Privacy Policy
Last updated: June 19, 2026
This is an English courtesy translation. In case of any discrepancy, the Spanish version prevails.
APOLLO SOLUTIONS, S.L.U. (hereinafter, «APOLLO» or «ApplySpainVisa»), as Data Controller and owner of this website, in accordance with Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), provides this privacy policy in order to inform you, in detail, about how we process your personal data and protect your privacy.
1. Data controller
- Identity: APOLLO SOLUTIONS, S.L.U.
- Tax ID (NIF): B13843859
- Registered office: C/ Diego de León 47, 28006 Madrid, Spain
- Email: support@applyspainvisa.com
2. Data Protection Officer (DPO)
The Data Protection Officer is AURIS CONSULTORÍA LEGAL I TRIBUTARIA, S.L.P., NIF B65951055 (www.aurisadvocats.com). For any query regarding the use of your personal data, you may contact the DPO via: xavi@aurisadvocats.com.
3. What data do we collect?
The personal data we collect can be grouped into the following categories:
- Basic and contact data: first name, last name, ID/NIE/passport, nationality, email address, address and phone number.
- Financial and economic data: payment details, refunds and commercial transactions carried out with us.
- Data essential for the service: information needed to assess eligibility and prepare the visa application, such as employment situation, income, education or professional experience and file data.
- Technical data: IP address, browser and version, time zone, operating system and technology used during access.
- Browsing data: information regarding browsing behavior when you visit our platform.
- Marketing and communication preferences: preferences for receiving communications and consents granted.
We will never collect specially protected or sensitive personal data. If, in order to prepare your file, it were necessary to provide documentation relating to a criminal record, such information will be processed solely for the purpose and for the time strictly necessary, and with your explicit consent.
4. How do we collect your data?
Most of your information is provided directly by you through web forms, email or telephone. We may also obtain information from:
- Third parties who have previously obtained your express consent.
- The cookies enabled on our website (see our Cookie Policy).
5. Purpose and legal basis of processing
| Purpose | Legal basis |
|---|---|
| Provide the self-service assistance service, manage payments and charges | Contractual performance / Consent |
| Answer through the AI case manager and, only when the user enables it for a specific question, analyse selected PDFs from their case | Contractual performance / Explicit consent where a document contains special categories of personal data |
| Registration as a user or new client | Consent / Contractual performance |
| Manage the client relationship (changes, surveys, support) | Contractual performance / Legal obligation / Legitimate interest |
| Administer and protect the web platform | Legal obligation / Legitimate interest |
| Improve the browsing experience through analytics cookies | Legitimate interest / Consent |
| Sending commercial communications | Express consent |
| Prevent and detect fraud | Legitimate interest |
| Respond to queries and incidents | Legitimate interest / Contractual performance |
| Comply with legal, accounting and tax obligations | Legal obligation |
6. With whom do we share your data?
We may need to share your information with:
- Subcontracted service providers, such as payment gateways (e.g., Stripe).
- Hosting, cloud infrastructure and support and communication tool providers.
- Artificial intelligence provider (OpenAI), solely to generate case-manager responses and, when expressly authorised by the user for a question, analyse up to three PDFs from that user’s own case.
- Banking entities we work with.
- Law enforcement and public administrations when required to do so by law.
All providers are contractually bound to us through the corresponding data processing agreements and guarantee compliance with the security measures necessary to safeguard your personal information.
7. Where do we host your information?
Your information is hosted on the servers of hosting and cloud infrastructure providers located, as a general rule, within the European Economic Area (EEA). Where an international transfer of data outside the EEA is necessary, such transfer will be subject to the safeguards required by current data protection regulations (standard contractual clauses, European Commission adequacy decisions, etc.).
AI case-manager requests are sent with response storage disabled and PDFs are transmitted as one-off inputs, without creating a permanent OpenAI file or vector index. The provider may nevertheless retain safety and abuse-prevention logs for the period stated in its applicable data policy.
8. How long do we keep your data?
Your data will be kept for the duration of the commercial relationship or until you exercise your right to erasure, objection or restriction of processing. Retention periods are aligned with legal responsibilities regarding limitation periods:
| Matter | Limitation period | Regulation |
|---|---|---|
| Accounting and commercial | 6 years | Art. 30 Commercial Code |
| Tax (tax debts) | 4 years | Art. 66 Law 58/2003 |
| Tax (offset amounts / deductions) | 10 years | Art. 66 bis Law 58/2003 |
| Offenses against the Public Treasury | 10 years | Art. 131 LO 10/1995 |
| Traffic and identifying data | 2 years | Applicable case law |
9. How do we protect your information?
We guarantee the implementation of appropriate physical, organizational and technological security measures to prevent your information from being accidentally lost, used or accessed in an unauthorized manner. We limit access to your data to authorized persons and all staff involved in processing are subject to a duty of confidentiality. We apply technical procedures to detect and respond to possible security breaches, notifying the competent supervisory authority where necessary.
10. Your rights (ARCOLP)
The GDPR and the LOPDGDD guarantee you the free exercise of the following rights at any time:
- Access: receive a copy of your personal information.
- Rectification: request the correction of errors in your personal information.
- Erasure (right to be forgotten): request that we delete your personal information in certain situations.
- Restriction: request the restriction of the processing of your data.
- Objection: object to processing for direct marketing or based on legitimate interest.
- Portability: receive your information in a structured and readable format, or transmit it to a third party.
- Automated decisions: not be subject to decisions based solely on automated processing that produce legal effects.
To exercise any of these rights, write to support@applyspainvisa.com or contact the DPO directly at xavi@aurisadvocats.com. You must attach legally valid proof of your identity.
11. How to stop receiving commercial communications
At any time you may revoke your consent to receive commercial communications using the unsubscribe (opt-out) option available in our communications or by sending an email with the subject «unsubscribe» to support@applyspainvisa.com. In accordance with the LSSI-CE, we never send SPAM.
12. Supervisory authority
If you wish to file a complaint with the competent data protection authority, you may contact the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid · www.aepd.es · Tel: 901 100 099 / 912 663 517.
13. Changes to the privacy policy
APOLLO reserves the right to modify this policy to adapt it to legislative or case-law developments. Changes will be published on this page with the corresponding update date.