UK Visa Online · EAS International
Privacy
2026-04-24
Introduction
The protection of your personal data is of the highest importance to EAS International. In this privacy policy we inform you in accordance with the revised Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) and, where applicable, the European General Data Protection Regulation (GDPR) about the processing of your personal data in connection with our UK Visa Online service.
Controller
EAS International
{{EAS_ADDRESS}}
{{EAS_KANTON}}, Switzerland
Email: {{EAS_EMAIL}}
Phone: {{EAS_PHONE}}
Categories of data we process
In the course of your order we process the following categories of personal data:
- Identification data: first name, last name, date of birth, nationality, gender.
- Passport data: passport number, place and date of issue, expiry date, issuing country. These are considered particularly sensitive under revFADP.
- Biometric data: facial portrait and digital copy of the passport data page. Biometric data is particularly protected under revFADP and GDPR.
- Contact data: email address, phone number, postal address.
- Travel data: purpose of travel, planned entry dates, address of stay.
- Self-declaration data: yes/no answers to criminal, immigration, security and extremism questions (required by the official ETA application).
- Payment data: card payments are processed exclusively through the payment service provider Stripe. We do not store any card data ourselves. We only receive confirmation and reference information (transaction ID, payment status, last 4 digits of the card).
- Technical data: IP address, browser type, language setting, timestamp, referrer, session identifier (via strictly necessary cookies).
Purposes of processing
- Processing your order and submission to the official GOV.UK application channel.
- Multilingual communication about the status of your case.
- Invoicing and payment processing.
- Compliance with statutory record-keeping and accountability obligations.
- Protection against misuse and fraud prevention.
- Quality assurance and further development of our service in anonymised form.
Legal bases
- Performance of contract: processing of data required for your order (Art. 31(2)(a) revFADP; Art. 6(1)(b) GDPR).
- Legal obligation: retention of business records under the Swiss Code of Obligations (Art. 31(2)(e) revFADP; Art. 6(1)(c) GDPR).
- Legitimate interests: fraud prevention, system security (Art. 31(2)(c) revFADP; Art. 6(1)(f) GDPR).
- Consent: biometric data and specific forms of communication (Art. 6(7) revFADP; Art. 9(2)(a) GDPR).
Recipients of your data
We share your data only with the following recipients and only to the extent necessary for the performance of the contract:
- UK Home Office / GOV.UK: transmission of the data required for the ETA or visa application through the official application channel.
- Stripe Payments Europe Ltd. (Ireland): processing of card payments.
- SMTP mail provider: sending and receiving emails in connection with your order.
- Hosting providers within Switzerland or the EU/EEA: operation of the website and database.
All processors are contractually bound to confidentiality and to the protection level of revFADP and GDPR.
International data transfers
Data is transmitted to the UK Home Office in the United Kingdom. The Swiss Federal Council has adopted an adequacy decision for the United Kingdom (Annex 1 FADPO), and the European Commission has likewise issued an adequacy decision. No additional contractual safeguards are therefore required.
Retention
- Order data is retained for 10 years after completion (commercial record-keeping requirement under Art. 958f Swiss Code of Obligations).
- Payment data is retained for 10 years.
- Uploaded passport copies and biometric images are irreversibly deleted at the latest 90 days after successful submission, unless a longer retention is required for legal defence.
- Technical log data is anonymised after at most 30 days.
Your rights
You have the right at any time to access, rectification, erasure, restriction of processing and data portability. Where processing is based on consent, you may withdraw it at any time with effect for the future.
Requests should be addressed to {{EAS_EMAIL}}. To protect against misuse, we may require identity verification.
You also have the right to file a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or — for EU customers — the competent supervisory authority.
Cookies and local storage
We use only strictly necessary cookies for session management, language and theme preferences, and protection against cross-site request forgery. We do not set any analytics, advertising or profiling cookies. No consent is required under revFADP or the EU ePrivacy directive.
Automated decision-making
For initial checks on your documents (e.g. photo quality, passport validity) we use simple plausibility checks. No fully automated decision with significant legal effect takes place on our side. The substantive decision on the UK ETA or visa application lies exclusively with the UK authority.
Changes
We reserve the right to amend this privacy policy in response to changes in law or in our services. The version in force at the time of the order applies.