Privacy Policy
Last updated: 19 August 2026
This policy explains what VisaCRM collects when you use visacrm.co, what we do with it, and the choices you have. It covers our marketing site, the onboarding lobby at visacrm.co/start, and the CRM instances we operate for our customers.
Who is responsible
VisaCRM is operated by Eyüp Yiğit Dilber, registered at Caferağa Mah. Soner Sk. No: 6 D: 3, Kadıköy, İstanbul, Türkiye. For questions about this policy or your personal data, contact hello@visacrm.co.
For visitors and prospective customers, we are the data controller. For personal data our customers put into their own CRM instance — their applicants' details — the customer is the controller and we act as their processor.
What we collect
We collect three kinds of data, and no more than we need for each:
- Site visitors. Pages viewed, approximate location by country, device and browser type, and the referrer or advertising click that brought you here. Collected through Google Analytics.
- Setup requests. When you sign up at visacrm.co/start: your name, work email, agency name, and optionally phone number, country, website, the services you want, expected monthly volume, and anything you write in the notes field.
- Live chat. Messages you send us, and — once you are signed in — your name, email and reference so we can see who we are talking to instead of an anonymous visitor.
Why we use it, and on what basis
- To answer your setup request and deliver what you asked for. Necessary for performance of a contract, or steps taken at your request before entering one.
- To operate, secure and support the service. Our legitimate interest in running a functioning business.
- To measure which marketing works, including which advertisement produced a signup. Our legitimate interest in understanding our own channels; where required, on the basis of your consent.
- To send service messages such as sign-in codes and delivery updates. Necessary to provide the service you asked for.
Cookies and similar technologies
We use a small number of first-party cookies, Google Analytics, and — when you allow it — Google's advertising measurement, so we can tell which ads bring visa agencies to this site. We do not sell your data.
You choose what to allow the first time you visit, and you can change it at any time through “Cookie settings” at the bottom of any page. In the EEA, the UK and Switzerland nothing beyond strictly necessary cookies is set until you agree; elsewhere, analytics and advertising cookies are set unless you turn them off.
- vc_consent — remembers your cookie choices so we do not ask again. 6 months.
- Google Analytics (_ga, _ga_*) — measures site usage. Up to 2 years.
- vc_attr — records the advertising click or campaign that brought you to the site, so a signup can be attributed to it. 90 days, first-party, no third party can read it.
- visacrm_lobby_session — keeps you signed in to the onboarding lobby. 30 days, httpOnly, unreadable by scripts.
- Live chat cookies (bf-live-chat-*) — keep your conversation attached to you between visits.
Who else processes your data
We use a small set of service providers, each only for the purpose listed. They process data on our instructions and are not permitted to use it for their own purposes.
- Google (Analytics, Ads) — measurement and advertising performance.
- Brandfine — live chat and content management.
- Resend — transactional email such as sign-in codes and notifications.
- DigitalOcean — hosting and databases, in the European Union (Frankfurt).
Where your data is held
Our servers and databases are located in the European Union. Some of our providers are based outside Türkiye and the EU, which means your data may be transferred internationally. Where that happens we rely on the safeguards those providers offer, such as the European Commission's standard contractual clauses.
How long we keep it
- Setup requests: for as long as we are in contact with you about the request, and up to 24 months afterwards so we can pick a conversation back up.
- Customer records and invoices: for as long as you are a customer, and afterwards for the period required by tax and commercial law.
- Analytics: up to 14 months.
- Live chat conversations: up to 24 months.
Your rights
Under Türkiye's Personal Data Protection Law (KVKK, article 11) and, where it applies to you, the GDPR, you may ask us whether we hold data about you, ask for a copy, ask us to correct or delete it, object to certain processing, or ask us to restrict it. You may also withdraw consent at any time where we relied on it.
Write to hello@visacrm.co and we will respond within 30 days. If you are not satisfied with our response you may complain to the Turkish Data Protection Authority (KVKK) or, in the EU, to your local supervisory authority.
Security
Data is encrypted in transit. Credentials and third-party keys are encrypted at rest. Each customer's CRM runs in its own isolated environment with its own database, so one customer's data is never mixed with another's. Access to production systems is limited to the people who need it.
Changes to this policy
If we change this policy we will update the date above. If a change materially affects how we handle your data, we will tell you by email.
Contact
Questions, requests, or complaints: hello@visacrm.co.

