Privacy policy
Last updated: 2 October 2026
This policy explains how AMVISA processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
1. Controller
Mariia Doronina, trading as AMVISA. NIF: Z0519760B. Address: Calle Deportista Juan Matos, Nº 1, Bloque 1 Francia, Piso 11, Puerta AD, 03016 Alicante (Alicante), Spain. Email: visa@amvisa.online. Phone: +34 635 815 289.
2. What data we process
- When you contact us by email, phone or Telegram: your name, your contact details and the information about your trip that you choose to share.
- When you use our services: the data needed for your visa application, for example identity and passport details, photographs, contact details, travel plans, information about your employment, finances and family members, previous visas and trips, and copies of supporting documents.
- When you visit the website: technical data that the web server records automatically (IP address, date and time, requested page, browser type). The form on the website does not send any data to us: it only prepares a message that you send yourself from your email or messaging app. The IP address is also used to open the Spanish or English version of the website automatically; it is not stored for this purpose.
Please do not send us other people’s data without their consent. Data of minors is provided by their parents or legal guardians.
3. Purposes and legal bases
- Answering your enquiries and preparing a quote: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR).
- Providing the services you order, including preparing documents and submitting them to the competent authorities: performance of a contract (Art. 6(1)(b) GDPR). If the authorities of the destination country require special categories of data (for example, health information), we process them only with your explicit consent (Art. 9(2)(a) GDPR).
- Accounting, invoicing and tax obligations: compliance with a legal obligation (Art. 6(1)(c) GDPR).
- Keeping the website secure: our legitimate interest (Art. 6(1)(f) GDPR).
We do not use your data for automated decision-making or profiling, and we do not send you advertising without your consent.
4. Who receives the data
- Embassies, consulates, visa application centres and other authorities of the destination country, to the extent necessary for your application.
- Providers acting on our behalf (data processors): website hosting by IONOS SE (Germany); email and other IT services.
- Messaging services such as Telegram, if you choose to contact us through them.
- Tax advisers, banks and public authorities, where required by law.
5. Transfers outside the European Economic Area
Many visa authorities are located outside the European Economic Area (EEA). Transferring your data to them is necessary to provide the service you have requested (Art. 49(1)(b) GDPR). Any other transfer outside the EEA takes place only with appropriate safeguards (such as the European Commission’s standard contractual clauses) or on another legal basis provided for in the GDPR.
6. How long we keep the data
- Enquiries that do not lead to a contract: up to 12 months.
- Copies of passports and supporting documents: for the duration of the service; afterwards they are deleted or returned to you, unless we must keep them to comply with legal obligations or to defend legal claims.
- Contract and billing data: for the periods required by Spanish commercial and tax law (generally up to 6 years).
- Web server logs: up to 14 days.
7. Your rights
You have the right to access, rectify and erase your data, to restrict or object to its processing, to data portability, and to withdraw your consent at any time (without affecting the lawfulness of processing before the withdrawal). To exercise these rights, write to visa@amvisa.online. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).
8. Security
We apply technical and organisational measures appropriate to the risk: encrypted connections (HTTPS), restricted access to client data and regular backups.
9. Cookies
This website does not use cookies, analytics tools or advertising trackers.
10. Changes
We may update this policy. The current version is always available on this page, and the date of the last update is shown at the top.