ETA·Service

Privacy Policy ETA-Service

How we process and protect personal data

Sovereign Solutions VOF
Trading as ETA-Service
Apollolaan 88 C, 6411 BD Heerlen, The Netherlands
Dutch Chamber of Commerce (KvK) 42011689 | Establishment number 000065152379
info@eta-service.com | https://eta-service.com/

1. Who is responsible?

Sovereign Solutions VOF, trading as ETA-Service, is the controller for the personal data processed through the website and services.

2. What personal data do we process?

  • Identity and passport data, such as name, date of birth, nationality, passport number, date of issue, expiry date, and issuing authority.
  • A passport scan, passport photo, and facial image when these are needed for the ETA application.
  • Contact details, such as address, email address, and phone number.
  • Travel and application data, answers to eligibility questions, and information about previous immigration or criminal circumstances when the application requires it.
  • Order, payment, and invoice data. ETA-Service normally does not receive full payment card details when a payment provider processes the payment.
  • Technical data, such as IP address, device, browser, log data, cookie preferences, and security information.
  • Communications, complaints, and information you provide to us yourself.

3. Why do we process this data?

  • To process and check your identity and application data and to submit it on your behalf to the competent UK government authority.
  • To perform the agreement, process payments, and inform you about the progress or outcome.
  • To handle questions, corrections, withdrawals, complaints, and possible disputes.
  • To prevent and investigate fraud, abuse, and security incidents.
  • To comply with tax, administrative, and other legal obligations.
  • To analyze and improve the website and services, to the extent that this is done with consent or has only a minor privacy impact.
  • To send marketing when you have given consent for it or when this is permitted by law on another basis. You can unsubscribe at any time.

4. Legal bases

We process personal data when this is necessary for performing the agreement or steps prior to the agreement, to comply with a legal obligation, on the basis of a legitimate interest, or with your consent. A legitimate interest may include security, fraud prevention, business operations, and improving our services. We weigh this interest against your privacy interest.

5. Data of other travelers and minors

If you apply for an ETA on behalf of another person, you must be authorized to provide their data and must inform that person about this privacy policy. For minors, the legal representative provides the data or gives consent for the application.

6. Who do we share data with?

We only share data that is necessary with the competent UK government authority and with service providers that support us, such as hosting, security, email, form, payment, administration, analytics, and customer service providers. These parties only receive data for their task. Where necessary, we enter into data processing agreements.

7. Transfers outside the EEA

For the ETA application, we transfer personal data to the competent authorities in the United Kingdom. At the time of this version, the United Kingdom has an adequacy decision from the European Commission. If another recipient outside the European Economic Area is not covered by a valid adequacy decision, we provide another legally permitted safeguard, such as standard contractual clauses.

8. Retention periods

  • Application and identity documents: no longer than necessary for the application, aftercare, security, and handling questions or disputes. We delete or anonymize this data as soon as reasonably possible after the purpose has ended.
  • Agreement, invoice, and payment records: in principle seven years where the tax retention obligation applies.
  • Customer service and complaints: for as long as needed for handling and afterwards for as long as a legal claim may reasonably arise.
  • Technical log and security data: as short as possible, depending on the security purpose.
  • Marketing data: until you withdraw your consent or object, unless we no longer need the data before then.

9. Security

We take appropriate technical and organizational measures. These include encrypted connections, access restrictions, strong authentication, logging, updates, backups, and agreements with service providers. No method offers complete certainty. We limit access to staff and parties that need the data.

10. Your rights

  • Access to your personal data.
  • Correction of inaccurate or incomplete data.
  • Deletion or restriction of processing where the law allows it.
  • Transfer of data based on consent or an agreement.
  • Objection to processing based on a legitimate interest and to direct marketing.
  • Withdrawal of consent. This does not affect processing that was lawful before the withdrawal.

Send your request to info@eta-service.com. We may ask for additional information to verify your identity. In principle, we respond within one month. You can also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

11. Automated decision-making

ETA-Service does not make decisions with legal effects based solely on automated processing. The competent UK government authority may use its own automated systems. ETA-Service does not determine that processing.

12. Cookies

Information about cookies and similar techniques is in the cookie policy. You can change your preferences through the cookie settings.

13. Changes

We may amend this privacy policy when the services, suppliers, or legislation change. The latest version is on the website. We communicate important changes when this is reasonably necessary.