Your data — including sensitive identity, financial and family information — is only ever collected, stored and shared to move your application forward. We ask for your permission before sharing it, encrypt everything sensitive, and protect it in line with applicable data-protection law.
01Who we are
GoldenVisaX (“GoldenVisaX”, “we”, “us”, “our”) is operated by Ajax Software LLC, of Ankerköz 2-4, Budapest 1061, Hungary, registered in Hungary under company registration number 01-09-966462 (EUID HUOCCSZ.0109966462). The GoldenVisaX platform is a secure service for creating, submitting, managing and tracking Citizenship by Investment (CBI) and Golden Visa / residence-by-investment applications across the programmes we support.
For the purposes of the EU General Data Protection Regulation (GDPR) and other applicable laws, Ajax Software LLC, trading as GoldenVisaX, is the data controller for the personal data described in this policy. Our contact details are in section 17.
02Scope and platforms
This policy applies to all personal data we process through:
- our website at goldenvisax.com, including the application wizard and your client dashboard;
- our Android app (distributed via Google Play); and
- our iOS app (distributed via the Apple App Store).
We collect the same categories of data across all three, and the data you enter is synced to the single case file tied to your account, so you can continue on any device.
03The data we collect
We collect the information you provide as you move through the application wizard, plus a limited amount of technical data. We only ask for what a given programme actually needs.
a. Information you give us
| Category | Examples (from the wizard steps) |
|---|---|
| Account & contact | Email address (verified by one-time code) and mobile phone number (verified by SMS). |
| Identity & personal details | First and last name, date of birth, country of residence, passport nationality, and long-term permanent-residence status. |
| Eligibility & financial profile | Investment budget, application goal, source of funds, and your declarations about any criminal record, sanctions exposure and politically-exposed-person (PEP) status, used for eligibility and the due-diligence / risk screening the programmes require; and your chosen investment option (donation, real estate or bonds). |
| Family & dependants | Details of any spouse, children or parents you add to the application — their name, date of birth and nationality — so we can price and screen them for the programme. |
| Identity documents | Your passport photo page; an identity selfie you take in the app so your case officer can confirm you match your passport; and the supporting documents you upload to your encrypted vault — bank statements, source-of-funds evidence, police certificate, CV, tax return, and birth or marriage certificates where relevant. The selfie is reviewed by a person; we run no facial recognition or other biometric matching on it. |
| Payment information | Records of the reservation retainer and programme invoices. Card and bank details are entered directly with our payment providers — see section 7. |
| Communications | Messages, notes and support requests you exchange with us or your assigned agent. |
b. Information collected automatically
- Device & technical data: IP address, device and browser type, operating-system version and app version, recorded by our servers to secure your session, rate-limit sign-in attempts and prevent abuse. Our mobile apps read no device, vendor or advertising identifier — your session is a token held in the device’s own secure keystore.
- Usage data (website only): which pages and wizard steps you view on goldenvisax.com, so we can keep the service reliable. Our iOS and Android apps contain no analytics, attribution or crash-reporting SDK and send us no usage or diagnostic telemetry.
- Cookies and similar technologies — see section 15.
04Mobile app permissions
Our Android and iOS apps request certain device permissions only when you use the feature that needs them, and only with your consent. You can decline or later revoke any of these in your device settings; some features may then be unavailable.
- Camera — to photograph or scan your passport and supporting documents for upload to your vault.
- Photos / files / storage — to let you select existing documents to upload.
- Notifications — case updates and alerts are shown inside the app, on the Alerts tab. Our apps do not send push notifications and do not request the notification permission; verification codes reach you by email or SMS.
- Network access — required to sync your application securely with your account.
We do not access your contacts, precise location, microphone, health data, or your photo library beyond the specific files you choose to upload. Photos and documents you capture in the app are used only for your application and are not used for advertising.
05App Store and Google Play privacy disclosure
Apple and Google each require us to declare, in a fixed set of categories, what our apps collect. This section states those declarations so you can check them against the labels shown on our App Store and Google Play listings. It describes the same processing as the rest of this policy, expressed in Apple’s categories.
Nothing in our apps is used for tracking. We do not link your data to data from other companies’ apps or websites, we do not share it with data brokers, and we run no advertising. Every category below is therefore declared as “Not used to track you”, and the iOS app never presents an App Tracking Transparency prompt.
| Apple category | What it covers in our apps | Linked to you | Used to track you |
|---|---|---|---|
| Contact Info Name, email, phone | Your name, the email address you sign in with, and the mobile number verified by SMS. Also the names of any dependants you add. | Yes | No |
| Financial Info Payment info, other financial info | Card details entered in Stripe’s own payment sheet (see below), plus the financial evidence you upload — bank statements, source-of-funds proof, tax returns — and your stated investment budget. | Yes | No |
| User Content Photos, other content, customer support | Your passport image, identity selfie and uploaded documents; and the messages you exchange with your assigned agent and our support team. | Yes | No |
| Identifiers User ID | The account number that identifies your case file on our servers. No device or advertising identifier is collected. | Yes | No |
| Sensitive Info | Your nationality and citizenship, and your declarations about criminal record, sanctions exposure and politically-exposed-person (PEP) status — all of which the programmes’ mandatory due-diligence checks require. | Yes | No |
| Purchases Purchase history | Whether the refundable retainer for your case has been paid, and the invoices raised against it. | Yes | No |
| Other Data | Your date of birth and country of residence, and the dates of birth of any dependants you add. | Yes | No |
Every category above is collected for one purpose only — App Functionality: assessing which programmes you qualify for, and preparing, submitting and tracking your application. None of it is used for analytics, personalisation, advertising or marketing.
What our apps do not collect
We declare the following Apple categories as not collected, and the apps contain no code that would gather them:
- Location — no location permission is requested and no location data is read. Your country of residence is simply a field you fill in.
- Contacts — we never read your address book. Dependants are people you type in yourself.
- Health & Fitness, Browsing History, Search History.
- Usage Data and Diagnostics — the apps ship with no analytics or crash-reporting SDK, so no product-interaction or crash telemetry is sent.
- Device ID and any advertising identifier (IDFA) — never read.
Third-party components in the apps
- Stripe — card and Apple Pay details are entered in Stripe’s own payment sheet and go directly to Stripe. Full card numbers never reach our servers; we keep only the payment status. Stripe processes this under its own privacy policy.
- Sign in with Apple — returns a verified email address and, if you allow it, your name. If you use Apple’s Hide My Email, we receive only the relay address and that is what your account uses.
- Google Sign-In — returns a verified email address and name when you choose that sign-in method.
These three are the only third-party SDKs in our apps. None of them is used for advertising or tracking, and we pass them no case data beyond what the sign-in or payment itself needs.
Deleting your account from the app
Both apps let you close your account from Profile → Close account, without contacting support. Because we hold identity documents that have been submitted to government authorities, we confirm your identity before erasing records, and we retain the minimum required by anti-money-laundering law — see sections 11 and 13.
06How we use your data
- To create and secure your account and verify your email and phone number.
- To recommend the programmes you qualify for and calculate your full costs.
- To run eligibility, due-diligence and risk checks required by the programmes.
- To prepare, submit, manage and track your application and your dependants’ applications.
- To process the reservation retainer and programme payments.
- To communicate with you, provide support and send service and case updates.
- To keep the platform safe, prevent fraud and abuse, and meet our legal, regulatory and anti-money-laundering (AML/KYC) obligations.
We do not sell your personal data, and we do not use your identity or document data for advertising.
07Who we share your data with
Delivering an application means passing your information to the professionals and authorities who process it. We share your data — including the relevant sensitive data — only with your permission and only with the parties needed for your chosen programme:
- Lawyers and law firms representing and advising on your case;
- Government authorities and licensed / authorised agents of the programmes you apply to;
- Real estate developers where your investment option is a qualifying property;
- Banks and financial institutions for account opening, escrow and source-of-funds verification;
- Due-diligence and background-check firms that carry out the mandatory vetting; and
- Payment providers that securely process your card, bank-transfer or other payments.
We also use trusted service providers (for cloud hosting, encrypted storage, email and SMS delivery) who process data strictly on our instructions under confidentiality and data-processing agreements. We may disclose data where required by law or to protect our legal rights. Some of these recipients are chosen by, or specific to, the programme you select; we tell you who they are before you proceed.
Because these recipients are part of the licensed programme process, sharing with them is necessary to deliver the service you request. You can withdraw your consent at any time (section 12), though this may mean we can no longer progress your application.
08Encryption and security
Protecting your data is fundamental to how the platform is built:
- All sensitive data is encrypted. Identity documents in your vault and other sensitive fields are encrypted at rest, and all traffic between your device and our servers is encrypted in transit (TLS/HTTPS).
- Passwordless, verified access using one-time email codes and SMS verification, with session controls to protect your account.
- Access controls so that only the specific parties involved in your case, and authorised staff, can see your information on a need-to-know basis.
- Data-protection by design — we collect the minimum necessary, and we protect your data in line with applicable data-protection rules, including the GDPR.
No system can be guaranteed 100% secure, but we maintain organisational and technical safeguards appropriate to the sensitivity of the data and will notify you and the relevant authorities of a qualifying data breach as required by law.
09Legal basis for processing
Where the GDPR applies, we rely on: consent (which you can withdraw) — including your explicit consent for special-category and sensitive data and for sharing with the parties in section 7; performance of a contract to deliver the service you request; legal obligation (for example AML/KYC and record-keeping); and our legitimate interests in securing and improving the platform, balanced against your rights.
10International transfers
Citizenship and residence programmes are international by nature, so your data may be transferred to authorities, agents, developers, banks and firms located outside your country and outside the European Economic Area. Where we transfer personal data internationally, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses, or your explicit consent for a specific programme.
11How long we keep your data
We keep your data for as long as your account is active and your application is in progress, and afterwards only as long as necessary to comply with legal, regulatory, tax and anti-money-laundering record-keeping obligations, or to resolve disputes. When no longer required, data is securely deleted or anonymised.
12Your rights
Subject to applicable law, you have the right to: access your data; correct inaccurate data; delete your data (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your data-protection authority — in Hungary, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
To exercise any right, contact us using the details in section 17. We respond within the timeframe required by law.
13Deleting your account and data
You can request deletion of your account and associated personal data at any time — no sign-in required — by:
- using our account closing & data deletion request page;
- using the account-deletion option in the app or your dashboard; or
- emailing [email protected] from your registered address with the subject “Delete my data”.
We will delete your data, except where we are legally required to retain certain records (for example AML/KYC and financial records), which we will hold securely for the required period and then delete.
14Children
The platform is intended for adults (18+). We do not knowingly allow anyone under 18 to create an account. Where a child is added as a dependant on an application, their data is provided and consented to by a parent or legal guardian solely for that application.
15Cookies, SDKs and analytics
Our website uses strictly necessary cookies to keep you signed in and secure your session, and limited analytics to understand and improve how the service is used. Our apps do not use cookies, and they embed exactly three third-party components: Sign in with Apple (Apple), Google Sign-In (Google) and Stripe for card payments. There is no advertising, analytics, attribution or crash-reporting SDK in either app. We do not track you across other companies’ apps or websites, so the iOS app never asks for permission to do so. You can control cookies in your browser and notifications in your device settings.
16Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “last updated” date above and, where appropriate, notify you in the app or by email. The current version always governs.
17How to contact us
For any question about this policy or to exercise your rights, contact our data-protection team:
Data controller
GoldenVisaXc/o Ajax Software LLC
Ankerköz 2-4, Budapest 1061, Hungary
Company reg. 01-09-966462 · EUID HUOCCSZ.0109966462
Email: [email protected]