Effective date: 2026-04-05
This Privacy Policy explains how VisaFy collects, uses, stores, discloses, and otherwise processes personal information in connection with our website, software applications, customer portals, integrations, and related services (collectively, the "Services").
1. Who we are
VisaFy is a SaaS platform used by visa, migration, and education consultancies to manage leads, clients, applications, documents, workflows, communication, reporting, and related operational work.
VisaFy is owned and operated by an individual sole proprietor.
Owner and operator: Sudarshan Uprety
Brand / service name: VisaFy
Website: https://visafyapp.com
Privacy email: privacy@visafyapp.com
Support email: support@visafyapp.com
Mailing address: Lalitpur, Nepal
2. Scope of this policy
This Privacy Policy applies to personal information that we process when:
- a consultancy, staff user, contractor, or administrator uses VisaFy;
- a client, applicant, student, or other end user interacts with a customer-facing portal or workflow powered by VisaFy;
- a user connects a Google account, Microsoft account, or another supported third-party identity or profile service;
- someone visits our website, requests a demo, contacts support, subscribes to updates, or otherwise interacts with us.
This Privacy Policy does not apply to third-party sites, platforms, products, or services that are not operated by VisaFy, even if they are linked from our Services.
3. Privacy roles
VisaFy may act in different privacy roles depending on the context:
- For account, billing, security, support, product operations, and website data relating to VisaFy's own business, VisaFy generally acts as the controller or business responsible for that processing.
- For client, applicant, case, immigration, education, document, and workflow data submitted by a consultancy customer into the platform, VisaFy generally acts as a processor or service provider on behalf of that customer.
If you are a client or applicant whose information was entered into VisaFy by a consultancy, that consultancy is usually the primary party responsible for your notices, consents, lawful basis, and customer relationship. In those situations, please contact the consultancy directly first.
4. Information we collect
We may collect the following categories of information:
4.1 Account and identity information
- name, email address, phone number, password hash, job title, profile image, and user role;
- organization, branch, team, or tenancy details;
- authentication, session, and account recovery data.
4.2 Customer and case data
- lead, client, applicant, guardian, sponsor, or emergency contact details;
- immigration, visa, travel, education, employment, financial, and case-progress information entered by customers;
- notes, comments, assignments, reminders, and workflow history;
- files and supporting evidence uploaded directly into VisaFy by customers who choose to store them in the platform.
4.3 Payment and commercial data
- subscription status, invoice information, plan details, transaction references, and payment-related records;
- communications related to contracts, renewals, collections, disputes, and account administration.
4.4 Technical and usage data
- IP address, device identifiers, browser type, operating system, referring URLs, timestamps, crash logs, and diagnostic events;
- feature usage, session activity, audit logs, and security events;
- approximate region inferred from IP or environment.
4.5 Support and communication data
- support tickets, chat messages, emails, feedback, call notes, and onboarding information;
- records of notices, preferences, and communication history.
4.6 Integration and connected account data
- connected account name, email address, profile photo, and provider account identifier;
- OAuth access tokens, refresh tokens, token expiry data, and permission metadata;
- limited account profile data returned by supported providers to establish, maintain, and secure the connection.
5. Sources of information
We collect information:
- directly from you;
- from your employer, consultancy, administrator, or other authorized users on your workspace;
- from your clients, applicants, or other people whose information is entered into the platform by customers;
- from connected identity, account, or profile providers that you authorize;
- automatically through use of the Services, security tools, logs, and device/browser interactions;
- from payment processors, hosting providers, analytics providers, and support vendors involved in operating the Services.
6. How we use information
We may use personal information to:
- provide, operate, host, maintain, and secure the Services;
- create and manage user accounts, tenancy access, permissions, and customer environments;
- support CRM, workflow, notification, reporting, finance, document, and operational features inside VisaFy;
- authenticate connected accounts and display basic provider profile details inside the product;
- monitor performance, detect bugs, investigate incidents, prevent fraud, and protect users and systems;
- provide support, onboarding, training, implementation assistance, and account administration;
- send transactional messages, product notices, release updates, renewal communications, and security alerts;
- send marketing or promotional communications about VisaFy where permitted by law and consistent with applicable preferences;
- analyze usage trends and improve product design, reliability, accessibility, and customer experience;
- comply with law, enforce agreements, resolve disputes, and protect our rights, property, users, and business operations.
7. Legal bases for processing
Where required by applicable law, we rely on one or more of the following legal bases:
- performance of a contract or taking steps requested before entering into a contract;
- legitimate interests, such as running and improving the Services, securing our platform, supporting customers, and preventing misuse;
- consent, where we specifically request it;
- compliance with legal obligations;
- protection of vital interests or establishment, exercise, or defense of legal claims where applicable.
8. Google, Microsoft, and account profile data
If you choose to connect a Google account, Microsoft account, or another supported account provider to VisaFy, we may process limited connected-account data such as your name, email address, profile photo, account identifier, and token metadata to:
- authenticate and maintain the connection;
- identify which account is connected to VisaFy;
- display basic connected-account details inside settings, profile, or account-management interfaces;
- support sign-in, profile, or account-linking features requested by the user;
- maintain security, troubleshoot failures, prevent abuse, and keep the integration functioning.
Under this integration model, VisaFy does not access, read, or store a user's Google Drive or OneDrive documents, file contents, folder contents, or cloud-storage metadata through the connected-account flow described in this policy.
VisaFy does not use data obtained through Google APIs, Microsoft APIs, or similar provider APIs for targeted advertising, advertising profiles, data brokerage, sale of data, or unrelated marketing purposes.
If VisaFy later enables document-storage, file-browsing, or cloud-content features through Google, Microsoft, or similar APIs in production, this Privacy Policy will be updated before those features are made generally available.
VisaFy's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. How we disclose information
We may disclose personal information to:
- hosting, cloud, email, logging, analytics, support, payment, and security service providers acting on our behalf;
- integration providers and third-party services that a customer chooses to connect;
- the relevant customer organization, administrators, managers, consultants, staff, or end users according to configured permissions;
- professional advisers such as lawyers, accountants, auditors, insurers, and financing counterparties;
- courts, regulators, law enforcement, or competent authorities when required by law or reasonably necessary to protect rights, safety, or security;
- acquirers, investors, successors, or affiliated entities in connection with a financing, merger, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.
We do not sell personal information in the ordinary sense of the term.
10. International transfers
We and our service providers may process personal information in countries other than the country where the data was originally collected. Where required by law, we use appropriate safeguards for cross-border transfers.
11. Data retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- provide the Services and maintain customer accounts;
- preserve security, backup, audit, and business continuity records;
- meet legal, tax, accounting, regulatory, and contractual requirements;
- resolve disputes and enforce agreements.
Retention periods vary depending on the type of information, the customer contract, legal obligations, system backup cycles, and whether the data remains necessary for the relevant purpose.
If a connected account is disconnected, associated tokens may be deleted immediately or retained only as long as needed for security, audit, fraud prevention, or lawful compliance purposes.
12. Security
We use reasonable technical, administrative, and organizational measures designed to protect personal information, including access controls, encryption where appropriate, activity logging, environment segregation, credential controls, and operational monitoring.
No security measure is perfect, and no method of transmission or storage can be guaranteed to be completely secure. You are responsible for maintaining the confidentiality of your credentials and for notifying us promptly if you suspect unauthorized access.
13. Your rights and choices
Depending on your location and the applicable law, you may have rights to:
- access personal information;
- correct or update inaccurate information;
- request deletion of certain information;
- object to or restrict certain processing;
- request portability of certain information;
- withdraw consent where processing is based on consent;
- opt out of non-essential marketing communications.
You can opt out of marketing emails by using the unsubscribe link in the message or by contacting us. We may still send you service-related and transactional communications.
If your account is managed by a consultancy or employer, some requests may need to be handled by that organization. If you are a client or applicant of a consultancy using VisaFy, please contact the consultancy first.
14. Cookies and similar technologies
VisaFy and its service providers may use cookies, local storage, session tokens, and similar technologies to:
- keep users signed in;
- remember session preferences and security state;
- measure reliability and diagnose technical issues;
- understand product usage and improve the Services.
Where required by law, we will obtain consent before using non-essential cookies or similar technologies.
15. Children's information
VisaFy is designed for professional and business use. It is not directed to children as a consumer service. Where customers use VisaFy to manage case data involving minors, they are responsible for ensuring they have the necessary authority and legal basis to submit that information.
16. Third-party services
The Services may link to or interact with third-party products, integrations, or websites. Those third parties operate under their own terms and privacy policies. We are not responsible for their independent privacy practices.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and provide additional notice where required by law or contract.