eSIM SurfereSIM Surfer

Privacy Policy

Effective from: 22 January 2025

The purpose of this Privacy Policy is to inform you how we collect, process, store and protect your personal data when you use the eSIM Surfer mobile application and related services, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and Hungarian data-protection legislation, in particular 2011. évi CXII. törvény (Infotv.; Act CXII of 2011 on informational self-determination and freedom of information).

Please read this document carefully before using our services.


1. Details of the Data Controller

Name: Derecskei Miklós egyéni vállalkozó

Registered office: 1039 Budapest, Jendrassik György utca 2., Magyarország

Tax number: 90374571-1-41

Registration number: 59560355

Email: support@esimsurfer.app

Website: https://esimsurfer.app

Under Article 37 GDPR, the Data Controller is not required to appoint, and has not appointed, a data protection officer. You may contact the Data Controller directly using the contact details above with any data-protection queries.


2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data (including collection, recording, storage, alteration and erasure).
  • Data Controller: the natural or legal person which determines the purposes and means of processing personal data.
  • Data Processor: the natural or legal person which processes personal data on behalf of the Data Controller.
  • Data subject: any natural person identified or identifiable on the basis of any information (you, as a user).

3. Legal bases for processing

We process your personal data on one of the following legal bases:

  • a) Performance of a contract (Article 6(1)(b) GDPR): processing necessary to perform the contract concluded with you (for example, providing the eSIM service and invoicing).
  • b) Legal obligation (Article 6(1)(c) GDPR): compliance with statutory obligations (for example, retention of accounting records).
  • c) Legitimate interests (Article 6(1)(f) GDPR): pursuit of the Data Controller's legitimate interests (for example, fraud prevention and maintaining service security).
  • d) Consent (Article 6(1)(a) GDPR): based on your voluntary consent (for example, marketing notifications).

4. Categories and purposes of personal data processed

4.1. Registration and account management

DataPurposeLegal basisRetention
Email addressIdentification, sign-in, communicationContractUntil account deletion
NameInvoicing, form of addressContractUntil account deletion
Language preferenceUser experienceContractUntil account deletion

4.2. Authentication

DataPurposeLegal basisRetention
Magic-link token (hashed)One-time sign-inContract15 minutes
Refresh token (hashed)Maintaining the sessionContract30 days
Passkey data (public key, credential ID)Passwordless sign-inContractUntil account deletion

4.3. Invoicing and payment

DataPurposeLegal basisRetention
Billing name, addressIssuing invoicesLegal obligation8 years
Payment transaction identifierTracking paymentLegal obligation8 years
Invoice dataAccounting recordsLegal obligation8 years (2000. évi C. tv.)

4.4. eSIM service

DataPurposeLegal basisRetention
ICCID (SIM identifier)eSIM identificationContractUntil account deletion
QR code, activation dataeSIM installationContractUntil account deletion
Data-usage statisticsDisplaying usageContractUntil account deletion

4.5. Device and technical data

DataPurposeLegal basisRetention
Push-notification tokenSending notificationsConsentUntil account deletion
Device type, OS versionCompatibility, troubleshootingLegitimate interestsUntil account deletion
IP address, User-AgentSecurity, abuse preventionLegitimate interests1 year

4.6. Website analytics

DataPurposeLegal basisRetention
Page visit, URLAnalysing website useLegitimate interestsAggregated, 24 hours
Referrer (referring page)Analysing traffic sourcesLegitimate interestsAggregated, 24 hours
Country, region (GeoIP)Geographic statisticsLegitimate interestsAggregated, 24 hours
Device type, browserImproving compatibilityLegitimate interestsAggregated, 24 hours

For website analytics, we use Vercel Analytics, which does not use cookies, does not store IP addresses and does not individually identify visitors. Data is collected anonymously and in aggregated form.

To analyse use of the mobile application, we use PostHog (with EU data storage in Frankfurt). On the basis of legitimate interests, PostHog processes event data (for example, screen views and button presses), as well as device and operating-system data, to improve the Service and identify faults. This data is not transferred outside the European Union.


5. Data Processors

To provide the service, we engage the following Data Processors, which process your data on the Data Controller's instructions and under contractual obligations:

ProviderActivityData processedData-storage location
Stripe Payments Europe Ltd.Payment processingEmail address, billing dataIreland (EU)
Airalo Singapore Pte. Ltd.eSIM serviceEmail address, ICCID, usage dataSingapore
Billingo Technologies Zrt.InvoicingName, address, email address, purchase detailsHungary (EU)
Resend, Inc.Email deliveryEmail address, email contentIreland (EU)
Expo (650 Industries, Inc.)Push notificationsPush token, device informationUSA*
DigitalOcean, LLCHostingAll stored dataFrankfurt, Germany (EU)
Vercel Inc.Website analyticsAnonymous visitor dataUSA*
PostHog Inc. (EU Cloud)Application analyticsEvent data, device and OS data, anonymous/identified user IDFrankfurt, Germany (EU)

* Expo (650 Industries, Inc.) and Vercel Inc. participate in the EU–US Data Privacy Framework and therefore provide appropriate safeguards for data protection.


6. International data transfers

We primarily store and process your personal data in the European Union. If data is transferred outside the EU during processing (for example, to the USA or Singapore), we apply one of the following safeguards:

  • Adequacy decision: Countries deemed adequate by the European Commission (for example, the EU–US Data Privacy Framework)
  • Standard contractual clauses (SCCs): Contractual terms approved by the European Commission
  • Binding corporate rules (BCRs): For transfers within a group of companies

7. Your rights (data-subject rights)

Under the GDPR, you have the following rights in relation to your personal data:

a) Right of access (Article 15 GDPR)

You are entitled to request confirmation as to whether your personal data is being processed and, if so, to access the data being processed.

b) Right to rectification (Article 16 GDPR)

You are entitled to request rectification of inaccurate personal data or completion of incomplete data.

c) Right to erasure ('right to be forgotten', Article 17 GDPR)

You are entitled to request erasure of your personal data if the legal basis for processing has ceased to apply or you object to the processing.

d) Right to restriction (Article 18 GDPR)

You are entitled to request restriction of processing if you contest the accuracy of the data or the processing is unlawful.

e) Right to data portability (Article 20 GDPR)

You are entitled to receive data concerning you in a structured, machine-readable format and transmit it to another data controller.

f) Right to object (Article 21 GDPR)

You are entitled to object to processing of your personal data based on legitimate interests, including processing for direct-marketing purposes.

g) Withdrawal of consent

Where processing is based on your consent, you may withdraw it at any time without giving reasons. Withdrawal does not affect the lawfulness of processing before withdrawal.

How to exercise your rights:

We will respond to requests without undue delay and at the latest within one month of receipt. This period may be extended by up to a further two months, taking into account the complexity and number of requests; we will inform you of any extension and its reasons within one month of receipt (Article 12(3) GDPR).


8. Automated decision-making and profiling

The Data Controller does not use decision-making based solely on automated processing, including profiling, which would produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).


9. Children's data

The Service is not directed at children under 16, and the Data Controller does not knowingly collect personal data concerning children under 16. If the Data Controller becomes aware that it processes a child's personal data without the consent of a parent or legal representative, it will erase that data without delay. If you are a parent or legal representative and believe that your child has provided us with personal data, please notify us at support@esimsurfer.app.


10. Data security

The Data Controller applies appropriate technical and organisational measures to protect your personal data:

  • Encrypted data transmission (HTTPS/TLS)
  • Hashed storage of passwords and tokens
  • Regular backups
  • Access controls and logging
  • Regular security reviews

11. Remedies

If you consider that we have infringed your rights in processing your personal data, the following options are available to you:

Complaint to the Data Controller

Email: support@esimsurfer.app

Complaint to the supervisory authority

National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9–11.

Telephone: +36 (1) 391-1400

Email: ugyfelszolgalat@naih.hu

Website: https://naih.hu

Judicial remedy

In the event of an infringement of your rights, you may bring proceedings before a court. Proceedings may also be commenced before the regional court having jurisdiction over your place of residence or stay.


12. Amendments to the Privacy Policy

The Data Controller reserves the right to amend this Privacy Policy unilaterally. Users will be notified of amendments in the application or by email. Continued use of the service constitutes acceptance of the amended terms.


Contact

Please contact us with any data-protection queries:

Email: support@esimsurfer.app

Data Controller: Derecskei Miklós egyéni vállalkozó

Address: 1039 Budapest, Jendrassik György utca 2., Magyarország

Last updated: 22 January 2025.