Global Migration Services

Privacy and document-retention policy

Effective 29 August 2026 · Version 1.0

Return to registration

At a glance

Applicant files are kept private, placed in quarantine, checked for permitted file type and integrity, and submitted to an approved malware scanner only when that service is configured. Files are never given a public download URL.

1. Who is responsible for your information

Global Digital Streams Ltd, operating Global Migration Services (GMS), is the data controller for this registration. Company number 16920095. Registered office: 3 Ravensbourne Terrace, Stanwell, Staines-upon-Thames, England, TW19 7RP. Contact: admin@globalmigrationservices.io or +44 7728 630 929.

2. Information we collect

We collect the contact, education, employment, route-preference, funding and immigration-position information you enter, together with your declaration, passport-style photograph and any identity, qualification, employment or immigration evidence you choose to upload. We also create technical security records such as file type, size, integrity hash, scan status, time and application reference.

Do not submit health information, criminal-offence information, payment-card information or unrelated sensitive records. If such information is later necessary, GMS will use a separate process and provide any additional privacy information required.

3. Why and how we use it

We use the information to receive and screen your EYITT enquiry, assess document readiness, contact you, prevent fraud and malware, maintain an application record, and establish or defend legal claims. Our intended lawful bases are taking steps at your request before a possible service arrangement, our legitimate interests in operating and securing the enquiry service, and compliance with legal duties where applicable. We request separate consent where consent is legally required.

Submitting this form does not authorise GMS to send your evidence to a training provider, employer or immigration authority. If a referral or disclosure is proposed, we will explain it and obtain any authorisation required first.

4. Document security and malware scanning

Uploads are accepted only through a time-limited application session, restricted to PDF, JPG and PNG, checked against file signatures, integrity-hashed and stored in private object storage with no public download address. New files enter a quarantine area.

When the approved scanning service is configured, each upload is automatically scanned before it receives a clean status. The scanner is configured to reject malware, executables, scripts, invalid files, password-protected content and other active or unsafe content. A malicious file is rejected and not retained. If the scanner is unavailable, the file remains quarantined and is not treated as clean.

Cloudmersive is the scanner integration prepared for this service. When activated, it may process a temporary copy solely to return a security result. Before activation, GMS must have appropriate contractual and international-transfer safeguards with that processor. GMS does not use public malware-sharing services for applicant documents.

5. Who receives information

Access is limited to authorised GMS personnel and contracted service providers that host, secure or support the registration system. They may process information only under GMS instructions and appropriate confidentiality and data-protection terms. We may disclose information where the law requires it or to protect legal rights.

6. International transfers

If a service provider processes information outside the United Kingdom, GMS will use a recognised transfer mechanism and conduct any required transfer-risk assessment. GMS will not activate an external document scanner for applicant files until those safeguards have been confirmed.

7. Document-retention schedule

We review records against the purpose for which they were collected and securely delete or anonymise them when they are no longer needed. The following maximum periods apply unless a shorter period is appropriate or a legal duty, complaint, investigation or claim requires a documented hold.

RecordMaximum retention
Incomplete applications and quarantined uploads30 days after the last activity, then deletion
Unsuccessful or inactive enquiries12 months after the last substantive contact
Identity, qualification and immigration evidenceUntil no longer needed for screening, and no later than 12 months after the enquiry closes unless a legal claim or duty requires longer
Records for applicants who become service clientsSix years after the service relationship ends, where needed for contractual, accounting or legal-claims records
Files rejected as maliciousThe file is not retained; limited security-event metadata may be kept for up to 12 months
Consent, declaration and security audit recordsUp to 24 months after the application record is deleted

At the end of a retention period, database records are deleted or anonymised and associated private objects are deleted. Backups, where used, expire through the provider's normal protected backup cycle.

8. Your data-protection rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or object to processing. You may withdraw consent where processing relies on consent; this does not affect earlier lawful processing. Contact admin@globalmigrationservices.io. We may need to verify your identity before acting.

You may complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

9. Cookies, changes and contact

This registration uses only storage and technical functions necessary to provide and secure the form; it does not use advertising cookies. We will update this notice before making a materially different use of applicant information and show a new effective date and version.