Privacy notice

How Viarify Ltd handles your personal data when you apply for a US ESTA through Viarify.

Last updated: this is a draft for review

Who is responsible for your data

Viarify Ltd (PLACEHOLDER — registered address, United Kingdom) is the data controller for the personal data described here. Contact us about anything on this page at support@viarify.com.

What we collect

  • Identity data: full name, date of birth, place and country of birth, nationality.
  • Passport data: document number, issue and expiry dates, issuing country.
  • Contact data: email address, phone number, home address.
  • Travel data: arrival and departure dates, US address, contact in the US.
  • Eligibility answers: responses to the standard ESTA health, criminal history and travel history questions. Some of these are special category data concerning health or alleged offences.
  • Document images and biometric data: a photograph of your passport page and a selfie, used to confirm the document is genuine and matches you. The face comparison creates biometric data.
  • Payment data: transaction reference and status. We never see or store card numbers.

Why we can process it (lawful basis)

Ordinary personal data is processed to perform our contract with you and, for security and fraud prevention, on the basis of our legitimate interests. Special category data — your health-related and criminal-offence answers, and the biometric face comparison — is processed on the basis of your explicit consent, given when you submit your application. You can withdraw that consent at any time, though we cannot file or continue an application without it.

Who we share it with

  • Didit — our identity verification provider. Didit receives your passport image and selfie and performs document authenticity, liveness and face-match checks, returning the result to us. Didit acts as our processor.
  • U.S. Customs and Border Protection — we submit the application data you give us to the official ESTA system on your behalf. Their handling of that data is governed by U.S. law, not by us.
  • Our payment provider — processes your payment and holds card details directly.
  • Our hosting and email providers — store the encrypted records and send you status updates.

Submitting an ESTA necessarily transfers your data to the United States. Where our providers process data outside the UK, we rely on the appropriate safeguards permitted by UK GDPR, such as International Data Transfer Agreements.

How long we keep it

Passport images and selfies are deleted once verification is complete and the application has been filed and decided — normally within 30 days, and no later than 90 days. Application records and proof of the service we provided are retained for 6 years to meet UK accounting and legal obligations, then deleted. PLACEHOLDER: confirm these retention periods before launch.

How we protect it

Data is encrypted in transit and at rest. Document images are held in private storage that is not publicly addressable; access requires an authenticated staff account with an explicit administrator role, and every access is logged.

Your rights

You can ask for a copy of your data, correction, erasure, restriction, portability, or to object to processing, and you can withdraw consent for the biometric and special category processing. Email support@viarify.com and we will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies

We use only the storage strictly necessary to keep your application progress and your signed-in session working. We do not run advertising trackers.