Use Case

Secure Immigration & Visa Document Collection

Collect passports, financial proof, and civil documents from applicants through an end-to-end encrypted intake — not email attachments or WhatsApp. GDPR-compliant immigration document collection with reminders and a full audit trail.

Collect Applicant Documents Securely

Applicants email photos of their passport

A scan of a passport, a bank statement, a birth certificate, sent as an attachment or over WhatsApp, then living in your inbox indefinitely.

You hold the most sensitive PII for dozens of applicants

Passports, financial proof, and personal histories across multiple applicants and countries — exactly the data privacy regulators write breach-notification laws about.

Endless chasing of missing or unreadable documents

You never know who has submitted what, or whether a scan is legible, until you open it. Every case turns into a string of 'did you get my documents?' messages.

No GDPR-ready record of how documents were handled

When an applicant asks what you hold or requests deletion, reconstructing it from inboxes and chat threads is slow and incomplete.

1

Build a reusable document checklist

Create one intake for exactly the documents a case requires (passport, proof of address, financial evidence, civil certificates) with clear labels so applicants submit the right file the first time.

2

Send each applicant a branded link

The applicant opens a professional page carrying your name. No account to create, no app to install, no public folder, which matters when you're asking a stranger abroad for their passport.

3

Documents are submitted encrypted

Every file is encrypted in the applicant's browser before it reaches our servers. You're notified as each submission lands, and reminders chase anything missing.

4

Review, track, and honor requests

Open submissions in the applicant's own case, keep a timestamped record, and delete at the individual level when an applicant exercises their right to erasure.

  • Passports and financial proof never transit through email or WhatsApp
  • Each applicant's documents isolated — never exposed to the next
  • End-to-end encrypted, GDPR-aligned collection with an audit trail
  • Automatic reminders chase missing or unreadable documents
  • No account required — the applicant just opens the link
  • Right-to-erasure honored at the individual submission level

An immigration case is a stack of someone's most sensitive documents. Email and WhatsApp are the wrong place for all of it.

A new applicant means collecting the most sensitive paperwork a person has: their passport, national ID, birth and marriage certificates, bank statements and financial proof, employment letters, police clearance, sometimes source-of-funds evidence for an investment visa. The default, "email or WhatsApp me a photo," turns your inbox into a store of passports and financials for dozens of applicants at once, across borders.

That passport scan is now searchable in your mail, backed up on servers you don't control, with no expiration and no record of who opened it. A shared upload folder is worse. It exposes one applicant's documents to the next. For a small consultancy this is the biggest privacy liability you carry, and it's exactly what breach-notification and GDPR rules are written about. There's a cleaner, encrypted way to run intake.

What you'll collect

One reusable document request replaces the attachment chaos. Everything the applicant submits is encrypted end-to-end in their browser and kept isolated from every other case:

  • Passport or national ID
  • Civil certificates (birth, marriage, divorce)
  • Financial proof and bank statements
  • Employment and tax letters
  • Police clearance certificate
  • A photo of the applicant, where the case requires it
  • Source-of-funds evidence, for investment or residency-by-investment cases

How the intake flow works

When you open a case: Send the applicant your standard document request — the same reusable checklist for every case of that type. It opens as a branded page carrying your name, not a generic form.

They submit their documents: Clear labels tell them exactly which document goes where, so you get legible files the first time. Everything is encrypted on their device before it's sent. If an applicant leaves the checklist half-finished, automatic reminders nudge them, so you stop chasing by hand.

You review in one place: Open each submission in the applicant's case, decrypt the documents, and see at a glance who has completed intake and who hasn't.

What your applicant experiences

A link, a form, a few uploads, submit. No account, no app, no public link that makes them anxious about who else can see their passport. Handing identity documents to someone in another country is the most sensitive step of any application. A page that visibly encrypts their passport on their own device is what earns the trust to complete it.

GDPR and the record you can show

Collecting this data means being able to show how you collected it. Every submission is logged: when the request was sent, when it was opened, when documents arrived, and the verification method used. When an applicant asks what you hold (Article 15) or requests erasure (Article 17), you answer precisely and delete at the individual level, with no hunt through inboxes and backups.

This page is the immigration view of a broader workflow. For the general playbook, see KYC & Identity Document Collection and GDPR-Compliant Data Collection. For the underlying practices, see our guides on securely receiving files from clients and maintaining audit trails for sensitive data sharing, or explore Secure Requests and the Audit Trail.

Handle sensitive client information securely — from onboarding to handoff. Try any workspace free for 3 days — no credit card required.

Collect Applicant Documents Securely