Privacy Policy

Last updated: 14 July 2026

This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the DataSIM website (data-sim.app), mobile applications, and eSIM services (together, the “Services”). We keep this policy in plain language — the same way we keep our product simple: no physical SIM, no eKYC, and no more data collected than we need.

1. Who We Are

The data controller for your personal data is ZEUST LIMITED, a company registered in Cyprus (registration no. HE 362856), trading as DataSIM.
Privacy contact: support@data-sim.app (subject line “Privacy”).

2. Data We Collect

  • Account data — when you sign in with Google or Apple, we receive your name and email address (or Apple’s private relay email if you choose “Hide My Email”) and a unique authentication identifier from the sign-in provider. We never receive or store your Google or Apple password.
  • Purchase & payment data — the plans you buy, transaction amounts, billing country, and payment method details. Full card numbers are handled by our payment processors, not stored by us.
  • Device data — device model, operating system, app version, language, and eSIM identifiers (such as ICCID and EID) needed to deliver and manage your eSIM.
  • Usage & connection data — data consumption, plan activation events, network registration, and technical connection logs generated when your eSIM is used.
  • Fraud-prevention signals — IP address, approximate location derived from it, and related technical indicators collected at registration, purchase, and refund requests.
  • Support communications — messages you send us by email, in-app chat, or WhatsApp.

We do not require identity documents or eKYC to sell travel data plans, and we do not collect the content of your internet traffic.

3. How and Why We Use Your Data

We process your personal data on the following legal bases under the EU General Data Protection Regulation (GDPR):

  • Performance of a contract — to create your account, deliver and manage your eSIM, process payments, provide top-ups, and respond to support requests.
  • Legal obligation — to keep billing and tax records, comply with telecommunications and consumer law, and respond to valid legal process (see Section 8).
  • Legitimate interests — to secure our platform, detect and prevent fraud and payment abuse, analyze aggregate usage to improve the Services, and defend legal claims (including payment disputes, where we may use installation, activation, and usage records as evidence).
  • Consent — for marketing emails and non-essential cookies. You can withdraw consent at any time without affecting the Services.

4. Who We Share Data With

We share personal data only where needed to run the Services:

  • Connectivity providers — the eSIM platform and mobile network partners that provision your eSIM and carry your data traffic (based in the UK, EU, and Asia depending on your plan).
  • Payment processors and acquirers — to process card and digital payments and handle refunds and disputes.
  • Authentication provider — Google Firebase Authentication, which handles sign-in with Google and Apple on our behalf.
  • App stores — Apple and Google, when you purchase or manage subscriptions through their platforms.
  • IT and service providers — hosting, email delivery, customer-support tooling, and analytics providers acting on our instructions.
  • Fraud-prevention providers — IP intelligence services used to detect fraudulent transactions.
  • Advertising platforms — such as Google and Meta, in aggregated or pseudonymized form, to measure and improve our advertising.
  • Authorities — where required by law (see Section 8).
  • Corporate transactions — in connection with a merger, acquisition, or sale of assets, subject to this policy.

We do not sell your personal data.

5. International Transfers

Because travel connectivity is global, your data may be processed outside your country of residence, including in the United Kingdom (covered by an EU adequacy decision) and other countries. Where data is transferred outside the EU/EEA to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

6. How Long We Keep Data

  • Account data — for as long as your account is active, then deleted or anonymized within a reasonable period after closure.
  • Billing and transaction records — up to 6 years, as required by Cyprus tax and accounting law.
  • Connection and usage logs — for a limited period (currently up to 12 months) for network operation, fraud prevention, dispute resolution, and compliance with lawful requests.
  • Support communications — for up to 2 years after the ticket is resolved.

When data is no longer needed, we securely delete or anonymize it.

7. Your Rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your data (“right to be forgotten”), subject to legal retention obligations;
  • Restrict or object to certain processing, including processing based on legitimate interests;
  • Receive your data in a portable format;
  • Withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, email support@data-sim.app with the subject “Privacy”. We respond within one month. You also have the right to lodge a complaint with your local data protection authority or with our supervisory authority, the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (dataprotection.gov.cy).

8. Law Enforcement & Legal Requests

We disclose personal data to law enforcement or other authorities only in response to valid legal process applicable to us (such as court orders, statutory notices, or lawful subpoenas), and we limit any disclosure to what the request lawfully requires. We review every request before responding.

9. Marketing

If you opt in (or where permitted, as an existing customer), we may send you emails about new destinations, plans, and offers. Every marketing email contains an unsubscribe link, and you can opt out at any time without affecting your Services. We also advertise on platforms such as Google and Meta; you can manage ad personalization directly in your settings on those platforms.

10. Cookies

Our website uses cookies and similar technologies. Essential cookies are required for the site to function; analytics and advertising cookies are used only with your consent, which you can give or withdraw via the cookie banner on our website. You can also control cookies in your browser settings, though disabling essential cookies may affect site functionality.

11. Security

We apply appropriate technical and organizational measures — including encryption in transit, access controls, and monitoring — to protect your personal data against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure, but we work to protect your data in line with industry standards.

12. Children

Our Services are not directed at children under 18, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes, we will notify you by email or in-app notice.

14. Contact

ZEUST LIMITED (trading as DataSIM)
Registered in Cyprus, company no. HE 362856
Address: 1 Avlonos Street, Maria House, 1075 Nicosia, Cyprus.
Contact: support@data-sim.app