Privacy Policy
Last updated: January 2025
Who we are
VisaVault is a trading name of AuditVault Limited(“we”, “us”), a company registered in England and Wales under company number 16924533. We are registered with the Information Commissioner's Office (ICO) under registration number ZC111499.
For privacy enquiries contact: support@visavault.co.uk
What data we collect
- Account data: email address, name (via Clerk authentication)
- Case answers: visa category, employment details, financial information, travel history — provided by you during the application wizard
- Payment data: billing information processed by Stripe (we do not store card numbers)
- Usage data: pages visited, feature interactions (via PostHog analytics, EU instance)
- Support communications: any emails you send us
We do not collect or store passport numbers. If entered in a form field, they are immediately excluded from all AI processing payloads.
How we use your data
- To generate your personalised document checklist and covering letter
- To process your payment and issue receipts
- To send you your completed application pack by email
- To improve the service through anonymised analytics
- To comply with legal obligations (e.g. fraud prevention, tax records)
Legal basis for processing
- Contract: processing your case data to deliver the service you purchased
- Legitimate interests: fraud prevention, analytics, service improvement
- Legal obligation: financial record-keeping
Data processors
We share data with the following trusted processors under data processing agreements:
- Supabase — database hosting (EU region)
- Clerk — authentication and user management
- Stripe — payment processing
- Resend — transactional email delivery
- AWS — application hosting (eu-west-2, London) and file storage
- Anthropic — AI document generation (anonymised case data only)
How we use artificial intelligence
VisaVault uses Claude, an AI model developed by Anthropic and accessed via AWS Bedrock, to generate personalised document checklists and covering letters for UK visa applications.
What data is sent to the AI
We apply strict data minimisation. The following information is sent to Claude to generate your checklist and letter: visa category, nationality, current immigration status, employer details (Skilled Worker), institution details (Student), sponsor details (Family), and residence history (ILR). Your full name is included in covering letter generation only.
What is never sent to the AI
Your passport number, date of birth, and passport expiry date are never included in any AI prompt. This is enforced in our code and tested on every deployment.
Accuracy and limitations
AI-generated content may not reflect very recent changes to UKVI immigration rules. We monitor GOV.UK daily for requirement changes and update our AI prompts accordingly. You should always verify document requirements on GOV.UK before submitting your application.
Reporting inaccuracies
If you believe your checklist or covering letter contained an error, please report it at visavault.co.uk/ai-accuracy or email support@visavault.co.uk with the subject line “AI accuracy issue”. We review every report and respond within 5 business days.
AI and automated decision-making
VisaVault does not make automated decisions about your visa eligibility. The AI generates a suggested document list and a draft letter. All decisions about which documents to submit remain with you. VisaVault is a document preparation service, not an immigration adviser.
Data retention
Case data is retained for 24 months after last access, then pseudonymised. Payment records are retained for 7 years as required by HMRC. You can request deletion at any time by contacting us — see “Your rights” below.
Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure of your data (“right to be forgotten”)
- Object to or restrict processing
- Data portability
- Withdraw consent at any time (where processing is consent-based)
To exercise any of these rights, email support@visavault.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the ICO.
Cookies
We use essential cookies for authentication (Clerk session) and analytics cookies (PostHog, EU instance only). No advertising or third-party tracking cookies are used.