Privacy Policy
How Unbordr collects, uses, stores and protects your personal data.
Last updated
This Privacy Policy ("Policy") explains how Clearpath Global Technologies Private Limited, a company incorporated under the Companies Act, 2013 and having its registered office at A-20, Sector 35, Noida, Gautam Buddha Nagar, Uttar Pradesh 201301, India, operating under the brand name "Unbordr" ("Unbordr", "we", "us", "our"), collects, uses, stores, shares, retains and protects your personal data when you access or use our website, tools, applications and services (together, the "Services").
We have written this Policy in clear and plain language, as required by Rule 3 of the Digital Personal Data Protection Rules, 2025, and because honesty is the whole point of what we do. Plain language does not reduce its legal effect: this Policy is a binding statement of our obligations and of your rights.
Legal framework. This Policy is issued under, and is to be read consistently with:
- the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), notified vide G.S.R. 846(E) dated 13 November 2025;
- the Information Technology Act, 2000 ("IT Act") and, until 13 May 2027, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules");
- the directions issued by the Indian Computer Emergency Response Team ("CERT-In") under section 70B(6) of the IT Act dated 28 April 2022; and
- the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020.
A note on commencement. The substantive obligations of the DPDP Act and DPDP Rules commence in phases, with full commencement on 13 May 2027. We have chosen to align our practices with the DPDP standard ahead of that date. Where a provision of this Policy states a standard higher than the law currently in force, we treat it as a contractual commitment to you and it is enforceable as such.
1. Definitions
In this Policy, capitalised terms have the meanings given below. Terms defined in the DPDP Act and not defined here carry the meaning given in that Act.
| Term | Meaning |
|---|---|
| Data Fiduciary | The person who alone or with others determines the purpose and means of processing personal data. For the Services, this is Unbordr. |
| Data Principal | The individual to whom personal data relates, which for the Services means you. Where the individual is a child, it includes the parent or lawful guardian; where the individual is a person with a disability, it includes the lawful guardian. |
| Data Processor | A person who processes personal data on our behalf and under a contract with us (for example, our hosting or payment provider). |
| Personal Data | Any data about an individual who is identifiable by or in relation to such data. |
| Processing | Any wholly or partly automated operation on digital personal data, including collection, recording, organisation, storage, use, sharing, retention and erasure. |
| Personal Data Breach | Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. |
| Board | The Data Protection Board of India constituted under Chapter V of the DPDP Act. |
| Services | Our website, tools, applications, document preparation and verification products, and advisor calls, as described in our Terms & Conditions. |
2. Who we are, and the scope of this Policy
We are the Data Fiduciary in respect of the personal data described in this Policy. We decide why and how that data is processed, and we are accountable to you and to the Board for it. That accountability is not diminished by our use of Data Processors.
What we do. Unbordr is a Schengen visa document preparation and verification service. We help you build and check the documents for your own visa application. We are not a government body, we do not issue visas, we are not affiliated with any embassy, consulate, VFS Global, BLS International or other visa application centre, and we do not submit your application to any authority on your behalf. You remain the applicant and you submit your own file. This shapes our approach to your data: we collect what we need to prepare and verify your documents, and little else.
Territorial scope. This Policy applies to the processing of digital personal data within India, and to processing outside India where that processing is in connection with any activity related to offering goods or services to Data Principals within India, in line with section 3 of the DPDP Act.
3. The lawful basis on which we process your data
We process your personal data only where we have a lawful basis under the DPDP Act. We rely on two bases, and we tell you which applies.
3.1 Your consent (section 6, DPDP Act)
For most of our processing we rely on your consent. Under the DPDP Act, valid consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. Accordingly:
- We obtain your consent through a distinct, unbundled, affirmative action. You must actively tick or select, and we do not use pre-ticked boxes, bundled consents, or inferred agreement.
- Continuing to browse our website is not treated by us as consent to processing that requires consent. Merely using the Services does not amount to consent for these purposes.
- Each consent request is accompanied by an itemised notice describing the personal data sought, the specified purpose, how you may exercise your rights, how you may withdraw consent, and how you may complain to the Board. That notice is presented independently of any other information, as required by Rule 3 of the DPDP Rules.
- You may access that notice in English or in any language specified in the Eighth Schedule to the Constitution of India, as required by section 5(3) of the DPDP Act. To request a copy in another language, write to us at the address in section 18.
- We maintain an auditable record of consent: what you consented to, when, through which interface, and the version of the notice you were shown.
3.2 Certain legitimate uses (section 7, DPDP Act)
Where you voluntarily provide personal data to us for a specified purpose and have not indicated that you object to its use for that purpose, we may process it on that basis under section 7(a). We also process personal data without consent where processing is necessary to comply with a law, judgment or order in force in India, or to comply with an obligation to disclose information to the State or its instrumentalities, subject to law.
We do not treat this Policy itself as your consent. Consent is collected separately, at the point of collection, through a dedicated notice. This Policy explains our practices; it does not substitute for that notice.
4. The personal data we collect
We collect only what is necessary for the specified purpose. Depending on the product you use and what you share when you book a call or complete your file, this may include:
4.1 Data you give us
- Identity and contact data: your name, email address (which also serves as your login credential), and mobile number.
- Communication preferences: for example, whether you opt in to receive updates on WhatsApp (call reminders, document requests and delivery of your finished file).
- Trip and application data: service type (new application or refusal recovery), destination country, travel dates, purpose of travel, and the number and type of travellers.
- Visa history: whether you have applied before and, for refusal cases, the date of refusal, the refusing country, the consulate or visa application centre, whether it is a first refusal, and the refusal letter you upload.
- Address data: including whether your current address matches the address on your Aadhaar, where relevant to your application. We record only the fact of a match or mismatch and the address itself. We do not collect, store or require your Aadhaar number, Aadhaar image, or any Aadhaar authentication data, and nothing in the Services should be read as Aadhaar authentication under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016.
- Document and profile data needed to prepare your file: passport details, employment or study details, financial information (such as bank statements or sponsor details), and accommodation and itinerary information.
- Content you provide: the documents you upload, notes you add for your advisor, and what you tell us on your advisor call or in messages.
- Advisor call records: where a call is recorded or transcribed, we do so only with your prior, separately obtained consent, given at or before the start of the call. You may decline recording and still receive the call.
4.2 Data we collect automatically
- Technical and usage data: IP address, browser and device type, operating system, referring URL, pages visited, and time spent, collected through cookies and similar technologies (see section 10).
- Security and audit logs: access logs, authentication events and system logs, which we retain for security, incident investigation and statutory purposes.
4.3 Data we receive from others
- Payment confirmation data from our payment gateway (transaction ID, status, amount, method type and the last four digits of the instrument). We do not receive full card or bank credentials.
- Data provided by a third party on your behalf, for example where a family member, sponsor or employer books on your behalf. If you provide another person's personal data to us, you confirm that you are authorised to do so and that they have been shown this Policy.
4.4 Sensitive categories, handled with additional care
Some data we handle, notably financial information and passport data, is treated as sensitive personal data or information under Rule 3 of the SPDI Rules and attracts heightened safeguards. We collect it only where genuinely required to prepare your file, we tell you why, and we protect it as described in section 12. We do not collect biometric data, health data, caste or religion data, sexual orientation data, or political affiliation data, and we do not ask for data we do not need. If a document you upload happens to contain such data incidentally, we do not extract, index or use it.
5. Why we process your data, and for how long
The table at Annexure A sets out, for each category of personal data, the specified purpose, the lawful basis, and the retention period. That Annexure forms part of this Policy. In summary, we process your personal data to:
- Provide the Services: build your personalised document list, prepare and verify your documents, conduct your 30-minute advisor call, and return your finished file.
- Communicate with you about your application: booking confirmations, calendar invites and meeting links, reminders, document requests, status updates and support, by email, telephone and (if you opt in) WhatsApp.
- Take and reconcile payment through our payment gateway, and issue tax invoices.
- Meet legal, tax, accounting and regulatory obligations, and establish, exercise or defend legal claims.
- Secure the Services: prevent, detect and investigate fraud, misuse and security incidents.
- Improve the Services, using aggregated, anonymised or de-identified data wherever possible. Where data has been irreversibly anonymised so that no individual is identifiable, it ceases to be personal data and this Policy does not restrict its use.
- Send you news or offers only where you have separately opted in. You may unsubscribe at any time, at no cost, using the link in every such message.
We do not sell your personal data. We do not rent, trade or otherwise make it available for consideration to any third party for that third party's own marketing. We do not use the documents you upload for any purpose other than providing the Service you asked for. These are contractual commitments, not aspirations.
Purpose limitation. We will not process your personal data for a new purpose that is incompatible with the purpose for which it was collected without giving you a fresh notice and, where required, obtaining fresh consent.
Accuracy. Where we use your personal data to make a decision that affects you, or disclose it to another Data Fiduciary, we take reasonable steps to ensure it is complete, accurate and consistent, as required by section 8(3) of the DPDP Act. Because our preparation can only be as accurate as the information you give us, you are responsible for the accuracy of the data you supply, and for notifying us of changes.
6. Withdrawing your consent
You may withdraw your consent at any time. We will make withdrawal as easy as giving consent, as required by section 6(6) of the DPDP Act. You can withdraw through your account settings, or by writing to the Grievance Officer at the address in section 18. We will not impose a fee, a retention offer, a multi-step obstacle course, or any other friction designed to discourage you.
On withdrawal:
- we will stop the processing that relied on that consent within a reasonable period;
- we will erase your personal data and cause each of our Data Processors to erase it, unless retention is required for compliance with a law in force in India, in which case we retain only what that law requires, for only as long as it requires (see Annexure A);
- the lawfulness of processing carried out before withdrawal is not affected; and
- withdrawal may mean we can no longer provide some or all of the Services. Where it prevents us from completing work you have paid for, the refund position is governed by our Terms & Conditions, and the consequences of withdrawal are yours to bear under section 6(5) of the DPDP Act.
7. Children and persons with a disability
Our Services are intended for adults. You must be at least 18 years old to use the Services on your own behalf. We operate an age declaration at sign-up and we do not knowingly process a child's personal data outside the circumstances below.
Where an application involves a child, for example a minor travelling with a family, we process the child's personal data only:
- after obtaining verifiable consent from the parent or lawful guardian, in accordance with section 9(1) of the DPDP Act and Rule 10 of the DPDP Rules. We will exercise due diligence to check that the person identifying themselves as the parent is an adult and is identifiable, by reference to reliable identity details already available to us, or, where available, a virtual token issued by an authorised digital locker service provider (DigiLocker) that maps to verified identity details;
- to the extent strictly necessary for that specific visa application; and
- in a manner that is not likely to cause any detrimental effect on the well-being of the child, as required by section 9(2).
Absolute prohibition on tracking and advertising to children. In accordance with section 9(3) of the DPDP Act, we do not undertake any tracking, behavioural monitoring or profiling of children, and we do not direct any advertising at children. Operationally, this means that where a file involves a child, that child's personal data is processed only within our document preparation environment and is excluded from every advertising, analytics and measurement tool we use, including Meta's. We do not transmit any child's personal data, or any identifier derived from it, to an advertising platform.
Persons with a disability. Where you are a person with a disability who has a lawful guardian appointed under law, we will process your personal data on the basis of that guardian's consent, having verified the guardian's appointment, in accordance with section 9(1) and Rule 11 of the DPDP Rules.
If we learn that we have processed a child's personal data without valid verifiable consent, we will cease processing and erase that data promptly, and we will notify the parent or guardian.
8. Who we share your data with
We share your data narrowly, on a need-to-know basis, and never carelessly.
8.1 Data Processors
We engage the Data Processors listed at Annexure B to help us operate. In accordance with section 8(2) of the DPDP Act, each is engaged only under a valid written contract that requires them to:
- process personal data only on our documented instructions and only for the purpose we specify;
- implement reasonable security safeguards at least equivalent to our own;
- not engage a sub-processor without our prior written authorisation, and to flow down equivalent obligations;
- notify us of any Personal Data Breach without undue delay and in any event in time for us to meet our own reporting deadlines;
- assist us in responding to Data Principal rights requests; and
- erase or return personal data on termination or on our instruction.
We remain accountable to you for the acts and omissions of our Data Processors. Engaging a processor does not transfer our obligations under the DPDP Act, and we do not seek to exclude our liability for their processing of your data.
8.2 Other disclosures
- We do not share your file with any consulate, embassy, visa application centre or government on your behalf, because we do not submit your application. You submit your own file directly.
- Professional advisers. Our auditors, lawyers and accountants, bound by professional confidentiality obligations.
- When required by law. We disclose pursuant to a valid summons, order, warrant or written direction from a court, tribunal or authorised government agency, or where disclosure is necessary to comply with a law in force in India. We will satisfy ourselves that the request is lawful and, where we are permitted to do so, we will inform you before disclosing.
- In a business transfer, such as a merger, amalgamation, acquisition, scheme of arrangement or sale of assets. Any transferee will be bound by a policy at least as protective as this one, and we will notify you of any change in the identity of the Data Fiduciary.
8.3 Advertising and analytics
We use Meta's advertising and analytics tools on our website for measurement and marketing. These tools may collect usage information through our site. Our commitments here are specific:
- These tools are loaded only after you give consent through our cookie banner, and never before.
- We do not transmit the contents of your uploaded documents, your passport details, your financial data, your visa history or your refusal letter to any advertising or analytics platform, in any form, hashed or otherwise.
- No child's personal data enters these tools (see section 7).
- You may control ad personalisation through your Meta account settings and your device settings, and you may withdraw cookie consent at any time through our cookie preference centre. Meta's own processing is governed by its privacy policy, over which we have no control.
9. Payments
We take payment through Razorpay, a payment aggregator authorised by the Reserve Bank of India under the Payment and Settlement Systems Act, 2007. We do not collect, store or have access to your full card number, CVV, PIN, UPI PIN, net-banking credentials or bank account credentials on our systems. Those are captured and processed directly by Razorpay in a PCI-DSS compliant environment, and card storage, where applicable, is by way of tokenisation in accordance with RBI's card-on-file tokenisation directions. We receive only the transaction confirmation data described in section 4.3. Razorpay's handling of your data is governed by its own privacy policy.
Never share your card number, CVV, OTP, PIN or password with anyone claiming to be from Unbordr. We will never ask for them.
11. How long we keep your data
We keep personal data only for as long as the specified purpose is being served, and thereafter only where retention is required by a law in force in India. When neither applies, we erase it or irreversibly anonymise it, and we require our Data Processors to do the same.
The specific retention periods that apply to each category of data are set out at Annexure A. In outline:
- Uploaded documents and prepared files. Retained for 60 days after delivery of your finished file, so that you can raise queries and we can support you, and then deleted. You may ask us to delete them sooner.
- Account and contact data. Retained while your account is active and for 3 years after your last interaction with us, after which it is erased, unless a longer statutory period applies.
- Financial and transaction records. Retained for 8 financial years as required by section 128(5) of the Companies Act, 2013, and for 72 months from the due date of the annual return as required by section 36 of the Central Goods and Services Tax Act, 2017. These are legal minimums we cannot waive, and they apply even if you withdraw consent.
- Security and access logs. Retained for 180 days within India, as required by the CERT-In Directions dated 28 April 2022.
- Records of consent, notices and rights requests. Retained for the duration of processing and for a reasonable period afterwards, to demonstrate compliance.
Where we retain data under a legal obligation after you have asked us to delete it, we retain the minimum data necessary for that obligation, we restrict it to archival access only, and we do not use it for any other purpose. We will tell you what we have retained and why.
12. How we protect your data
We implement reasonable security safeguards to prevent a Personal Data Breach, as required by section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules. These include:
- Encryption of personal data in transit (TLS) and at rest, and masking or tokenisation of sensitive fields where practicable;
- Access control on a least-privilege, need-to-know basis, with document access restricted to authorised team members assigned to your file, individual named accounts, and multi-factor authentication for administrative access;
- Logging and monitoring of access to and processing of personal data, retained and reviewed so that unauthorised access can be detected and investigated;
- Backups and continuity measures reasonably designed to allow continued processing in the event of loss of availability;
- Contractual safeguards with every Data Processor, as described in section 8.1;
- Confidentiality undertakings and background-appropriate onboarding for personnel with access to files, and prompt revocation of access on exit;
- Periodic review of our safeguards, and of the technical and organisational measures of our Data Processors.
No system can be guaranteed perfectly secure, and we do not claim otherwise. What we commit to is that we will apply safeguards appropriate to the sensitivity of visa documentation, and that we will not seek to contract out of our statutory obligation to do so. Nothing in this Policy or in our Terms & Conditions excludes or limits any liability we have under the DPDP Act, which can extend to a penalty of up to ₹250 crore for failure to take reasonable security safeguards.
Your part. You are responsible for keeping your login credentials confidential and for the security of the device and email account you use to access the Services. Please tell us immediately if you suspect unauthorised access to your account.
13. If a Personal Data Breach occurs
If a Personal Data Breach occurs, we will:
- Notify you, each affected Data Principal, without delay, in a concise, clear and plain manner, through the user account and by email or other registered mode of communication. That notification will describe the nature, extent and timing of the breach and the likely consequences relevant to you, the measures we have taken or propose to take to mitigate risk, the safety measures you may take, and the contact details of a person able to answer your questions, in accordance with Rule 7(1) of the DPDP Rules.
- Notify the Data Protection Board without delay with the available particulars, and provide the Board with the further particulars required by Rule 7(2), including the broad facts, circumstances and reasons, mitigation measures, findings on the person who caused it, remedial measures to prevent recurrence, and our report on the notices given to you, within 72 hours of becoming aware, or such longer period as the Board may allow on request.
- Report to CERT-In within 6 hours of noticing or being notified of a reportable cyber security incident, as required by the CERT-In Directions dated 28 April 2022.
- Notify any other regulator to whom reporting is required, and cooperate fully with any investigation.
We maintain an internal incident response procedure covering detection, containment, assessment, notification and post-incident review, and we test it periodically.
14. Where your data is processed
Your personal data is primarily stored and processed in India. Some of our Data Processors may process limited data on infrastructure outside India; the countries and the data involved are identified at Annexure B.
Where personal data is transferred outside India, we do so in accordance with section 16 of the DPDP Act, which permits such transfer except to a country or territory restricted by notification of the Central Government. We will not transfer personal data to any restricted territory, and we monitor those notifications. Any transfer is additionally subject to:
- a written contract with the recipient imposing safeguards at least equivalent to those in this Policy, and obliging the recipient to make the data available to us and to the Central Government on demand where required;
- any requirement of a sectoral law or regulator that requires data to be held in India, including RBI's payment data storage requirements, which our payment gateway is responsible for meeting; and
- data minimisation, so that only the data necessary for the processor's function leaves India.
Section 16 of the DPDP Act does not restrict the applicability of any other law that provides a higher degree of protection or restriction on transfer.
15. Your rights as a Data Principal
Under Chapter III of the DPDP Act you have the following rights. There is no charge for exercising them.
| Right | What it means | How to exercise it |
|---|---|---|
| Access (s. 11) | A summary of the personal data we process about you and the processing activities undertaken, the identities of all other Data Fiduciaries and Data Processors with whom it has been shared and a description of what was shared, and any other prescribed information. | Email the Grievance Officer, or use the request form in your account. |
| Correction, completion, updating and erasure (s. 12) | Correction of inaccurate or misleading data; completion of incomplete data; updating; and erasure of data no longer necessary for the purpose, unless retention is required by law. | Email the Grievance Officer, or edit directly in your account where the field is editable. |
| Withdrawal of consent (s. 6(4)) | Withdraw consent at any time, as easily as it was given. | Account settings, the link in any message, or email. |
| Grievance redressal (s. 13) | A readily available means of registering a grievance, with a response within the period specified in section 17 below. You must exhaust this before approaching the Board. | Email the Grievance Officer (section 18). |
| Nomination (s. 14) | Nominate another individual to exercise your rights in the event of your death or incapacity. | Submit a nomination through your account or by written notice to the Grievance Officer. |
| Complain to the Board | Escalate to the Data Protection Board of India if our response is unsatisfactory or absent. | See section 17. |
Identity verification. We may ask you for information reasonably necessary to verify your identity before acting on a request, in order to protect your data from being disclosed to someone impersonating you. We will not use that information for any other purpose.
Timelines. We will act on a valid request as soon as reasonably practicable and in any event within the timelines prescribed under the DPDP Act and DPDP Rules. Where a request is manifestly unfounded, excessive or repetitive, we may decline it, and we will tell you why and how to escalate.
16. Your duties as a Data Principal
Section 15 of the DPDP Act places duties on you as well. In particular, you must not:
- impersonate another person while providing personal data for a specified purpose;
- suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State;
- register a false or frivolous grievance or complaint with us or with the Board; or
- furnish any false particulars, suppress material information, or impersonate another person when exercising your right to correction or erasure.
Breach of these duties may attract a penalty of up to ₹10,000 under the First Schedule to the DPDP Act, in addition to any consequence under our Terms & Conditions or the general law.
17. Grievances, and how to escalate
Step 1: Contact our Grievance Officer. Write to the Grievance Officer named in section 18 with your name, registered email, a description of your grievance and any supporting material.
- We will acknowledge your grievance and issue a unique complaint reference number within 48 hours, in line with Rule 4(5) of the Consumer Protection (E-Commerce) Rules, 2020.
- We will redress the grievance within 30 days of receipt where it relates to the Services, as required by those Rules.
- For grievances relating specifically to the processing of your personal data, we will in any event respond within the period specified under the DPDP Rules, and no later than 90 days from receipt.
Step 2: Escalate to the Data Protection Board of India. If your grievance remains unresolved, or you are not satisfied with our response, you may complain to the Board under section 13(3) read with section 15 of the DPDP Act. The Board may be approached at the address and through the mechanism notified by it from time to time. You must ordinarily have exhausted Step 1 first.
Step 3: Other routes remain open. Nothing in this Policy limits your right to approach a consumer commission under the Consumer Protection Act, 2019, the National Consumer Helpline (1915) or the e-Daakhil portal, or any other authority or court of competent jurisdiction.
18. Contact us
| Data Fiduciary | Clearpath Global Technologies Private Limited (brand name: Unbordr) |
|---|---|
| Grievance Officer | Anirudh Singh |
| Email (grievances) | anirudh@unbordr.co |
| Email (general) | info@unbordr.co |
| Address | A-20, Sector 35, Noida, Gautam Buddha Nagar, Uttar Pradesh 201301, India |
The Grievance Officer is resident in India and is the person able to answer questions about our processing of your personal data, as contemplated by the DPDP Rules. We will publish any change to these details on our website.
19. Automated decision-making, and what we do not do
We do not make any decision producing legal or similarly significant effects concerning you solely by automated means. Our tools generate a suggested document list and highlight gaps; a human advisor reviews your file and the assessment you receive is a human one. We do not use your personal data to train third-party generative models, and we do not permit our Data Processors to do so.
20. Third-party links
Our website and communications may link to third-party sites, including government portals, VFS Global, BLS International and airline or accommodation providers. We do not control those sites and are not responsible for their content or privacy practices. Their processing of your data is governed by their own policies, which you should read.
21. Changes to this Policy
We may update this Policy from time to time. Where a change is material, for example a new purpose, a new category of recipient, a materially longer retention period, or a change in the identity of the Data Fiduciary, we will:
- post the updated Policy on our website with a new version number and "Last updated" date;
- give you at least 15 days' advance notice by email to your registered address, where you have an active account or an open file; and
- where the change requires it, seek your fresh consent rather than relying on your continued use of the Services.
For non-material changes, posting the updated Policy is sufficient. We maintain an archive of previous versions, available on request. Continued use of the Services after a non-material change indicates acceptance of it; continued use is not treated as consent to a material change that requires fresh consent under the DPDP Act.
22. Severability and interpretation
If any provision of this Policy is held to be invalid, illegal or unenforceable, that provision will be severed to the minimum extent necessary and the remainder will continue in full force. Where any provision of this Policy is inconsistent with the DPDP Act, the DPDP Rules or any other law in force in India, the law prevails and this Policy is to be read as modified to the minimum extent necessary to comply with it. Headings are for convenience only. This Policy is governed by the laws of India.
This Policy should be read together with our Terms & Conditions. In the event of conflict between the two on any matter concerning personal data, this Policy prevails.
Itemised record of processing
This Annexure forms part of the Policy and satisfies the itemised description requirement in Rule 3 of the DPDP Rules. "Consent" means section 6 of the DPDP Act; "Legitimate use" means section 7; "Legal obligation" means processing required by a law in force in India.
| Personal data | Specified purpose | Lawful basis | Retention |
|---|---|---|---|
| Name, email, mobile number | Account creation, authentication, service delivery, communication about your file | Consent; Legitimate use | Active account + 3 years from last interaction |
| Communication preferences (incl. WhatsApp opt-in) | Sending call reminders, document requests and your finished file through your chosen channel | Consent | Until withdrawn, then erased |
| Trip and application details (service type, destination, dates, purpose, travellers) | Building your personalised document list; advisor call preparation | Consent | 60 days after delivery |
| Visa history and refusal letter | Refusal Recovery analysis; identifying gaps in the previous file | Consent | 60 days after delivery |
| Address details, incl. Aadhaar-address match indicator (not the Aadhaar number) | Determining proof-of-address requirements for the application | Consent | 60 days after delivery |
| Passport details | Preparing and verifying application forms and the cover letter | Consent | 60 days after delivery |
| Employment / study details | Preparing and verifying employment or enrolment evidence | Consent | 60 days after delivery |
| Financial information (bank statements, sponsor details) | Verifying sufficiency of means as required by the Schengen Visa Code | Consent | 60 days after delivery |
| Accommodation and itinerary information | Preparing and verifying travel evidence | Consent | 60 days after delivery |
| Uploaded documents and prepared file | Preparing, verifying and delivering your file; post-delivery support | Consent | 60 days after delivery, then deleted |
| Advisor call recording / transcript | Quality assurance and accurate capture of advice given | Separate, specific consent | 60 days, or immediately on request |
| Payment confirmation data (transaction ID, amount, status, last 4 digits) | Payment reconciliation, invoicing, refunds, dispute handling | Legal obligation; Legitimate use | 8 financial years (Companies Act s.128(5)); 72 months (CGST Act s.36) |
| Technical and usage data (IP, device, browser, pages) | Site operation and security, plus analytics and advertising where you have consented | Consent (non-essential); Legitimate use (essential) | 13 months for analytics; per cookie table |
| Security, access and audit logs | Detecting and investigating unauthorised access; statutory log retention | Legal obligation | 180 days in India (CERT-In Directions, 28 April 2022) |
| Consent records, notices served, rights requests | Demonstrating compliance with the DPDP Act | Legal obligation | Duration of processing + 3 years |
| Child's personal data (where a minor is a co-applicant) | Preparing that child's application only | Verifiable parental consent (s.9) | 60 days after delivery. Never used for tracking, profiling or advertising. |
Data Processors and recipients
Each processor below is engaged under a written contract meeting the requirements of section 8(2) of the DPDP Act. This list is current as at the effective date and is updated on our website.
| Recipient | Function | Data accessed | Processing location |
|---|---|---|---|
| Razorpay (Razorpay Software Private Limited) | Payment aggregation, refunds, invoicing support | Name, email, mobile, transaction data. No card credentials are visible to us. | India |
| Supabase | Database, authentication and hosting | All account and file data, including uploaded documents | To be confirmed |
| Meta Platforms | Advertising and measurement on our website | Website usage data and identifiers only, after cookie consent. No document, passport, financial or child data. | Outside India (Meta infrastructure) |
| Professional advisers (auditors, lawyers, accountants) | Statutory audit, legal advice, dispute defence | Only what is necessary, on a need-to-know basis | India |