Your information, handled with care

Privacy & Data Protection at Indus Emissary

Indus Emissary supports candidates through complex international study, travel, training and relocation journeys. We understand that visa applications require sensitive personal documents. This notice explains what information we collect, why we use it, how we protect it, who may receive it, how long we keep it, and the choices available to you.

Secure document portal Role-based staff access Clear consent choices Transparent case records

General information, not legal advice

This page provides general privacy information about how Indus Emissary handles personal data. It does not replace formal legal advice. Visa, immigration and data protection rules differ by country and change over time — speak with a qualified adviser for advice on your specific situation.

1. Who we are

Indus Emissary is the trading name under which these services are provided. Website: https://indusemissary.com. General contact: hello@indusemissary.com.

Depending on the service, the relevant Indus Emissary operating entity or Xharvoc Ltd. may act as the controller of your personal data. The applicable controller and its contact details will be identified in the service agreement, the application flow, or the privacy notice presented to you.

Trading name
Indus Emissary
Legal operating entity
Xharvoc Ltd. (final legal entity for a given service is confirmed in your service agreement)
UK company information
Registered in England & Wales · Company number 16590285
Registered office
71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
EU operational presence
We work with colleagues and partners in the European Union and Germany. This is an operational presence for coordination and delivery only, and should not be treated as the legal controller address unless it is formally confirmed to you in writing.
Data protection contact
hello@indusemissary.com

We have not appointed a statutory Data Protection Officer unless and until this is required. For privacy requests, contact hello@indusemissary.com.

2. Scope of this notice

This notice applies to:

  • Website visitors
  • People who use our enquiry and consultation forms
  • Candidate account holders
  • Applicants using the candidate portal
  • German language academy learners
  • Partners, consultants, host families, employers and institutional partners, where applicable
  • Anyone who contacts us by email, messaging or social channels

It does not govern third-party websites, embassies, consulates, universities, language schools, host families, employers, payment providers or government authorities. Each of those organisations has its own privacy practices, and we encourage you to read them.

3. Personal data we collect

CategoryExamplesWhy it may be needed
Identity and profile data
  • Full name
  • Date of birth
  • Nationality
  • Passport or national ID details
  • Photograph
  • Gender, only where a visa application or placement requires it
  • Immigration or residency status where relevant
To identify you correctly on an application and complete official forms exactly as authorities require.
Contact and account data
  • Email address
  • Phone number
  • Postal address
  • Login credentials
  • Account and communication preferences
To create and secure your portal account and to contact you about your case.
Eligibility and application data
  • Education history and CV
  • Employment history and qualifications
  • Professional registration
  • Language level and certificates
  • Visa history and travel plans
  • Family status where relevant to eligibility
  • Motivation letters and application answers
To assess preliminary eligibility and prepare a complete, accurate application file.
Sensitive case documents
  • Passport scans
  • Academic transcripts
  • Police clearance certificates
  • Financial evidence and bank statements
  • Health-insurance documents
  • Employment or placement contracts
  • Embassy forms
  • Medical or disability information, only where you voluntarily provide it and it is relevant
Because consulates, universities, host organisations and employers require these documents to process a case.
Communications data
  • Contact-form entries
  • Emails and support requests
  • Portal messages
  • Notes you submit
  • Consultation notes where lawfully recorded
To answer your questions, keep an accurate case record and hand over correctly between consultants.
Technical and usage data
  • IP address
  • Device and browser data
  • Security and login activity logs
  • Form submission records
  • Cookie preferences
  • Website analytics data, subject to consent where required
To keep the portal secure, prevent abuse and understand how the website is used.
Payment and transaction data
  • Invoice information
  • Payment status
  • Transaction reference
To issue invoices and keep service records. Card details are processed directly by payment providers, not stored by us.

Only upload what is asked for

Please upload only the documents requested through your application checklist or by an authorised consultant. Do not send unrelated sensitive information — if we do not need it, we do not want to hold it.

4. How we use personal data

Under the GDPR and UK GDPR we must have a lawful basis for each purpose. Consent is not the basis for all processing — most of what we do is necessary to deliver the service you asked for.

PurposeLawful basis
Responding to enquiries and consultation requestsLegitimate interests; steps before entering a contract
Creating and managing candidate accountsContract performance
Assessing preliminary eligibilitySteps before entering a contract; contract performance
Delivering consultancy, language, document-review and application-support servicesContract performance
Preparing checklists, forms and case filesContract performance
Communicating application progress and document issuesContract performance
Coordinating with authorised third parties where instructed or necessary for the agreed serviceContract performance; your instructions or consent where required
Managing German language course enrolment and progressContract performance
Processing payments, invoices and service recordsContract performance; legal obligation
Fraud prevention, security, abuse prevention and account protectionLegitimate interests; legal obligation
Compliance with legal, accounting, tax and regulatory dutiesLegal obligation
Service improvement and operational analyticsLegitimate interests; consent where required
Marketing communicationsConsent, or where otherwise permitted by applicable law
Acting in a rare emergency affecting someone's life or safetyVital interests

Legitimate interests

Where we rely on legitimate interests — security, service management, fraud prevention, improving our operations and responding to enquiries — we balance those interests against your rights and freedoms, and you may object at any time.

India DPDP framework

Where India's Digital Personal Data Protection Act, 2023 applies, we process personal data for lawful purposes, with notice and consent where required, or on another permitted lawful basis or legitimate use where applicable. Consent is requested through a clear affirmative action — never a pre-ticked box.

You can withdraw consent at any time. Where processing is necessary to provide or continue a requested service, to meet a legal obligation, or to establish or defend legal claims, withdrawal may mean we can no longer deliver part or all of that service. Withdrawal does not affect processing already lawfully carried out before the withdrawal took effect.

5. Special category / sensitive data

Sensitive documents are handled on a need-to-know basis

Visa and immigration processes can require documents containing particularly sensitive information. We request and use only what is reasonably necessary for the relevant service and case.
  • Access is restricted to authorised staff, your assigned partner or consultant, and authorised third parties where a case requires it.
  • Please do not upload medical, biometric, criminal-record, financial or other highly sensitive information unless it is requested through the portal or by an authorised consultant for a legitimate application need.
  • Sensitive data may be processed where necessary for the service, with explicit consent where required, to meet legal obligations, to establish, exercise or defend legal claims, or on other valid grounds under applicable law.
  • We cannot promise absolute security, and we cannot promise that no third party will ever access data — authorities and institutions require documents as part of an application.

6. Who we share data with

Depending on your case, categories of recipients may include:

  • Indus Emissary employees, consultants and authorised partners with a case-related need to know
  • Xharvoc Ltd. and relevant affiliated operational entities, where needed to operate the service
  • Educational institutions, language schools, Erasmus partners, host families, employers, placement organisations or recruitment partners, only where relevant and authorised
  • Visa application centres, embassies, consulates, immigration authorities and other government authorities where required for an application
  • Translation, document-verification, courier, insurance, banking, blocked-account, relocation and appointment-support providers where selected or needed
  • Cloud hosting, authentication, email, storage, analytics, support, payment and security service providers
  • Professional advisers, auditors, insurers and legal authorities where required
  • Any other recipient where you have given instructions or consent

What we never do

We do not sell personal data. We do not share your documents with unrelated third parties for their own marketing purposes.

Where an partner introduces a candidate, that partner may only access the information necessary to manage that candidate's case, and only where the candidate relationship, the case assignment and the applicable permissions allow it.

7. International data transfers

We may operate from, or use service providers in, the European Economic Area, the United Kingdom, India, Nepal, Bhutan, Germany, Spain, Mauritius and other countries relevant to your requested service. Data may therefore be transferred internationally when necessary for platform hosting, consultancy delivery, an educational or placement process, or visa-related coordination.

Where the GDPR or UK GDPR applies, we use appropriate transfer safeguards where required — such as an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. Transfers to authorities, institutions, employers or partners may be necessary where you ask us to support an application or placement. We do not claim that all data stays within Europe.

Ask about international transfers

8. Data retention

RecordIndicative retention period
Enquiries without a signed service agreementUp to 12 months after the last meaningful contact
Candidate account and application recordsGenerally up to 6 years after case closure, unless a longer or shorter period is required by law, a dispute, an immigration process or a client request
Financial and invoice recordsThe period required by applicable tax and accounting law
Portal messages and status historyGenerally aligned with the application file retention period
Marketing preferencesUntil consent is withdrawn or the data is no longer needed
Security and login logsA limited, proportionate security period
Language course records and certificatesAs long as needed to verify completion and provide learner support

Retention periods may vary depending on the service, jurisdiction, legal obligations, unresolved disputes, immigration requirements, or a request to preserve records.

When data is no longer needed, we delete it, anonymise it, or securely archive it in accordance with our retention procedures.

9. Security

  • A secure candidate portal with authentication and role-based access controls
  • Candidates can access only their own account data
  • Partner access limited to assigned cases; consultant and admin access based on operational role
  • Secure file storage with controlled document access
  • Status history and audit trails for case and document changes
  • Encryption in transit over HTTPS
  • Access reviews and reasonable organisational safeguards
  • Cloudflare Turnstile on public forms to prevent automated abuse
  • Monitoring for suspicious activity
  • Data minimisation and restricted staff access

No system is completely secure

We use reasonable technical and organisational measures designed to protect personal data. However, no online system, transmission or storage method can be guaranteed to be completely secure. We make no claim of 100% security, end-to-end encryption, external certification, or data-residency guarantees.

10. Cookies, analytics & Turnstile

  • Essential cookies are used for security, authentication, session management and portal functionality.
  • Optional analytics or marketing cookies are used only where the required consent has been obtained.
  • Cloudflare Turnstile may collect technical information to distinguish human users from bots and protect our forms from abuse.
  • You can change your choices at any time through cookie settings.
Cookie settings and details

11. Your GDPR / UK GDPR rights

Requests can be made by writing to hello@indusemissary.com or through the privacy request form. We may need to verify your identity before releasing or changing data, and we handle every request in accordance with applicable law.

12. Your rights under India's Digital Personal Data Protection Act, 2023

Where the DPDP Act applies, you may have the right to:

  • Request information about the personal data we process about you
  • Request correction, completion, updating or erasure of your personal data where applicable
  • Withdraw consent you previously gave
  • Nominate another person to exercise your rights in the circumstances recognised by law
  • Use our grievance-redressal mechanism
  • Complain to the Data Protection Board of India where applicable

Grievance process

  • Privacy and grievance contact: hello@indusemissary.com
  • You can also submit a request through our Privacy & Grievance Request form, which issues you a reference number.
  • We acknowledge requests and respond within the timeframe required by applicable law. We do not quote a fixed number of days until that timeframe is confirmed for your jurisdiction.
  • If you are not satisfied after using our internal grievance mechanism, you may escalate to the Data Protection Board of India where applicable.

Consent management

  • Candidates can withdraw consent and update marketing preferences from the Privacy section of the candidate portal.
  • We log the consent version, timestamp, source and purpose, and the timestamp and impact of any withdrawal.
  • Where processing is necessary to run your account or application, withdrawing it may limit or end those services.

Language accessibility

This notice is currently published in English. Our content system is built so that it can be translated later into Hindi, Nepali, Bengali and other relevant languages. We will not claim a translation exists until it is actually published.

Raise a DPDP grievance

13. Children and minors

Our services are generally intended for adults and eligible applicants. Where a service involves a minor, or a person who cannot give legally valid consent, we may require a parent, guardian or legally authorised representative to act for them. We do not knowingly collect personal data from children unless it is needed for a requested service and handled with the appropriate authorisation.

14. Automated decision-making & AI

  • We may use tools to organise information, provide preliminary guidance, automate reminders and support staff workflows.
  • Final visa, admission, employment or immigration decisions are made by the relevant authorities, institutions, employers or placement organisations — never by Indus Emissary.
  • We do not make solely automated decisions producing legal or similarly significant effects on candidates, unless we provide appropriate notice and rights where required.
  • If AI-assisted document, SOP or CV tools are introduced, we will disclose this visibly and candidates will always review generated material before it is used.

15. Changes to this notice

We may update this notice when our services, systems, legal requirements or operating entities change. Material changes will be communicated through the website, the portal, email or another appropriate channel. This version is 1.0, last updated 20 August 2026 and effective from 20 August 2026.

16. Contact & privacy requests

For any privacy question, request or grievance, write to hello@indusemissary.com or use the privacy request form. You will receive a reference number so you can track progress, and candidates can follow the status inside the candidate portal.