Here you can get legitimate visa support and insurance and make up a ready-to-file visa application pack to submit it to a Russian visa center or consulate in a few minutes.An important advantage of the service is that you receive an invitation letter for a Russian visa without the middleman and save time and money

Apply for a Russian visa Business Invitation Tourist Invitation

Russian visa
invitation online
in just 4 steps

1
2

Choose the services you need and fill out the visa application form. After that we will email you a welcome letter for you to log in your user account, which will display the services you’ve selected

You will pay for the service and receive an invitation letter and insurance policy we will send to you by email. All the documents can be also viewed on your user account

3
4

You will further go to the website of the Russian Ministry of Foreign Affairs and fill the visa application form for your Russian visa. If you are short of time or not sure you’ll do it all right, our managers will do it for you

Print your invitation letter, insurance policy and visa application form, attach your 3.5x4.5cm photo and passport (your passport should be still valid for six months beyond your visa expiry date) and pick up your visa in a Russian consulate or visa center

Choose the services you need and fill out the visa application form. After that we will email you a welcome letter for you to log in your user account, which will display the services you’ve selected

You will pay for the service and receive an invitation letter and insurance policy we will send to you by email. All the documents can be also viewed on your user account

You will further go to the website of the Russian Ministry of Foreign Affairs and fill the visa application form for your Russian visa. If you are short of time or not sure you’ll do it all right, our managers will do it for you

Print your invitation letter, insurance policy and visa application form, attach your 3.5x4.5cm photo and passport (your passport should be still valid for six months beyond your visa expiry date) and pick up your visa in a Russian consulate or visa center

CERTIFICATE STRONGEST
IN ESTONIA 2019

Digital professional solution for you

Business invitation letter service for a Russian visa

This is the most popular type of long-term visa with the validity period from 30 days to 5 years. Business purposes of entry include finding, and holding negotiations with business partners, entering into or extending contracts, taking part in exhibitions or auctions, or doing marketing research. Your business visa will be issued against a business invitation letter you can receive with us. Here you can find some examples of invitation letters for a business visa

Tourist invitation letter service for a Russian visa

Russian tourist visa is the most affordable and inexpensive type of visa. It perfectly suits for short-term (up to 30 days) stays in Russia to hold business negotiations or visit a private individual, participate in an exhibition, auction or cultural event, etc. To apply for a tourist visa, you require a special invitation letter,which you can get from us. Here you can have a look at some samples of a tourist voucher and a confirmation about the admission of a foreign tourist

Insurance Policy

In order to obtain a Russian visa, you need to hold a health insurance policy to be valid throughout your travel and provide coverage in the entire territory of Russia, with the insured sum of at least $30,000. You may buy it with us at a lower price. The policy will be accepted at all Russian consulates abroad and will be issued in accordance with the relevant requirements

Visa application assistance

In order to submit visa application documents to a Russian consulate or visa center, you should fill out an online form on the website of the Russian Ministry of Foreign Affairs at https://visa.kdmid.ru/PetitionChoice.aspx. If you are short of time or not sure you’ll fill it in all right, our managers will do it for you at just €20

Insurance policy for a Russian visa

In order to obtain a Russian visa, you need to hold a health insurance policy to be valid throughout your travel and provide coverage in the entire territory of Russia, with the insured sum of at least $30,000. You may buy it with us at a lower price. The policy will be accepted at all Russian consulates abroad and will be issued in accordance with the relevant requirements.

Our partner is LEXGARANT Insurance Company, registration number in the Unified State Register of Insurance Agents: 0348. Founded in March 1993, LEXGARANT is a member of many professional and sectoral associations

Insurance policies and certificates of insurance issued by LEXGARANT are recognized both in Russia and abroad. The entire pack of insurance documents can be provided both in Russian and English

Issue an insurance policy
Contact us

Privacy Policy

Privacy Policy

RUSVISA.travel and KOLOBOK.online
Version 9 September 2026

This policy explains how Octagon Labs OÜ processes personal data when you visit our service, contact us, use an account or order visa invitation letters, visa application assistance, including electronic visa applications, or travel insurance. It covers customers, travellers and authorised representatives. Reading this policy or using the website does not itself give consent to optional processing.

1 Who is responsible for your data

The controller is Octagon Labs OÜ, formerly Scantravel OÜ, an Estonian company with registry code 12063112. Our address is Pärnu mnt 142, 11317 Tallinn, Estonia. For privacy questions and requests, write to info@rusvisa.travel or to our postal address. A change of company name does not create a new legal entity.

2 The data we collect and its sources

Depending on your service, we process your name, date and place of birth, nationality, contact details, passport details and copies, photograph, travel dates, itinerary, accommodation or host details, invitation information, visa application answers and supporting documents. Applications may also require employment, education, family or previous travel information. We collect only what is needed for the selected service.

We also process order and account details, correspondence, application status, invoices, payment references and transaction status. Website use may generate IP addresses, device and browser information, access times, security logs and cookie or similar identifiers, subject to the rules in section 8.

Data normally comes from you. It may also come from the traveller, a parent or other authorised representative, a booking agent or corporate customer, and service providers or authorities handling your order. If another person supplies your data, we provide the applicable privacy information within the GDPR deadlines, normally by our first communication or disclosure and no later than one month after obtaining it, unless a lawful exception applies.

If you order for another person, give them this policy and make sure you are authorised to provide their details. A representative’s agreement is not automatically valid consent on behalf of an adult traveller. For children, we verify parental or other lawful authority as needed.

3 Required information and sensitive answers

Fields needed for an application, payment or statutory record are identified when requested. Without necessary information we may be unable to accept the order, complete the application or provide the selected service. Optional marketing consent is not required to buy a service.

Do not send unrelated medical records or other sensitive information. Where a requested service requires health or other special-category data, we identify the relevant Article 9 GDPR condition before collection and obtain separate explicit consent where that is the applicable condition. Passport photographs are not automatically biometric data; they become biometric data within Article 9 when technically processed for unique identification. Criminal-conviction and offence data requires authorisation under Article 10, not merely consent; absent that authorisation, you must enter such answers directly on the official portal without sending them to us.

 

 

Why we process data and who receives it

4 Purposes and legal grounds

Application and order processing: we use the necessary identity, travel, contact and application information to assess your request, prepare documents, arrange the ordered services, communicate with you and manage payments or refunds. Where you are our contracting customer, the basis is Article 6(1)(b) GDPR, including steps you request before a contract.

Where a company or another person contracts for a traveller, Article 6(1)(b) does not automatically cover that traveller. For ordinary data, we assess Article 6(1)(f): our and the customer’s legitimate interest in arranging the authorised travel service, balanced against the traveller’s rights. We use another basis where required. Special-category data and international transfers require the additional conditions described in sections 3 and 6.

Accounting and binding legal duties: we retain required transaction records and respond to legally binding requests under Article 6(1)(c), including obligations under the Estonian Accounting Act. A foreign authority’s requirement does not by itself establish an EU legal obligation under this provision.

Security, complaints and legal claims: we use relevant account, transaction and correspondence data under Article 6(1)(f) to prevent abuse, resolve disputes and establish, exercise or defend claims. We assess necessity and balance these interests against your rights. Service improvement based on identifiable feedback is subject to the same assessment; tracking and marketing follow the consent rules below.

Optional marketing and non-essential tracking: we rely on Article 6(1)(a) consent. We request this separately and you may refuse or withdraw it. Operational messages about an order are part of providing the service. We do not treat acceptance of contract terms as permission for advertising.

5 Recipients of personal data

Access is limited to people and organisations that need the information for the relevant purpose. Depending on your order, recipients include authorised staff; hosting, IT, account-management and communications providers; payment providers, banks and accountants; invitation issuers, travel partners and insurers; visa centres, consulates and competent Russian authorities, including the Ministry of Foreign Affairs through its official visa portals; and professional advisers or authorities where disclosure is legally justified.

A provider acting only on our instructions must be bound by an appropriate data-processing agreement. Banks, insurers, invitation issuers and government bodies may instead act as independent controllers where they determine their own purposes and legal duties. Their privacy notices apply to their own processing. We disclose only the data needed for the selected service, rather than making every order available to every partner.

The insurer or invitation issuer used for your order is identified in the relevant service or order documents. You can request details of recipients and the applicable transfer safeguards at director@octagon.ink. We do not sell personal data.

 

 

International transfers and retention

6 Transfers outside the European Economic Area

Your selected service may require sending identity, passport, photograph, travel and application information to invitation issuers, insurers, visa centres or public authorities in Russia. Entering information on an official Russian visa portal is also a disclosure to the receiving authority. Other suppliers may process data outside the European Economic Area, including through remote access.

Russia is not covered by a European Commission adequacy decision. Protection and remedies may differ from those in the European Economic Area, and authorities may access data under local law. A contract for visa assistance or acceptance of this policy does not, by itself, authorise an international transfer.

Before a transfer, we identify its recipient, country and lawful mechanism. Where applicable, we use an adequacy decision or appropriate safeguards under Article 46 GDPR, such as the European Commission’s standard contractual clauses, together with an assessment of the destination and any necessary supplementary measures. We do not assume that a contract clause alone makes every transfer lawful.

Only where its specific conditions are met may a derogation under Article 49 apply. In particular, the contract-related derogations require strict necessity and an occasional transfer; they are not a blanket basis for routine outsourcing or repeated operational transfers. Where explicit consent to a particular transfer is the appropriate derogation, we first explain the recipient, data, purpose and risks arising from the absence of an adequacy decision and appropriate safeguards, and request that consent separately.

Before collecting data for a service requiring such a transfer, we provide the applicable recipient, destination and mechanism in the service-specific notice. You may request a copy or description of safeguards, with necessary redactions, using our privacy contact. If a lawful mechanism is unavailable, we do not carry out the affected transfer and explain the effect on the service. Withdrawal cannot undo data already lawfully disclosed or require a foreign authority to disregard its own retention duties.

7 How long we keep data

We keep identifiable data only while needed for its purpose. Application working files, passport copies and photographs are kept through completion of the service and any necessary correction or follow-up, then deleted unless a specific legal duty or documented dispute requires particular items. We do not keep a complete passport or application file merely because an invoice must be retained.

Account information is kept while the account is active and needed to provide access to ongoing services or documents. We review inactive accounts and remove data no longer needed. Unconverted enquiries are kept only for the period needed to answer and conclude the enquiry. Security logs are retained only for the necessary detection and investigation period; incident evidence may be isolated for longer where justified.

Accounting source documents are retained for seven years from the end of the financial year in which the transaction was recorded, subject to other applicable statutory rules. Records needed for a complaint or claim are kept for the relevant limitation period and, if a dispute arises, until its final resolution and any required enforcement period.

Marketing contact data is kept until consent is withdrawn or the purpose ends. A minimal suppression record may be retained to honour an opt-out, and proportionate consent records to demonstrate compliance. Cookie lifetimes are specified in the applicable cookie information. Deleted data remaining in restricted backups is removed through the backup lifecycle and is not restored to ordinary use without reapplying deletion requirements.

 

 

Cookies security and your rights

8 Cookies and similar technologies

Strictly necessary technologies support functions you request, such as session management, security and remembering privacy choices. Other technologies, including audience analytics, advertising pixels and cross-site tracking, require your prior consent. Declining them must not prevent access to the core service.

Before optional technologies are enabled, the cookie information must identify their providers, purposes, data, lifetimes and relevant international transfers, and offer a way to accept, reject or choose categories. Consent must be as easy to withdraw as to give. Browser controls can delete or block cookies but do not replace our obligation to obtain prior consent. If an optional technology cannot meet these requirements, it must remain disabled.

Third-party links lead to services governed by their own notices. An embedded third-party tracker or plugin is still subject to the applicable consent and disclosure rules on our website. Contact info@rusvisa.travel for information about cookies or to withdraw a consent given to us.

9 Security and automated decisions

We apply technical and organisational measures proportionate to the risks, including access restrictions, confidentiality requirements, secure handling of application documents and incident procedures. No transmission or storage method is completely risk-free. Where a breach meets the applicable notification thresholds, we notify the supervisory authority and affected people within the required periods.

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Visa decisions are made by the competent authorities, whose own processes and privacy rules apply. If we introduce processing covered by Article 22 GDPR, we will provide the required information and safeguards before it begins.

10 Your rights and how to use them

Subject to the GDPR conditions, you may request access and a copy of your data, correction, erasure and restriction of processing. You may receive data you supplied in a structured, commonly used, machine-readable format and request its transfer to another controller where processing is automated and based on consent or a contract.

You may object on grounds relating to your situation to processing based on legitimate interests. We then stop unless the GDPR permits continuation, including for overriding compelling grounds or legal claims. You may object to direct marketing at any time, including related profiling, and we will stop that processing.

You may withdraw consent at any time by writing to director@octagon.ink or using the relevant withdrawal control. This does not affect the lawfulness of earlier processing. Where the withdrawn consent is necessary for a particular optional or sensitive-data service, we explain which part can no longer be performed.

Send requests to info@rusvisa.travel. We may ask for proportionate information to verify identity. We respond without undue delay and normally within one month; where legally justified, we may extend by up to two further months and explain why within the first month. Requests are normally free of charge. Refusal or a reasonable fee is possible only in the circumstances permitted by the GDPR.

You may complain to the Estonian Data Protection Inspectorate, Andmekaitse Inspektsioon, at info@aki.ee, Tatari 39, 10134 Tallinn, Estonia, or through www.aki.ee. You may also complain to a competent authority in the EU/EEA country of your habitual residence, place of work or the alleged infringement, and seek a judicial remedy.

11 Changes to this policy

We publish the current version with its revision date and bring material changes to your attention as appropriate. A policy update does not replace consent where new consent is required. This policy is governed by the GDPR and applicable Estonian law without limiting mandatory rights available to you.