange documents: we process the data you send us for the work on the basis of our contract with you (our terms of service). For criminal record certificates and health data the law requires explicit consent. You give it when you accept our terms of service, and we use this data only to prepare your visa application.

6. What client data we process and why

Depending on the visa and the service, this may include:

  • passport details and a photo;
  • date and place of birth, nationality, address;
  • education and place of study, admission documents;
  • employment and income, bank statements, sponsor details;
  • marital status and details of relatives, if the application requires them;
  • visa and travel history, including refusals;
  • a criminal record certificate, if your visa requires one;
  • health insurance details;
  • bookings, tickets and invitations.

7. Who we share client data with

We don’t share data with consulates, embassies or visa centres. You submit your visa documents yourself. We help you prepare them.

On your instructions. If you’ve asked us to arrange something for you, we share the data needed for it with:

  • language schools and other educational institutions, to enrol you on a course;
  • insurance companies, to take out a policy;
  • sworn translators and organisations that issue apostilles, to translate and legalise documents.

We share only the data needed for the specific task. Each of these organisations then processes it under its own rules.

Services we use to run our business: email, messengers, cloud document storage and accounting. They process data on our behalf.

Public authorities, only where the law requires it.

We don’t sell personal data or share it with third parties for their own advertising.

8. Where data is processed

We work with clients from many countries, so your data may be processed outside the country where you live. This includes:

  • Armenia, where our company is registered and our team works;
  • Spain, where the schools, insurers and translators are based, if you’ve asked us to contact them;
  • the United States, where Cloudflare’s and Google’s servers are;
  • Russia, where Yandex’s servers are, if you consent to analytics;
  • the countries where the servers of the messengers and email services we use are located.

We transfer data abroad only to the extent needed for the purposes of this policy, and we follow the cross-border transfer rules that apply to us. For example, for transfers from the EU to countries without an adequacy decision we use the European Commission’s standard contractual clauses, and for transfers from Armenia we use the mechanisms provided by Armenian law.

9. How long we keep data

  • Requests from the Site that don’t lead to work together: 12 months after our last contact with you.
  • Copies of client documents (passport, certificates, statements): while we’re working together and for 6 months after the work ends, so we can help with a new application or an appeal. Then we delete them, unless you ask us to keep them longer.
  • The contract, related correspondence and payment data: 3 years after our services end. Payment records are kept as long as accounting and tax law requires.
  • Analytics and cookie data: as set out in our Cookie policy.

If you ask us to delete your data sooner, we will, except for data the law requires us to keep. Messenger conversations may remain in the chat history on both your side and ours. We’ll delete them on our side if you ask.

10. How we protect data

Only the team members who need your data to work on your case have access to it. We use secure connections (HTTPS) and services with access controls, and we keep documents no longer than stated above. No system is completely secure. If a breach occurs that may affect your rights, we’ll notify you and the supervisory authorities as and when the law requires.

11. Your rights

Depending on the laws of your country, you can:

  • find out what data we hold about you and get a copy of it;
  • correct inaccurate or incomplete data;
  • ask us to delete your data or restrict its processing;
  • object to processing based on our legitimate interest;
  • receive the data you gave us in a machine-readable format;
  • withdraw your consent at any time. This doesn’t make processing carried out before the withdrawal unlawful;
  • lodge a complaint with a data protection authority.

To exercise your rights, write to [PRIVACY_EMAIL]. We may ask you to confirm your identity so that we don’t disclose your data to someone else. We reply within 10 working days, unless the law of your country requires a faster reply.

Supervisory authorities: in Armenia, the Personal Data Protection Agency of the Ministry of Justice; in the EU, the authority of the country where you live (in Spain, the AEPD); elsewhere, the competent authority in your country. But please write to us first: we can usually sort things out faster.

12. Children

Our services are intended for adults. If a minor needs a visa, the request is sent and the work agreed by their parent or legal guardian, who also consents to the processing of the child’s data. If we learn that we’ve received a child’s data without such consent, we’ll delete it.

13. Links to other websites

The Site contains links to the websites of consulates, visa centres, messengers and other organisations. We’re not responsible for how they process data.

14. Applicable law

We process data in accordance with the Law of the Republic of Armenia "On Protection of Personal Data" No. HO-49-N of 18 May 2015. We also take into account the data protection rules of the countries whose residents our services are aimed at, to the extent those rules apply to us. These include the EU General Data Protection Regulation (GDPR), Spain’s Organic Law 3/2018 (LOPDGDD), Russian Federal Law No. 152-FZ "On Personal Data" and China’s Personal Information Protection Law (PIPL).

15. Changes to this policy

We may update this policy. The current version is always published on this page, with its date at the top. We’ll announce material changes on the Site and notify current clients directly.

16. Contact

[COMPANY_NAME]
[COMPANY_ADDRESS]
Email: [PRIVACY_EMAIL]