Skip to main content
EntryNovaKnow what you need before you go.
  • Entry Plan
  • Trips
  • Alerts
  • Applications
  • Passport
  • Ask
  • Guides
  • What we can do

Free validation beta. EntryNova is in free validation beta. We prepare and check your application using verified official sources. We are not a government authority and have no affiliation with any government. Where an application must be lodged through an official government system, we direct you to it.

Privacy Policy

1. Who is responsible for your data

The data controller is Svetlana Melichova, an individual established in Ireland, acting in a personal capacity. There is no company: EntryNova is a trading name.

Contact for any privacy question or request: [email protected]

We publish an email address rather than a postal one. Article 13(1)(a) of the GDPR requires the controller's identity and contact details; it does not require a geographical address, and an address that reaches a person is what the right depends on. If you need to write to us on paper, ask at the address above and we will give you a postal address for your request.

We are not required to appoint a Data Protection Officer and have not appointed one. Privacy questions go to the address above and are handled by the controller personally.

2. What this policy covers, and why it matters here

To prepare a travel authorisation we necessarily handle passport data and identity documents. We treat that as sensitive whether or not the law formally classifies it that way, because the consequences of losing it are serious for you and not reversible.

This policy tells you exactly what we hold, why, who else sees it, how long we keep it, and how to make us delete it.

3. What we collect

3.1 Your account

  • email address
  • a password, stored only as a cryptographic hash (PBKDF2-HMAC-SHA256) — we cannot read it and cannot tell you what it is

3.2 Traveller and passport details

For each traveller in an application:

  • name, date of birth, sex, nationality as they appear on the travel document
  • passport number, issuing state, nationality code, issue and expiry dates
  • whether the machine-readable zone was verified

3.3 Documents you upload

Passport scans and supporting documents. We store:

  • the file itself, in object storage, under an unpredictable key;
  • metadata: filename, type, size, a SHA-256 checksum, malware-scan status;
  • facts extracted from the document by automated reading, together with a confidence score.

Document files are never stored in our database and are never placed in our source code repository.

3.4 Trips and applications

Destinations, dates, purpose of travel, your answers to the application questions, the status of each application, and the checks we ran.

3.5 Payments

Handled by Stripe. We never see or store your card number. We keep the Stripe payment reference, the amount, the currency and the status.

3.6 Support

Messages you send us and our replies, and the time spent, so we can measure whether the service is sustainable.

3.7 Usage

Pages viewed and steps completed, so we can see where people get stuck. Server logs including IP address, kept for security purposes.

Questions asked of our assistant are stripped of identifying details and grouped. A group is only ever analysed once enough separate people have asked something similar that no individual can be picked out of it.

Please do not type sensitive personal details into the assistant — in particular anything about criminal convictions or offences, health conditions, religion or political views. We do not need them to prepare your application, we do not ask for them, and we delete them if you send them anyway. Data about criminal convictions is subject to Article 10 of the GDPR and we are not permitted to process it in the ordinary course of this service. If a destination's form genuinely requires such information, we will collect it separately, tell you why, and — where the law requires it — ask for your explicit consent first.

4. Why we use it, and on what legal basis

What forLegal basis (GDPR Article 6)
Preparing, checking and — where permitted — lodging your applicationPerformance of a contract, Art. 6(1)(b)
Creating and running your accountContract, Art. 6(1)(b)
Taking paymentContract, Art. 6(1)(b)
Keeping accounting and tax recordsLegal obligation, Art. 6(1)(c)
Security, fraud prevention, abuse detection, audit loggingLegitimate interests, Art. 6(1)(f)
Fixing faults and improving the service using aggregated usage dataLegitimate interests, Art. 6(1)(f)
Defending or bringing a legal claimLegitimate interests, Art. 6(1)(f)
Optional emails about the service that are not required for your applicationConsent, Art. 6(1)(a) — withdrawable at any time

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and limited what we do accordingly — for example usage analysis is aggregated, and audit logs record actions rather than document content.

4.1 Travellers who are not the account holder

When someone applies on behalf of another traveller, we receive that traveller's data from the account holder, not from them. Consent given by the account holder is not the traveller's consent, so we do not rely on it as our legal basis. For the traveller's own data we rely on our legitimate interest in providing the service the account holder asked for (Article 6(1)(f)); we have weighed that against the traveller's rights and collect only what the authority requires.

As Article 14 requires, we make this notice available to every traveller in an application and, where we hold an email address for them, we send it to them directly. Any traveller may exercise every right in section 7 in their own name — including erasure — whether or not they hold an account, by writing to [email protected].

4.2 Passport data and special categories

A passport can reveal information — such as place of birth or nationality — from which a person's ethnic origin might be inferred, and it contains a photograph.

Our position is that we do not process special category data under Article 9: we read the machine-readable zone and document fields to complete an application, and we do not perform facial recognition or any biometric matching, so the photograph is not processed for the purpose of uniquely identifying you.

This position follows the definition in Article 4(14): a photograph becomes biometric data only through "specific technical processing" that allows unique identification, and Recital 51 says the same. We do no such processing.

The position is stated so you can disagree with it. If you believe your passport data should be treated as special category data in your case, write to [email protected] and we will explain what we hold and why, or delete it.

During the free beta the question is theoretical: we do not accept passport scans or any document upload. Those parts of the service are switched off, and this section describes how they will work when they open.

Where a specific authority requires a document that does contain special category data, we will ask for your explicit consent under Article 9(2)(a) before collecting it, and we will say what it is for.

5. Who else sees your data

We do not sell your data. We do not share it for anyone else's marketing. Ever.

We use a small number of processors, chosen deliberately so that as much as possible stays with one provider in the EU:

ProcessorWhat they doWhere
UpCloud LtdHosting, database, document storage, backupsFinland (EU)
CloudflareDNS, TLS termination, protection against attacksEU edge; US company
StripePayment processingEU/US

Cloudflare terminates TLS, which means encrypted traffic passes through it; that is why it is listed as a processor rather than a mere network provider.

We also disclose data where we are legally required to — for example a valid order from a court or a regulator.

We do not transmit your data to any immigration authority except as part of an application you have asked us to prepare, and, for products where submission on your behalf is permitted, to lodge.

5.1 Transfers outside the EEA

Hosting, the database and your documents remain in the EU. Stripe, and in some circumstances Cloudflare, may process data outside the EEA. Where that happens it is covered by the European Commission's Standard Contractual Clauses and the safeguards in those providers' data processing agreements. You may ask us for details.

6. How long we keep things

These periods are decided and enforced by an automatic job, not by anyone remembering. "We keep it until you ask us to delete it" is not an acceptable answer for passport scans.
DataProposed retention
Uploaded documents (passport scans and supporting files)90 days after the application reaches a final state, then deleted automatically. You may ask us to keep a specific document for reuse on a future trip; we then hold it for 12 months from the day you asked, and you can cancel that at any time
Traveller and passport details12 months after your last activity, then deleted
Application records and the checks we ran12 months after your last activity
Payment and invoice records6 years, because Irish tax law requires it. These contain the amount, the currency and the payment reference — not your documents. If you delete your account before then, we keep only these figures and remove every link to you: no name, no email, no account, no application
Audit log of actions taken on your data12 months
Server logs including IP address30 days
Aggregated, anonymised usage statisticsIndefinitely — these are no longer personal data
Questions asked of the assistant30 days in identifiable form; the anonymised, grouped version is kept
AccountUntil you delete it

"Last activity" means creating or changing an application — not simply signing in or opening an email. We say so because a definition that counted any visit would make the period effectively endless for anyone who keeps an account open, which would defeat the point of having one.

When you delete your account we delete the underlying records and the stored files, and we keep one anonymised marker recording that a deletion happened, so that we can demonstrate we honoured it.

7. Your rights

Under the GDPR you may:

  • get a copy of your data — the records we hold are downloadable from your account at any time. The uploaded files themselves are not in that download; ask us at [email protected] and we will send them within one month, usually within two working days;
  • correct anything inaccurate;
  • have it erased — available immediately in your account. This deletes the database records *and* the stored files, and requires your password;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, where we relied on consent.

We answer requests within one month. We do not charge for this.

If you are unhappy with how we handle your data you may complain to the Irish Data Protection Commission (dataprotection.ie), or to the supervisory authority in the EU country where you live.

8. Security

  • Everything travels over TLS. Documents are stored under unpredictable keys and are never publicly readable; the application checks your authorisation before issuing a short-lived link.
  • The database and object storage are reachable only over a private network and are not exposed to the internet.
  • Passwords are hashed, never stored or logged in readable form.
  • Every action taken on personal data is written to an audit log.
  • Uploaded files are checked for type and size, fingerprinted with SHA-256, and stored apart from the application that serves them. We do not currently run a third-party antivirus engine over uploads, and we do not claim to. During the free beta the question does not arise: we do not accept document or passport uploads at all, and those parts of the service are switched off.

No system is perfect. If a breach is likely to result in a high risk to you we will tell you directly, and we will notify the Data Protection Commission within 72 hours as the law requires.

9. Automated decision-making

We use automated processing to read your documents and to check your application for inconsistencies.

This does not produce a legal or similarly significant decision about you under Article 22. It produces a draft and a list of things to check, which a person can review. Whether you receive a travel authorisation is decided by a government authority, not by us and not by our software.

Our system is built so that a language model never determines an immigration requirement. Requirements come from rules recorded from official sources with the source, URL and verification date. This is enforced in code, not merely promised here.

10. Cookies

We use only what is necessary to make the service work — keeping you signed in, and protecting against attacks. These do not require your consent under the ePrivacy rules.

We do not use advertising or cross-site tracking cookies. If that ever changes we will ask for your consent first, through a banner that lets you refuse as easily as accept.

11. Children

This service is for adults. We do not knowingly create accounts for anyone under

  1. An adult may include a child as a traveller in an application, and by doing

so confirms they have parental responsibility or the guardian's consent.

12. Changes

We will post any change here and update the date at the top. If a change is significant we will tell account holders by email before it takes effect.

EntryNova shows entry requirements from verified official sources and helps you prepare your application. We are not a government authority and have no affiliation with any government. We are not a law firm and do not give legal advice, and we never predict whether an authority will approve an application.

TermsPrivacyRefundsEarly access