Sub-processors

Last updated: 18 August 2026Effective from: 18 August 2026

Skybyte — a trading name of Banxs Technologies EOOD

Version 2.0


What this page is

To run Skybyte we rely on a small number of specialist suppliers. Some of them process personal data on our behalf. Under Article 28 of the GDPR those suppliers are our sub-processors, and we are required to keep a record of who they are, what they do, and what protects the data they handle.

This page is that record. It is not a marketing page and it is not a general list of vendors — a company we buy laptops from is not on here, because they do not touch your data. Everything listed below receives personal data, and each entry states exactly which categories.

The list is authoritative. Our Data Processing Agreement incorporates it by reference, and our Privacy Policy points here for the detail.


How we choose and control sub-processors

Before we engage a sub-processor we assess:

  • whether the function genuinely requires personal data, and if so the minimum categories needed;
  • where processing takes place, and what transfer mechanism applies if that is outside the EEA;
  • the supplier's security posture, certifications and breach history;
  • whether their standard data processing terms meet the requirements of Article 28(3) GDPR, and if not, whether they will agree to terms that do;
  • what happens to the data if we stop using them.

Every sub-processor is engaged under a written contract that requires them, at minimum, to:

  • process personal data only on our documented instructions;
  • keep it confidential and impose confidentiality obligations on their own personnel;
  • implement appropriate technical and organisational security measures under Article 32 GDPR;
  • obtain our authorisation before engaging their own sub-processors, and remain liable for them;
  • assist us in responding to data subject rights requests;
  • notify us of a personal data breach without undue delay, and in any event within twenty-four hours;
  • delete or return the data when the relationship ends, and certify that they have done so;
  • submit to audit.

We review the list at least annually, and whenever we add or change a supplier.


Notification of changes

We give thirty (30) days' notice before a new sub-processor begins processing personal data, and before we replace an existing one.

Notice is given by:

  • updating this page, with the version and date at the foot of it;
  • emailing business customers who have asked to be notified.

To subscribe to change notifications, write to contact@banxs.com with the subject line "Sub-processor notifications".

Business customers may object to a proposed sub-processor on reasonable data protection grounds within fifteen (15) days. Section 8.6 of the Data Processing Agreement sets out what happens then.

Where a supplier ceases operating without notice, or where continuing to use them would create a material security or legal risk, we may replace them faster than thirty days. In that case we notify as soon as we practicably can, and the same right of objection applies.


Current sub-processors

Infrastructure and platform

Supabase Application database, authentication, file storage

Function Hosts the primary application database, user authentication and object storage
Processing location European Union
Data categories Account and identity data; authentication data; order and billing data; payment reference data (never full card numbers); connectivity and usage data; support content; consent records; audit records
Transfer mechanism None required — processing within the EEA
Security Encryption at rest and in transit; row-level security enforced at the database engine; point-in-time recovery

Cloudflare, Inc. Content delivery, security and edge compute

Function Serves the website, mitigates denial-of-service attacks, provides web application firewall and TLS termination
Processing location Global edge network with EU-first routing; corporate entity in the United States
Data categories IP address; request metadata (user agent, timestamps, requested paths); transient request and response content in the course of delivery
Transfer mechanism Standard Contractual Clauses (Decision (EU) 2021/914) and EU–US Data Privacy Framework certification
Notes Content is processed in transit, not stored, other than short-lived caching of static assets

Payments

PayNovus AD Card acquiring and payment processing

Function Acquires and processes card payments; handles authorisation, capture, refunds and chargebacks
Processing location Bulgaria
Data categories Cardholder name; email address; billing country; transaction amount and currency; full card data entered directly into their environment
Transfer mechanism None required — processing within the EEA
Notes Full primary account numbers are captured by PayNovus and never transmitted through or stored on Skybyte systems. Skybyte receives only card brand, last four digits, expiry and a transaction token. This is why Skybyte's PCI DSS scope is limited to SAQ A.

See the Payment Disclosures for the full description of how card payments are handled.


Connectivity

eSIM Go Ltd Wholesale eSIM provisioning — primary supplier

Function Issues eSIM profiles, provides activation credentials, reports usage against allowance
Processing location United Kingdom
Data categories ICCID; IMSI; destination country or region; plan parameters (data volume, validity); activation status and timestamp; aggregate consumption counters
Transfer mechanism UK adequacy decision (Commission Implementing Decision (EU) 2021/1772)
Notes Receives technical identifiers only. Does not receive customer name, email address or payment details.

Maya Mobile Inc. Wholesale eSIM provisioning — failover supplier

Function Alternative provisioning route used where the primary supplier lacks coverage or is unavailable
Processing location United States
Data categories ICCID; IMSI; destination country or region; plan parameters; activation status and timestamp; aggregate consumption counters
Transfer mechanism Standard Contractual Clauses (Decision (EU) 2021/914) with supplementary measures
Notes As above — technical identifiers only, no name, email or payment data

Communications

Transactional email provider Order confirmations, eSIM delivery, service notices

Function Delivers transactional email — order confirmations, QR codes and installation instructions, expiry warnings, refund confirmations, password resets, security notices
Processing location United States
Data categories Name; email address; order and eSIM reference data; the content of the message sent, which includes the eSIM QR code
Transfer mechanism Standard Contractual Clauses (Decision (EU) 2021/914) and EU–US Data Privacy Framework certification
Notes Message content is retained by the provider for a limited period for delivery diagnostics

Meta Platforms Ireland Ltd WhatsApp Business messaging — optional channel

Function Delivers notifications over WhatsApp where the customer has explicitly opted in to that channel
Processing location Ireland, with onward transfer to the United States
Data categories Telephone number; message content; delivery and read status
Transfer mechanism EEA controller for the Irish entity; Standard Contractual Clauses for onward transfer to Meta Platforms, Inc.
Notes Used only where the customer has opted in. Not used for marketing. Opting out returns the customer to email-only delivery with no loss of service.

Observability

Better Stack Application logging, error tracking and uptime monitoring

Function Collects application logs and error reports so that faults can be diagnosed; monitors service availability
Processing location European Union and United States
Data categories IP address; user agent; request path and timestamps; sanitised error context
Transfer mechanism Standard Contractual Clauses (Decision (EU) 2021/914) and EU–US Data Privacy Framework certification
Notes Sensitive values — authentication tokens, secrets, payment identifiers — are stripped from error context before transmission

Not sub-processors

Three categories of third party are deliberately excluded from the list above, and it is worth explaining why.

Mobile network operators

When your eSIM is active, a licensed mobile network operator in the country you are visiting carries your traffic. That operator processes connection data — the cell your device is attached to, session start and end times, data volumes — under the telecommunications and lawful interception law of its own jurisdiction.

Those operators are not our sub-processors. They are independent controllers. We cannot place them under our contractual control and we do not claim to. This is inherent to how mobile networks work everywhere, including on your normal home SIM.

What we can tell you is what is disclosed to enable the connection: the technical identifiers of the eSIM profile and the destination. Your name, email address and payment details are never disclosed to a mobile network operator.

Analytics

We use a self-hosted analytics system running on our own infrastructure. Because no third party receives the data, there is no sub-processor to list. This was a deliberate choice.

Advertising and tracking technology

There is nothing to list here because we use none. Specifically, we do not use Google Analytics, Google Ads, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, X/Twitter conversion tracking, Pinterest Tag, Reddit Pixel, or any comparable advertising or cross-site tracking technology.


Professional advisers

Our lawyers, accountants, auditors and insurers may receive personal data where it is necessary for them to advise us — for example in defending a legal claim or completing a statutory audit.

They are not listed as sub-processors because they act as independent controllers subject to their own professional obligations, and because the disclosure is occasional and specific rather than systematic. They are bound by professional confidentiality duties in every case.


Questions

Write to contact@banxs.com.

If you are a business customer conducting vendor due diligence and need documentation beyond this page — a completed security questionnaire, a copy of the transfer safeguards for a specific supplier, or a countersigned Data Processing Agreement — say so and we will provide what we can.


Banxs Technologies EOOD (trading as Skybyte) · Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria · EIK 206285017 · VAT BG206285017 · Registered with the Bulgarian Registry Agency · Data protection contact: contact@banxs.com

Version 2.0


Need a signed PDF copy? Email contact@banxs.com.