
Global Migration Services
Privacy and document-retention policy
Effective 29 August 2026 · Version 1.0
At a glance
Applicant files are kept private, placed in quarantine, checked for permitted file type and integrity, and submitted to an approved malware scanner only when that service is configured. Files are never given a public download URL.
1. Who is responsible for your information
Global Digital Streams Ltd, operating Global Migration Services (GMS), is the data controller for this registration. Company number 16920095. Registered office: 3 Ravensbourne Terrace, Stanwell, Staines-upon-Thames, England, TW19 7RP. Contact: admin@globalmigrationservices.io or +44 7728 630 929.
2. Information we collect
We collect the contact, education, employment, route-preference, funding and immigration-position information you enter, together with your declaration, passport-style photograph and any identity, qualification, employment or immigration evidence you choose to upload. We also create technical security records such as file type, size, integrity hash, scan status, time and application reference.
Do not submit health information, criminal-offence information, payment-card information or unrelated sensitive records. If such information is later necessary, GMS will use a separate process and provide any additional privacy information required.
3. Why and how we use it
We use the information to receive and screen your EYITT enquiry, assess document readiness, contact you, prevent fraud and malware, maintain an application record, and establish or defend legal claims. Our intended lawful bases are taking steps at your request before a possible service arrangement, our legitimate interests in operating and securing the enquiry service, and compliance with legal duties where applicable. We request separate consent where consent is legally required.
Submitting this form does not authorise GMS to send your evidence to a training provider, employer or immigration authority. If a referral or disclosure is proposed, we will explain it and obtain any authorisation required first.
4. Document security and malware scanning
Uploads are accepted only through a time-limited application session, restricted to PDF, JPG and PNG, checked against file signatures, integrity-hashed and stored in private object storage with no public download address. New files enter a quarantine area.
When the approved scanning service is configured, each upload is automatically scanned before it receives a clean status. The scanner is configured to reject malware, executables, scripts, invalid files, password-protected content and other active or unsafe content. A malicious file is rejected and not retained. If the scanner is unavailable, the file remains quarantined and is not treated as clean.
Cloudmersive is the scanner integration prepared for this service. When activated, it may process a temporary copy solely to return a security result. Before activation, GMS must have appropriate contractual and international-transfer safeguards with that processor. GMS does not use public malware-sharing services for applicant documents.
5. Who receives information
Access is limited to authorised GMS personnel and contracted service providers that host, secure or support the registration system. They may process information only under GMS instructions and appropriate confidentiality and data-protection terms. We may disclose information where the law requires it or to protect legal rights.
6. International transfers
If a service provider processes information outside the United Kingdom, GMS will use a recognised transfer mechanism and conduct any required transfer-risk assessment. GMS will not activate an external document scanner for applicant files until those safeguards have been confirmed.
7. Document-retention schedule
We review records against the purpose for which they were collected and securely delete or anonymise them when they are no longer needed. The following maximum periods apply unless a shorter period is appropriate or a legal duty, complaint, investigation or claim requires a documented hold.
| Record | Maximum retention |
|---|---|
| Incomplete applications and quarantined uploads | 30 days after the last activity, then deletion |
| Unsuccessful or inactive enquiries | 12 months after the last substantive contact |
| Identity, qualification and immigration evidence | Until no longer needed for screening, and no later than 12 months after the enquiry closes unless a legal claim or duty requires longer |
| Records for applicants who become service clients | Six years after the service relationship ends, where needed for contractual, accounting or legal-claims records |
| Files rejected as malicious | The file is not retained; limited security-event metadata may be kept for up to 12 months |
| Consent, declaration and security audit records | Up to 24 months after the application record is deleted |
At the end of a retention period, database records are deleted or anonymised and associated private objects are deleted. Backups, where used, expire through the provider's normal protected backup cycle.
8. Your data-protection rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or object to processing. You may withdraw consent where processing relies on consent; this does not affect earlier lawful processing. Contact admin@globalmigrationservices.io. We may need to verify your identity before acting.
You may complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
9. Cookies, changes and contact
This registration uses only storage and technical functions necessary to provide and secure the form; it does not use advertising cookies. We will update this notice before making a materially different use of applicant information and show a new effective date and version.