Privacy Policy

Last updated: 16 August 2026Effective from: 16 August 2026

Skybyte — a trading name of Banxs Technologies EOOD

Version 2.0


In short

We are a Bulgarian company selling prepaid travel eSIM data plans. To do that we need your email address, your payment details, and the technical identifiers of the eSIM we issue you. We keep records of what you bought because Bulgarian tax law requires it. We use a small number of suppliers — an acquirer, a connectivity wholesaler, an email provider — and we tell you exactly who they are and what each one receives.

We do not sell your data. We do not use it to train machine learning models. We do not run third-party advertising trackers on this website.

You can access, correct, export or delete your data yourself from your account at any time, and you can complain to the Bulgarian data protection authority if you think we have handled it badly.

The rest of this document is the detail. It is long because the detail matters, not because we are trying to bury anything.


1. Who we are

Banxs Technologies EOOD, trading as Skybyte, is the data controller responsible for the personal data described in this policy.

Legal entity Banxs Technologies EOOD
Trading name Skybyte
Registered office Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria
Company number (EIK) 206285017
VAT number BG206285017
Register Bulgarian Registry Agency (Търговски регистър)
Privacy contact contact@banxs.com
Customer support support@skybytesim.com

We are established in Bulgaria and our lead supervisory authority is the Bulgarian Commission for Personal Data Protection.

1.1 Scope of this policy

This policy covers:

  • the Skybyte website at skybytesim.com and any subdomain;
  • your Skybyte account;
  • the purchase, delivery, activation and use of Skybyte eSIM data plans;
  • support interactions by email, in-app chat, or messaging channel;
  • marketing communications, where you have asked to receive them.

It does not cover:

  • the networks that carry your data. Once your eSIM is active, the licensed mobile network operator in the country you are visiting processes your traffic data as an independent controller under the telecommunications law of that country. We do not control that processing and we do not receive the contents of your communications. See Section 6.4.
  • websites and apps you reach through your connection. Their own privacy policies apply.
  • business customers' arrangements with their own staff. Where an organisation buys Skybyte eSIMs for its employees, that organisation is the controller of its employees' data and we act as its processor. Our Data Processing Agreement governs that relationship.

1.2 Changes to this policy

We will update this policy when our processing changes. For material changes we will give at least thirty (30) days' notice by email to account holders and by prominent notice on the website before the change takes effect. Where a change requires your consent, we will ask for it rather than assume it. Previous versions are available on request to contact@banxs.com.


2. The personal data we collect

We have grouped this by where the data comes from, because that is usually what people want to know.

2.1 Data you give us

When you create an account Email address; password (stored only as a cryptographic hash — we never see or store the plaintext); display name if you choose to set one; preferred language; preferred display currency.

When you buy a plan Billing country; VAT identification number if you are purchasing as a business; the destination and plan you selected. Your card details are entered on a payment form hosted by our acquirer and are never transmitted through or stored on our systems. We receive back only the card brand, the last four digits, the expiry month and year, and a token that lets us reference the transaction for refunds and support.

When you contact support Whatever you tell us — the content of your messages, any screenshots or attachments you send, the device and destination you are asking about.

When you set preferences Marketing consent choices; cookie consent choices; notification channel preferences; unsubscribe requests.

2.2 Data generated by using the service

Your eSIM The ICCID (the unique identifier of the eSIM profile), the IMSI associated with it, the activation timestamp, the destination country or region, the validity window, the volume of data consumed against your allowance, and the remaining balance. We receive aggregate consumption figures from our connectivity supplier. We do not receive, and cannot see, the websites you visit, the apps you use, or the content of anything you send.

Your orders Order references, timestamps, amounts, currency, VAT treatment applied, invoice numbers, credit notes, refund records.

Your consents A record of each consent you give or withdraw, including the timestamp, the channel, and the version of the notice that was shown to you at the time. This includes the specific record created when you activate an eSIM and thereby waive the fourteen-day withdrawal right under EU consumer law — see Section 3.6.

Audit records A record of material actions taken in your account: sign-ins, order state changes, refunds, consent events, data export and deletion requests. Sensitive values such as tokens and payment identifiers are stripped before these records are written.

2.3 Data collected automatically

IP address; browser user-agent string; device type and operating system; screen characteristics where relevant to rendering; timezone; referring page; timestamps of pages viewed and actions taken; and cookie identifiers as described in our Cookie Policy.

We use a self-hosted analytics system rather than a third-party advertising platform. It records page views and aggregate behaviour, and does not build cross-site profiles of you.

2.4 Data we receive from others

From our acquirer: the outcome of a payment authorisation, fraud risk indicators, chargeback and dispute notifications.

From our connectivity suppliers: provisioning confirmation, activation status, and aggregate usage counters for your eSIM.

From tax validation services: confirmation of whether a VAT number you supply is valid and registered, obtained from the European Commission's VIES service. We store the validation result, not a copy of any wider record.

2.5 Data we do not collect

We do not collect, and we ask you not to send us, special categories of personal data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. We do not collect data relating to criminal convictions or offences under Article 10 GDPR.

Our service is not designed to handle such data and our security measures are not calibrated to it. If you send it to us in a support message we will remove it once the matter is resolved.

We do not collect government identity documents from consumers. Where an anti-money-laundering obligation requires identity verification in a specific case, we will tell you at the time, explain the legal basis, and handle the documents separately under a shorter retention period.


Under Article 6(1) GDPR every processing activity needs a lawful basis. This table sets out ours, activity by activity. This is the section a regulator would read first.

3.1 Performance of a contract — Article 6(1)(b)

Activity Data used
Creating and maintaining your account Email, password hash, preferences
Authenticating you when you sign in Email, password hash, session identifiers, MFA factors
Processing your order and taking payment Order data, billing country, payment reference data
Determining the correct VAT treatment Billing country, VAT number where supplied
Provisioning your eSIM and delivering the QR code Email, destination, plan, ICCID, IMSI
Showing you your remaining data allowance ICCID, usage counters
Processing top-ups Order data, ICCID, payment reference data
Handling refunds and cancellations Order data, payment reference data, refund records
Responding to support enquiries about your order Support content, order and eSIM references

3.2 Legal obligation — Article 6(1)(c)

Activity Data used Obligation
Issuing and retaining sequential invoices Order and billing data Bulgarian Value Added Tax Act; Bulgarian Accountancy Act
Maintaining accounting records Order, invoice, refund data Bulgarian Accountancy Act, Art. 12
VAT reporting across EU member states Billing country, amounts, VAT treatment Council Directive 2006/112/EC and its EU One-Stop-Shop provisions
Sanctions screening of orders Name, billing country, destination EU restrictive measures; UN sanctions lists
Anti-money-laundering record-keeping where applicable Identity and transaction data Bulgarian Measures Against Money Laundering Act
Responding to lawful requests from authorities Whatever is lawfully compelled Applicable procedural law
Recording consent so we can evidence it Consent receipts Art. 7(1) GDPR
Honouring your rights under this policy Whatever the request concerns Chapter III GDPR

3.3 Legitimate interests — Article 6(1)(f)

We rely on legitimate interests only where we have assessed that our interest is not overridden by your rights and freedoms. We have carried out and documented that balancing exercise for each of the following.

Activity Our interest Why it is balanced
Detecting and preventing fraudulent orders Preventing financial loss and card scheme penalties Limited to order and technical data; a human review path exists; a declined order does not prevent you obtaining connectivity elsewhere
Securing our systems and detecting attacks Protecting all customers' data Technical data only; retained for a limited period
Diagnosing errors and improving reliability Delivering a working service Error context is sanitised before it is logged
Aggregate analytics on how the site is used Understanding which destinations and plans matter Self-hosted; no third-party sharing; no cross-site profiling
Enforcing our Acceptable Use Policy Protecting network integrity and other customers Investigation is proportionate to the suspected breach
Establishing, exercising or defending legal claims Access to justice Retention limited to the applicable limitation period
Sending service-related notices you have not opted into — for example a security alert or a change to these terms You need to know Not marketing; you cannot be harmed by being told

You have the right to object to processing based on legitimate interests. See Section 8.6.

3.4 Consent — Article 6(1)(a)

We rely on consent for:

  • marketing emails about new destinations, features and offers;
  • WhatsApp or other messaging-channel notifications, where you have opted in to that channel;
  • functional cookies that remember your preferences;
  • analytics cookies.

Consent is always optional, always separate from the purchase, and always withdrawable. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it, and it does not affect your ability to buy or use an eSIM.

You can withdraw at any time from Account → Privacy, from the unsubscribe link in any marketing email, or by writing to contact@banxs.com.

3.5 Vital interests — Article 6(1)(d)

In rare cases we may process data to protect someone's life — for example if we receive a credible indication that a person is in danger and a public authority requests our assistance. We have never done this. We include it because it is a lawful basis that could theoretically apply.

This one deserves explaining in plain terms because it affects your refund rights.

Under Article 16(m) of the EU Consumer Rights Directive, you normally have fourteen days to change your mind about an online purchase. But if you ask us to supply a digital service immediately within that period, and you acknowledge that doing so ends your right to withdraw, then the right ends.

Activating an eSIM is exactly that. So before we reveal your QR code, we show you a notice explaining this, and we record your acknowledgement: the timestamp it was shown, the timestamp you confirmed, the version of the wording you saw, and the order and eSIM it relates to.

We keep that record for five years. Its purpose is evidential — it protects you as much as us, because it establishes precisely what you were told and when. Our Refund Policy explains what remains refundable after activation.


4. How long we keep your data

We keep personal data only as long as we need it. Deletion is enforced by an automated process that runs daily and logs each execution, so retention is not dependent on someone remembering to do it.

Category Retention period Why
Account and profile data For as long as your account exists, then 30 days after you request deletion, then anonymised Gives you a window to change your mind
Invoices, credit notes and accounting records 10 years from the end of the year of issue Bulgarian Accountancy Act, Art. 12
VAT records and supporting documentation 5 years from expiry of the limitation period for the relevant liability Bulgarian Value Added Tax Act
Order and payment reference records 10 years, aligned to the accounting record above Tax and accounting; dispute defence
Refund and chargeback records 10 years Card scheme dispute windows; accounting
eSIM provisioning and usage records 3 years from the end of the plan validity period Support, billing disputes, network reconciliation
Support threads and messages 3 years from closure of the thread Service quality; complaint handling; defence of claims
Consent receipts 5 years from the date consent was given or withdrawn Art. 7(1) GDPR — we must be able to demonstrate consent
Activation consent records 5 years Evidence of the Art. 16(m) acknowledgement
Audit log entries 7 years Accountability under Art. 5(2) GDPR; anti-money-laundering record-keeping
Webhook and integration events 1 year Operational reconciliation
Notification delivery logs 1 year Proving a message was sent when a dispute arises
Suppression list (people who have unsubscribed) Indefinite Deleting it would mean emailing you again, which is the opposite of what you asked for
Marketing preferences Until withdrawn, then 1 year Evidence of the withdrawal
Cookie consent records 12 months, then we ask again Consent should not be permanent
Anti-money-laundering records, where created 5 years from the end of the business relationship Bulgarian Measures Against Money Laundering Act
Backups Rotated on a cycle not exceeding 35 days Disaster recovery

Where we are required to keep something after you have asked us to delete your data, we restrict it — it is kept for the legal purpose only and is not used for anything else.


5. Who we share your data with

We share data only where it is necessary. We do not sell personal data, and we have never sold personal data.

5.1 Our suppliers

These organisations process personal data on our behalf, under written contracts that impose confidentiality, security and deletion obligations, and that prohibit them from using the data for their own purposes.

Supplier What they do Where they process What they receive
Supabase (cloud database platform) Hosts the database, authentication and file storage European Union Substantially all account, order and service data
Cloudflare, Inc. Content delivery, DDoS protection, web application firewall Global edge, EU-first routing IP address, request metadata, transient request content
PayNovus AD Card acquiring and payment processing Bulgaria Name, email, order amount, card data (which we never see)
eSIM Go Ltd Wholesale eSIM provisioning — primary supplier United Kingdom ICCID, IMSI, destination, plan parameters, activation status
Maya Mobile Inc. Wholesale eSIM provisioning — failover supplier United States ICCID, IMSI, destination, plan parameters, activation status
Transactional email provider Sends order confirmations, QR codes and service notices United States Name, email address, order and eSIM references, message content
Meta Platforms Ireland Ltd WhatsApp Business messaging, if you opt in to that channel Ireland, with onward transfer to the United States Telephone number, message content, delivery status
Better Stack Application logging, error tracking and uptime monitoring European Union and United States IP address, technical data, sanitised error context

The current list is maintained at /legal/sub-processors. We give thirty days' notice before adding or replacing a supplier that processes personal data.

Notably absent from that list: we do not use Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, or any other third-party advertising or cross-site tracking technology.

5.2 Authorities

We disclose personal data to public authorities only where we are legally obliged to. That includes the Bulgarian National Revenue Agency for tax purposes, and law enforcement or regulatory bodies acting under a valid legal instrument.

We assess every request. We do not accept informal requests. Where a request appears to exceed the requesting authority's powers, we challenge it. Where we are permitted to tell you that your data has been requested, we will.

5.3 Business transfers

If Skybyte or Banxs Technologies EOOD is involved in a merger, acquisition, or sale of assets, personal data may transfer to the acquiring entity. We would notify you before any such transfer took effect and before your data became subject to a different privacy policy, and the acquirer would be bound by commitments no less protective than these.

5.4 Professional advisers

We may share data with our lawyers, accountants, auditors and insurers where necessary and where they are bound by professional confidentiality obligations.

5.5 Not shared

We do not share your personal data with advertisers, data brokers, credit reference agencies, or any organisation for its own marketing purposes.


6. International transfers

We are in Bulgaria and most of your data stays in the European Economic Area. Some does not, and this section explains what protects it.

6.1 Transfers within the EEA

No special mechanism is required. Our database platform and our acquirer both process within the EEA.

6.2 Transfers to the United Kingdom

The European Commission has decided that the United Kingdom provides an adequate level of protection (Commission Implementing Decision (EU) 2021/1772). Transfers to our primary eSIM supplier rely on that decision.

6.3 Transfers to the United States

For US-based suppliers we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, and, where the supplier is certified, on the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795).

Following the Schrems II judgment we also apply supplementary measures:

  • data is encrypted in transit and at rest;
  • suppliers receive only the minimum categories of data needed for their function, which is why the table in Section 5.1 lists different data for each;
  • suppliers are contractually required to notify us of any binding government request for disclosure, to the extent they are legally permitted to do so;
  • suppliers are required to challenge overbroad requests where there is a reasonable basis, and to disclose only the minimum legally required;
  • we reassess the position in each jurisdiction periodically, and will suspend a transfer if we conclude it can no longer be adequately protected.

You may request a copy of the safeguards in place for any specific transfer by writing to contact@banxs.com.

6.4 Transfers inherent to mobile connectivity

This one is different in kind and we want to be honest about it.

When you use a Skybyte eSIM abroad, your device connects to a licensed mobile network operator in that country. That operator processes your connection data — location of the cell you are attached to, session times, volumes — under the telecommunications and lawful interception law of its own jurisdiction. This is inherent to how mobile networks work anywhere in the world, including on your normal home SIM.

We are not able to place that operator under our contractual control and we do not pretend otherwise. What we can tell you is what we disclose to enable the connection: the technical identifiers of the eSIM profile and the destination. We do not disclose your name, email address or payment details to mobile network operators.

If you are travelling somewhere where this matters to you, consider that the same is true of any mobile connectivity, and take the precautions you would normally take.


7. How we protect your data

Security is a set of practices, not a claim. Here is what we actually do.

Encryption. TLS 1.2 or above for everything in transit, TLS 1.3 preferred. AES-256 or equivalent at rest. HTTP Strict Transport Security enforced.

Passwords. Stored using a memory-hard adaptive hashing algorithm with a unique salt per user. Nobody at Skybyte can retrieve your password. If you lose it, we can only reset it.

Card data. We never receive your full card number. It goes directly from your browser to our acquirer's payment environment. Our own PCI DSS scope is limited to SAQ A, which is the narrowest scope available and reflects the fact that card data never touches our systems.

Database isolation. Every table containing personal data has row-level security enforced by the database engine itself, not by application code. This means a bug in our application cannot expose another customer's data, because the database refuses the query regardless of what the application asks for.

Access control. Least privilege by default. Staff access is role-scoped, requires multi-factor authentication, is logged to an append-only audit record, and is reviewed quarterly.

Financial integrity. Order and payment state changes are constrained by an explicit state machine. Invoice numbers are issued from a dedicated sequential allocator to satisfy the gap-free requirement in Bulgarian VAT law. Duplicate processing of payment events is prevented by idempotency controls.

Logging discipline. Sensitive values — tokens, secrets, payment identifiers — are stripped from error context and audit metadata before anything is written.

Availability. Automated backups with point-in-time recovery. Multi-availability-zone infrastructure. Automated reconciliation that detects and recovers stalled payment and provisioning states.

Testing. Dependency vulnerability scanning on every build. Static analysis and type checking enforced before deployment. Periodic security assessment and penetration testing.

No system is perfectly secure. If we suffer a breach affecting your personal data we will notify the Bulgarian Commission for Personal Data Protection within seventy-two hours as Article 33 GDPR requires, and we will notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms.


8. Your rights

You have the following rights. Exercising them is free, and we will not treat you differently for doing so.

8.1 Access — Article 15

You can ask what personal data we hold about you and receive a copy, along with information about why we process it, who we share it with, and how long we keep it.

Self-service: Account → Privacy → Export my data.

8.2 Rectification — Article 16

You can correct inaccurate data and complete incomplete data.

Self-service: Account → Profile. Some fields on issued invoices cannot be changed after issue because tax law requires the original record to be preserved; we would issue a corrected document instead.

8.3 Erasure — Article 17

You can ask us to delete your data. We will, except where we are legally required to keep something — principally accounting and tax records. In that case we restrict the retained data to the legal purpose and delete everything else.

Self-service: Account → Privacy → Delete my account. There is a thirty-day grace period before deletion completes, during which you can cancel.

8.4 Restriction — Article 18

You can ask us to stop processing your data while a dispute about its accuracy or our legal basis is resolved. We will hold it but not use it.

8.5 Portability — Article 20

You can receive the data you gave us in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller where technically feasible.

Self-service: Account → Privacy → Export my data (JSON).

8.6 Objection — Article 21

You can object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed for legal claims.

You can object to direct marketing at any time and we will always stop. No balancing test applies to marketing objections — the right is absolute.

8.7 Withdrawal of consent — Article 7(3)

Where we rely on consent, you can withdraw it as easily as you gave it.

Self-service: Account → Privacy, or the unsubscribe link in any marketing email.

8.8 Automated decision-making — Article 22

We run automated fraud screening on orders. It can decline an order or hold it for review. We do not consider this to produce legal effects concerning you or to affect you similarly significantly, because a declined order does not prevent you obtaining connectivity and a human review path is available on request to support@skybytesim.com.

We do not carry out profiling to evaluate your personal characteristics, preferences, behaviour, location or movements beyond what is described in this policy.

8.9 How to exercise a right

Use the self-service tools where they exist — they are faster. Otherwise write to contact@banxs.com.

We will acknowledge within five business days and respond substantively within one month. Where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month.

We may ask you to verify your identity before we act, particularly for access, portability and erasure requests. This protects you: it prevents someone else obtaining your data by pretending to be you.

We do not charge a fee. If a request is manifestly unfounded or excessive — in particular because it is repetitive — we may charge a reasonable administrative fee or refuse it, and we would explain why.

8.10 Complaints

If you think we have handled your data badly, tell us first at contact@banxs.com and give us a chance to fix it.

If you remain dissatisfied you have the right to complain to a supervisory authority:

Commission for Personal Data Protection (Комисия за защита на личните данни) 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria kzld@cpdp.bg · www.cpdp.bg

You may also complain to the supervisory authority in your own EU member state of residence or place of work, or where you believe the infringement occurred. You may also seek a judicial remedy.


9. Cookies and tracking

Our Cookie Policy sets out every cookie we use, what it does, how long it lasts, and which category it belongs to.

In summary: strictly necessary cookies keep you signed in and keep the checkout working, and do not require consent. Functional and analytics cookies do require consent and are off until you give it. We use no advertising cookies at all.

We honour the Do Not Track browser header and the Global Privacy Control (Sec-GPC) signal. If either is present we treat it as a refusal of non-essential cookies without asking you again.


10. Children

Skybyte is not directed at children and we do not knowingly collect personal data from anyone under sixteen. Our Terms of Service require account holders to be at least eighteen.

If you are a parent or guardian and believe a child has provided us with personal data, write to contact@banxs.com and we will delete it.


11. Marketing

We only send marketing emails if you have opted in. Opting in is never a condition of buying anything.

Every marketing email has a working one-click unsubscribe link. Unsubscribing takes effect immediately and we add you to a suppression list so you are not accidentally re-added later.

Service messages are different and you cannot opt out of them while you hold an active plan: order confirmations, your eSIM QR code, low-balance and expiry warnings, refund confirmations, security alerts, and notices of changes to these terms. These are not marketing — they are the service.


12. Business customers

Where an organisation buys Skybyte eSIMs for individuals it is responsible for — employees, contractors, delegates, students — that organisation is the controller of those individuals' personal data and Skybyte acts as its processor.

In that arrangement our Data Processing Agreement governs, and the organisation is responsible for telling those individuals how their data is used. If you have received a Skybyte eSIM through your employer or another organisation, ask them first — they determine what happens to your data. We will of course still honour your rights directly, and will coordinate with them.


13. If you are not in the European Union

We sell into 249 countries and territories. Our baseline is the GDPR, applied to everyone regardless of where you live, because operating two standards would be both harder and worse. Some jurisdictions give you additional or differently-framed rights, and this section covers the main ones.

13.1 United Kingdom

The UK GDPR and the Data Protection Act 2018 apply to UK residents. Your rights are substantially the same as those in Section 8. Your supervisory authority is the Information Commissioner's Office (ico.org.uk), and you may complain to it directly.

We have not appointed a UK representative under Article 27 UK GDPR, on the basis that our processing of UK residents' data is occasional and does not involve large-scale processing of special category data. If that assessment changes we will appoint one and update this policy.

13.2 Switzerland

The revised Swiss Federal Act on Data Protection applies to Swiss residents. Your rights broadly mirror those in Section 8. Your supervisory authority is the Federal Data Protection and Information Commissioner (edoeb.admin.ch).

References in this policy to the GDPR should be read as including the equivalent provisions of the Swiss FADP where you are a Swiss resident.

13.3 California

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information is collected, used, shared or sold; to delete it; to correct it; to opt out of sale or sharing; and to limit use of sensitive personal information.

Three specific statements for California residents:

  • We do not sell your personal information and have not done so in the preceding twelve months.
  • We do not share your personal information for cross-context behavioural advertising and have not done so in the preceding twelve months. This is why there are no advertising pixels on this site.
  • We do not collect sensitive personal information as that term is defined in the CPRA.

We honour the Global Privacy Control signal as a valid opt-out request, as described in Section 9. We will not discriminate against you for exercising any CCPA right.

13.4 Brazil

The Lei Geral de Proteção de Dados gives Brazilian residents rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. These map closely to Section 8 and we handle them through the same channels. Your authority is the Autoridade Nacional de Proteção de Dados (gov.br/anpd).

13.5 Other jurisdictions

If your local law gives you rights beyond those in Section 8, write to contact@banxs.com and we will honour them to the extent the law requires. If your local law appears to reduce the protection this policy gives you, we will apply this policy anyway.


14. Keeping your data accurate

We rely on you to keep your account details current, and it matters more here than on most services: your eSIM QR code is delivered to the email address on your account, and your billing country determines the VAT you pay.

If your email address becomes invalid we cannot deliver your purchase, and we may not be able to reach you about a problem with it. If your billing country is wrong, the VAT treatment applied to your invoice will be wrong, which can create a tax problem for you as well as for us.

You can update both from Account → Profile. We do not independently verify what you enter, other than validating VAT numbers against the European Commission's VIES service where you supply one.

Where we discover data is inaccurate — for example an email address that consistently bounces — we may correct or suppress it without being asked, and we will tell you if we can reach you by another means.


15. Anonymisation

When we say we anonymise data, we mean we irreversibly remove or replace the identifiers that link it to you, so that neither we nor anyone else can reasonably re-identify you from it, whether alone or by combining it with other information available to us.

Anonymised data falls outside the GDPR and we may retain and use it indefinitely — for example, to understand which destinations are growing, how long activation typically takes, or where errors cluster. This is genuinely anonymous data, not pseudonymised data held under a key we still possess.

Where we cannot anonymise something because we need to be able to identify it later — an invoice, for instance — we do not claim to have anonymised it. We restrict it instead, as described in Section 4.


16. What happens if a supplier relationship ends

If we stop using a supplier listed in Section 5.1, our contract with them requires that they delete or return the personal data they hold on our behalf, within a defined period, and certify that they have done so.

We will update the sub-processor list and, where the change is material to how your data is handled, we will tell you. Replacing a supplier does not by itself change what data we collect or why.


17. Security incidents

We maintain a documented incident response procedure. In outline:

Detection. Automated monitoring, error aggregation and access logging, supplemented by reports from customers, researchers and suppliers.

Assessment. We establish what data was affected, how many people, and what the likely consequences are. Where a supplier is the source, we require notification to us within twenty-four hours so that we retain time to meet our own obligations.

Containment and remediation. We isolate the cause, close it, and preserve evidence for investigation.

Notification. Where a breach is likely to result in a risk to your rights and freedoms we notify the Bulgarian Commission for Personal Data Protection within seventy-two hours of becoming aware of it, as Article 33 GDPR requires. Where the risk is high, we notify you directly and without undue delay, in plain language, telling you what happened, what it means for you, and what we are doing about it.

Review. Every incident, including near misses, is reviewed and the findings feed back into our controls.

If you believe you have found a security vulnerability in our systems, please report it to contact@banxs.com. We will acknowledge it, investigate, and will not pursue action against anyone who reports a genuine issue in good faith and does not access or exfiltrate other people's data in the process.


18. Contact

Privacy and data protection contact@banxs.com

Customer support support@skybytesim.com

Post Banxs Technologies EOOD, Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria

We aim to acknowledge privacy enquiries within five business days.


Banxs Technologies EOOD (trading as Skybyte) · Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria · EIK 206285017 · VAT BG206285017 · Registered with the Bulgarian Registry Agency · Data controller for the purposes of Regulation (EU) 2016/679

Version 2.0


Need a signed PDF copy? Email contact@banxs.com.