Privacy Policy
Effective from: 22 January 2025
The purpose of this Privacy Policy is to inform you how we collect, process, store and protect your personal data when you use the eSIM Surfer mobile application and related services, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and Hungarian data-protection legislation, in particular 2011. évi CXII. törvény (Infotv.; Act CXII of 2011 on informational self-determination and freedom of information).
Please read this document carefully before using our services.
1. Details of the Data Controller
Name: Derecskei Miklós egyéni vállalkozó
Registered office: 1039 Budapest, Jendrassik György utca 2., Magyarország
Tax number: 90374571-1-41
Registration number: 59560355
Email: support@esimsurfer.app
Website: https://esimsurfer.app
Under Article 37 GDPR, the Data Controller is not required to appoint, and has not appointed, a data protection officer. You may contact the Data Controller directly using the contact details above with any data-protection queries.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data (including collection, recording, storage, alteration and erasure).
- Data Controller: the natural or legal person which determines the purposes and means of processing personal data.
- Data Processor: the natural or legal person which processes personal data on behalf of the Data Controller.
- Data subject: any natural person identified or identifiable on the basis of any information (you, as a user).
3. Legal bases for processing
We process your personal data on one of the following legal bases:
- a) Performance of a contract (Article 6(1)(b) GDPR): processing necessary to perform the contract concluded with you (for example, providing the eSIM service and invoicing).
- b) Legal obligation (Article 6(1)(c) GDPR): compliance with statutory obligations (for example, retention of accounting records).
- c) Legitimate interests (Article 6(1)(f) GDPR): pursuit of the Data Controller's legitimate interests (for example, fraud prevention and maintaining service security).
- d) Consent (Article 6(1)(a) GDPR): based on your voluntary consent (for example, marketing notifications).
4. Categories and purposes of personal data processed
4.1. Registration and account management
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Identification, sign-in, communication | Contract | Until account deletion |
| Name | Invoicing, form of address | Contract | Until account deletion |
| Language preference | User experience | Contract | Until account deletion |
4.2. Authentication
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Magic-link token (hashed) | One-time sign-in | Contract | 15 minutes |
| Refresh token (hashed) | Maintaining the session | Contract | 30 days |
| Passkey data (public key, credential ID) | Passwordless sign-in | Contract | Until account deletion |
4.3. Invoicing and payment
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Billing name, address | Issuing invoices | Legal obligation | 8 years |
| Payment transaction identifier | Tracking payment | Legal obligation | 8 years |
| Invoice data | Accounting records | Legal obligation | 8 years (2000. évi C. tv.) |
4.4. eSIM service
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| ICCID (SIM identifier) | eSIM identification | Contract | Until account deletion |
| QR code, activation data | eSIM installation | Contract | Until account deletion |
| Data-usage statistics | Displaying usage | Contract | Until account deletion |
4.5. Device and technical data
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Push-notification token | Sending notifications | Consent | Until account deletion |
| Device type, OS version | Compatibility, troubleshooting | Legitimate interests | Until account deletion |
| IP address, User-Agent | Security, abuse prevention | Legitimate interests | 1 year |
4.6. Website analytics
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Page visit, URL | Analysing website use | Legitimate interests | Aggregated, 24 hours |
| Referrer (referring page) | Analysing traffic sources | Legitimate interests | Aggregated, 24 hours |
| Country, region (GeoIP) | Geographic statistics | Legitimate interests | Aggregated, 24 hours |
| Device type, browser | Improving compatibility | Legitimate interests | Aggregated, 24 hours |
For website analytics, we use Vercel Analytics, which does not use cookies, does not store IP addresses and does not individually identify visitors. Data is collected anonymously and in aggregated form.
To analyse use of the mobile application, we use PostHog (with EU data storage in Frankfurt). On the basis of legitimate interests, PostHog processes event data (for example, screen views and button presses), as well as device and operating-system data, to improve the Service and identify faults. This data is not transferred outside the European Union.
5. Data Processors
To provide the service, we engage the following Data Processors, which process your data on the Data Controller's instructions and under contractual obligations:
| Provider | Activity | Data processed | Data-storage location |
|---|---|---|---|
| Stripe Payments Europe Ltd. | Payment processing | Email address, billing data | Ireland (EU) |
| Airalo Singapore Pte. Ltd. | eSIM service | Email address, ICCID, usage data | Singapore |
| Billingo Technologies Zrt. | Invoicing | Name, address, email address, purchase details | Hungary (EU) |
| Resend, Inc. | Email delivery | Email address, email content | Ireland (EU) |
| Expo (650 Industries, Inc.) | Push notifications | Push token, device information | USA* |
| DigitalOcean, LLC | Hosting | All stored data | Frankfurt, Germany (EU) |
| Vercel Inc. | Website analytics | Anonymous visitor data | USA* |
| PostHog Inc. (EU Cloud) | Application analytics | Event data, device and OS data, anonymous/identified user ID | Frankfurt, Germany (EU) |
* Expo (650 Industries, Inc.) and Vercel Inc. participate in the EU–US Data Privacy Framework and therefore provide appropriate safeguards for data protection.
6. International data transfers
We primarily store and process your personal data in the European Union. If data is transferred outside the EU during processing (for example, to the USA or Singapore), we apply one of the following safeguards:
- Adequacy decision: Countries deemed adequate by the European Commission (for example, the EU–US Data Privacy Framework)
- Standard contractual clauses (SCCs): Contractual terms approved by the European Commission
- Binding corporate rules (BCRs): For transfers within a group of companies
7. Your rights (data-subject rights)
Under the GDPR, you have the following rights in relation to your personal data:
a) Right of access (Article 15 GDPR)
You are entitled to request confirmation as to whether your personal data is being processed and, if so, to access the data being processed.
b) Right to rectification (Article 16 GDPR)
You are entitled to request rectification of inaccurate personal data or completion of incomplete data.
c) Right to erasure ('right to be forgotten', Article 17 GDPR)
You are entitled to request erasure of your personal data if the legal basis for processing has ceased to apply or you object to the processing.
d) Right to restriction (Article 18 GDPR)
You are entitled to request restriction of processing if you contest the accuracy of the data or the processing is unlawful.
e) Right to data portability (Article 20 GDPR)
You are entitled to receive data concerning you in a structured, machine-readable format and transmit it to another data controller.
f) Right to object (Article 21 GDPR)
You are entitled to object to processing of your personal data based on legitimate interests, including processing for direct-marketing purposes.
g) Withdrawal of consent
Where processing is based on your consent, you may withdraw it at any time without giving reasons. Withdrawal does not affect the lawfulness of processing before withdrawal.
How to exercise your rights:
- In the application: Profile → Settings
- By email: support@esimsurfer.app
We will respond to requests without undue delay and at the latest within one month of receipt. This period may be extended by up to a further two months, taking into account the complexity and number of requests; we will inform you of any extension and its reasons within one month of receipt (Article 12(3) GDPR).
8. Automated decision-making and profiling
The Data Controller does not use decision-making based solely on automated processing, including profiling, which would produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
9. Children's data
The Service is not directed at children under 16, and the Data Controller does not knowingly collect personal data concerning children under 16. If the Data Controller becomes aware that it processes a child's personal data without the consent of a parent or legal representative, it will erase that data without delay. If you are a parent or legal representative and believe that your child has provided us with personal data, please notify us at support@esimsurfer.app.
10. Data security
The Data Controller applies appropriate technical and organisational measures to protect your personal data:
- Encrypted data transmission (HTTPS/TLS)
- Hashed storage of passwords and tokens
- Regular backups
- Access controls and logging
- Regular security reviews
11. Remedies
If you consider that we have infringed your rights in processing your personal data, the following options are available to you:
Complaint to the Data Controller
Email: support@esimsurfer.app
Complaint to the supervisory authority
National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11.
Telephone: +36 (1) 391-1400
Email: ugyfelszolgalat@naih.hu
Website: https://naih.hu
Judicial remedy
In the event of an infringement of your rights, you may bring proceedings before a court. Proceedings may also be commenced before the regional court having jurisdiction over your place of residence or stay.
12. Amendments to the Privacy Policy
The Data Controller reserves the right to amend this Privacy Policy unilaterally. Users will be notified of amendments in the application or by email. Continued use of the service constitutes acceptance of the amended terms.
Contact
Please contact us with any data-protection queries:
Email: support@esimsurfer.app
Data Controller: Derecskei Miklós egyéni vállalkozó
Address: 1039 Budapest, Jendrassik György utca 2., Magyarország
Last updated: 22 January 2025.
