Privacy Policy

Last updated

DS160.io prepares and files US DS-160 visa applications. For each applicant it holds everything the form asks, including the answers about health and criminal history. It encrypts those answers, sends them to the US Department of State when the application is filed, and deletes them within 30 days of a verified request.

Who we are

DS160.io is operated by Galah Enterprises Pty Ltd (ACN 682 927 779, ABN 61 682 927 779), a company registered in New South Wales, Australia (“DS160.io”, “we”). Our postal address is 26 Knight Street, Arncliffe NSW 2205, Australia. Questions about this policy or about personal data go to privacy@ds160.io.

We have no establishment in the European Union or the United Kingdom.

Whose data this policy covers

  • Visitors: anyone who browses ds160.io.
  • Account holders: people with a DS160.io login. Some hold an individual account for their own or their family’s applications; others are staff of a business customer.
  • Business customers: visa agencies, immigration firms and similar businesses that use a business workspace to prepare applications for their clients.
  • Applicants: the people whose DS-160 is prepared on DS160.io. An applicant may be the account holder, a member of the account holder’s family, or a client of a business customer who fills in their answers through a link the business sends.

Our role

Personal dataRole of DS160.ioController
Applicant data in an individual accountControllerDS160.io
Applicant data in a business workspaceProcessor, under our Data Processing Agreement with the business customerThe business customer
Account holders’ account and billing data, including business customers’ staffControllerDS160.io
Visitors’ usage dataControllerDS160.io

Where DS160.io is a processor, under the Data Processing Agreement that forms part of our Terms of Service, the business customer decides why and how its clients’ data is used, provides its own privacy notice, and answers its clients’ requests about their data. DS160.io acts only on its instructions and helps it answer those requests. The rest of this policy describes DS160.io’s own processing as controller, and what DS160.io does as processor where that is the same.

Personal data we process

About applicants

Application content. Everything the DS-160 asks: names, date and place of birth, nationality, national identification and passport details, addresses, phone numbers, email addresses and social media identifiers; travel plans and travel history; family members; education and work history; and the answers to the security and background questions.

Special categories and criminal data. The DS-160’s security and background questions ask about health (for example communicable diseases, mental or physical disorders and drug use) and about arrests, convictions and other criminal matters. These are special categories of personal data (Article 9 GDPR) and data relating to criminal convictions and offences (Article 10 GDPR). DS160.io processes them only because the US government requires them on the DS-160, and only to complete and file the application.

Photo and documents. The visa photo and any documents uploaded for the application. The photo is checked automatically (face position, size, eyes open) on DS160.io’s own servers; it is not sent to a third party for this.

Filing records. When an application is filed on CEAC: the Application ID, the security question answer used to retrieve it, the confirmation page, and a PDF of every page CEAC showed back.

Edit history. Each change to an answer, who made it and when, so the account holder or business customer can see who changed what.

About account holders

Account data. Email address, name if given, a password hash or Google sign-in identity, language, and multi-factor authentication settings. For business customers’ staff, also their workspace, role and the workspace’s name and branding.

Payment data. When an account holder pays, Stripe or PayPal handles the card or account details. DS160.io receives only a payment reference, the amount and its status, and never sees a full card number.

Support messages. What an account holder sends us by email.

About visitors and account holders

Usage data. Pages visited, clicks, browser and device, IP address, and in-product events. See “Analytics and cookies”.

Logs. Technical records of what DS160.io’s systems did, such as errors and the steps of a filing run.

These are the legal bases for the processing DS160.io carries out as controller. For applicant data in a business workspace, the business customer determines the legal basis.

PurposeLegal basis
Providing accounts, storing application content, filing the DS-160 on CEAC and returning the confirmationPerformance of a contract with the account holder (Article 6(1)(b))
Translating free-text answers written in another language into EnglishPerformance of a contract with the account holder
Taking payment and keeping accounting recordsPerformance of a contract; legal obligation (Article 6(1)(c)) for tax records
Keeping the service secure, investigating failed filings, preventing abuseLegitimate interests (Article 6(1)(f)) in running a reliable and secure service
Service emails (activation, reminders, filing status)Performance of a contract with the account holder

Recipients

The US Department of State. Filing a DS-160 means entering the applicant’s answers on CEAC, which the US government operates. Sending them there is the service requested.

The business customer, for applicant data in its workspace. Its staff see and edit the applicant’s answers and filing records.

Our own servers. DS160.io’s database, application servers and the browser that fills in and files each DS-160 run on its own hardware, on premises at its headquarters in the United States. No hosting provider holds this data; the providers below are the only third parties that process it for DS160.io.

Service providers (sub-processors), each only for the purpose listed:

ProviderWhat it does for usData involvedLocation
Backblaze (B2)Stores photos, documents and filed-application PDFsPhotos, documents, filing recordsUnited States
Google (Gemini API)Translates free-text answers into EnglishThe text of the answer being translatedUnited States
Google (Sign-In)Lets account holders sign in with a Google accountGoogle identity and emailUnited States
Google (Analytics, Ads)Website analytics and ad conversion measurementUsage data, cookie identifiersUnited States
PostHogProduct analyticsUsage data, in-product eventsUnited States
StripeCard payments for business workspacesPayment details, workspace referenceUnited States
PayPalPayments for individual ordersPayment detailsUnited States
Amazon Web Services (SES)Sending emailRecipient email address, email contentsUnited States

A business customer can send email through its own mail server instead of ours; that server is chosen and controlled by the business customer.

DS160.io does not sell personal data, and does not share it with advertisers or recruiters. It may disclose data where the law requires it, or to a buyer of its business, which would be bound by this policy.

International transfers

DS160.io’s servers are at its headquarters in the United States, so all personal data it processes is stored and processed there. Personal data sent to DS160.io from outside the US is transferred to the US, and the GDPR and this policy continue to apply to it there.

CEAC is in the United States. Transferring an applicant’s answers there is necessary to perform the service requested (Article 49(1)(b) GDPR).

The service providers listed above are also in the United States:

  • Backblaze, Google, PostHog, Stripe and Amazon Web Services are certified under the EU-U.S. Data Privacy Framework and its UK Extension, and DS160.io relies on that certification. Their data processing terms also include the European Commission’s Standard Contractual Clauses.
  • PayPal transfers data under its Binding Corporate Rules and the Standard Contractual Clauses. When an account holder pays with PayPal, PayPal decides how it uses the payment details and is responsible for them under its own privacy statement.

Retention

  • Accounts, application content, edit history, photos, documents and filing records are kept while the account or business workspace exists. On a request to privacy@ds160.io, or on a business customer’s instruction for its workspace, DS160.io deletes them within 30 days.
  • Backups of the database, and earlier versions of stored photos, documents and PDFs, are kept for 7 days, so deleted data leaves them 7 days after deletion.
  • Diagnostic records of a failed filing run (logs, screenshots, the page being filled): deleted after 90 days.
  • Records of each filing run’s steps: deleted after 30 days.
  • Photos queued for manual review: deleted from that queue after 14 days.
  • Security codes (captchas) shown during filing: deleted after 10 minutes.
  • Sign-in sessions: a sign-in lasts 4 hours at a time. The token that renews it lasts 30 days and is deleted when it expires.
  • Payment and accounting records: kept as long as tax law requires, including after an account is deleted.

Analytics and cookies

DS160.io keeps a signed-in account holder’s session, language and a few interface preferences in the browser’s local storage. The site needs them to work.

It also uses:

  • Google Analytics and Google Ads, to measure visits and which adverts lead to sign-ups. They set cookies such as _ga and _gcl_au.
  • PostHog, to understand how the product is used. It sets a cookie beginning with ph_.

Security

All DS-160 form data is encrypted at rest with AES-256. That covers every answer on an application, including the security and background questions and passport details, the edit history of those answers, the copy of the application made each time it is filed, the CEAC Application ID and security answer, and the diagnostic records of a filing run. The encryption key is kept apart from the database and its backups, so neither can be read without it. Only the applicant’s name, year of birth, consulate and visa type stay readable, because the application lists show them.

All traffic to DS160.io travels over HTTPS. Mail server passwords, authentication keys and similar secrets are stored encrypted.

Only DS160.io’s team can reach the production systems, and every account can turn on multi-factor authentication. DS160.io staff do not open an account or an application unless the account holder, or for a business workspace the business customer, has given permission to investigate a problem. Outside that, staff see only the diagnostic records of failed filing runs, to find and fix the cause. Any change staff make during an investigation is recorded as made by DS160.io, not by the account holder.

DS160.io’s operational alerts run on its own servers, not a third-party chat service, and name accounts and applications by internal ID, never by name or email address.

Data subject rights

Under the GDPR, data subjects have the right to:

  • access their personal data and receive a copy;
  • have it corrected if it is wrong (account holders can edit most of it themselves);
  • have it deleted;
  • restrict or object to its processing;
  • receive it in a portable, machine-readable format.

Requests about data DS160.io controls go to privacy@ds160.io, from the email address on the account where there is one, and are answered within one month. Applicants whose application was prepared by a business customer should send their request to that business, which is the controller; DS160.io helps it answer.

Once a DS-160 is filed, the copy held by the US Department of State is outside DS160.io’s control. Deleting data at DS160.io does not delete it from CEAC.

Data subjects also have the right to complain to a data protection authority, in particular the one where they live or work.

Children

DS160.io accounts are for adults. Applicants may be children: a parent, guardian or authorised business customer may prepare a DS-160 for a child, and is then responsible for providing the child’s data.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change affects how data already collected is used, DS160.io emails account holders before it takes effect.

Contact

Questions about this policy or about personal data: privacy@ds160.io.