Data Processing Agreement

Last updated: 16 August 2026Effective from: 16 August 2026

Skybyte — a trading name of Banxs Technologies EOOD

Version 2.0


Preamble

This Data Processing Agreement (the "DPA") forms part of, and is subject to, the Skybyte Terms of Service (the "Principal Agreement") between Banxs Technologies EOOD, trading as Skybyte ("Skybyte", "Processor", "we", "us") and the business customer identified in the Principal Agreement ("Customer", "Controller", "you").

This DPA applies only where the Customer is acting in the course of a trade, business, craft or profession and where Skybyte processes Personal Data on the Customer's behalf. It is intended primarily for organisations that purchase Skybyte eSIM connectivity for their employees, contractors, delegates or other individuals whose Personal Data the organisation controls.

It does not apply to individual consumers. Where a natural person purchases a Skybyte eSIM for their own use, Skybyte acts as an independent Controller in respect of that individual's Personal Data, and the Skybyte Privacy Policy governs that relationship in full. Nothing in this DPA is intended to reduce, qualify or displace the rights that individual purchasers enjoy under Regulation (EU) 2016/679 or the Bulgarian Personal Data Protection Act.

Where this DPA conflicts with the Principal Agreement in respect of the processing of Personal Data, this DPA prevails. Where this DPA conflicts with the Standard Contractual Clauses incorporated under Section 9, the Standard Contractual Clauses prevail.

Parties

Processor

Banxs Technologies EOOD (trading as Skybyte) Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria EIK: 206285017 VAT: BG206285017 Registered with the Bulgarian Registry Agency (Търговски регистър)

Contact for all matters arising under this DPA: contact@banxs.com

Controller

The business entity identified in the Principal Agreement, including its Affiliates where they receive the Services under the same account.


1. Definitions

1.1 Terms defined in the GDPR bear the same meaning in this DPA. In particular, "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority", "Personal Data Breach" and "Special Categories of Personal Data" carry their GDPR meanings.

1.2 In addition, the following definitions apply:

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means ownership of more than 50% of voting securities or the power to direct management.

"Applicable Data Protection Law" means, as applicable to the processing in question: (a) Regulation (EU) 2016/679 (the "GDPR"); (b) the Bulgarian Personal Data Protection Act (Закон за защита на личните данни) and its implementing regulations; (c) Directive 2002/58/EC as implemented in Bulgaria and in the Customer's jurisdiction (the "ePrivacy Directive"); (d) the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018 (the "UK GDPR") together with the Data Protection Act 2018; and (e) any other data protection or privacy legislation applicable to a party's processing under this DPA.

"Customer Personal Data" means Personal Data that Skybyte processes on the Customer's behalf under the Principal Agreement, as further described in Appendix 1.

"eSIM" means an embedded subscriber identity module profile provisioned electronically to a compatible device, together with the associated mobile data entitlement.

"ICCID" means the Integrated Circuit Card Identifier uniquely identifying an eSIM profile.

"IMSI" means the International Mobile Subscriber Identity associated with a provisioned profile.

"Restricted Transfer" means a transfer of Personal Data from the European Economic Area to a third country not benefiting from an adequacy decision under Article 45 GDPR, or the equivalent under UK GDPR.

"Services" means the eSIM connectivity products and associated account, support, billing and reporting functions supplied by Skybyte under the Principal Agreement.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and, in respect of transfers subject to UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

"Sub-processor" means any processor engaged by Skybyte to process Customer Personal Data in connection with the Services.

"Supervisory Authority" means, in respect of Skybyte, the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни, the "CPDP"), and, in respect of the Customer, the competent supervisory authority in the Customer's jurisdiction.

"Technical and Organisational Measures" or "TOMs" means the measures described in Appendix 2.


2. Roles of the parties and scope

2.1 Allocation of roles. In respect of Customer Personal Data, the Customer is the Controller and Skybyte is the Processor. Where the Customer is itself acting as a processor on behalf of a third-party controller, the Customer warrants that it has the authority of that controller to appoint Skybyte as a sub-processor on the terms of this DPA, and references in this DPA to the Customer's instructions shall be read as instructions ultimately deriving from that controller.

2.2 Independent controller processing. Skybyte acts as an independent Controller, and this DPA does not apply, in respect of:

(a) Personal Data of the Customer's own personnel that Skybyte collects for the purposes of account administration, billing, credit assessment, fraud prevention and relationship management;

(b) Personal Data processed for the purposes of complying with Skybyte's own legal obligations, including obligations under the Bulgarian Accountancy Act, the Bulgarian Value Added Tax Act, the Bulgarian Measures Against Money Laundering Act, sanctions screening obligations, and payment card scheme rules;

(c) aggregated, de-identified or statistical data derived from use of the Services, provided such data cannot reasonably be used to identify any Data Subject, whether alone or in combination with other information reasonably available to Skybyte;

(d) network and service telemetry processed for the purposes of maintaining the security, integrity and availability of the Services;

(e) Personal Data of individual consumers who purchase eSIMs directly for their own use.

Where Skybyte acts as an independent Controller, the Skybyte Privacy Policy applies.

2.3 No joint controllership. Nothing in this DPA is intended to create a relationship of joint controllership under Article 26 GDPR. If a Supervisory Authority or court of competent jurisdiction determines that the parties are joint controllers in respect of any processing, the parties shall negotiate in good faith an arrangement under Article 26(1) GDPR within thirty (30) days of becoming aware of that determination.

2.4 Customer's controller obligations. The Customer warrants and undertakes that:

(a) it has established and will maintain a valid legal basis under Article 6 GDPR for all Customer Personal Data it discloses to Skybyte and for all processing it instructs Skybyte to perform;

(b) where required, it has provided Data Subjects with all information required by Articles 13 and 14 GDPR, including identifying Skybyte and its Sub-processors as recipients of their Personal Data;

(c) it has obtained any consent required under Applicable Data Protection Law, including under the ePrivacy Directive where applicable;

(d) its instructions to Skybyte will not cause Skybyte to breach Applicable Data Protection Law;

(e) it will not instruct Skybyte to process Special Categories of Personal Data, criminal conviction data, or the Personal Data of children under 16, and will not upload or submit such data to the Services. The Services are not designed to process such data and Appendix 2 does not describe measures appropriate to it.

2.5 Skybyte's reliance. Skybyte is entitled to rely on the Customer's warranties in Section 2.4 and is not obliged to verify, and does not verify, the lawfulness of the Customer's collection of Customer Personal Data or the adequacy of the notices the Customer provides to Data Subjects.


3. Duration of processing

3.1 This DPA takes effect on the earlier of (a) the effective date of the Principal Agreement and (b) the date Skybyte first processes Customer Personal Data.

3.2 This DPA continues for the duration of the Principal Agreement and, in respect of any Customer Personal Data retained after termination, until that data has been deleted or returned in accordance with Section 13.

3.3 Obligations that by their nature should survive termination — including Sections 6.2 (confidentiality), 12 (liability), 13 (deletion and return) and 14 (audit, in respect of the period during which processing occurred) — survive termination of this DPA and of the Principal Agreement.


4. Nature and purpose of processing

4.1 Skybyte processes Customer Personal Data solely for the purpose of providing the Services, namely:

(a) creating and administering Customer accounts and sub-accounts;

(b) accepting and processing orders for eSIM data plans;

(c) provisioning eSIM profiles through wholesale connectivity suppliers and delivering activation credentials (QR codes and manual installation parameters) to the individuals nominated by the Customer;

(d) recording and reporting data consumption against purchased allowances;

(e) issuing invoices, receipts and credit notes;

(f) providing customer and technical support in response to enquiries;

(g) detecting, investigating and preventing fraud, abuse and breaches of the Acceptable Use Policy;

(h) maintaining audit records required by Applicable Data Protection Law, Bulgarian financial regulation and payment card scheme rules;

(i) complying with lawful requests from competent authorities.

4.2 A detailed description of the processing operations, categories of Data Subjects and categories of Personal Data is set out in Appendix 1.


5. Processor obligations — instructions

5.1 Documented instructions. Skybyte shall process Customer Personal Data only on documented instructions from the Customer, including with regard to Restricted Transfers, unless required to do otherwise by Union or Member State law to which Skybyte is subject. Where such a legal requirement applies, Skybyte shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

5.2 What constitutes an instruction. The Customer's documented instructions comprise:

(a) this DPA and the Principal Agreement;

(b) the Customer's configuration and use of the Services through the account interface and any application programming interface Skybyte makes available;

(c) written instructions given by the Customer to Skybyte and acknowledged in writing by Skybyte.

The Customer may issue additional instructions during the term. Skybyte will use reasonable efforts to comply, but reserves the right to charge on a time-and-materials basis for instructions that fall outside the scope of the Services as configured, and to decline instructions that are technically infeasible or that would require material modification of the Services.

5.3 Unlawful instructions. Skybyte shall immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Skybyte may suspend performance of the affected instruction pending resolution, without liability, and without prejudice to its obligations under the Principal Agreement in respect of unaffected Services.

5.4 Limitation on use. Skybyte shall not:

(a) sell Customer Personal Data;

(b) use Customer Personal Data for its own marketing purposes or for the marketing purposes of any third party;

(c) use Customer Personal Data to train, fine-tune, evaluate or otherwise develop machine learning models, other than models operating solely on aggregated and de-identified data for the purposes of fraud detection and service reliability within Skybyte's own environment;

(d) combine Customer Personal Data with Personal Data obtained from other sources, except as strictly necessary for fraud prevention and security purposes;

(e) disclose Customer Personal Data to any third party other than a Sub-processor engaged in accordance with Section 8 or as required by law.


6. Processor obligations — personnel and confidentiality

6.1 Access limitation. Skybyte shall ensure that access to Customer Personal Data is limited to those personnel who require access in order to perform Skybyte's obligations under the Principal Agreement. Access is granted on a least-privilege basis, is subject to documented approval, and is reviewed at least quarterly.

6.2 Confidentiality. Skybyte shall ensure that all personnel authorised to process Customer Personal Data are subject to a binding contractual duty of confidentiality that survives termination of their engagement, or are under an appropriate statutory obligation of confidentiality.

6.3 Training. Skybyte shall ensure that personnel with access to Customer Personal Data receive data protection and information security training on appointment and at least annually thereafter, and that completion of such training is recorded.

6.4 Screening. Personnel with administrative access to production systems are subject to background verification proportionate to the sensitivity of the data accessible, to the extent permitted by applicable employment law.

6.5 Access logging. All administrative access to systems containing Customer Personal Data is logged to an append-only audit record, retained in accordance with Appendix 1 §7, and is reviewable by the Customer on request in accordance with Section 14.


7. Processor obligations — security

7.1 Article 32 measures. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity to the rights and freedoms of natural persons, Skybyte shall implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk.

7.2 The measures Skybyte has implemented are described in Appendix 2. The Customer has reviewed those measures and confirms that, in the context of the processing described in Appendix 1, they provide an appropriate level of security.

7.3 Changes to measures. Skybyte may update the measures described in Appendix 2 from time to time, provided that no update shall materially reduce the overall level of security. Skybyte shall publish the current version of Appendix 2 at the URL of this DPA and shall notify the Customer of material changes not less than thirty (30) days in advance.

7.4 Card data. Skybyte does not store, process or transmit full primary account numbers. Payment card data is captured directly by Skybyte's acquiring partner within that partner's PCI DSS-assessed environment. Skybyte's PCI DSS scope is limited to SAQ A. Skybyte retains only the card brand, the last four digits, the expiry month and year, and a token issued by the acquirer, each of which is used solely for transaction reference, fraud screening and refund processing. Further detail is set out in the Payment Disclosures.

7.5 Encryption. Customer Personal Data is encrypted in transit using TLS 1.2 or above (TLS 1.3 preferred) and at rest using AES-256 or an equivalent or stronger algorithm. Encryption keys are managed by the underlying platform provider and are not accessible to Skybyte personnel in plaintext.

7.6 Tenant isolation. Customer Personal Data is logically segregated at the database layer through row-level security policies enforced by the database engine rather than by application logic alone. Every table containing Customer Personal Data carries an enabled row-level security policy. Service-role credentials capable of bypassing row-level security are restricted to server-side execution contexts and are not exposed to browser clients.


8. Sub-processors

8.1 General authorisation. The Customer grants Skybyte general written authorisation to engage Sub-processors for the purposes described in Section 4, subject to the conditions in this Section 8.

8.2 Current Sub-processors. The Sub-processors engaged at the date of this DPA are listed in Appendix 3 and are maintained in current form at /legal/sub-processors. That published list forms part of this DPA.

8.3 Flow-down obligations. Skybyte shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those imposed on Skybyte by this DPA, including in respect of confidentiality, security measures, assistance with Data Subject rights, breach notification, deletion and return of data, and audit.

8.4 Liability for Sub-processors. Skybyte remains fully liable to the Customer for the performance of each Sub-processor's obligations, and shall be liable for the acts and omissions of its Sub-processors to the same extent as for its own acts and omissions.

8.5 Notification of changes. Skybyte shall notify the Customer of any intended addition or replacement of a Sub-processor not less than thirty (30) days before that Sub-processor begins processing Customer Personal Data. Notification will be given by email to the address nominated by the Customer for this purpose and by publication of the updated list at /legal/sub-processors. The Customer may subscribe to notification of changes by writing to contact@banxs.com.

8.6 Objection. The Customer may object to a proposed Sub-processor on reasonable data protection grounds by giving written notice within fifteen (15) days of Skybyte's notification. The parties shall discuss the objection in good faith. If the parties cannot agree a resolution within a further thirty (30) days, either party may terminate the affected Services on written notice, and Skybyte shall refund any prepaid fees attributable to the terminated Services for the period after termination. Termination on this ground is the Customer's sole remedy in respect of a Sub-processor objection.

8.7 Emergency replacement. Where a Sub-processor ceases to provide services without adequate notice, or where continued use of a Sub-processor would present a material security or legal risk, Skybyte may engage a replacement Sub-processor with shorter notice than provided in Section 8.5. In such a case Skybyte shall notify the Customer as soon as reasonably practicable and shall provide the Customer with an equivalent right of objection under Section 8.6.

8.8 Connectivity suppliers. The Customer acknowledges that eSIM provisioning necessarily involves the disclosure of technical identifiers (ICCID, IMSI, and, where required, the destination country and device compatibility parameters) to wholesale connectivity suppliers and, through them, to the licensed mobile network operators whose networks carry the traffic. Those operators process traffic data as independent controllers under the telecommunications law of their own jurisdictions. Skybyte cannot and does not contractually control that downstream processing, and it falls outside the scope of this DPA. Skybyte does not disclose the name, email address or billing details of any Data Subject to mobile network operators.


9. International transfers

9.1 Transfer mechanism. Skybyte shall not make a Restricted Transfer of Customer Personal Data unless it has first put in place an appropriate transfer mechanism under Chapter V GDPR.

9.2 Adequacy. Where the recipient is located in a country benefiting from an adequacy decision of the European Commission under Article 45 GDPR, that decision is the transfer mechanism relied upon. As at the date of this DPA this includes the United Kingdom (Commission Implementing Decision (EU) 2021/1772) and, in respect of certified recipients, the United States under the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795).

9.3 Standard Contractual Clauses. Where no adequacy decision applies, the Standard Contractual Clauses are incorporated into this DPA by reference and are deemed executed by the parties, as follows:

(a) Module Two (Controller to Processor) applies where the Customer is a Controller and Skybyte is a Processor;

(b) Module Three (Processor to Processor) applies where the Customer is itself a processor acting on behalf of a third-party controller;

(c) the optional docking clause in Clause 7 is incorporated;

(d) in Clause 9, Option 2 (general written authorisation) applies, with the notice period specified in Section 8.5 of this DPA;

(e) in Clause 11, the optional independent dispute resolution provision is not incorporated;

(f) in Clause 17, the governing law is the law of Bulgaria;

(g) in Clause 18(b), the competent courts are the courts of Bulgaria;

(h) Annex I, Annex II and Annex III of the Standard Contractual Clauses are populated by Appendix 1, Appendix 2 and Appendix 3 of this DPA respectively.

9.4 UK transfers. In respect of transfers subject to UK GDPR, the International Data Transfer Addendum to the Standard Contractual Clauses is incorporated, with Table 1 populated by the party details in the Preamble, Table 2 selecting the Approved EU SCCs as set out in Section 9.3, Table 3 populated by the Appendices, and Table 4 specifying that neither party may terminate the Addendum in accordance with Section 19 of the Addendum.

9.5 Supplementary measures. In light of the judgment of the Court of Justice of the European Union in Case C-311/18 (Schrems II) and the recommendations of the European Data Protection Board on supplementary measures, Skybyte applies the following measures to Restricted Transfers:

(a) encryption in transit and at rest as described in Section 7.5, with keys held within the European Economic Area where technically available;

(b) contractual commitments from Sub-processors to notify Skybyte of any binding request for disclosure from a public authority, to the extent legally permitted;

(c) contractual commitments from Sub-processors to challenge such requests where there is a reasonable legal basis for doing so, and to disclose only the minimum data legally required;

(d) data minimisation, such that Sub-processors receive only the categories of Personal Data strictly necessary for their function, as recorded in Appendix 3;

(e) periodic reassessment of the legal environment in each recipient jurisdiction.

9.6 Government access requests. Skybyte shall notify the Customer of any legally binding request from a public authority for disclosure of Customer Personal Data, unless prohibited from doing so — for example by a criminal law prohibition designed to preserve the confidentiality of a law enforcement investigation. Where notification is prohibited, Skybyte shall use reasonable efforts to obtain a waiver of the prohibition and shall document those efforts, making the documentation available to the Customer at the earliest date on which disclosure is lawful. Skybyte shall not voluntarily disclose Customer Personal Data to any public authority in the absence of a legally binding request.

9.7 Change in transfer mechanism. If a transfer mechanism relied upon under this Section 9 is invalidated, annulled or otherwise ceases to provide a lawful basis for transfer, the parties shall in good faith agree an alternative mechanism within thirty (30) days. Pending agreement, Skybyte shall suspend the affected transfer to the extent it can do so without materially impairing the Services, and shall notify the Customer of any such impairment.


10. Assistance with Data Subject rights

10.1 Technical measures. Taking into account the nature of the processing, Skybyte shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising Data Subject rights under Chapter III GDPR.

10.2 Self-service. Skybyte provides self-service functionality within the account interface enabling the Customer, and where the Customer permits, individual account holders, to:

(a) export account and order data in a structured, commonly used and machine-readable format (Article 20);

(b) correct account and profile information (Article 16);

(c) request deletion of an account and associated data (Article 17);

(d) view and amend marketing and communications preferences, and withdraw consent (Article 7(3));

(e) view a record of consents given, including the timestamp and the version of the notice presented.

10.3 Requests received directly. If Skybyte receives a request from a Data Subject that relates to Customer Personal Data, Skybyte shall:

(a) not respond to the substance of the request, except to acknowledge receipt and to direct the Data Subject to the Customer, unless the Customer has authorised Skybyte in writing to respond;

(b) notify the Customer without undue delay and in any event within five (5) business days of receipt;

(c) provide the Customer with the information reasonably necessary to enable the Customer to respond.

10.4 Assistance beyond self-service. Where the Customer requires assistance that cannot be satisfied through the functionality described in Section 10.2, Skybyte shall provide reasonable assistance. Skybyte may charge on a time-and-materials basis where the request is manifestly unfounded or excessive, in particular because of its repetitive character, or where the assistance requires bespoke engineering work.

10.5 Automated decision-making. Skybyte operates automated fraud screening in respect of orders. That screening may result in an order being declined or held for manual review. It does not produce legal effects concerning Data Subjects or similarly significantly affect them within the meaning of Article 22(1) GDPR, since a declined order does not prevent the individual from obtaining connectivity by other means and a manual review path is available on request to support@skybytesim.com. Skybyte does not carry out profiling for the purposes of evaluating personal aspects relating to natural persons beyond this fraud screening.


11. Personal Data Breach

11.1 Notification to the Customer. Skybyte shall notify the Customer without undue delay, and in any event within twenty-four (24) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

This period is deliberately shorter than the seventy-two (72) hours allowed to a Controller under Article 33(1) GDPR, in order to leave the Customer adequate time to assess and, where required, notify its own Supervisory Authority.

11.2 Content of notification. The notification shall, to the extent known at the time and updated as further information becomes available, describe:

(a) the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;

(b) the name and contact details of Skybyte's contact point for further information;

(c) the likely consequences of the Personal Data Breach;

(d) the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects;

(e) the date and time at which the Personal Data Breach is believed to have occurred and the date and time at which Skybyte became aware of it.

11.3 Staged notification. Where it is not possible to provide all the information in Section 11.2 at once, Skybyte shall provide the information available at the time of the initial notification and shall provide further information in phases without further undue delay.

11.4 Investigation and mitigation. Skybyte shall take all reasonable steps to investigate, contain, mitigate and remediate the Personal Data Breach, and shall preserve evidence relevant to the investigation.

11.5 Cooperation. Skybyte shall cooperate with the Customer and shall provide the assistance the Customer reasonably requires in order to comply with its obligations under Articles 33 and 34 GDPR, including in the preparation of any notification to a Supervisory Authority or communication to Data Subjects.

11.6 No admission. Skybyte's notification of a Personal Data Breach is not, and shall not be construed as, an acknowledgement by Skybyte of fault or liability in respect of that Personal Data Breach.

11.7 Communication to Data Subjects. Skybyte shall not communicate directly with the Customer's Data Subjects in respect of a Personal Data Breach without the Customer's prior written consent, unless required to do so by law or by a Supervisory Authority.


12. Assistance with impact assessments and prior consultation

12.1 Taking into account the nature of the processing and the information available to it, Skybyte shall provide reasonable assistance to the Customer in:

(a) carrying out data protection impact assessments under Article 35 GDPR;

(b) conducting prior consultation with a Supervisory Authority under Article 36 GDPR;

(c) demonstrating compliance with Articles 32 to 36 GDPR.

12.2 Skybyte shall make available to the Customer, on request and subject to reasonable confidentiality undertakings:

(a) the current version of Appendix 2;

(b) a summary of the results of security assessments carried out in respect of the Services, redacted as necessary to protect the security of the Services and the confidentiality of other customers;

(c) a description of the data flows relevant to the Customer's processing.

12.3 Skybyte may charge on a time-and-materials basis for assistance under this Section 12 that goes beyond the provision of standard documentation.


13. Deletion and return of Customer Personal Data

13.1 Election. At the Customer's election, made by written notice given at any time up to thirty (30) days after termination or expiry of the Principal Agreement, Skybyte shall either delete or return all Customer Personal Data.

13.2 Default. If the Customer makes no election within that period, Skybyte shall delete Customer Personal Data in accordance with Section 13.4.

13.3 Return. Where the Customer elects return, Skybyte shall provide the data in a structured, commonly used and machine-readable format within thirty (30) days of the election, and shall then delete its copies in accordance with Section 13.4.

13.4 Deletion timetable. Deletion shall be completed within ninety (90) days of the later of termination and the Customer's election, save that:

(a) data held in encrypted backups shall be deleted on the expiry of the applicable backup rotation cycle, which does not exceed thirty-five (35) days, and shall not be restored to production in the interim other than for the purpose of disaster recovery;

(b) data that Skybyte is required by Union or Member State law to retain shall be retained for the period specified in Section 13.5, shall be placed beyond further use, and shall be processed solely for the purpose that requires its retention.

13.5 Statutory retention. The following categories are retained after termination as a matter of legal obligation and not on the Customer's instruction. In respect of these categories Skybyte acts as an independent Controller.

Category Retention period Legal basis
Invoices, credit notes and accounting records 10 years from the end of the year of issue Bulgarian Accountancy Act, Art. 12
VAT records and supporting documentation 5 years from expiry of the limitation period for the relevant tax liability Bulgarian Value Added Tax Act
Anti-money-laundering records and identification data 5 years from the end of the business relationship Bulgarian Measures Against Money Laundering Act
Audit log entries evidencing consent and material system actions 7 years Accountability under Art. 5(2) GDPR; evidential requirements under Art. 7(1) GDPR
Records necessary for the establishment, exercise or defence of legal claims Until expiry of the applicable limitation period Art. 17(3)(e) GDPR

13.6 Certification. Skybyte shall certify deletion in writing on the Customer's request.


14. Audit and information rights

14.1 Information. Skybyte shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA.

14.2 Documentation first. The Customer acknowledges that the documentation Skybyte makes available under Section 12.2 is intended to satisfy the Customer's audit requirements in the ordinary course, and agrees to accept that documentation in lieu of an on-site audit where it reasonably addresses the Customer's concerns.

14.3 Audit. Where documentation is insufficient, the Customer may conduct, or mandate an independent auditor to conduct, an audit of Skybyte's processing of Customer Personal Data, subject to the following conditions:

(a) the Customer gives not less than thirty (30) days' written notice;

(b) audits are conducted during normal business hours, in a manner that minimises disruption to Skybyte's operations;

(c) audits are limited to one per calendar year, save where an audit is required by a Supervisory Authority or follows a confirmed Personal Data Breach affecting Customer Personal Data, in which case an additional audit may be conducted;

(d) the auditor is not a competitor of Skybyte and executes a confidentiality undertaking on terms reasonably acceptable to Skybyte before the audit begins;

(e) the audit does not extend to data, systems or premises relating to other customers of Skybyte, to Skybyte's own commercially confidential information, or to any matter the disclosure of which would place Skybyte in breach of an obligation owed to a third party;

(f) the Customer bears its own costs and the costs of its auditor, and shall reimburse Skybyte's reasonable costs of supporting an audit beyond eight (8) hours of personnel time.

14.4 Findings. The Customer shall share the findings of any audit with Skybyte. Skybyte shall remediate any confirmed non-compliance within a reasonable period proportionate to the risk identified.

14.5 Supervisory Authority. Skybyte shall permit and contribute to audits and inspections conducted by a Supervisory Authority exercising powers under Article 58 GDPR.

14.6 Sub-processor audits. Skybyte shall exercise its own audit rights against Sub-processors where the Customer reasonably requests it to do so and provides grounds for the request, and shall share the outcome with the Customer subject to any confidentiality restrictions.


15. Liability

15.1 The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.

15.2 Nothing in this DPA limits or excludes:

(a) either party's liability for death or personal injury caused by its negligence;

(b) either party's liability for fraud or fraudulent misrepresentation;

(c) any liability that cannot lawfully be limited or excluded;

(d) the rights of Data Subjects under Article 82 GDPR, which are unaffected by this DPA.

15.3 Where the parties are jointly liable to a Data Subject or to a Supervisory Authority, liability shall be apportioned between them according to their respective degrees of responsibility for the damage, in accordance with Article 82(5) GDPR.

15.4 Nothing in this Section 15 limits the rights of Data Subjects under the third-party beneficiary provisions of the Standard Contractual Clauses.


16. General

16.1 Order of precedence. In the event of conflict: the Standard Contractual Clauses prevail over this DPA; this DPA prevails over the Principal Agreement; and the Principal Agreement prevails over any other document, in each case only in respect of the processing of Personal Data.

16.2 Severance. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions continue in full force, and the parties shall negotiate in good faith a replacement provision that achieves as nearly as possible the commercial and legal effect of the invalid provision.

16.3 Variation. Skybyte may vary this DPA where required to reflect a change in Applicable Data Protection Law, a decision of a competent authority, or a change in the Services, provided that no variation shall materially reduce the protections afforded to Data Subjects. Skybyte shall give the Customer not less than thirty (30) days' written notice of a material variation. Continued use of the Services after the effective date constitutes acceptance.

16.4 Notices. Notices under this DPA shall be given in writing to contact@banxs.com in the case of Skybyte, and to the email address nominated by the Customer in its account, in the case of the Customer. Notices are deemed received on the next business day after transmission.

16.5 Governing law and jurisdiction. This DPA is governed by the law of the Republic of Bulgaria. The courts of Bulgaria have exclusive jurisdiction, save that this does not deprive a Data Subject of any right to bring proceedings in the courts of their habitual residence under Article 79(2) GDPR or under the Standard Contractual Clauses.

16.6 Execution. This DPA does not require signature. It is incorporated into the Principal Agreement and takes effect in accordance with Section 3.1. A Customer requiring a countersigned copy for its own records may request one by writing to contact@banxs.com.


Appendix 1 — Description of the Processing

This Appendix populates Annex I of the Standard Contractual Clauses.

1. Data exporter

The Customer, as identified in the Principal Agreement. Activities relevant to the transfer: procurement of mobile connectivity for individuals associated with the Customer's organisation. Role: Controller (or, where Section 2.1 applies, Processor).

2. Data importer

Banxs Technologies EOOD (trading as Skybyte), Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria, EIK 206285017. Contact: contact@banxs.com. Activities relevant to the transfer: supply of prepaid eSIM connectivity and associated account, billing and support services. Role: Processor.

3. Categories of Data Subjects

  • Individuals nominated by the Customer to receive and use an eSIM ("End Users") — typically employees, contractors, delegates, students or guests;
  • Individuals authorised by the Customer to administer the Customer's account ("Administrators");
  • Individuals who contact Skybyte support in connection with the Customer's account.

4. Categories of Personal Data

Account and identity data. Name, business email address, business telephone number (optional), organisational role, account role and permissions, country of residence where required for tax determination, preferred language, preferred presentment currency.

Authentication data. Hashed password (Skybyte does not have access to plaintext passwords), multi-factor authentication enrolment status and factors, session identifiers, password reset tokens, last sign-in timestamp.

Order and billing data. Order identifiers, plan identifiers, order timestamps, amounts, currency, VAT treatment and VAT identification number where supplied, invoice numbers and invoice PDFs, credit notes, refund records, billing country.

Payment reference data. Card brand, last four digits of the card number, expiry month and year, acquirer-issued transaction and token references, authorisation and settlement status, statement descriptor applied. Full primary account numbers are not stored, processed or transmitted by Skybyte — see Section 7.4.

Connectivity and usage data. ICCID, IMSI, activation status and timestamp, destination country or region, plan validity window, aggregate data volume consumed, remaining allowance, top-up records, device compatibility parameters where the End User has submitted them.

Support data. Support thread and message content, attachments submitted by the individual, ticket status and category, agent notes, resolution outcome.

Consent and preference data. Marketing consent status and timestamp, cookie consent categories and timestamp, the version of the notice presented at the time consent was given, activation consent records evidencing waiver of the right of withdrawal under Article 16(m) of Directive 2011/83/EU, unsubscribe records.

Technical data. IP address, user agent string, device type, browser, operating system, timezone, referring URL, timestamps of interaction with the Services.

Audit data. Records of material actions taken within the Services, including the identity of the actor, the action, the affected entity, the timestamp, and sanitised metadata from which sensitive values are removed before persistence.

5. Special Categories of Personal Data

None. The Services are not designed to process Special Categories of Personal Data within the meaning of Article 9 GDPR, nor Personal Data relating to criminal convictions and offences within the meaning of Article 10 GDPR. The Customer undertakes under Section 2.4(e) not to submit such data.

6. Frequency of the transfer

Continuous, for the duration of the Principal Agreement.

7. Nature and purpose of the processing

As described in Section 4 of this DPA: account administration, order processing, eSIM provisioning and delivery, usage reporting, billing and invoicing, customer support, fraud prevention, audit and legal compliance.

8. Retention

Category Retention
Account and profile data For the duration of the account, then 30 days after deletion request, then anonymised
Order records, invoices and credit notes 10 years from the end of the year of issue (Bulgarian Accountancy Act, Art. 12)
Refund records 10 years
eSIM provisioning and usage records 3 years from expiry of the plan validity period
Support threads and messages 3 years from closure of the thread
Consent receipts 5 years from the date consent was given or withdrawn
Audit log entries 7 years
Webhook and integration event records 1 year
Notification delivery logs 1 year
Suppression list entries Retained indefinitely, as deletion would defeat the purpose of the record
Backups Rotated on a cycle not exceeding 35 days

Retention is enforced by an automated scheduled process that runs daily and records each execution to an auditable log.

9. Transfers to Sub-processors

As set out in Appendix 3. Sub-processors receive only the categories of Personal Data recorded against them in that Appendix, for the purposes and durations recorded there.

10. Competent Supervisory Authority

The Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria — www.cpdp.bg.


Appendix 2 — Technical and Organisational Measures

This Appendix populates Annex II of the Standard Contractual Clauses. It describes the measures in force at the date of publication and is subject to Section 7.3.

1. Pseudonymisation and encryption

  • TLS 1.2 minimum, TLS 1.3 preferred, for all data in transit, with HTTP Strict Transport Security enforced.
  • AES-256 or equivalent for data at rest, including database storage and object storage.
  • Passwords stored using a memory-hard adaptive hashing function with per-user salt. Plaintext passwords are never persisted or logged.
  • Payment card primary account numbers are never received by Skybyte systems. Tokenisation occurs within the acquirer's PCI DSS-assessed environment.
  • Audit metadata is sanitised before persistence to remove authentication tokens, secrets and payment identifiers.

2. Confidentiality

Access control. Role-based access control with least-privilege defaults. Distinct roles for customer, support agent, administrator and compliance functions. Administrative access requires multi-factor authentication.

Database-layer isolation. Row-level security enabled on every table containing Personal Data, enforced by the database engine. Application code cannot bypass these policies. Credentials capable of bypassing row-level security are confined to server-side execution and are never present in browser-delivered code.

Network control. Services delivered over a content delivery network providing distributed denial-of-service mitigation and web application firewall capability. Administrative interfaces are authentication-gated at the route layer.

Physical control. Physical security of processing infrastructure is provided by the underlying cloud platform operators identified in Appendix 3, each of which maintains recognised physical security certifications for its data centre estate.

3. Integrity

  • Input validation and schema enforcement on all server-side entry points.
  • Financial state transitions are constrained by an explicit state machine; direct mutation of order and payment status outside that state machine is not permitted by the data layer.
  • Invoice numbering is gap-free and sequential, satisfying Bulgarian Value Added Tax Act requirements, and is issued from a dedicated serial allocation mechanism rather than derived from application state.
  • Idempotency controls prevent duplicate processing of repeated payment and provisioning events.
  • Append-only audit logging for material actions. Audit records cannot be edited or deleted through the application interface.
  • Content Security Policy and violation reporting are configured for browser-delivered surfaces.

4. Availability and resilience

  • Automated backups with point-in-time recovery, retained on a rotation cycle not exceeding 35 days.
  • Infrastructure operated across multiple availability zones by the underlying platform provider.
  • Health endpoint and structured application logging with error aggregation and alerting.
  • Automated reconciliation processes detect and remediate stalled payment and provisioning states.

5. Restoration of availability

  • Documented recovery procedure covering restoration of service and of data from backup.
  • Point-in-time recovery available within the backup retention window described in Section 4.
  • Backup restoration is tested periodically as part of operational readiness review.

6. Testing and evaluation

  • Dependency vulnerability scanning on the build pipeline.
  • Static analysis and type checking enforced before deployment.
  • Periodic review of access rights, at least quarterly.
  • Security assessment and penetration testing carried out periodically and following material changes to the Services.

7. User identification and authorisation

  • Unique account identity per individual. Shared credentials are prohibited by the Acceptable Use Policy.
  • Optional multi-factor authentication for customer accounts; mandatory for administrative accounts.
  • Session expiry and revocation on password change.
  • Password reset flows use single-use, time-limited tokens delivered out of band.

8. Data minimisation and quality

  • Only the data categories in Appendix 1 §4 are collected.
  • Sub-processors receive only the subset recorded against them in Appendix 3.
  • Self-service correction of account data by the individual.
  • Automated retention enforcement as described in Appendix 1 §8.

9. Accountability

  • Record of processing activities maintained under Article 30 GDPR.
  • Data protection contact point published and monitored: contact@banxs.com.
  • Documented breach response procedure aligned to the timetable in Section 11.
  • Sub-processor register maintained and published at /legal/sub-processors.
  • Data protection and security training for personnel on appointment and annually.

10. Measures for transfers

As described in Section 9.5.


Appendix 3 — Sub-processors

This Appendix populates Annex III of the Standard Contractual Clauses. The authoritative and current list is published at /legal/sub-processors.

Sub-processor Function Processing location Data categories Transfer mechanism
Supabase / underlying cloud platform Application database, authentication, object storage European Union All categories in Appendix 1 §4 EEA — no Restricted Transfer
Cloudflare, Inc. Content delivery, DDoS mitigation, edge compute, WAF Global edge network, EU-first routing Technical data; transient request content SCCs + EU–US Data Privacy Framework
PayNovus AD Card acquiring and payment processing Bulgaria Payment reference data; order data; name; email EEA — no Restricted Transfer
eSIM Go Ltd Wholesale eSIM provisioning (primary) United Kingdom ICCID, IMSI, destination, plan parameters, activation status UK adequacy decision (EU) 2021/1772
Maya Mobile Inc. Wholesale eSIM provisioning (failover) United States ICCID, IMSI, destination, plan parameters, activation status SCCs + supplementary measures
Transactional email provider Order confirmations, QR delivery, service notices United States Name, email address, order and eSIM reference data SCCs + EU–US Data Privacy Framework
Meta Platforms Ireland Ltd WhatsApp Business messaging (optional channel) Ireland; onward to United States Telephone number, message content, delivery status EEA controller; SCCs for onward transfer
Better Stack (Logtail) Application logging, error aggregation, uptime monitoring European Union and United States Technical data; sanitised error context SCCs + EU–US Data Privacy Framework

Notes.

  1. Mobile network operators carrying End User traffic are not Sub-processors of Skybyte. They process traffic data as independent controllers under the telecommunications law of their jurisdiction. See Section 8.8.
  2. This list reflects the Sub-processors engaged as at the version date. Additions and replacements are notified in accordance with Section 8.5 and published at /legal/sub-processors, which is the authoritative current list.

Banxs Technologies EOOD (trading as Skybyte) · Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria · EIK 206285017 · VAT BG206285017 · Registered with the Bulgarian Registry Agency · Data protection contact: contact@banxs.com

Version 2.0. Questions about this agreement, or requests for a countersigned copy, should be directed to contact@banxs.com.


Need a signed PDF copy? Email contact@banxs.com.