Skybyte — a trading name of Banxs Technologies EOOD
Version 2.0
In short
We are a Bulgarian company selling prepaid travel eSIM data plans. To do that we need your email address, your payment details, and the technical identifiers of the eSIM we issue you. We keep records of what you bought because Bulgarian tax law requires it. We use a small number of suppliers — an acquirer, a connectivity wholesaler, an email provider — and we tell you exactly who they are and what each one receives.
We do not sell your data. We do not use it to train machine learning models. We do not run third-party advertising trackers on this website.
You can access, correct, export or delete your data yourself from your account at any time, and you can complain to the Bulgarian data protection authority if you think we have handled it badly.
The rest of this document is the detail. It is long because the detail matters, not because we are trying to bury anything.
1. Who we are
Banxs Technologies EOOD, trading as Skybyte, is the data controller responsible for the personal data described in this policy.
| Legal entity | Banxs Technologies EOOD |
| Trading name | Skybyte |
| Registered office | Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria |
| Company number (EIK) | 206285017 |
| VAT number | BG206285017 |
| Register | Bulgarian Registry Agency (Търговски регистър) |
| Privacy contact | contact@banxs.com |
| Customer support | support@skybytesim.com |
We are established in Bulgaria and our lead supervisory authority is the Bulgarian Commission for Personal Data Protection.
1.1 Scope of this policy
This policy covers:
- the Skybyte website at skybytesim.com and any subdomain;
- your Skybyte account;
- the purchase, delivery, activation and use of Skybyte eSIM data plans;
- support interactions by email, in-app chat, or messaging channel;
- marketing communications, where you have asked to receive them.
It does not cover:
- the networks that carry your data. Once your eSIM is active, the licensed mobile network operator in the country you are visiting processes your traffic data as an independent controller under the telecommunications law of that country. We do not control that processing and we do not receive the contents of your communications. See Section 6.4.
- websites and apps you reach through your connection. Their own privacy policies apply.
- business customers' arrangements with their own staff. Where an organisation buys Skybyte eSIMs for its employees, that organisation is the controller of its employees' data and we act as its processor. Our Data Processing Agreement governs that relationship.
1.2 Changes to this policy
We will update this policy when our processing changes. For material changes we will give at least thirty (30) days' notice by email to account holders and by prominent notice on the website before the change takes effect. Where a change requires your consent, we will ask for it rather than assume it. Previous versions are available on request to contact@banxs.com.
2. The personal data we collect
We have grouped this by where the data comes from, because that is usually what people want to know.
2.1 Data you give us
When you create an account Email address; password (stored only as a cryptographic hash — we never see or store the plaintext); display name if you choose to set one; preferred language; preferred display currency.
When you buy a plan Billing country; VAT identification number if you are purchasing as a business; the destination and plan you selected. Your card details are entered on a payment form hosted by our acquirer and are never transmitted through or stored on our systems. We receive back only the card brand, the last four digits, the expiry month and year, and a token that lets us reference the transaction for refunds and support.
When you contact support Whatever you tell us — the content of your messages, any screenshots or attachments you send, the device and destination you are asking about.
When you set preferences Marketing consent choices; cookie consent choices; notification channel preferences; unsubscribe requests.
2.2 Data generated by using the service
Your eSIM The ICCID (the unique identifier of the eSIM profile), the IMSI associated with it, the activation timestamp, the destination country or region, the validity window, the volume of data consumed against your allowance, and the remaining balance. We receive aggregate consumption figures from our connectivity supplier. We do not receive, and cannot see, the websites you visit, the apps you use, or the content of anything you send.
Your orders Order references, timestamps, amounts, currency, VAT treatment applied, invoice numbers, credit notes, refund records.
Your consents A record of each consent you give or withdraw, including the timestamp, the channel, and the version of the notice that was shown to you at the time. This includes the specific record created when you activate an eSIM and thereby waive the fourteen-day withdrawal right under EU consumer law — see Section 3.6.
Audit records A record of material actions taken in your account: sign-ins, order state changes, refunds, consent events, data export and deletion requests. Sensitive values such as tokens and payment identifiers are stripped before these records are written.
2.3 Data collected automatically
IP address; browser user-agent string; device type and operating system; screen characteristics where relevant to rendering; timezone; referring page; timestamps of pages viewed and actions taken; and cookie identifiers as described in our Cookie Policy.
We use a self-hosted analytics system rather than a third-party advertising platform. It records page views and aggregate behaviour, and does not build cross-site profiles of you.
2.4 Data we receive from others
From our acquirer: the outcome of a payment authorisation, fraud risk indicators, chargeback and dispute notifications.
From our connectivity suppliers: provisioning confirmation, activation status, and aggregate usage counters for your eSIM.
From tax validation services: confirmation of whether a VAT number you supply is valid and registered, obtained from the European Commission's VIES service. We store the validation result, not a copy of any wider record.
2.5 Data we do not collect
We do not collect, and we ask you not to send us, special categories of personal data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. We do not collect data relating to criminal convictions or offences under Article 10 GDPR.
Our service is not designed to handle such data and our security measures are not calibrated to it. If you send it to us in a support message we will remove it once the matter is resolved.
We do not collect government identity documents from consumers. Where an anti-money-laundering obligation requires identity verification in a specific case, we will tell you at the time, explain the legal basis, and handle the documents separately under a shorter retention period.
3. Why we process your data, and our legal basis
Under Article 6(1) GDPR every processing activity needs a lawful basis. This table sets out ours, activity by activity. This is the section a regulator would read first.
3.1 Performance of a contract — Article 6(1)(b)
| Activity | Data used |
|---|---|
| Creating and maintaining your account | Email, password hash, preferences |
| Authenticating you when you sign in | Email, password hash, session identifiers, MFA factors |
| Processing your order and taking payment | Order data, billing country, payment reference data |
| Determining the correct VAT treatment | Billing country, VAT number where supplied |
| Provisioning your eSIM and delivering the QR code | Email, destination, plan, ICCID, IMSI |
| Showing you your remaining data allowance | ICCID, usage counters |
| Processing top-ups | Order data, ICCID, payment reference data |
| Handling refunds and cancellations | Order data, payment reference data, refund records |
| Responding to support enquiries about your order | Support content, order and eSIM references |
3.2 Legal obligation — Article 6(1)(c)
| Activity | Data used | Obligation |
|---|---|---|
| Issuing and retaining sequential invoices | Order and billing data | Bulgarian Value Added Tax Act; Bulgarian Accountancy Act |
| Maintaining accounting records | Order, invoice, refund data | Bulgarian Accountancy Act, Art. 12 |
| VAT reporting across EU member states | Billing country, amounts, VAT treatment | Council Directive 2006/112/EC and its EU One-Stop-Shop provisions |
| Sanctions screening of orders | Name, billing country, destination | EU restrictive measures; UN sanctions lists |
| Anti-money-laundering record-keeping where applicable | Identity and transaction data | Bulgarian Measures Against Money Laundering Act |
| Responding to lawful requests from authorities | Whatever is lawfully compelled | Applicable procedural law |
| Recording consent so we can evidence it | Consent receipts | Art. 7(1) GDPR |
| Honouring your rights under this policy | Whatever the request concerns | Chapter III GDPR |
3.3 Legitimate interests — Article 6(1)(f)
We rely on legitimate interests only where we have assessed that our interest is not overridden by your rights and freedoms. We have carried out and documented that balancing exercise for each of the following.
| Activity | Our interest | Why it is balanced |
|---|---|---|
| Detecting and preventing fraudulent orders | Preventing financial loss and card scheme penalties | Limited to order and technical data; a human review path exists; a declined order does not prevent you obtaining connectivity elsewhere |
| Securing our systems and detecting attacks | Protecting all customers' data | Technical data only; retained for a limited period |
| Diagnosing errors and improving reliability | Delivering a working service | Error context is sanitised before it is logged |
| Aggregate analytics on how the site is used | Understanding which destinations and plans matter | Self-hosted; no third-party sharing; no cross-site profiling |
| Enforcing our Acceptable Use Policy | Protecting network integrity and other customers | Investigation is proportionate to the suspected breach |
| Establishing, exercising or defending legal claims | Access to justice | Retention limited to the applicable limitation period |
| Sending service-related notices you have not opted into — for example a security alert or a change to these terms | You need to know | Not marketing; you cannot be harmed by being told |
You have the right to object to processing based on legitimate interests. See Section 8.6.
3.4 Consent — Article 6(1)(a)
We rely on consent for:
- marketing emails about new destinations, features and offers;
- WhatsApp or other messaging-channel notifications, where you have opted in to that channel;
- functional cookies that remember your preferences;
- analytics cookies.
Consent is always optional, always separate from the purchase, and always withdrawable. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it, and it does not affect your ability to buy or use an eSIM.
You can withdraw at any time from Account → Privacy, from the unsubscribe link in any marketing email, or by writing to contact@banxs.com.
3.5 Vital interests — Article 6(1)(d)
In rare cases we may process data to protect someone's life — for example if we receive a credible indication that a person is in danger and a public authority requests our assistance. We have never done this. We include it because it is a lawful basis that could theoretically apply.
3.6 The activation consent record
This one deserves explaining in plain terms because it affects your refund rights.
Under Article 16(m) of the EU Consumer Rights Directive, you normally have fourteen days to change your mind about an online purchase. But if you ask us to supply a digital service immediately within that period, and you acknowledge that doing so ends your right to withdraw, then the right ends.
Activating an eSIM is exactly that. So before we reveal your QR code, we show you a notice explaining this, and we record your acknowledgement: the timestamp it was shown, the timestamp you confirmed, the version of the wording you saw, and the order and eSIM it relates to.
We keep that record for five years. Its purpose is evidential — it protects you as much as us, because it establishes precisely what you were told and when. Our Refund Policy explains what remains refundable after activation.
4. How long we keep your data
We keep personal data only as long as we need it. Deletion is enforced by an automated process that runs daily and logs each execution, so retention is not dependent on someone remembering to do it.
| Category | Retention period | Why |
|---|---|---|
| Account and profile data | For as long as your account exists, then 30 days after you request deletion, then anonymised | Gives you a window to change your mind |
| Invoices, credit notes and accounting records | 10 years from the end of the year of issue | Bulgarian Accountancy Act, Art. 12 |
| VAT records and supporting documentation | 5 years from expiry of the limitation period for the relevant liability | Bulgarian Value Added Tax Act |
| Order and payment reference records | 10 years, aligned to the accounting record above | Tax and accounting; dispute defence |
| Refund and chargeback records | 10 years | Card scheme dispute windows; accounting |
| eSIM provisioning and usage records | 3 years from the end of the plan validity period | Support, billing disputes, network reconciliation |
| Support threads and messages | 3 years from closure of the thread | Service quality; complaint handling; defence of claims |
| Consent receipts | 5 years from the date consent was given or withdrawn | Art. 7(1) GDPR — we must be able to demonstrate consent |
| Activation consent records | 5 years | Evidence of the Art. 16(m) acknowledgement |
| Audit log entries | 7 years | Accountability under Art. 5(2) GDPR; anti-money-laundering record-keeping |
| Webhook and integration events | 1 year | Operational reconciliation |
| Notification delivery logs | 1 year | Proving a message was sent when a dispute arises |
| Suppression list (people who have unsubscribed) | Indefinite | Deleting it would mean emailing you again, which is the opposite of what you asked for |
| Marketing preferences | Until withdrawn, then 1 year | Evidence of the withdrawal |
| Cookie consent records | 12 months, then we ask again | Consent should not be permanent |
| Anti-money-laundering records, where created | 5 years from the end of the business relationship | Bulgarian Measures Against Money Laundering Act |
| Backups | Rotated on a cycle not exceeding 35 days | Disaster recovery |
Where we are required to keep something after you have asked us to delete your data, we restrict it — it is kept for the legal purpose only and is not used for anything else.
5. Who we share your data with
We share data only where it is necessary. We do not sell personal data, and we have never sold personal data.
5.1 Our suppliers
These organisations process personal data on our behalf, under written contracts that impose confidentiality, security and deletion obligations, and that prohibit them from using the data for their own purposes.
| Supplier | What they do | Where they process | What they receive |
|---|---|---|---|
| Supabase (cloud database platform) | Hosts the database, authentication and file storage | European Union | Substantially all account, order and service data |
| Cloudflare, Inc. | Content delivery, DDoS protection, web application firewall | Global edge, EU-first routing | IP address, request metadata, transient request content |
| PayNovus AD | Card acquiring and payment processing | Bulgaria | Name, email, order amount, card data (which we never see) |
| eSIM Go Ltd | Wholesale eSIM provisioning — primary supplier | United Kingdom | ICCID, IMSI, destination, plan parameters, activation status |
| Maya Mobile Inc. | Wholesale eSIM provisioning — failover supplier | United States | ICCID, IMSI, destination, plan parameters, activation status |
| Transactional email provider | Sends order confirmations, QR codes and service notices | United States | Name, email address, order and eSIM references, message content |
| Meta Platforms Ireland Ltd | WhatsApp Business messaging, if you opt in to that channel | Ireland, with onward transfer to the United States | Telephone number, message content, delivery status |
| Better Stack | Application logging, error tracking and uptime monitoring | European Union and United States | IP address, technical data, sanitised error context |
The current list is maintained at /legal/sub-processors. We give thirty days' notice before adding or replacing a supplier that processes personal data.
Notably absent from that list: we do not use Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, or any other third-party advertising or cross-site tracking technology.
5.2 Authorities
We disclose personal data to public authorities only where we are legally obliged to. That includes the Bulgarian National Revenue Agency for tax purposes, and law enforcement or regulatory bodies acting under a valid legal instrument.
We assess every request. We do not accept informal requests. Where a request appears to exceed the requesting authority's powers, we challenge it. Where we are permitted to tell you that your data has been requested, we will.
5.3 Business transfers
If Skybyte or Banxs Technologies EOOD is involved in a merger, acquisition, or sale of assets, personal data may transfer to the acquiring entity. We would notify you before any such transfer took effect and before your data became subject to a different privacy policy, and the acquirer would be bound by commitments no less protective than these.
5.4 Professional advisers
We may share data with our lawyers, accountants, auditors and insurers where necessary and where they are bound by professional confidentiality obligations.
5.5 Not shared
We do not share your personal data with advertisers, data brokers, credit reference agencies, or any organisation for its own marketing purposes.
6. International transfers
We are in Bulgaria and most of your data stays in the European Economic Area. Some does not, and this section explains what protects it.
6.1 Transfers within the EEA
No special mechanism is required. Our database platform and our acquirer both process within the EEA.
6.2 Transfers to the United Kingdom
The European Commission has decided that the United Kingdom provides an adequate level of protection (Commission Implementing Decision (EU) 2021/1772). Transfers to our primary eSIM supplier rely on that decision.
6.3 Transfers to the United States
For US-based suppliers we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, and, where the supplier is certified, on the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795).
Following the Schrems II judgment we also apply supplementary measures:
- data is encrypted in transit and at rest;
- suppliers receive only the minimum categories of data needed for their function, which is why the table in Section 5.1 lists different data for each;
- suppliers are contractually required to notify us of any binding government request for disclosure, to the extent they are legally permitted to do so;
- suppliers are required to challenge overbroad requests where there is a reasonable basis, and to disclose only the minimum legally required;
- we reassess the position in each jurisdiction periodically, and will suspend a transfer if we conclude it can no longer be adequately protected.
You may request a copy of the safeguards in place for any specific transfer by writing to contact@banxs.com.
6.4 Transfers inherent to mobile connectivity
This one is different in kind and we want to be honest about it.
When you use a Skybyte eSIM abroad, your device connects to a licensed mobile network operator in that country. That operator processes your connection data — location of the cell you are attached to, session times, volumes — under the telecommunications and lawful interception law of its own jurisdiction. This is inherent to how mobile networks work anywhere in the world, including on your normal home SIM.
We are not able to place that operator under our contractual control and we do not pretend otherwise. What we can tell you is what we disclose to enable the connection: the technical identifiers of the eSIM profile and the destination. We do not disclose your name, email address or payment details to mobile network operators.
If you are travelling somewhere where this matters to you, consider that the same is true of any mobile connectivity, and take the precautions you would normally take.
7. How we protect your data
Security is a set of practices, not a claim. Here is what we actually do.
Encryption. TLS 1.2 or above for everything in transit, TLS 1.3 preferred. AES-256 or equivalent at rest. HTTP Strict Transport Security enforced.
Passwords. Stored using a memory-hard adaptive hashing algorithm with a unique salt per user. Nobody at Skybyte can retrieve your password. If you lose it, we can only reset it.
Card data. We never receive your full card number. It goes directly from your browser to our acquirer's payment environment. Our own PCI DSS scope is limited to SAQ A, which is the narrowest scope available and reflects the fact that card data never touches our systems.
Database isolation. Every table containing personal data has row-level security enforced by the database engine itself, not by application code. This means a bug in our application cannot expose another customer's data, because the database refuses the query regardless of what the application asks for.
Access control. Least privilege by default. Staff access is role-scoped, requires multi-factor authentication, is logged to an append-only audit record, and is reviewed quarterly.
Financial integrity. Order and payment state changes are constrained by an explicit state machine. Invoice numbers are issued from a dedicated sequential allocator to satisfy the gap-free requirement in Bulgarian VAT law. Duplicate processing of payment events is prevented by idempotency controls.
Logging discipline. Sensitive values — tokens, secrets, payment identifiers — are stripped from error context and audit metadata before anything is written.
Availability. Automated backups with point-in-time recovery. Multi-availability-zone infrastructure. Automated reconciliation that detects and recovers stalled payment and provisioning states.
Testing. Dependency vulnerability scanning on every build. Static analysis and type checking enforced before deployment. Periodic security assessment and penetration testing.
No system is perfectly secure. If we suffer a breach affecting your personal data we will notify the Bulgarian Commission for Personal Data Protection within seventy-two hours as Article 33 GDPR requires, and we will notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
8. Your rights
You have the following rights. Exercising them is free, and we will not treat you differently for doing so.
8.1 Access — Article 15
You can ask what personal data we hold about you and receive a copy, along with information about why we process it, who we share it with, and how long we keep it.
Self-service: Account → Privacy → Export my data.
8.2 Rectification — Article 16
You can correct inaccurate data and complete incomplete data.
Self-service: Account → Profile. Some fields on issued invoices cannot be changed after issue because tax law requires the original record to be preserved; we would issue a corrected document instead.
8.3 Erasure — Article 17
You can ask us to delete your data. We will, except where we are legally required to keep something — principally accounting and tax records. In that case we restrict the retained data to the legal purpose and delete everything else.
Self-service: Account → Privacy → Delete my account. There is a thirty-day grace period before deletion completes, during which you can cancel.
8.4 Restriction — Article 18
You can ask us to stop processing your data while a dispute about its accuracy or our legal basis is resolved. We will hold it but not use it.
8.5 Portability — Article 20
You can receive the data you gave us in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller where technically feasible.
Self-service: Account → Privacy → Export my data (JSON).
8.6 Objection — Article 21
You can object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed for legal claims.
You can object to direct marketing at any time and we will always stop. No balancing test applies to marketing objections — the right is absolute.
8.7 Withdrawal of consent — Article 7(3)
Where we rely on consent, you can withdraw it as easily as you gave it.
Self-service: Account → Privacy, or the unsubscribe link in any marketing email.
8.8 Automated decision-making — Article 22
We run automated fraud screening on orders. It can decline an order or hold it for review. We do not consider this to produce legal effects concerning you or to affect you similarly significantly, because a declined order does not prevent you obtaining connectivity and a human review path is available on request to support@skybytesim.com.
We do not carry out profiling to evaluate your personal characteristics, preferences, behaviour, location or movements beyond what is described in this policy.
8.9 How to exercise a right
Use the self-service tools where they exist — they are faster. Otherwise write to contact@banxs.com.
We will acknowledge within five business days and respond substantively within one month. Where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month.
We may ask you to verify your identity before we act, particularly for access, portability and erasure requests. This protects you: it prevents someone else obtaining your data by pretending to be you.
We do not charge a fee. If a request is manifestly unfounded or excessive — in particular because it is repetitive — we may charge a reasonable administrative fee or refuse it, and we would explain why.
8.10 Complaints
If you think we have handled your data badly, tell us first at contact@banxs.com and give us a chance to fix it.
If you remain dissatisfied you have the right to complain to a supervisory authority:
Commission for Personal Data Protection (Комисия за защита на личните данни) 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria kzld@cpdp.bg · www.cpdp.bg
You may also complain to the supervisory authority in your own EU member state of residence or place of work, or where you believe the infringement occurred. You may also seek a judicial remedy.
9. Cookies and tracking
Our Cookie Policy sets out every cookie we use, what it does, how long it lasts, and which category it belongs to.
In summary: strictly necessary cookies keep you signed in and keep the checkout working, and do not require consent. Functional and analytics cookies do require consent and are off until you give it. We use no advertising cookies at all.
We honour the Do Not Track browser header and the Global Privacy Control (Sec-GPC) signal. If either is present we treat it as a refusal of non-essential cookies without asking you again.
10. Children
Skybyte is not directed at children and we do not knowingly collect personal data from anyone under sixteen. Our Terms of Service require account holders to be at least eighteen.
If you are a parent or guardian and believe a child has provided us with personal data, write to contact@banxs.com and we will delete it.
11. Marketing
We only send marketing emails if you have opted in. Opting in is never a condition of buying anything.
Every marketing email has a working one-click unsubscribe link. Unsubscribing takes effect immediately and we add you to a suppression list so you are not accidentally re-added later.
Service messages are different and you cannot opt out of them while you hold an active plan: order confirmations, your eSIM QR code, low-balance and expiry warnings, refund confirmations, security alerts, and notices of changes to these terms. These are not marketing — they are the service.
12. Business customers
Where an organisation buys Skybyte eSIMs for individuals it is responsible for — employees, contractors, delegates, students — that organisation is the controller of those individuals' personal data and Skybyte acts as its processor.
In that arrangement our Data Processing Agreement governs, and the organisation is responsible for telling those individuals how their data is used. If you have received a Skybyte eSIM through your employer or another organisation, ask them first — they determine what happens to your data. We will of course still honour your rights directly, and will coordinate with them.
13. If you are not in the European Union
We sell into 249 countries and territories. Our baseline is the GDPR, applied to everyone regardless of where you live, because operating two standards would be both harder and worse. Some jurisdictions give you additional or differently-framed rights, and this section covers the main ones.
13.1 United Kingdom
The UK GDPR and the Data Protection Act 2018 apply to UK residents. Your rights are substantially the same as those in Section 8. Your supervisory authority is the Information Commissioner's Office (ico.org.uk), and you may complain to it directly.
We have not appointed a UK representative under Article 27 UK GDPR, on the basis that our processing of UK residents' data is occasional and does not involve large-scale processing of special category data. If that assessment changes we will appoint one and update this policy.
13.2 Switzerland
The revised Swiss Federal Act on Data Protection applies to Swiss residents. Your rights broadly mirror those in Section 8. Your supervisory authority is the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
References in this policy to the GDPR should be read as including the equivalent provisions of the Swiss FADP where you are a Swiss resident.
13.3 California
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information is collected, used, shared or sold; to delete it; to correct it; to opt out of sale or sharing; and to limit use of sensitive personal information.
Three specific statements for California residents:
- We do not sell your personal information and have not done so in the preceding twelve months.
- We do not share your personal information for cross-context behavioural advertising and have not done so in the preceding twelve months. This is why there are no advertising pixels on this site.
- We do not collect sensitive personal information as that term is defined in the CPRA.
We honour the Global Privacy Control signal as a valid opt-out request, as described in Section 9. We will not discriminate against you for exercising any CCPA right.
13.4 Brazil
The Lei Geral de Proteção de Dados gives Brazilian residents rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. These map closely to Section 8 and we handle them through the same channels. Your authority is the Autoridade Nacional de Proteção de Dados (gov.br/anpd).
13.5 Other jurisdictions
If your local law gives you rights beyond those in Section 8, write to contact@banxs.com and we will honour them to the extent the law requires. If your local law appears to reduce the protection this policy gives you, we will apply this policy anyway.
14. Keeping your data accurate
We rely on you to keep your account details current, and it matters more here than on most services: your eSIM QR code is delivered to the email address on your account, and your billing country determines the VAT you pay.
If your email address becomes invalid we cannot deliver your purchase, and we may not be able to reach you about a problem with it. If your billing country is wrong, the VAT treatment applied to your invoice will be wrong, which can create a tax problem for you as well as for us.
You can update both from Account → Profile. We do not independently verify what you enter, other than validating VAT numbers against the European Commission's VIES service where you supply one.
Where we discover data is inaccurate — for example an email address that consistently bounces — we may correct or suppress it without being asked, and we will tell you if we can reach you by another means.
15. Anonymisation
When we say we anonymise data, we mean we irreversibly remove or replace the identifiers that link it to you, so that neither we nor anyone else can reasonably re-identify you from it, whether alone or by combining it with other information available to us.
Anonymised data falls outside the GDPR and we may retain and use it indefinitely — for example, to understand which destinations are growing, how long activation typically takes, or where errors cluster. This is genuinely anonymous data, not pseudonymised data held under a key we still possess.
Where we cannot anonymise something because we need to be able to identify it later — an invoice, for instance — we do not claim to have anonymised it. We restrict it instead, as described in Section 4.
16. What happens if a supplier relationship ends
If we stop using a supplier listed in Section 5.1, our contract with them requires that they delete or return the personal data they hold on our behalf, within a defined period, and certify that they have done so.
We will update the sub-processor list and, where the change is material to how your data is handled, we will tell you. Replacing a supplier does not by itself change what data we collect or why.
17. Security incidents
We maintain a documented incident response procedure. In outline:
Detection. Automated monitoring, error aggregation and access logging, supplemented by reports from customers, researchers and suppliers.
Assessment. We establish what data was affected, how many people, and what the likely consequences are. Where a supplier is the source, we require notification to us within twenty-four hours so that we retain time to meet our own obligations.
Containment and remediation. We isolate the cause, close it, and preserve evidence for investigation.
Notification. Where a breach is likely to result in a risk to your rights and freedoms we notify the Bulgarian Commission for Personal Data Protection within seventy-two hours of becoming aware of it, as Article 33 GDPR requires. Where the risk is high, we notify you directly and without undue delay, in plain language, telling you what happened, what it means for you, and what we are doing about it.
Review. Every incident, including near misses, is reviewed and the findings feed back into our controls.
If you believe you have found a security vulnerability in our systems, please report it to contact@banxs.com. We will acknowledge it, investigate, and will not pursue action against anyone who reports a genuine issue in good faith and does not access or exfiltrate other people's data in the process.
18. Contact
Privacy and data protection contact@banxs.com
Customer support support@skybytesim.com
Post Banxs Technologies EOOD, Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria
We aim to acknowledge privacy enquiries within five business days.
Banxs Technologies EOOD (trading as Skybyte) · Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria · EIK 206285017 · VAT BG206285017 · Registered with the Bulgarian Registry Agency · Data controller for the purposes of Regulation (EU) 2016/679
Version 2.0