Is VisaEvo GDPR compliant?
What VisaEvo collects, how long it's kept, your rights, and how to request deletion — under UK GDPR, EU GDPR, and the Data Protection Act 2018.
Key takeaways
- 01VisaEvo complies with the UK GDPR, EU GDPR, and the Data Protection Act 2018.
- 02You have full data subject rights: access, rectification, erasure, portability, restriction, objection, and withdrawal of consent.
- 03If you delete your account, personal data is erased within 30 days, except where the law requires retention (e.g. payment records for up to 7 years).
- 04To exercise any right, email privacy@visaevo.com — we respond within one calendar month, free of charge.
Your rights under GDPR
The rights you can exercise over your personal data at any time.
Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Ask us to correct inaccurate or incomplete data.
Right to erasure
Request deletion of your personal data (“right to be forgotten”).
Right to data portability
Receive your data in a structured, machine-readable format such as JSON or CSV.
Right to restrict processing
Ask us to limit how we use your data in certain circumstances.
Right to object
Object to processing based on legitimate interests or direct marketing.
Right to withdraw consent
Withdraw consent at any time, without affecting prior lawful processing.
Data retention schedule
How long each category of data is kept, and why.
| Feature | Data type | Retention period |
|---|---|---|
| Account data | Name, email, login | While your account is active; erased within 30 days of deletion |
| Application & document data | Uploads, checklist, notes | While active; deleted on account deletion or on request |
| Payment records | Billing & transactions | Up to 7 years (UK tax & accounting law) |
| Technical logs | IP, errors, performance | Up to 90 days, then automatically purged |
| AI conversation data | Assistant prompts & history | While active; deleted on account deletion |
How to delete your data
Exercising your right to erasure takes four simple steps.
- Step 01
Delete in-app or email us
Delete your account from Settings, or email privacy@visaevo.com from the address linked to your account requesting erasure.
- Step 02
We verify your identity
To protect your data, we confirm the request comes from you before acting on it.
- Step 03
We erase within 30 days
Your personal data is deleted within 30 days, except records we're legally required to keep (such as payment records for up to 7 years).
- Step 04
You receive confirmation
We confirm once deletion is complete. You can also lodge a complaint with the ICO if you're unhappy with our response.
Who processes your data
We do not sell your data. These trusted processors act on our behalf under data processing terms.
Stripe
Payment processing (PCI DSS Level 1)
Supabase
Authentication, database, and file storage
Anthropic
AI assistant (does not train on API inputs)
Resend
Transactional email delivery
Where data is transferred outside the UK/EEA, we rely on Standard Contractual Clauses or adequacy decisions. Full details are in our Privacy Policy. You can also read about our security measures.
Frequently asked questions
Common questions about GDPR, data retention, and deletion at VisaEvo.
Don't let a missing document delay your visa.
Be ready when you apply. Organise documents, check the financial requirement, and build checklists from gov.uk guidance.
- Free forever tier
- No credit card required
- Pay once, lifetime access
- 30-day money-back guarantee
VisaEvo is self-service software. We do not provide immigration advice. You are responsible for your own application decisions.