Privacy Policy

This policy explains how we collect, use, share, retain, and protect data across the website, admin workspace, customer portal, visa documents, and email OTP flows.

Last updated: July 6, 2026

This policy is a template for the implemented system. It should be reviewed by counsel and completed with the correct legal entity, privacy contact or DPO details, and applicable jurisdiction before being published as the official version.

Who We Are

VisaDubai acts as the service provider and, for many processing activities, the data controller for personal data collected through this website, consultation forms, admin workspace, customer portal, email OTP login, and related service communications.

For questions or data rights requests, contact us through the website contact form or the email address shown in your service communications.

Data We Collect

We may collect identity and contact data, including name, email, phone, nationality, passport details, family details, travel plans, visa history, employment or business details, education details, financial evidence, property information, uploaded document links, customer notes, admin notes, and case status records.

We also collect technical and operational data such as IP address, browser or device details, page path, referral data, analytics identifiers, OTP request logs, session logs, email delivery logs, consent records, and customer support communications.

Sensitive and High-Risk Data

Visa and relocation services may require sensitive or high-risk information, including passport copies, identification numbers, financial records, health or medical appointment information, biometric-related process references, police clearance, immigration status, family relationships, and legal status documents.

We process this data only where needed for requested services, legal compliance, fraud prevention, vital interests, explicit consent where required, or other lawful bases available under applicable privacy laws.

How We Use Data

We use personal data to respond to inquiries, score and manage leads, create customer records, open and manage cases, build document checklists, send OTP codes, send workflow email templates, review documents, coordinate third parties, prepare applications, provide customer support, and keep audit records.

We may also use data for security monitoring, fraud prevention, service improvement, legal compliance, accounting, dispute handling, analytics, and business reporting.

Email OTP and Portal Security

Admin and customer portal access is authenticated with email one-time passcodes. We store hashed OTP codes, session token hashes, request metadata, expiry times, and attempt counts to protect the portal and prevent abuse.

You are responsible for keeping your email account secure. If your email account is compromised, someone may be able to request or read OTP codes.

Legal Bases

Depending on your location and the service, our legal bases may include contract performance, pre-contract steps requested by you, consent, explicit consent for sensitive data where required, legitimate interests, legal obligations, vital interests, establishment or defense of legal claims, and fraud prevention.

Where processing relies on consent, you may withdraw consent at any time. Withdrawal does not affect processing already completed lawfully and may limit our ability to continue services that require the data.

Sharing and Processors

We may share data with authorized staff, government or immigration authorities, embassies, free zones, banks, schools, medical centers, insurers, translators, courier providers, professional advisers, payment providers, cloud hosting providers, database providers, email providers, analytics providers, and security vendors.

Current technical processors may include hosting on Vercel, database storage through Neon/Postgres, email delivery through Postmark, and analytics or tag tools used on the website. Processor lists may change as operations evolve.

International Transfers

Your data may be processed in Thailand, the UAE, the United States, the European Economic Area, and other countries where our team, authorities, or processors operate.

Where required, we use appropriate safeguards such as contractual commitments, processor agreements, access controls, transfer assessments, consent, or transfer mechanisms recognized by applicable law.

Retention

We keep data only as long as needed for service delivery, customer support, accounting, legal compliance, audit trails, fraud prevention, dispute handling, and legitimate business records.

Typical retention may include active case duration plus a reasonable post-service period. Some records may be retained longer where immigration, tax, accounting, legal, security, or dispute requirements apply. You may request deletion, but some records may need to be retained where legally or operationally necessary.

Security

We use administrative, technical, and organizational safeguards such as email OTP, HTTP-only session cookies, hashed session tokens, access restrictions, database controls, email logs, and least-privilege admin processes.

No internet system is perfectly secure. You should avoid sending highly sensitive documents through unsecured links and should notify us promptly if a link, email account, or document may have been exposed.

Your Rights

Depending on applicable law, you may have rights to be informed, access your data, receive a copy, correct inaccurate data, request deletion, restrict processing, object to processing, withdraw consent, request portability, and complain to a competent authority.

We may need to verify your identity before acting on a request. Some rights are subject to legal limits, service obligations, fraud prevention, records retention, or rights of others.

Cookies and Analytics

We may use essential cookies for portal sessions and security, plus optional analytics or marketing tags to understand website performance, traffic sources, and lead attribution.

You can accept or decline optional analytics and change that choice from the Cookie settings link in the footer. Disabling essential cookies in your browser may prevent portal login or secure session features from working.

Children and Dependents

Visa services may involve dependent or family member information. The person submitting dependent information confirms they have legal authority or appropriate consent to provide it.

We do not knowingly invite children to create portal accounts directly without a parent, guardian, or authorized representative.

Updates

We may update this Privacy Policy when our services, technology, vendors, legal requirements, or data practices change. The posted effective date shows the latest version.

Material changes may be communicated through the website, email, or portal where appropriate.

WhatsApp