NEW HOLLAND CREDIT COMPANY LLC is an independent travel assistance provider. We are not affiliated with, endorsed by, operated by, or representing the European Union, ETIAS, or any government authority.
Legal
Privacy Policy
How we handle the information travelers share with us.
1. Overview & Data Protection Frameworks
Our company and service values your privacy and trust is paramount. This Privacy Policy details how we collect, process, safeguard, and disclose your personal details when you access our website or utilize our EU ETIAS document review and application assistance services.
We deliver travel documentation assistance globally, including to applicants residing in countries whose nationals are eligible for visa-exempt travel to the Schengen Area and are therefore required to obtain ETIAS authorization, across the European Union (EU), United Kingdom (UK), United States (US), and other international jurisdictions. Consequently, we align our data operations with relevant global privacy standards:
- EU General Data Protection Regulation (EU GDPR – Regulation 2016/679)
- UK GDPR & Data Protection Act 2018
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
- Applicable US state privacy legislation and international data privacy laws
For all privacy inquiries, data rights requests, or supervisory communications, please contact our privacy compliance team using the contact form.
2. Personal Information We Collect
A. Information Provided Directly by You
To fulfill your EU ETIAS application, we collect required personal details including:
- Identification & Personal Details: Full name, date of birth, place of birth, gender, primary citizenship, and any national identification numbers or secondary citizenship details.
- Travel Document Details: Passport number, issuance and expiration dates, issuing country, and digital passport scans/images.
- Verification Media: Facial photographs or selfies submitted to verify identity against your passport documentation.
- Contact Details: Email address, telephone/mobile number, home address, emergency contact details (both within and outside the applicant's country of residence), and parent details (full names of parents as required by ETIAS filing requirements for minors).
- Employment Data: Current or previous employer name, job title, and company contact information.
- First Intended Member State & Travel Details: The first Schengen member state you intend to enter, intended address or accommodation information, point of contact, and travel purpose.
- Statutory ETIAS Security Declarations: Responses to statutory eligibility and security questions (including medical background, criminal record history, prior travel to conflict zones, and any previous refusals of entry or removal from an EU member state).
- Billing Reference Data: Payment confirmation identifiers. (Note: Complete credit/debit card details are processed directly by certified third-party payment gateways and are never stored on our servers).
- Support Inquiries: Transcripts and correspondence sent through our contact channels.
B. Technical & Usage Information Collected Automatically
When navigating our portal, our systems automatically collect:
- Network identifiers (IP address and approximate geographic location).
- Device characteristics, browser specifications, and operating system details.
- Navigation paths, time spent on pages, referral links, and cookie interactions (see Section 5).
C. Third-Party Data Sources
Where permitted by law, we may receive verification signals from accredited identity verification checks, anti-fraud systems, or payment processors to validate transactions.
3. How We Process Your Data & Legal Grounds
We rely on defined legal bases under applicable data privacy frameworks to process your personal data:
| Processing Purpose | Categories of Data | Legal Ground |
|---|---|---|
| Processing EU ETIAS Application | Identifiers, passport details, travel/employment data | Performance of Contract |
| Identity Verification | Passport scans, selfie images | Performance of Contract / Explicit Consent |
| ETIAS Security Declarations | Statutory eligibility declarations | Legal Obligation / Public Task |
| Payment Handling | Payment references, order details | Performance of Contract |
| Customer Support & Updates | Contact information, interaction logs | Performance of Contract / Legitimate Interest |
| Legal Compliance & Security | Transaction history, IP logs | Legal Obligation / Legitimate Interest |
| Site Optimization & Analytics | Cookie identifiers, interaction metrics | Legitimate Interest / Consent |
| Marketing Communications | Email address | Explicit Consent (Opt-in) |
4. Special Category Data, Biometrics & Automated Checks
Biometric Safeguards
Facial imagery and passport photo uploads used to confirm applicant identity may be categorized as biometric data under applicable law. We handle this sensitive data under explicit user consent and strict necessity.
- Encryption: Biometric media is encrypted during transmission and storage using industry-standard AES-256 protocols.
- Access Control: Access is restricted strictly to technical staff directly processing your filing.
- Zero Commercial Use: Biometric assets are never analyzed for marketing, user profiling, or commercial resale.
- Accelerated Deletion: Media files are purged under our accelerated removal schedule in Section 7.
Automated Checks & Human Oversight
We utilize automated matching software to compare selfie images against passport documentation to detect fraud and formatting errors. These tools assist—but do not replace—human review. No final decision leading to application rejection or legal consequence is taken solely via automated processing. Applicants can request a manual human review of automated checks by emailing us using the contact form.
5. Cookie Policy & Tracking Management
Our website utilizes cookie files and similar technical tracking to maintain portal stability, evaluate site traffic, and support user preferences.
Cookie Choices
When launching our portal, our banner allows you to select:
- Accept All: Enables necessary, analytical, and functional optimization cookies.
- Necessary Only: Restricts tracking exclusively to essential operational cookies.
Categories
- Strictly Necessary Cookies: Essential for session management, application step retention, portal security, and secure checkout. These cannot be disabled.
- Analytics & Preference Cookies: Allow us to evaluate visitor engagement, detect software errors, and store language settings. Enabled only with your consent.
You may update your preferences at any time by clearing browser cookies or contacting our team.
6. Data Sharing & Third-Party Vendors
Sharing Your Data
We share personal data with:
- Government and EU authorities: including the ETIAS Central Unit, the ETIAS National Units of Schengen member states, Frontex, eu-LISA, and border authorities of the Schengen Area, and also necessary entities to process and send your application, or otherwise required by law;
- Third-party service providers and customer support platforms under information processing statutes;
- Legal and professional companies when needed;
- Law enforcement and regulators: national data enforcement bureaus, where required by law;
- Fraud prevention agencies: to protect against fraud.
We do not sell your personal data to third parties for marketing purposes.
For fraud mitigation and risk aversion purposes, our processor also captures certain data (including device, browser, and click data) as an independent data controller in its own right, separate from its role as our payment processor.
Our platform may contain links to external websites, software, or integrations. We have no control over, and accept no responsibility for, the content, security practices, terms, or privacy policies of any third-party site or service, and you access and use such tools entirely at your own risk. In order to provide our services effectively, we may work with trusted third-party service providers — for example, secure payment processors and customer support platforms — each of whom processes user data only under binding data protection agreements.
7. Data Retention & Accelerated Deletion Schedule
We retain personal information only for as long as required to deliver our service and fulfill legal and accounting requirements.
General Schedule
- Application Text Records (Name, Travel Details, Employment Data): Kept for 12 months from submission to resolve service inquiries and track application status, then securely archived or deleted.
- Statutory ETIAS Security Declarations: Permanently destroyed within 2 to 4 days following application submission to the official ETIAS system.
- Financial & Order Records: Retained for 7 years to satisfy accounting, tax, and audit obligations.
- Support Inquiries: Kept for up to 3 years from the last interaction.
Accelerated Biometric Deletion Schedule
Raw passport images and facial verification photos are deleted under accelerated timelines:
| Trigger Event | Deletion Timeline |
|---|---|
| Application Approved & Delivered | Deleted within 24 hours |
| Application Rejected by Government | Deleted within 24 hours |
| Application Cancelled by User | Deleted Immediately |
| Full or Partial Refund Processed | Deleted within 24 hours |
| Incomplete/Abandoned Application | Deleted automatically after 14 days |
8. Data Security Measures
We enforce rigorous technical and organizational controls to safeguard personal data against unauthorized access, loss, or alteration. Measures include AES-256 encryption at rest, TLS encryption in transit, strict role-based access limits, and regular security assessments. In the unlikely event of a security incident impacting your rights, we will notify relevant supervisory authorities and affected users as required by law.
9. Protection of Minors
Our services are not intended for independent use by individuals under 18 years of age. Minors may only apply through a parent, legal guardian, or authorized representative who submits data on their behalf. Children's details provided for family travel filings are handled with identical security and retention protections as adult filings. If you suspect a minor has submitted information directly without parental authorization, contact us using the contact form for immediate deletion.
10. Direct Marketing
If you opt-in to receive promotional updates or service announcements, we may send periodic emails. You can withdraw consent at any time via the "Unsubscribe" link in any communication or by contacting support.
11. Policy Modifications
We may update this Privacy Policy to reflect changing regulatory requirements or service enhancements. Revisions will be published on this page with an updated "Last Updated" date.
12. Region-Specific Provisions
12.1 European Union (EU) Residents
- Data Controller: NEW HOLLAND CREDIT COMPANY LLC acts as the data controller for personal data processed via this website.
- International Data Transfers: As our Operating Entity is located outside the European Economic Area (EEA), transfers of EU personal data to us rely on European Commission-approved Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms to guarantee equivalent data protection.
- Your EU Rights: Under the EU GDPR, you have the right to request access, rectification, erasure, processing restriction, data portability, and objection to processing. You also maintain the right to lodge a complaint with your local EU Data Protection Authority.
12.2 United Kingdom (UK) Residents
- UK Data Framework: Processing of UK data subjects is conducted under UK GDPR and the Data Protection Act 2018.
- Cross-Border Transfers: Transfers outside the UK utilize the UK International Data Transfer Agreement (IDTA) or Addendum.
- Your UK Rights: You maintain the right to access, amend, port, or erase your data, and may contact the Information Commissioner's Office (ICO) at www.ico.org.uk for supervisory concerns.
12.3 United States Residents (including California CCPA/CPRA)
- Categories Collected: Identifiers, commercial records, passport/biometric details (for verification), geolocation data, employment history, and device activity.
- We Do Not Sell Personal Data: We do not sell or share personal information for third-party targeted advertising.
California Consumer Rights:
- Right to Know & Access: Request details regarding personal data collected over the past 12 months.
- Right to Delete: Request removal of personal information, subject to statutory retention exemptions.
- Right to Correct: Request correction of inaccurate personal records.
- Limit Sensitive Data Use: Request limits on the processing of sensitive identifiers (passport numbers, biometric verification files, security responses).
- Non-Discrimination: We will not deny services or alter pricing for exercising privacy rights.
Submitting US Requests: Email us using the contact form with the subject line "US Privacy Rights Request." We acknowledge and process verified requests within state-mandated timelines (e.g., 45 days for CCPA).
13. Contact Information
For privacy questions, data access requests, or regulatory inquiries, please reach out to our team:
- Email: using the contact form
- Operating Entity: NEW HOLLAND CREDIT COMPANY LLC
- Mailing Address: 120 Brubaker Avenue, New Holland, PA 17557, United States