PRIVACY AND DATA PROTECTION POLICY
Last Updated: March 30, 2026
This Privacy Policy describes how Evisa Travel Services S.L. (hereinafter, “MyTripVisa“), in its capacity as Data Controller, collects, uses, and protects personal information. This document complies with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Spanish Organic Law 3/2018 (LOPDGDD), and international transparency standards for data management.
1. IDENTIFICATION OF THE DATA CONTROLLER
- Entity: Evisa Travel Services S.L.
- Tax ID (NIF): B56264856
- Registered Address: C/ Demetrio López 5, 5A, 28027 Madrid, Spain.
- Contact Email: info@mytripvisa.com
2. TECHNICAL INFRASTRUCTURE AND DATA PROCESSOR
To provide our electronic visa processing and mediation services, MyTripVisa utilizes the high-security technological platform provided by Voyzo Inc.
- Role of Voyzo: Voyzo Inc. acts as the Data Processor, operating the secure environment hosted on our application subdomains (e.g., apply.mytripvisa.com).
- Compliance: All data is processed under the strict documented instructions of MyTripVisa. Voyzo is contractually obligated to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including SSL/TLS encryption.
3. INFORMATION WE COLLECT AND MINIMIZATION
We collect only the information strictly necessary to perform the requested mediation service:
- Identity and Travel Data: Full name, passport details (number, issuance/expiry dates), nationality, gender, date of birth, travel dates, and any specific documentation required by the destination government.
- Contact Information: Email address and telephone number, used exclusively for notifications regarding the status of the visa application.
- Payment and Financial Data: MyTripVisa acts as the Merchant of Record. However, we do not store credit or debit card information on our servers. All payments are handled via encrypted, PCI-DSS compliant gateways (e.g., Square). Financial data is processed directly by the payment provider; MyTripVisa and Voyzo only receive confirmation of the transaction.
- Technical Data: IP addresses, browser type, and device identifiers, used solely for fraud prevention, transaction security, and ensuring the technical integrity of the application portal.
4. PURPOSE AND LEGAL BASIS FOR PROCESSING
The legal basis for processing your data is the performance of a contract (Art. 6.1.b GDPR) for visa mediation services. The purposes are:
- Processing, validating, and submitting your application to the relevant foreign government authorities.
- Managing the payment of official government fees on your behalf.
- Communicating critical updates regarding your travel authorization.
- Complying with legal and audit obligations (e.g., anti-money laundering and tax regulations).
5. INTERNATIONAL DATA TRANSFERS
5.1. Government Submission: By requesting a visa for a country outside the European Economic Area (EEA), the User acknowledges and explicitly consents that their personal data must necessarily be transferred to the Government or immigration authority of the destination country.
5.2. Technology Provider: Our technical processor, Voyzo Inc., is located in the United States. This transfer is governed by Standard Contractual Clauses (SCCs) or other valid adequacy mechanisms to ensure that your data receives a level of protection equivalent to that of the EU.
6. DATA RETENTION
Personal data will be retained for the period necessary to fulfill the visa application process and, subsequently, for the duration of any applicable statute of limitations for legal, tax, or administrative liabilities (typically 5 to 10 years in accordance with Spanish law).
7. COOKIE CONSENT AND CROSS-DOMAIN TRACKING
We use CookieYes technology to manage user consent. To provide a seamless experience, we implement Cross-Domain Consent Sharing. This means that your privacy preferences (Accept/Reject) selected on mytripvisa.com are automatically synchronized with our processing subdomains (e.g., apply.mytripvisa.com), ensuring we respect your choices across our entire digital infrastructure without redundant interruptions.
8. YOUR RIGHTS (GDPR & CCPA)
Under the GDPR, you have the following rights:
- Access, Rectification, and Erasure: You may request to see, correct, or delete your data.
- Restriction and Objection: You may limit how we use your data.
- Data Portability: You may request a copy of your data in a structured format.
- Withdrawal of Consent: Where processing is based on consent, you may withdraw it at any time.
Exercise of Rights: Please contact us at info@mytripvisa.com. As the Controller, MyTripVisa will coordinate with Voyzo Inc. to ensure any technical request is fulfilled promptly.
9. DATA SECURITY MEASURES
We regularly audit the security protocols of our technical partner, Voyzo, to ensure data integrity. This includes firewalls, encrypted databases, and restricted access controls. In the event of a data breach, we are committed to notifying the relevant Supervisory Authority (AEPD) and affected users within the timeframes established by law.