Last updated 13 May 2026. This is a service that handles sensitive immigration data. Treat the encryption claim as a feature, not a slogan.
MigrationProvision B.V. (in registration), Bezuidenhoutseweg 30, 2594 AV The Hague — privacy@migrationprovision.com. We are the data controller for all personal data processed through the platform.
Special categories of data (Art. 9 GDPR — e.g. data revealing race, ethnicity, health status that may appear in immigration files) are processed where strictly necessary for the substantial public interest of access to justice (Art. 9(2)(g) GDPR, UAVG Art. 23(e)).
All personally identifying fields are encrypted at rest with AES-256-GCM using per-record envelope keys. The master key is stored in a hardware-protected key vault separate from the application database. Uploaded documents are encrypted with the same scheme. TLS 1.3 in transit, HSTS preload, certificate pinning at the API layer.
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Mollie B.V. | Payment processing | NL | PSD2-licensed, GDPR-compliant DPA |
| Hetzner Online GmbH | Application hosting | DE / FI (EU) | DPA, ISO 27001 |
| Postmark (ActiveCampaign) | Transactional email | EU region | SCCs, DPA |
| PostNL | Registered-mail handling (opt-in only) | NL | DPA, addresses only |
| Plausible Analytics | Privacy-friendly analytics | EU | No cookies, no personal data |
No data is transferred outside the EU/EEA except where you explicitly initiate a submission to the OHCHR (Geneva, Switzerland — an Art. 45 GDPR adequate-protection jurisdiction).
Under GDPR Articles 15–22 you have the right to access, rectification, erasure, restriction, portability and objection. Most rights can be exercised directly from Account → Privacy in the portal; otherwise write to privacy@migrationprovision.com. Response within 30 days.
You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch DPA) — autoriteitpersoonsgegevens.nl.
We use one strictly necessary cookie for the login session. No third-party analytics or advertising cookies are set. Plausible Analytics runs cookieless. A cookie banner is therefore unnecessary; if regulatory practice changes, we will add one.
The service is not directed at children under 16. Where a minor's immigration case is the subject, the account is held by a parent or legal guardian.
Material changes notified at least 14 days in advance by email and portal banner. Version history available on request.