Privacy policy
English|Română
Privacy Policy
VISA CATCHER S.R.L. — visacatcher.bot and the @VisaCatcherBot Telegram bot
Version 2.0 — effective 15 August 2026. This policy replaces the "Policy on Personal Data Processing" dated 18 July 2024.
This policy explains how we process personal data when you use our website https://visacatcher.bot, our Telegram bot @VisaCatcherBot, your order page (Personal Account), and the related services. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Romanian Law no. 190/2018.
Scope notes:
- For certain departure countries the service is contracted with a partner operator rather than with us. That operator's identity and its own privacy terms are shown to you before you place the order, and those terms govern how it uses your data. We operate the platform through which such orders are placed and handle the order data for that operator, on its instructions, for the purpose of delivering the service you ordered; for the security, integrity and fraud prevention of the platform itself we act on our own account, as described in this policy. Requests about such an order can be sent to us at hello@visacatcher.bot and we will route them to the operator.
- Visa application centres ("VACs" — e.g. VFS Global, TLScontact, BLS International, Almaviva) and diplomatic missions process your data under their own privacy notices once it is submitted to their systems.
- If you are an agent or business partner, the data we process about you (registration details, contract data, signature, correspondence with agents@visacatcher.bot — which may be processed with AI-assisted tooling as described in section 4) is processed for the performance and administration of the partnership agreement; the rest of this policy applies to it accordingly.
1. Controller
VISA CATCHER S.R.L., Trade Register no. J2024013792408, fiscal code (CUI) 50369315, registered office: Aleea Slt. Adrian Cârstea nr. 13, bl. 37, sc. 2, et. 8, ap. 141, Sector 3, Bucharest, Romania.
Privacy contact: hello@visacatcher.bot (please mark privacy requests "Data protection").
2. What data we process
Data you (or the person ordering for you) provide:
- Identity and applicant data: name, date of birth, gender, nationality, passport number and expiry date, address, phone number, e-mail address — the data set required by the VAC's appointment system for your route.
- Passport images and extracted data: where your route requires it, an image of your passport data page. We read the machine-readable zone (MRZ) to extract the passport fields; this optical character recognition runs on our own systems and the image is not sent to any external OCR service. We do not perform facial recognition or any biometric identification.
- Photographs: where the VAC's process requires it, a facial photograph (and, for certain routes, additional photographs used by the VAC's own identity-verification step). We use them only to complete the VAC's process; the VAC may use them for its own identity verification under its own notice.
- Order details: destination, departure country, city, visa category, preferred dates, number of applicants.
- Contact and account identifiers: your Telegram ID/username (orders and notifications are handled via Telegram), e-mail address, and the password protecting your order page (stored as a secure hash).
- Support communications: messages, attachments and related metadata when you contact support. Please never send passport images or other identity documents through chat — use the upload forms in your Personal Account; documents received in chat despite this are removed from chat tooling and, where needed, moved to your order.
- Voluntary submissions: data you choose to submit to our public visa-statistics project (dates, countries, outcome, optional name). Please do not include other people's personal data in free-text fields.
Data we create or receive during the service:
- Booking data: appointment details, booking references, the confirmation documents returned by the VAC's system, and the dedicated booking e-mail accounts and VAC portal accounts we operate for your order (including their credentials and the messages those mailboxes receive).
- Payment data: amounts, currency, order reference, payment status, and — for certain payment routes — your IP address, transmitted to the payment provider for fraud prevention. Card data is entered only on the payment processor's secure page and never reaches us.
- Technical data: IP address, device/browser information, logs of interactions with the Platform.
- Data received from agents and group bookers (Article 14 GDPR): where a travel agent, or the person arranging a family/group booking, submits an order that includes your data, we receive the categories listed above from them. Agents are contractually required to inform you and to have a lawful basis before submitting your data. Independently of that, we provide this information ourselves: it is published here, shown on the order page, and — where we hold your own contact details and you have not already been informed — sent to you within one month of receiving your data, or at the latest when we first contact you. You can also request it at any time at hello@visacatcher.bot.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the services ordered: monitoring availability, booking appointments, waitlist registration, delivering notifications and results, operating your Personal Account | Identity and applicant data, passport data, photographs, order details, booking data, contact identifiers | Performance of a contract — Art. 6(1)(b) GDPR |
| Processing the data of applicants covered by an order who are not themselves the customer (family members, minors, applicants of agent orders) | The same applicant categories | Art. 6(1)(b), the contract being concluded for the applicant's benefit; the person ordering confirms they are authorised to provide the data |
| Submitting applicant data to the VAC's/Mission's booking system for the selected route | Applicant data as required by that system | Performance of a contract — Art. 6(1)(b) |
| Payment processing, invoicing, accounting and tax records | Payment data, identity data | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (Romanian accounting and fiscal law) |
| Customer support, complaint and refund handling | Support communications, order data | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (consumer law) |
| Security, fraud prevention, abuse detection, service diagnostics and logs | Technical data, order metadata (never passport images or passport numbers) | Legitimate interests — Art. 6(1)(f): keeping the service secure and preventing abuse |
| Defending payment disputes and chargebacks: providing the order record, monitoring logs and communications to the payment processor, acquirer or card issuer | Order data, monitoring and delivery records, communications | Legitimate interests — Art. 6(1)(f): defending a disputed charge |
| Recovering amounts due and preventing non-payment | Order and payment data, contact details | Legitimate interests — Art. 6(1)(f). Any decision to decline a new order for non-payment is reviewed by a person |
| Establishing, exercising or defending legal claims | Order, payment and communication records (passport images and passport numbers are excluded — they are deleted under section 6, and the retained record identifies applicants by name and date of birth) | Legitimate interests — Art. 6(1)(f) |
| Publishing aggregated visa statistics | Voluntary submissions | Consent — Art. 6(1)(a) (you choose what to submit; aggregate publication) |
| Analytics cookies (see section 8) | Technical data | Consent — Art. 6(1)(a) |
We deliberately do not rely on legitimate interests for any processing of passport numbers or other national identification numbers; they are processed only as necessary for the contract and deleted under the schedule in section 6 (Law 190/2018, art. 4). For Automated Booking and Automated Waitlisting, providing the applicant data marked as required is a contractual requirement — without it we cannot make a booking or register you on a waiting list. Slot Notifications need only your route criteria and a Telegram account.
We do not use your data for automated decision-making producing legal effects (Art. 22 GDPR). MRZ reading is data extraction, not a decision about you. We do not sell personal data or use it for third-party advertising.
4. Who receives your data
- VACs and diplomatic missions for the route you order: your applicant data is entered into the booking system of the relevant VAC/Mission — this is the purpose of the service. From that point, processing is governed by the privacy notices of the Mission (controller) and its VAC (processor). Where your destination country's Mission is outside the EEA, this disclosure is necessary for the performance of your contract (Art. 49(1)(b) GDPR).
- Payment providers: Stripe (card payments; Stripe Payments Europe Ltd, with intra-group transfers to the US covered by the EU-US Data Privacy Framework and standard contractual clauses); and, where offered for your order, any other payment provider shown at checkout, which receives the payment data and — where its fraud checks require it — your IP address, as necessary to execute your payment.
- Telegram: ordering, notifications and support run over Telegram, which acts as an independent controller of its messaging service (Telegram's own privacy policy applies). Attachments you send in support chats are stored on Telegram's infrastructure. We also use Telegram internally for operational alerts about orders (order reference and route only — no applicant identity data). Communication over Telegram happens because you choose it as your channel and it is necessary to perform the contract through that channel.
- IT service providers (processors): hosting and database infrastructure, object storage for uploaded documents, e-mail delivery, SMS delivery (where we send you SMS updates), customer-communication aggregation tooling, and AI-assisted support tooling that helps our staff classify messages and draft replies — the AI tooling processes support-message content together with related order summaries and customer profile details, and for agents their correspondence with agents@visacatcher.bot; it never processes passport images or document uploads. Our processors are bound by data-processing agreements under Art. 28 GDPR.
- Mailbox providers: where a booking requires a dedicated e-mail account, the account is hosted with a provider whose service the VAC's system accepts, established in the EEA or in a country covered by an adequacy decision.
- Google: analytics only, and only where you consent (section 8).
- Debt-recovery agents, lawyers and courts, where an amount due remains unpaid, limited to what is needed to pursue or defend the claim.
- Professional advisers and authorities where required by law (accounting, legal claims, lawful requests).
- Your agent, where your order was placed by one, receives the order status and results.
5. International transfers
We are established in Romania. Where a recipient is outside the European Economic Area, we rely on: an adequacy decision of the European Commission (for example the EU-US Data Privacy Framework for certified US providers such as Stripe, Google and our AI-tooling providers); the European Commission's Standard Contractual Clauses together with a transfer impact assessment; or, for disclosures necessary to perform your contract — the Mission/VAC of a non-EEA destination you select, a non-EEA payment provider executing your payment, or the messaging channel you chose — the contractual-necessity derogation (Art. 49(1)(b) GDPR). You can request a copy of the applicable safeguards via the privacy contact.
Our application databases and document storage, including backup copies, are hosted within the European Economic Area. Backup copies follow the same retention and location rules as the primary data.
6. How long we keep data
| Data | Retention |
|---|---|
| Passport images, MRZ extracts and passport numbers | Deleted within 90 days after the order is completed or cancelled (including backup copies, on the backup rotation schedule) |
| Order, booking and applicant records (name, date of birth, contact, booking details — without passport numbers) | 3 years after completion of the order (general limitation period for claims) |
| Invoices and accounting records | 5 years (Romanian Accounting Law 82/1991) |
| Support conversations | 12 months after the last message, unless needed for an ongoing dispute |
| Booking mailbox contents | For the life of the order and up to 3 years after completion, to support rescheduling and disputes |
| Visa-statistics submissions | Published and retained in aggregate; identifying fields (e.g. optional name) removed on request |
| Personal Account access | Until the retention periods above expire; you may request earlier deletion via the privacy contact |
| Monitoring and notification records (route, Monitoring start, alerts sent, delivery timestamps) | 3 years after the order ends — they evidence how the service was carried out and any cancellation charge |
| Order confirmations, withdrawal and cancellation records, and the statements you make at checkout | 3 years after the order ends |
| Technical logs | Up to 12 months |
When a retention period ends, data is deleted or irreversibly anonymised.
7. Your rights
You have the right to: access your data; rectify inaccurate data; erase data (where no legal ground requires keeping it); restrict processing; data portability for data you provided under contract; object to processing based on legitimate interests; and withdraw consent at any time for consent-based processing, without affecting prior processing.
To exercise any right, write to hello@visacatcher.bot. We respond within one month (extendable by two months for complex requests, with notice). We may ask you to verify your identity.
You also have the right to lodge a complaint with the Romanian supervisory authority: ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania; anspdcp@dataprotection.ro; +40 31 805 9211; www.dataprotection.ro — or with the supervisory authority of your country of residence.
8. Cookies and analytics
- Strictly necessary cookies (session, authentication, payment flow, the signed cookie of the mailbox viewer) are used without consent, as they are required for the service you request.
- Analytics (Google Analytics) runs only with your consent, given through the cookie banner, and can be withdrawn there at any time.
A detailed cookie list is available in the banner's settings panel.
9. Children
Our services are contracted by adults. Applicant data of minors is provided by their parent or legal guardian as part of a family booking; we process it only as needed for the ordered appointment.
10. Security
We protect personal data with technical and organisational measures, including: TLS encryption in transit; access controls and role separation for our staff; hashed passwords; card payments handled exclusively by the payment processor (we never see card numbers); dedicated per-order booking mailboxes instead of asking for your personal e-mail password; and signed, non-stored access tokens for the order mailbox viewer.
If a personal-data breach occurs, we notify ANSPDCP without undue delay (and within 72 hours where feasible) unless the breach is unlikely to result in a risk to you, and we notify you directly where the breach is likely to result in a high risk to your rights and freedoms (Articles 33-34 GDPR).
11. Changes to this policy
We may update this policy; each version is dated and numbered, and material changes are announced on the Platform. The current version is always available at https://visacatcher.bot/privacy-policy.