This Privacy Policy describes how Vistus handles personal data, documents, financial information, technical records, and user-submitted content in connection with the platform.
The platform may receive sensitive data and high-impact documents. Vistus therefore follows minimization, security, access limitation, and transparency as operating principles without promising absolute protection from every possible risk.
By using the platform, you acknowledge that you must have authorization and a legitimate basis to submit your own or third-party data, and that you remain responsible for the lawfulness, accuracy, and suitability of submitted content.
Data controller and data-protection contact
Vistus acts as controller of personal data processed on the platform. Because it is a digital-only service, Vistus does not provide in-person service; contact with the operator and data-protection contact is handled electronically.
Requests concerning personal data and the exercise of rights may be sent to support@vistus.app. The operator's tax and registration details appear on receipts and invoices issued by the payment provider.
Data we may collect
We may collect data supplied directly by users, data generated while the platform is used, and data received from technical providers needed for authentication, payment, security, support, analysis, and operations.
Collection varies based on features used, account settings, documents submitted, purchases made, enabled integrations, and support communications.
- Registration data such as name, email, country, language, protected password, and preferences.
- Account, team, permission, invitation, session, device, and authentication data.
- Documents, text, evidence, files, images, metadata, and analysis results.
- Financial data, receipts, payment status, credits, coupons, packages, and transaction history.
- Technical logs, IP address, browser, operating system, security events, errors, and usage metrics.
- Support communications, feedback, legal requests, and privacy preferences.
Sensitive documents and data
Immigration documents may contain passports, identifiers, professional history, family information, financial data, academic evidence, government records, health information, national origin, minors' data, or other sensitive information.
You decide which documents to submit and should avoid attaching unnecessary data. When third-party data is submitted, you represent that you have authorization or another legitimate basis for submission and processing within the platform.
Financial data and payments
Payments, credits, access levels, coupons, packages, and charges may be processed by third-party providers. Vistus may receive transaction identifiers, statuses, receipts, amounts, currency, the last digits of a card when provided, tax data, and fraud-prevention metadata.
Vistus need not store full card numbers. Financial data may be used for billing, reconciliation, fraud prevention, support, accounting, auditing, legal compliance, and defense of rights.
Purposes of processing
We process data to operate the platform, authenticate users, process documents, generate analyses, display results, enable payments, provide support, maintain security, improve quality, meet legal obligations, and protect rights.
We may also use aggregated, anonymized, or statistical data for metrics, diagnostics, product planning, abuse prevention, and operational improvement, provided it does not reasonably identify a user directly.
- Create and manage accounts, sessions, permissions, and preferences.
- Receive, store, process, and audit submitted documents.
- Generate scores, metrics, comparisons, reports, suggestions, and history.
- Process purchases, credits, access levels, coupons, refunds, and charges.
- Detect abuse, fraud, unauthorized access, malicious prompts, and Terms violations.
- Respond to support, privacy, security, government, and dispute requests.
Legal bases
Where data-protection law requires a specific legal basis, Vistus may process data based on contract performance, consent, compliance with a legal obligation, legitimate interests, the exercise of legal rights, fraud prevention, security, or another basis recognized by applicable law.
The specific basis may vary by country, data type, user relationship, feature used, and processing purpose. Where consent is required, you may withdraw it through available means without affecting processing already performed lawfully.
Data sharing
We may share data with providers of hosting, databases, storage, authentication, payments, communications, support, monitoring, security, artificial intelligence, analytics, and professional services needed to operate the platform.
We may also share information in connection with a corporate reorganization, acquisition, merger, financing, audit, defense of rights, fraud prevention, legal compliance, or where a user authorizes or requests it.
Use of artificial intelligence
Vistus may process documents and text through automation and artificial-intelligence systems to generate analyses, summaries, scores, comparisons, and suggestions. User content is treated as audit input, not as authoritative instructions controlling the platform.
Vistus does not use user-submitted documents to train third-party foundation models unless there is specific authorization, an express setting, or a contractual basis clearly disclosed in another applicable document.
Government authorities and legal requirements
Vistus may preserve, access, restrict, or disclose data when it reasonably and in good faith believes this is necessary to comply with law, a valid order, a legitimate request from a competent authority, a judicial or administrative proceeding, defense of rights, platform security, or fraud prevention.
Where permitted and feasible, we will seek to limit disclosure to what is necessary. This Policy creates no duty to conceal data, resist an authority, indemnify a user, or assume responsibility for legal consequences arising from a user's content, conduct, or decisions.
International data transfers
The platform and its providers may operate in different countries. Data may be processed or stored outside a user's country of residence and be subject to different laws and protection standards.
Where required by applicable law, Vistus will use reasonable mechanisms to protect international transfers, such as contracts, technical controls, vendor assessments, and security measures appropriate to the nature of the data.
Retention and deletion
We retain data for as long as needed to fulfill the purposes described in this Policy, meet legal obligations, prevent fraud, maintain security, conduct audits, provide support, bill users, exercise rights, and preserve records related to platform use.
You may delete documents or request data deletion through available features. Some records may remain where needed to comply with law, resolve disputes, preserve transaction history, maintain audit integrity, prevent abuse, or defend rights.
Information security
We use reasonable technical and organizational measures to protect data against unauthorized access, loss, alteration, improper disclosure, and abuse. These may include encryption, access controls, authentication, monitoring, logs, and privilege restrictions.
Even so, no digital environment is 100% secure. You should protect passwords, devices, email, sessions, access links, and downloaded documents. Relevant incidents will be handled according to applicable legal obligations and risk assessments.
User rights and choices
Depending on applicable law, you may have rights to access, correct, delete, or port data; object to or restrict processing; withdraw consent; request review of automated decisions; or receive information about sharing.
Requests will be evaluated based on the requester's identity, the nature of the data, legal obligations, security, third-party rights, fraud prevention, and technical feasibility. We may refuse, limit, or delay requests where permitted by law.
If you believe processing violates applicable law, you may lodge a complaint with the competent data-protection authority in your jurisdiction.
Minors
The platform is not intended for independent use by minors. Minors' data may appear in immigration, family, or dependent documents only when submitted by an authorized user for a legitimate purpose.
Anyone submitting a minor's data represents that they have appropriate authorization and accepts responsibility for the lawfulness, necessity, and proportionality of the submission.
User responsibility for submitted data
You are responsible for reviewing content before upload, removing unnecessary data, obtaining authorizations, respecting professional confidentiality, complying with contracts, and ensuring that you do not violate privacy, secrecy, intellectual property, or third-party rights.
Vistus assumes no responsibility for data submitted without authorization, false documents, excessive information, unlawful content, user violations, or consequences of decisions made based on platform results.
Changes to this Policy
We may update this Policy to reflect changes in the product, security, law, vendors, data practices, or operations. The current version will be published on this page with its effective date.
Where required by law or where a change is material, we may provide additional notice. Continued use of the platform after an update indicates awareness of the current version.
Privacy contact
Requests about privacy, personal data, security, or the exercise of rights may be sent to support@vistus.app. For operational support, use support@vistus.app.