Independent service provider, not the government. You can also arrange an application yourself through the official portal.

Privacy Policy (GDPR) - Request a Visa

Last updated: July 1, 2026

This privacy policy explains how Request a Visa processes your personal data when you use our service to apply for a travel authorization or e-visa. We take your privacy seriously, precisely because we work with sensitive data such as your passport details and passport photo. Please read this policy carefully, so that you know exactly which data we collect, why, with whom we share it and what rights you have. Important preliminary note: Request a Visa is an independent, private service provider and is in no way connected to, affiliated with or endorsed by any government, embassy, consulate or official authority. We submit your application on your behalf to the official portal; the decision on your travel authorization rests solely with the relevant foreign authority. This policy has been drawn up in accordance with the General Data Protection Regulation (GDPR) and the Dutch Telecommunications Act. Last updated: 1 July 2026.

1. Who is responsible for your data?

The data controller responsible for processing your personal data is the company operating under the trade name Request a Visa. This means that we determine which data is collected, for which purposes and in which manner. Our full company details are: trade name Request a Visa, registered with the Dutch Chamber of Commerce under Chamber of Commerce number 65752376, VAT number NL002452287B94, established at Pastoor Petersstraat 170-46, 5612 LW Eindhoven, the Netherlands.

For all questions, requests or complaints regarding privacy and the processing of your personal data, you can contact us by email at info@requestavisa.com. We aim to respond to your request within one month.

We have not appointed a legally mandatory Data Protection Officer (DPO), because in our assessment our processing does not qualify as large-scale structural processing within the meaning of Article 37 GDPR. We reassess this obligation periodically as our activities grow. For privacy questions, the email address info@requestavisa.com serves as a fixed point of contact.

2. What we do (and do not do)

Request a Visa is a commercial convenience service. We help you apply for electronic travel authorizations and e-visas, such as the ESTA for the United States, the eTA for Canada, and e-visas for Egypt, India, Indonesia and Sri Lanka. Specifically, we check your data for errors and completeness, we process your application and we submit it on your behalf to the official government portal. We then monitor the status and inform you of the outcome.

We are emphatically not a government authority, embassy or consulate, and we are also not authorized by or affiliated with any government. The official decision on your travel authorization, and therefore also what happens to your data afterwards at the foreign authority, is entirely beyond our control. If you wish, you can also submit the same application yourself, often more cheaply, directly through the official portal. Our service fees are separate from and in addition to any official government charges.

Because we have to submit your data to these official portals, sharing your personal and passport data with foreign authorities is an inherent and unavoidable part of the service you obtain from us. This privacy policy explains how we handle your data in doing so.

3. Which personal data do we collect?

In order to apply for a travel authorization on your behalf, we need a number of categories of personal data. This concerns identity data such as your first and last name, date of birth, place of birth, country of birth, gender and nationality. In addition, we collect passport data: your passport number, the date of issue, the expiry date and the country of issue.

In many cases we also ask for a scan or photo of your passport and/or a passport photo, because some portals require this or because it helps us to transfer your data correctly and without errors. Furthermore, we process travel data (such as your destination and expected travel date), contact details (your email address and, where applicable, phone number), and payment data needed to process your payment.

Finally, we automatically collect certain technical data when you visit our website, such as your IP address, browser type, device information and data about your use of the site via cookies and similar techniques. We use this technical data for security, error tracing and, solely with your consent, for analysis and marketing.

4. Sensitive data and why we are extra careful with it

Some of the data we process is extra sensitive. Your nationality and country of birth may, for example, reveal information about your race or ethnic origin, and a passport photo may under certain circumstances qualify as biometric data. Under the GDPR (Article 9), stricter rules apply to this type of special category personal data.

We process this data solely because it is strictly necessary in order to be able to submit your application to the relevant authority, and on the basis of your explicit consent, which you give when placing your order. We do not use your passport photo to identify you biometrically and uniquely; we only process it as part of the application that the authority requires from you.

Because we are aware of the sensitive nature of this data, we apply additional safeguards: we ask only for what is necessary, we secure the data strictly and we retain passport scans and passport photos for as short a time as possible (see the section on retention periods).

5. For which purposes and on which legal basis do we process your data?

The GDPR requires us to have a purpose and a legal basis for each processing operation. First and foremost, we process your data in order to perform the agreement with you: checking, processing and submitting your application and informing you of the outcome. The legal basis for this is the performance of the agreement (Article 6(1)(b) GDPR).

For the processing of the sensitive data from your passport scan, passport photo and nationality, we rely on your explicit consent (Article 9(2)(a) GDPR). You actively give this consent when placing your order, and you can withdraw it again at any time. Please note: if you withdraw your consent after the application has already been submitted, we cannot undo the action already performed.

In addition, we process certain data because the law obliges us to do so, for example for our administration and the fiscal retention obligation (Article 6(1)(c) GDPR). For fraud prevention and the security of our service, we rely on our legitimate interest (Article 6(1)(f) GDPR), whereby we always weigh your privacy interest against this interest. For non-essential cookies, analysis and marketing (including Google Ads Enhanced Conversions), we always ask for your consent in advance (Article 6(1)(a) GDPR).

6. With whom do we share your data? (processors)

In order to be able to provide our service, we engage a number of specialized service providers who process personal data on our behalf as processors. With each of these parties we have concluded a data processing agreement as prescribed by Article 28 GDPR, in which it is laid down that they may only process your data in accordance with our instructions and with appropriate security.

Specifically, we work with the following processors: PayPal (for processing payments), MongoDB Atlas (for the secure storage of application data), Vercel (for hosting our website), Brevo (for sending transactional and service emails), Zoho (for our email and customer communication), Anthropic (for automatically reading your passport data via OCR technology), and Google (for advertising and analysis purposes, solely to the extent that you have given your consent for this).

We never sell your personal data to third parties. We only share your data with the aforementioned processors for the stated purposes, with the foreign authority to which we submit your application, and where we are legally obliged to do so (for example on the basis of a court order).

7. Passport OCR with artificial intelligence (Anthropic)

In order to prevent errors and process your application faster, we use OCR technology (Optical Character Recognition) provided by Anthropic, a provider of artificial intelligence. When you upload a passport scan, the image is submitted to this service in order to automatically read out the text data (such as your name, passport number and date of birth) and transfer it into your application.

We have made arrangements with Anthropic so that your data is not used to train their AI models, and we strive to apply commercial terms with limited or no data retention. Where possible, we limit the data we submit to what is strictly necessary.

Important to know: this AI processing does not make any decision with legal effect concerning you. The OCR only helps with transferring data; the final check is carried out by a human and the decision on your travel authorization always rests with the competent government. There is therefore no automated decision-making within the meaning of Article 22 GDPR.

8. Transfer of your data outside the European Economic Area

Some of our processors are established in or process data in the United States, including PayPal, MongoDB Atlas, Vercel, Anthropic and Google. When your data is transferred to countries outside the European Economic Area (EEA), we ensure appropriate safeguards, such as the EU-US Data Privacy Framework (insofar as the relevant party is certified under it) or the Standard Contractual Clauses approved by the European Commission.

In addition, there is a second, unavoidable form of transfer: in order to be able to submit your application, we transfer your personal and passport data to the competent authority of your destination country, for example the United States, Canada, India, Egypt, Indonesia or Sri Lanka. These countries do not all have a level of protection recognized as adequate by the European Commission.

The legal basis for this transfer to foreign governments is that it is necessary for the performance of the agreement you conclude with us (Article 49(1)(b) GDPR), and your explicit consent after having been informed of the possible risks (Article 49(1)(a) GDPR). We expressly point out to you that we have no control or influence whatsoever over what the foreign authority subsequently does with your data, how long it retains it or with whom it shares it. This falls under the law and policy of the relevant country.

9. How long do we retain your data?

We do not retain your personal data for longer than is necessary for the purposes for which it was collected, unless the law obliges us to retain it for longer. For our financial and administrative data (such as invoices and payment data), the statutory fiscal retention obligation of 7 years applies pursuant to Article 52 of the Dutch General Act on State Taxes.

For sensitive data, we go further in data minimization: we delete your passport scan and passport photo as soon as possible after your application has been completed, and in principle at the latest within a short, justified period after completion, unless we still need it in connection with an ongoing dispute, a chargeback or a legal obligation.

We retain the remaining application data for as long as is necessary for the performance of the service and for a reasonable period thereafter in order to be able to handle any questions, complaints or disputes. Data that we process on the basis of your consent for marketing or analysis, we retain no longer than the duration of that consent. After expiry of the applicable periods, we delete or anonymize your data.

10. Cookies and similar techniques

Our website uses cookies and similar techniques. Strictly necessary cookies, which are needed for the functioning of the site, your session, security and payment, we place without consent, because you cannot properly use the site without these cookies. For all other cookies, including analytical and marketing cookies, we ask for your active consent in advance via our cookie banner.

In the cookie banner you can choose per category what you want to allow or refuse, whereby refusing is just as easy as accepting. We only place non-essential cookies after you have actively given consent; we do not use pre-ticked boxes and do not regard merely browsing through the site as consent. You can change or withdraw your cookie preferences at any time via the dedicated link on our website.

In our separate cookie policy you will find a detailed overview of all cookies used, with, for each cookie, the purpose, the type (functional, analytical or marketing), the retention period and the party involved. We also retain proof of the consent you have given, so that we can demonstrate that and for what you have granted consent.

11. Google Ads and Enhanced Conversions

When you have given your consent for this, we make use of Google Ads, including the Enhanced Conversions feature. With this feature, certain customer data is shared with Google in encrypted (hashed) form in order to measure how effective our advertisements are and to attribute conversions.

This sharing only takes place after you have given consent for it via our cookie banner, and we have implemented Google Consent Mode so that no advertising or analysis data is sent to Google without your consent. Without consent, this functionality is not activated.

You can withdraw your consent for Google Ads and analysis at any time via the cookie settings on our website. Google also processes the data as a data controller for its own purposes; you can find more information about this in Google's privacy policy.

12. Your responsibility for the accuracy of data

You are responsible for the accuracy, completeness and timeliness of the data you provide to us. We process and submit the application on the basis of the information you supply. Therefore, always carefully check whether your data is correct before confirming your application.

If you provide incorrect, incomplete or outdated data, this may lead to a rejection, delay or invalidity of your travel authorization. The consequences and any costs thereof are for your own account and risk, and do not give rise to any right to a refund of our service fees. We advise you to compare your data with your official passport before submitting.

When you make an application on behalf of someone else, for example a family member or a minor child, you warrant that you are authorized to do so and that the data you provide is correct.

13. Security of your data

We take the security of your personal data seriously and have taken appropriate technical and organizational measures to protect your data against loss, misuse and unauthorized access, as referred to in Article 32 GDPR. These measures include, among other things, encryption of data during transmission and storage, access restriction on a need-to-know basis, and, where possible, multi-factor authentication for access to systems.

We select our processors partly on the basis of their level of security and have contractually laid down with them that they likewise take appropriate security measures. Nevertheless, no transmission via the internet or electronic storage can be entirely secure; we do our utmost, but cannot guarantee absolute security.

Should a data breach unexpectedly occur that poses a risk to your rights and freedoms, we will report this within 72 hours to the Dutch Data Protection Authority. When a data breach entails a high risk for you, which is quickly the case with passport data, we will also inform you as soon as possible. We maintain an internal data breach response plan for this purpose.

14. Data of minors

Our service is not intended to be used independently by minors. An application for a minor can only be submitted by a parent or legal guardian who is authorized to do so.

When a parent or guardian makes an application for a minor child, we process the child's data solely on the basis of and within the limits of the consent and authorization of that parent or guardian. The parent or guardian is responsible for the accuracy of the child's data provided.

If you suspect that we have processed data of a minor without the required consent, please contact us at info@requestavisa.com, and we will delete this data where necessary.

15. Automated decision-making

We do not make decisions with legal effects concerning you, or that otherwise significantly affect you, that are based solely on automated processing, as referred to in Article 22 GDPR.

Although we use automated OCR technology to read out passport data, this serves solely to transfer data correctly. No substantive judgment or decision about you is made by our systems.

The final decision on whether or not to grant a travel authorization is made by the competent foreign authority, and not by us or by an automated system of ours.

16. Your rights under the GDPR

Under the GDPR you have a number of rights with regard to your personal data. You have the right of access to the data we process about you, and the right to have incorrect data corrected (rectification). You also have, under certain circumstances, the right to erasure of your data, to restriction of processing and to the transfer of your data to another party (data portability).

In addition, you have the right to object to certain processing operations, and the right to withdraw a previously given consent at any time. Withdrawing your consent does not affect the lawfulness of the processing that has already taken place before then. Please bear in mind that we cannot delete certain data as long as we are legally required to retain it or need it for an ongoing application or dispute.

You can exercise your rights by sending a request to info@requestavisa.com. We will in principle respond to your request within one month. In order to be able to establish your identity, we may ask you for additional information. If you do not agree with how we handle your data, you always have the right to lodge a complaint with the Dutch supervisory authority, the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).

17. Changes to this privacy policy and other documents

We may amend this privacy policy from time to time, for example when our services change or when new laws or regulations give cause to do so. The most recent version is always available on our website, stating the date of the last change at the top of this document. We advise you to consult this policy regularly.

This privacy policy forms part of our broader legal documentation. For the terms of our services, including our refund and cancellation policy, our liability and the right of withdrawal, we refer to our General Terms and Conditions and our Withdrawal Policy. For details about cookies we refer to our separate Cookie Policy.

Do you still have questions, comments or requests after reading this privacy policy about the way in which we handle your personal data? Then please feel free to contact us at info@requestavisa.com. Dutch law applies to this processing of personal data and to this privacy policy.

Company details

Request a Visa

Pastoor Petersstraat 170-46

5612 LW Eindhoven, Nederland

KvK: 65752376

BTW: NL002452287B94

E-mail: info@requestavisa.com