Skip to content

Privacy Policy

Information on the processing of your data pursuant to Art. 13 ff. GDPR

The protection of your personal data is of particular concern to us. We use your data exclusively in accordance with applicable data protection principles, in particular the provisions of the EU General Data Protection Regulation (GDPR). This privacy policy explains how VISARIGHT processes personal data in accordance with Art. 13 ff. GDPR.

1. General Information

The following privacy policy informs you about the nature and scope of the processing of personal data by VISARIGHT GmbH (hereinafter “VISARIGHT”, “we”, “us” or “our”). Personal data is any information that enables the direct or indirect identification of a person. The use of our services, products, technologies or functions as well as all associated pages, applications and services (collectively “Services”) is subject to this privacy policy.

The data collected by VISARIGHT can essentially be divided into two categories:

  • All data required for the processing, preparation, and fulfillment of a contract with VISARIGHT. If other service providers are involved in the fulfillment of the contract (e.g., visa authorities, optimization services, or hosting providers), your data will be shared with them to the extent necessary.
  • When you access our services, certain information is exchanged between your device and our server or the servers of the services we use. This may include personal data. The information obtained in this way is used, among other things, to improve our services.

Age requirement: Our services are only available to users who are at least 16 years old. If you are not yet 16 years old, you may only use our services with the consent of your parents.

2. Data Controller

Responsible for data processing:

VISARIGHT GmbH
c/o orangery Magdeburg
Breiter Weg 232a
39104 Magdeburg
Germany
Managing director: Andreas Kopysov
Commercial register: Amtsgericht Stendal, HRB 28149

Email: support@visaright.eu

3. Own Services

3.1 Contact Requests

You can contact us at any time by phone, in writing, by email, fax, or in person. The data you provide with your request is always provided voluntarily. We process the following personal data in accordance with Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR:

  • Name
  • Company (if applicable)
  • Subject
  • Phone number
  • Email address
  • Message

We generally do not share your personal data with third parties but process it internally. We store your personal data until it is no longer required for the respective purposes. Correspondence subject to commercial retention obligations is stored for 6 years.

3.2 Application Processing

To provide our services, particularly for processing visa applications, we process the following data in accordance with Art. 6(1)(b) GDPR and Art. 9(2)(a) GDPR:

  • Email address
  • First and last name
  • Residential address
  • Nationality
  • Gender
  • Date and place of birth
  • Marital status
  • Education
  • Occupation
  • Information entered by you

The submitted data is forwarded to the responsible authority. The data required for application processing is stored until it is no longer needed for this purpose. During the retention period (usually 6 to 10 years after conclusion of the contract), the data is only used in the context of a tax audit.

3.3 Business Partners and Service Providers

Most of our business partners and service providers designate an employee as a contact person. We process the following data in accordance with Art. 6(1)(f) GDPR:

  • First and last name
  • Company
  • Phone number
  • Email address

In the case of visa applications, the data is transmitted to the responsible authority. The data is stored for the legally prescribed periods (usually 2 to 5 years for visa applications).

3.4 Anonymous Contributions (Comments, Feedback, Processing Time Reports)

You can submit contributions on the Platform without a user account: comments, feedback on content, and processing time reports. Registration is neither required nor possible for this; contributions are stored without any link to an account or a person. In doing so, we process the following data:

  • The content of your contribution (e.g., comment text, rating, processing time details)
  • An optional, freely chosen display name (you may use a pseudonym)
  • Your IP address – only transiently, to limit the submission rate (rate limiting) and to prevent abuse

The IP address is processed only briefly in the server's memory (counting submissions per time window) and is deleted automatically; it is not stored together with your contribution. To detect automated submissions, we additionally use a form field that is invisible to humans (a so-called honeypot); no additional data is collected in the process.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in operating the community features and in protecting the Platform against abuse and automated access). Your contribution only becomes personal data insofar as you voluntarily include personal information in the contribution or the display name; please do not include sensitive data there.

Contributions are stored for as long as they are displayed on the Platform. Since they are not linked to an account, you cannot delete them yourself; to have a contribution removed, contact us at support@visaright.eu.

3.5 Advisory services (written case analysis & video consultation)

Via the platform you can order a written case analysis or request a video consultation. The legal service is provided by the partner law firm cooperating with us (attorney Eva Witt — Witt Legal, Berlin); the advisory contract is concluded directly between you and the law firm. For initiation, referral and technical processing we process the following data pursuant to Art. 6 (1) (b) GDPR — and, where your case description contains special categories of personal data (e.g. health data), on the basis of your explicit consent pursuant to Art. 9 (2) (a) GDPR:

  • Name
  • Email address
  • Your case description and any details and documents you submit
  • Booking or order data (selected service, time of request)

We transmit your details to the partner law firm to carry out the consultation. The law firm is an independent controller for the processing within the advisory or mandate relationship and is bound by attorney-client confidentiality (§ 43a BRAO, § 203 StGB).

Payment is processed via the payment service provider Stripe; the payment recipient is the partner law firm. Your payment data is processed by Stripe; VISARIGHT does not receive complete payment data.

We store the request and referral data until it is no longer required for processing; correspondence subject to commercial or tax retention obligations is stored for 6 or 10 years. The law firm's own privacy notices apply to processing within the firm.

4. Forms and Client Portal (secure.visaright.eu)

In addition to the other sections of this privacy policy, this section explains how personal data is processed on the surfaces of secure.visaright.eu: the public forms operated by VISARIGHT (Create Case, Complete Profile, Apartment Search) and the B2B Client Portal (/portal).

Forms operated by partner law firms under their own name (white-label) are governed by the privacy notice of the respective law firm as controller; VISARIGHT acts as a processor in those cases.

4.1 Data we process, purposes and legal bases

a) Case intake form (/create-case) — submitted by your employer's HR team: company and contact data of the HR contact; identity, contact, passport, employment and visa-related data of the employee concerned; uploaded documents. Purpose: creating and processing the relocation/immigration case we are commissioned to handle. Legal bases: performance of the contract with the employer (Art. 6(1)(b) GDPR); for the employee's data, our legitimate interest in performing the commissioned service (Art. 6(1)(f) GDPR). Where the employee's data is provided by HR rather than the employee, we inform the employee at the latest when we first contact them; our privacy information is made available to them as part of that contact and via the profile form.

b) Employee profile form (/complete-profile) — completed by the employee: identity, contact and address data, passport data, family members, qualifications and diplomas, uploaded documents. Purpose: completing the case file and preparing the visa / residence-permit application. Legal bases: Art. 6(1)(b) GDPR (steps at the request of the data subject and performance of the service concerning them) and Art. 6(1)(f) GDPR.

c) Apartment search form (/apartment-search) — your contact data (name, email, phone) and free-text comments together with the selected service. Purpose: processing your apartment-search request and referring it to our external housing-search partner (see section 4.2), who searches for suitable housing on your behalf. Legal bases: Art. 6(1)(b) and (f) GDPR.

d) Client portal (/portal) — used by authorised contacts of our business clients to follow the immigration cases of their employees. To sign in, we process your work email address and a one-time login code sent to that address; a session token is stored in your browser. Through the portal you can view the status, details, and invoices of your company's cases and send us messages. Purpose: providing the client portal and secure access to the case information relating to your company. Legal bases: performance of, or steps prior to, the contract with your company (Art. 6(1)(b) GDPR) and our legitimate interest in a secure, passwordless login (Art. 6(1)(f) GDPR). The login is protected by Cloudflare Turnstile (see section 4.6).

Immigration matters can involve special categories of personal data (Art. 9 GDPR), for example health data in insurance documents. We process such data only where necessary for the case and on a permissible basis under Art. 9(2) GDPR.

The case file can contain personal data of family members (e.g. spouse and children) whom the employee provides in the profile form — such as their name, date of birth, nationality and passport details — because these are required for the visa / residence-permit application. These family members are also data subjects within the meaning of the GDPR. Where we do not obtain their data from them directly, we rely on the employee to make this information available to them; the present notice describes the processing.

4.2 Recipients and processors

  • Supabase (Supabase, Inc.) — database and file storage; hosted in the EU (region Frankfurt, Germany).
  • Netlify, Inc. (USA) — web hosting / delivery of the form pages.
  • Cloudflare, Inc. (USA) — “Turnstile” bot protection on the forms (see section 4.6).
  • Mailjet (Mailjet SAS, 4 rue Jules Lefebvre, 75009 Paris, France; part of the Sinch group) — dispatch of transactional emails (e.g. confirmation and notification emails, and the client-portal login code); processing in the EU.
  • Slack Technologies LLC (a Salesforce company, USA) — internal team notifications: when a new submission arrives, we post a short alert to our internal Slack workspace so our team is notified. Depending on the form, this includes the name and email address of the person concerned and, additionally, the submitting HR contact's email address and the list of booked services (case intake), the number of uploaded documents and the case reference (profile form), or the selected service (apartment search). The uploaded documents themselves are not sent to Slack.
  • AI provider for diploma analysis — where an educational certificate or diploma is uploaded (case intake or profile form), we use an AI service to read the document and pre-fill the degree-recognition (ANABIN) check. Only the uploaded certificate is transmitted. This AI service runs on Google Cloud (Vertex AI, Gemini model), region europe-west1 (Belgium), within the EU; the provider does not use the data to train AI models. This is AI-assisted extraction, not an automated decision (see section 4.5).
  • Atlassian (Trello) (USA/Australia) — housing referrals are managed as cards on an internal Trello board. A card is created both from the apartment search form and from a case intake (/create-case) that includes an apartment-search service; the card carries the name of the person concerned, the selected service and its price. The Complete Profile form and the Client Portal do not transmit data to Trello.

The infrastructure providers listed above act as our processors under Art. 28 GDPR data processing agreements.

Housing-search partner (apartment search form only). The purpose of the apartment search form is to refer your request to our external housing-search partner (Homesearch Berlin, An der Kolonnade 11-13, 10117 Berlin, Germany). For that referral we forward your name, email address, phone number, the selected service (booked package) and any comments to this partner so they can search for suitable housing on your behalf. This partner is a recipient outside our organisation and processes your data under its own responsibility; it is not a mere processor acting on our instructions.

4.3 Third-country transfers

Where providers are based in the USA (Netlify, Cloudflare, Slack, Atlassian), transfers are safeguarded by the EU–US Data Privacy Framework certification of the provider and/or the European Commission's Standard Contractual Clauses. Our housing-search partner is established in the EU. Case content is stored in the EU (Supabase, region Frankfurt). You can request a copy of the safeguards via support@visaright.eu.

4.4 Retention

Case-related data is stored for the duration of the service and thereafter as long as statutory retention duties require (commercial and tax law: six to ten years). Apartment referral data is retained no longer than necessary for the referral and is deleted once it is no longer required, unless statutory duties require longer storage. Form submissions that do not lead to a case are deleted within a reasonable period. Client-portal one-time login codes are valid for about ten minutes and are not usable thereafter; an authenticated portal session ends at the latest after 24 hours.

4.5 Is providing data mandatory?

Providing the data marked as required is necessary to process the case or referral — without it we cannot provide the service. There is no statutory obligation to provide data. We do not use automated decision-making (Art. 22 GDPR).

4.6 Bot protection (Cloudflare Turnstile)

To protect this form against automated abuse (bots, spam) we use “Turnstile”, a service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (“Cloudflare”). Based on technical characteristics of your browser and your connection, Turnstile checks whether an entry comes from a human or from an automated program. In doing so, Cloudflare processes in particular your IP address, a TLS fingerprint, your user agent (browser/device details) and the identifier of this website. Turnstile does not set any cookies for advertising or tracking purposes and does not create cross-site profiles; according to Cloudflare, the signals processed are limited to what is strictly necessary for bot detection and do not allow Cloudflare to directly identify individual persons.

Purpose and legal basis. The processing serves to prevent abuse, spam and automated attacks and to ensure the security and availability of our forms. The legal basis is our legitimate interest therein (Art. 6(1)(f) GDPR).

Recipients and Cloudflare's dual role. Insofar as Cloudflare processes these signals solely to protect this form, Cloudflare acts as our processor (Art. 28 GDPR). According to its Turnstile privacy notice, Cloudflare additionally processes the same signals under its own responsibility in order to continuously improve its own bot-detection methods; in that respect Cloudflare is an independent controller and bases that processing on its legitimate interest (Art. 6(1)(f) GDPR). We have no influence over this further processing carried out under Cloudflare's own responsibility.

Transfer to a third country. Cloudflare, Inc. is established in the USA. The transfer is safeguarded by Cloudflare, Inc.'s certification under the EU–US Data Privacy Framework (adequacy decision of the European Commission) and, additionally, by the European Commission's Standard Contractual Clauses. We provide a copy of the safeguards on request.

Retention. Cloudflare does not state a fixed retention period in its Turnstile privacy notice; the signals are processed only for as long as this is necessary for bot detection or for improving the detection methods.

Your right to object. You can object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR). Regarding the processing carried out by Cloudflare under its own responsibility, please address your objection to Cloudflare's data protection officer (dpo@cloudflare.com). Further information can be found in the Turnstile privacy notice and in Cloudflare's general privacy policy.

Turnstile privacy notice

Cloudflare privacy policy

5. Data Processing During Website Visits

5.1 Server Log Files

Each time you access our website, the hosting provider (Vercel Inc.) automatically collects information in so-called server log files that your browser automatically transmits. This includes:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of server request
  • IP address

Processing is carried out on the basis of Art. 6(1)(f) GDPR. The data is not merged with other data sources. Collection is technically necessary for providing the website.

5.2 Cookies and Local Storage

This website uses technically necessary cookies for language settings. These are set without consent on the basis of Art. 6(1)(f) GDPR and Section 25(2) TDDDG, as they are essential for the operation of the website. We also use analytics cookies that are only activated after your explicit consent (details in section 5.6). You can withdraw your consent at any time via the cookie settings in the page footer. Your settings are stored in your browser (localStorage). Storage duration: technically necessary cookies up to 1 year, analytics cookies up to 2 years.

5.3 Hosting

This website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). Vercel processes the above-mentioned data on our behalf. The transfer to the USA is based on the EU Commission's standard contractual clauses. Further information can be found in Vercel's privacy policy.

Vercel Privacy Policy

5.4 Database Service

For the management of service data, we use Supabase, Inc. (65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513), a company incorporated in the USA (Delaware). Data processing takes place exclusively on EU servers (AWS eu-west-1, Ireland); personal data does not leave the EU/EEA. Supabase primarily stores publicly accessible administrative data as well as the anonymous contributions described in Section 3.4; this data only relates to a person insofar as you voluntarily include information in your contribution. Processing is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in the reliable and secure provision of the website). Further information can be found in Supabase's privacy policy.

Supabase Privacy Policy

5.5 Error Monitoring

To detect and fix technical errors, we use Sentry, operated by Functional Software, Inc. (45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA). When an error occurs, Sentry automatically collects the following technical data:

  • IP address (anonymized)
  • Browser type and version
  • Operating system
  • Error stack trace (does not contain personal data)
  • URL of the page where the error occurred
  • Time of the error

Processing is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in the stability and security of the website). Data is stored exclusively on EU servers (Frankfurt, Germany) and does not leave the EU/EEA. Sentry's automatic data scrubbing is enabled. Data retention period is 90 days. Further information can be found in Sentry's privacy policy.

Sentry Privacy Policy

5.6 Analytics (Google Analytics)

We use Google Analytics 4, a web analytics service provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). The service is only activated with your explicit consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). As long as you do not confirm the analytics cookies, no data is transmitted to Google. With consent enabled, the following data is processed pseudonymously:

  • Pseudonymous device ID from the _ga cookie
  • Pages visited and interactions (e.g. searches, language switches, scroll depth)
  • Technical information: browser type, operating system, approximate IP-based region

IP anonymization is enabled; full IP addresses are not stored. Data transfer to the USA is based on Google's EU-US Data Privacy Framework certification and the EU Commission's standard contractual clauses. Event data is retained for up to 14 months. You can withdraw your consent at any time via the cookie settings in the page footer; after withdrawal, no further data is collected.

Google Privacy Policy

6. Your Rights

You have the following rights regarding the processing of your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

To exercise these rights, please contact us at support@visaright.eu.

You also have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the Landesbeauftragte für den Datenschutz Sachsen-Anhalt, Magdeburg.

7. Data Security

We apply the highest standards of data security for our infrastructure and the processing of your data. We use protective mechanisms such as firewalls and data encryption. All personal data transmitted by you is transferred via the secure SSL standard (Secure Socket Layer).

8. AI-Assisted Content and Services

VISARIGHT uses artificial intelligence (AI) for various functions on this website. Below we explain what data is processed in each case.

8.1 AI-Assisted Content Creation

Parts of the plain-language law texts and editorial notes on authorities on this website are created with the support of AI. The AI exclusively processes publicly available official sources (in particular legal texts and publicly accessible authority information). No personal user data is processed as part of content creation. Processing is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in the understandable preparation of administrative information).

8.2 AI Service Providers

We use the following service providers for AI-assisted functions:

Anthropic, PBC
548 Market St., PMB 90375, San Francisco, CA 94104, USA
AI model (Claude) for content creation

As part of AI-assisted content creation (Section 8.1), only publicly available administrative and legal data is transmitted to Anthropic; no personal user data is transferred to the USA. Anthropic has committed to not using the transmitted data for training AI models.

Anthropic Privacy Policy

Jina AI GmbH
Prinzessinnenstraße 19-20, 10969 Berlin, Germany
Search embeddings and reranking for the website search

Jina AI is based in Germany. No personal data is transferred to third countries.

Jina AI Privacy Policy

Google Cloud EMEA Limited
70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland
AI model (Gemini) for search-query processing

Processing takes place within the EU (EU multi-region); the processed search queries are not transferred to a third country. The data is not used to train AI models. Google Cloud EMEA Limited (Ireland) is the contracting party; its US parent Google LLC is bound by the EU Standard Contractual Clauses (Module 3).

Google Cloud data processing terms

8.3 Your Rights Regarding AI Processing

In addition to the rights mentioned in Section 6, you have the right to object to the processing of your data by AI systems. For questions about AI-assisted data processing, please contact us at support@visaright.eu.

9. Protection of Minors

Protecting the privacy of children and young people is particularly important to us. For this reason, we do not knowingly collect or request personal data from persons under 16 years of age. If you are under 16 years of age, please do not send us any information about yourself. If we determine that we have collected personal data from a child under 16 years of age without parental consent, we will delete this data immediately.

10. Changes to the Privacy Policy

Changes to this privacy policy take effect upon publication on this page. If we change our privacy policy, we will publish the changes on this page to inform you about the data collected, its use, and the circumstances of any possible disclosure.

If you have any questions about our privacy policy, you can reach us at any time at support@visaright.eu.

Magdeburg, August 10, 2026