2Mig Privacy Policy
Document version: `privacy/v1-draft` Effective date: to be set on publication Owner and operator of the personal data: QAIT Inc., a Delaware C Corporation. Privacy contact: yera@2mig.kz
---
1. Scope
This Policy explains what we do with personal data when you use 2Mig. It applies to applicants, to anyone whose data an applicant provides — a co-traveller, a child, an inviting person — and to visitors to our website.
If you provide someone else's data, you are telling us you are entitled to, and we will treat that person as a data subject with the rights described in section 8.
2. What we collect
Because you give it to us, to run your case:
- contact and account data — name, email, phone, and the optional profile avatar
- you choose (one of our illustrations or a photograph you upload);
- identity and travel document data — passport details, dates, numbers, and the
- machine-readable zone where we read it from a scan you upload;
- application answers — purpose of travel, dates, itinerary, employment,
- education, family and previous travel history;
- supporting documents — employment and income evidence, bank statements,
- invitations, bookings, insurance, and whatever else the corridor requires;
- payment references. We do not receive or store your full card number; that is
- handled by our payment provider.
Because the case generates it:
- the case journal — what was requested, what you confirmed, when a mandate was
- granted or revoked, what we did and when;
- messages between you and our support;
- application reference numbers, and status results — read from the official
- portal where the corridor supports that, and otherwise reported to us by you.
- Your order confirmation says which applies to your corridor; today only the
- Sri Lanka corridor supports a portal lookup, and for Schengen the status is
- whatever you tell us.
Because we run a service on the internet:
- device, browser and IP data, and security and access logs.
Sensitive categories. Where a destination requires a photograph of your face as part of the application, we collect it for that corridor only, and only with the consent recorded for that purpose. We do not collect biometric data. An optional profile photograph is separate from application documents. We resize it, remove embedded metadata, and use it only as your account avatar; changing your avatar replaces it, and closing your account deletes it. Fingerprints and other biometric identifiers are enrolled by you in person at the visa centre or authority; they never pass through us. If a corridor ever requires otherwise, we will say so here before that corridor opens.
What we deliberately do not collect. We do not collect your data for any corridor we are not providing to you.
Portal credentials. No service we offer today asks for your password to a government or operator portal, and none stores one. If that ever changes, we will describe here what is stored, where, and on what basis, before we ask you for it.
3. Why we use it, and on what basis
| Purpose | Basis | |---|---| | Preparing and checking your application, and lodging it where the corridor allows and you have given us a mandate. On every corridor open today, you lodge it yourself — see Annex A of the Terms | Performance of the contract with you, and your consent to the processing and to the transfer described in section 6 | | Showing the optional avatar you select across your signed-in devices | Your choice to use this optional account feature | | Reading your application status from an official portal | Same | | Support, complaints and refund decisions | Contract; and our legal obligations to consumers | | Fraud prevention, security, and protecting the integrity of the Service | Our legitimate operational need, and legal obligations | | Accounting, tax and payment records | Legal obligation | | Improving the Service, as limited by section 5 | Consent, recorded separately from the consent to run your case |
Consent to run your case and consent to improvement use are separate records. Withdrawing the second does not affect your case.
4. Who receives it
Only where necessary, and only what is necessary:
- the visa authority or its official system in the destination country —
- this is the point of the exercise, and it is a cross-border transfer; see
- section 6;
- a visa application centre, operator or courier, where the corridor
- involves physical documents. We name the specific one before your documents
- leave your hands;
- our payment provider, for the transaction;
- infrastructure and security providers hosting the Service — subject to
- section 7 on where data is stored;
- an AI model provider, and only if you agreed when uploading — the content
- of supporting documents (bank statements, employment and income
- certificates), so we can check them against the destination's requirements.
- Never your passport, ID, photographs or biometric data. See section 5;
- professional advisers, auditors and, where legally compelled, state bodies
- acting within their powers and on a lawful basis we can identify;
- Google, and only if you accepted measurement cookies — see section 11. It
- receives page addresses, a random device identifier and coarse technical
- facts (device type, browser, approximate country). It receives **nothing from
- your application**: not your name, your email, your passport details or any
- document. Refuse measurement and it receives nothing at all.
Each recipient is bound by confidentiality and security obligations. We do not sell personal data, we do not share it for advertising, and we do not licence it to anyone for model training.
5. Automated checks, AI, and what we never feed to a model
We use rules and automated checks to compare your case against published requirements. These do not decide anything about your visa — the authority does that — and a human reviews any rule package before it is published.
We minimise what any AI system sees. Specifically:
- **passport and ID scans, identity photographs and biometric data are
- processed only on our servers in Kazakhstan** and are never sent to an
- external AI model, by default or otherwise;
- supporting documents — bank statements, employment and income
- certificates and similar — are sent to an AI model provider to check their
- content against the corridor's requirements: dates, amounts, period and
- holder. You agree to this when you accept the Terms of Service at sign-up;
- the sign-in screen says so beside the button. The provider does not use them
- to train models;
- you can turn it off at any time in your account settings. What was
- already read from your files is then deleted, and a specialist checks your
- supporting documents by hand. It takes longer and does not otherwise affect
- your case. When the automatic check cannot decide — a different currency, a
- name it cannot compare, a document it is unsure of — a specialist decides
- too, and your case waits for that decision;
- **we do not use identity or financial documents to train, fine-tune or
- evaluate models**, ours or anyone else's;
- what we do use to improve the Service is the outcome of a case measured
- against a known set of facts, aggregated or de-identified wherever that will
- do the job.
This matches section 8 of the Terms of Service. If the two documents ever disagree, the narrower statement is the one we are bound by, and the wider one is a defect to be fixed.
6. Cross-border transfer
To obtain a visa or travel authorisation, your application data must reach the authority of the destination country. That is a cross-border transfer, and we make it only for the corridor you selected, only to the official system or authorised operator named in your order confirmation, and only with your consent recorded for that purpose (Law No. 94-V, article 7(6) and article 16).
We tell you, before you pay, which country and which system your data will go to.
The level of protection your data receives once it is in the hands of a foreign authority is determined by that country's law, not by us. We cannot recall data from an authority, and we cannot promise deletion by one.
A second transfer serves your application. Supporting documents are processed by an AI model provider on servers outside Kazakhstan — a separate transfer, on your consent under article 16, which you give by accepting the Terms of Service at sign-up and can withdraw in your account settings at any time. Identity documents are never part of it. With the consent withdrawn, a specialist checks the documents instead.
One transfer is not about your application at all. If you accept measurement cookies, the analytics data described in section 11 is processed by Google on servers outside Kazakhstan. It is a separate transfer, on a separate basis — your consent in the cookie banner, under article 16 — and declining it does not affect the Service at all. Nothing from your application is included in it. If you would rather it did not happen, choose "Essential only" and it does not.
7. Where your data is stored
Your personal data is stored in a database located in the Republic of Kazakhstan. This is not a preference; it is a statutory requirement. Article 12(2) of Law No. 94-V requires storage in a database located in the territory of the Republic of Kazakhstan, without exception, and paragraph 14 of the Rules requires that database to sit in a server room or data centre in Kazakhstan. Paragraph 13 goes further and requires the collection and processing of personal data of restricted access to take place through digital facilities located in Kazakhstan — so the servers that receive your uploads must be in Kazakhstan too, not only the storage behind them.
Resolved 2026-09-14, and stated with the same limit the code itself carries. Production document intake opened on `ps.kz`, inside Kazakhstan — owner's decision, `docs/lessons/cases-documents-pii.md`. This is our own declared placement, checked at every boot by a required acknowledgement (`DOCUMENT_RESIDENCY_ACK`), not an independent audit of the provider's data centre. What this does not yet cover: an older database backup can still hold a document's key even after the live row is erased, so deletion is not yet provable against backups; that needs a managed key service before it is closed.
8. Security
Access to a case is limited to the people who need it, and access to documents is recorded.
We will tell you about a personal data breach affecting you, and the regulator where the law requires it, without waiting to be asked.
We do not make claims about specific cryptographic standards. You will not find "AES-256" or "bank-grade encryption" on our pages, because a security claim we cannot evidence is worth less than silence.
9. How long we keep it
We keep data for as long as the case, and then the legal, accounting, dispute and security periods that apply to it, require:
| Class | Period | |---|---| | Identity and financial documents you uploaded | to be published once legal review sets this | | Application data and case journal | to be published once legal review sets this | | Payment and accounting records | to be published once legal review sets this | | Security and access logs | to be published once legal review sets this | | Marketing consent records | Until withdrawn, plus the period needed to evidence the withdrawal |
We have not invented these numbers, and we will not publish placeholders. When counsel sets them, they go in this table and in the code that enforces deletion — the table is not the mechanism, the deletion job is.
After the period ends, data is deleted or irreversibly de-identified.
10. Your rights
You may:
- ask what data we hold about you and where it came from;
- have inaccurate data corrected;
- have data blocked or deleted where we have no lawful ground to keep it;
- withdraw a consent, including consent to improvement use, without affecting
- your case;
- object to how we are handling your data, and complain to us or to the
- authorised state body for the protection of personal data.
Write to yera@2mig.kz. We may need to verify your identity first — the request is about your data, so proving it is yours protects you. We will answer within the period counsel sets for this once published.
Two honest limits. We cannot delete data an authority already holds. And where the law requires us to keep a record — a payment, a submission — we keep that record and delete what is not required.
11. Cookies
We use cookies for two purposes, and neither of them is tracking you across other websites.
Necessary — no consent asked, because without them the site does not work for you:
- session cookies that keep you signed in (`vissa_at`, `vissa_rt`). Removing
- them signs you out;
- interface settings — your language, which applications you hid from the
- list, whether an introduction has already been shown to you. Removing them
- does not lock you out, but the site forgets how you set it up.
Optional — asked for, and refusable:
- the invitation marker (`vissa_ref`), set for 30 days when you arrive through
- someone's referral link. Its only job is to make sure the person who invited
- you is credited when you sign up. Refuse it and you can still sign up
- normally; only the credit is lost.
- audience measurement (Google Firebase Analytics). It records which pages
- are opened, from what kind of device and from which country, under a random
- identifier stored in cookies beginning `_ga`. We use it to see which parts of
- the site people actually use. It loads only if you accept it — choose
- "Essential only", or simply close the banner without answering, and the
- script is never fetched at all.
What we do not have. No advertising or social pixels, no profiling for advertising, and no selling of your data to anyone. We do not send your name, your email, your passport details or anything from your application to the measurement service; it sees page addresses and a device, not a person.
Where measurement data goes, and what that costs you. Firebase Analytics is operated by Google, and the data it collects is processed on Google's servers outside Kazakhstan. That is a cross-border transfer, and it happens only on the basis of the consent you give in the banner — it is one of the things you are agreeing to when you press "Accept all". If you would rather it did not happen, "Essential only" prevents it, and nothing about the Service works less well.
Your choice is stored and honoured. The banner records your answer for a year. Choosing "Essential only" also deletes an invitation marker that was already set, rather than only applying from that moment on. You can change your mind by clearing cookies for this site in your browser.
What changing your mind can and cannot undo. Switching to "Essential only" stops any further measurement immediately. It does not reach back and delete what was already sent to Google before you changed your mind, and it does not remove Google's own `_ga` cookies from your browser — clearing cookies for this site does that, and you can also ask us to help under section 9.
12. Children
We process a child's data only as part of an application made by a person entitled to act for them. We do not offer the Service directly to children and we do not market to them.
13. Changes
We will publish updates with a version identifier and effective date, and give notice of material changes. Consents you have given are tied to the version of this Policy you saw; a new version does not retroactively widen them.
---