Last updated: January 2026
This Privacy Policy explains how ESIMSS (“Company”, “we”, “us”, or “our”) processes personal data of users located in the European Economic Area (EEA) in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
For the purposes of the GDPR, the data controller is:
ESIMSS
Website: https://esimss.com
Email: info@esimss.com
2. Legal Bases for Processing (Article 6 GDPR)
We process personal data only when at least one of the following legal bases applies:
Performance of a contract (Article 6(1)(b))
→ to provide eSIM services, process orders, deliver products, and manage accountsLegal obligation (Article 6(1)(c))
→ to comply with tax, accounting, and regulatory requirementsLegitimate interests (Article 6(1)(f))
→ to improve services, prevent fraud, ensure security, and analyze Website performanceConsent (Article 6(1)(a))
→ for marketing communications and non-essential cookies
(you may withdraw consent at any time)
3. Categories of Personal Data Processed
3.1 Identification & Contact Data
Name
Email address
Phone number (if provided)
Billing information
3.2 Transaction Data
Order details
Payment status
Purchase history
Payment card data is processed only by certified third-party payment providers.
3.3 Technical & Usage Data
IP address
Device type
Browser and OS
Approximate location (country/region)
Log files and timestamps
3.4 eSIM Service Data
eSIM activation status
Device compatibility data
Network metadata (non-content)
🚫 We do not monitor, log, or store internet traffic content.
4. Data Recipients
We may share personal data with:
Payment processors (e.g., Stripe, PayPal)
Hosting and infrastructure providers
Analytics and performance service providers
Customer support tools
Legal or regulatory authorities when required by law
All processors act under Data Processing Agreements (DPA) in accordance with Article 28 GDPR.
5. International Data Transfers
Your personal data may be transferred outside the EEA.
Where such transfers occur, we ensure adequate safeguards, including:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions where applicable
Technical and organizational security measures
6. Data Retention
We retain personal data only for as long as necessary to:
Fulfill contractual obligations
Comply with legal requirements
Resolve disputes
Enforce agreements
Retention periods vary depending on data category and legal obligations.
7. Data Subject Rights (Articles 12–23 GDPR)
As an EU data subject, you have the right to:
Access your personal data (Art. 15)
Rectification of inaccurate data (Art. 16)
Erasure (“right to be forgotten”) (Art. 17)
Restriction of processing (Art. 18)
Data portability (Art. 20)
Object to processing (Art. 21)
Withdraw consent at any time (Art. 7)
To exercise your rights, contact us at:
📧 info@esimss.com
We respond within 30 days, as required by GDPR.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with your local Supervisory Authority if you believe your data protection rights have been violated.
9. Cookies & Tracking (GDPR compliant)
We use cookies only with appropriate consent, except for strictly necessary cookies.
Users in the EU are provided with:
Cookie consent banner
Ability to accept/reject non-essential cookies
Clear information about cookie usage
10. Security Measures
We apply appropriate technical and organizational measures, including:
Data encryption
Access controls
Secure hosting infrastructure
Regular security reviews
11. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on users (Article 22 GDPR).
12. Children’s Data
Our services are not intended for individuals under 18 years of age.
We do not knowingly process children’s personal data.
13. Changes to This Policy
We may update this GDPR Privacy Policy periodically.
The latest version will always be available on this page.
14. Contact Details
For any GDPR-related questions or requests: