Legal

Privacy Policy

Last updated: August 7, 2026

1. Overview

This Privacy Policy explains how VizaFlow (“we,” “us,” or “our”) collects, uses, stores, and shares information when you visit our website, request a demo, or use the VizaFlow platform (the “Service”).

VizaFlow is built for education consultancies and visa processing teams. Depending on how you interact with us, we may act as a controller of account and marketing data, and as a processor of Customer Data that organizations store in the Service.

2. Information we collect

Information you provide

  • Contact and account details such as name, work email, company name, role, and phone number
  • Demo or support requests and the content of your messages
  • Billing and subscription details needed to manage your plan
  • Customer Data your organization uploads or generates in the Service (for example student, lead, applicant, visa, and staff records)

Information collected automatically

  • Device and log data such as IP address, browser type, pages viewed, and timestamps
  • Usage data about how features are used within the Service
  • Cookies and similar technologies used for session management, preferences, and analytics

3. How we use information

We use information to:

  • Provide, operate, secure, and improve the Service
  • Create and manage accounts, organizations, branches, and entitlements
  • Respond to demos, sales inquiries, and support requests
  • Process subscriptions, invoices, and related communications
  • Monitor performance, prevent abuse, and troubleshoot issues
  • Comply with legal obligations and enforce our Terms of Service
  • Send product or service communications; marketing messages only where permitted

4. Customer Data and your organization

Organizations that use VizaFlow control the Customer Data they store, including personal data about students, applicants, counselors, and other contacts. Organization administrators decide who can access that data within their tenant and branches.

We process Customer Data to provide the Service to the organization. We do not sell Customer Data. Organizations are responsible for ensuring they have a lawful basis to collect and process personal data in the Service, and for responding to requests from individuals whose data they control.

5. How we share information

We may share information with:

  • Service providers who help us host, secure, analyze, communicate, or bill for the Service, under contractual confidentiality and data-protection obligations
  • Professional advisors such as lawyers or accountants when needed
  • Authorities when required by law, legal process, or to protect rights, safety, and security
  • A successor entity in connection with a merger, acquisition, or asset transfer, subject to appropriate safeguards

Within an organization, users with appropriate roles may access Customer Data according to that organization’s configuration.

6. Cookies and similar technologies

We use cookies and similar technologies that are necessary for the website and Service to function (for example session and authentication cookies). We may also use analytics cookies to understand usage and improve the product. You can control cookies through your browser settings; disabling some cookies may affect functionality.

7. Data retention

We retain account, billing, and support information for as long as needed to provide the Service and meet legal, accounting, or dispute-resolution requirements. Customer Data is retained while the organization’s subscription is active and for a reasonable period afterward, unless a longer retention period is required by law or agreed with the organization. Organizations may request export or deletion of Customer Data subject to technical and legal limits.

8. Security

We use administrative, technical, and organizational measures designed to protect information, including access controls and encryption in transit where appropriate. No method of transmission or storage is completely secure. Please protect your credentials and notify us promptly of suspected unauthorized access.

9. International transfers

Information may be processed in Nepal and in other countries where we or our service providers operate. Where required, we take steps intended to provide appropriate safeguards for cross-border transfers.

10. Your choices and rights

Depending on applicable law, you may have rights to access, correct, update, delete, or restrict certain personal information, or to object to certain processing. For Customer Data held in an organization’s VizaFlow account, please contact that organization first. For information we control directly (such as demo inquiries or website analytics identifiers), contact us using the details below.

You may unsubscribe from marketing emails using the link in those messages. Transactional and service messages may still be sent as needed to operate your account.

11. Children’s privacy

The Service is intended for business use by consultancies and their staff. We do not knowingly market the Service to children. Organizations that store information about minors are responsible for doing so lawfully and with appropriate safeguards.

12. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be highlighted on this page or communicated through the Service or email when appropriate.

13. Contact

For privacy questions or requests, reach us through our contact page. Related contractual terms are in our Terms of Service.