Skybyte — a trading name of Banxs Technologies EOOD
Version 2.0
What this page is
To run Skybyte we rely on a small number of specialist suppliers. Some of them process personal data on our behalf. Under Article 28 of the GDPR those suppliers are our sub-processors, and we are required to keep a record of who they are, what they do, and what protects the data they handle.
This page is that record. It is not a marketing page and it is not a general list of vendors — a company we buy laptops from is not on here, because they do not touch your data. Everything listed below receives personal data, and each entry states exactly which categories.
The list is authoritative. Our Data Processing Agreement incorporates it by reference, and our Privacy Policy points here for the detail.
How we choose and control sub-processors
Before we engage a sub-processor we assess:
- whether the function genuinely requires personal data, and if so the minimum categories needed;
- where processing takes place, and what transfer mechanism applies if that is outside the EEA;
- the supplier's security posture, certifications and breach history;
- whether their standard data processing terms meet the requirements of Article 28(3) GDPR, and if not, whether they will agree to terms that do;
- what happens to the data if we stop using them.
Every sub-processor is engaged under a written contract that requires them, at minimum, to:
- process personal data only on our documented instructions;
- keep it confidential and impose confidentiality obligations on their own personnel;
- implement appropriate technical and organisational security measures under Article 32 GDPR;
- obtain our authorisation before engaging their own sub-processors, and remain liable for them;
- assist us in responding to data subject rights requests;
- notify us of a personal data breach without undue delay, and in any event within twenty-four hours;
- delete or return the data when the relationship ends, and certify that they have done so;
- submit to audit.
We review the list at least annually, and whenever we add or change a supplier.
Notification of changes
We give thirty (30) days' notice before a new sub-processor begins processing personal data, and before we replace an existing one.
Notice is given by:
- updating this page, with the version and date at the foot of it;
- emailing business customers who have asked to be notified.
To subscribe to change notifications, write to contact@banxs.com with the subject line "Sub-processor notifications".
Business customers may object to a proposed sub-processor on reasonable data protection grounds within fifteen (15) days. Section 8.6 of the Data Processing Agreement sets out what happens then.
Where a supplier ceases operating without notice, or where continuing to use them would create a material security or legal risk, we may replace them faster than thirty days. In that case we notify as soon as we practicably can, and the same right of objection applies.
Current sub-processors
Infrastructure and platform
Supabase Application database, authentication, file storage
| Function | Hosts the primary application database, user authentication and object storage |
| Processing location | European Union |
| Data categories | Account and identity data; authentication data; order and billing data; payment reference data (never full card numbers); connectivity and usage data; support content; consent records; audit records |
| Transfer mechanism | None required — processing within the EEA |
| Security | Encryption at rest and in transit; row-level security enforced at the database engine; point-in-time recovery |
Cloudflare, Inc. Content delivery, security and edge compute
| Function | Serves the website, mitigates denial-of-service attacks, provides web application firewall and TLS termination |
| Processing location | Global edge network with EU-first routing; corporate entity in the United States |
| Data categories | IP address; request metadata (user agent, timestamps, requested paths); transient request and response content in the course of delivery |
| Transfer mechanism | Standard Contractual Clauses (Decision (EU) 2021/914) and EU–US Data Privacy Framework certification |
| Notes | Content is processed in transit, not stored, other than short-lived caching of static assets |
Payments
PayNovus AD Card acquiring and payment processing
| Function | Acquires and processes card payments; handles authorisation, capture, refunds and chargebacks |
| Processing location | Bulgaria |
| Data categories | Cardholder name; email address; billing country; transaction amount and currency; full card data entered directly into their environment |
| Transfer mechanism | None required — processing within the EEA |
| Notes | Full primary account numbers are captured by PayNovus and never transmitted through or stored on Skybyte systems. Skybyte receives only card brand, last four digits, expiry and a transaction token. This is why Skybyte's PCI DSS scope is limited to SAQ A. |
See the Payment Disclosures for the full description of how card payments are handled.
Connectivity
eSIM Go Ltd Wholesale eSIM provisioning — primary supplier
| Function | Issues eSIM profiles, provides activation credentials, reports usage against allowance |
| Processing location | United Kingdom |
| Data categories | ICCID; IMSI; destination country or region; plan parameters (data volume, validity); activation status and timestamp; aggregate consumption counters |
| Transfer mechanism | UK adequacy decision (Commission Implementing Decision (EU) 2021/1772) |
| Notes | Receives technical identifiers only. Does not receive customer name, email address or payment details. |
Maya Mobile Inc. Wholesale eSIM provisioning — failover supplier
| Function | Alternative provisioning route used where the primary supplier lacks coverage or is unavailable |
| Processing location | United States |
| Data categories | ICCID; IMSI; destination country or region; plan parameters; activation status and timestamp; aggregate consumption counters |
| Transfer mechanism | Standard Contractual Clauses (Decision (EU) 2021/914) with supplementary measures |
| Notes | As above — technical identifiers only, no name, email or payment data |
Communications
Transactional email provider Order confirmations, eSIM delivery, service notices
| Function | Delivers transactional email — order confirmations, QR codes and installation instructions, expiry warnings, refund confirmations, password resets, security notices |
| Processing location | United States |
| Data categories | Name; email address; order and eSIM reference data; the content of the message sent, which includes the eSIM QR code |
| Transfer mechanism | Standard Contractual Clauses (Decision (EU) 2021/914) and EU–US Data Privacy Framework certification |
| Notes | Message content is retained by the provider for a limited period for delivery diagnostics |
Meta Platforms Ireland Ltd WhatsApp Business messaging — optional channel
| Function | Delivers notifications over WhatsApp where the customer has explicitly opted in to that channel |
| Processing location | Ireland, with onward transfer to the United States |
| Data categories | Telephone number; message content; delivery and read status |
| Transfer mechanism | EEA controller for the Irish entity; Standard Contractual Clauses for onward transfer to Meta Platforms, Inc. |
| Notes | Used only where the customer has opted in. Not used for marketing. Opting out returns the customer to email-only delivery with no loss of service. |
Observability
Better Stack Application logging, error tracking and uptime monitoring
| Function | Collects application logs and error reports so that faults can be diagnosed; monitors service availability |
| Processing location | European Union and United States |
| Data categories | IP address; user agent; request path and timestamps; sanitised error context |
| Transfer mechanism | Standard Contractual Clauses (Decision (EU) 2021/914) and EU–US Data Privacy Framework certification |
| Notes | Sensitive values — authentication tokens, secrets, payment identifiers — are stripped from error context before transmission |
Not sub-processors
Three categories of third party are deliberately excluded from the list above, and it is worth explaining why.
Mobile network operators
When your eSIM is active, a licensed mobile network operator in the country you are visiting carries your traffic. That operator processes connection data — the cell your device is attached to, session start and end times, data volumes — under the telecommunications and lawful interception law of its own jurisdiction.
Those operators are not our sub-processors. They are independent controllers. We cannot place them under our contractual control and we do not claim to. This is inherent to how mobile networks work everywhere, including on your normal home SIM.
What we can tell you is what is disclosed to enable the connection: the technical identifiers of the eSIM profile and the destination. Your name, email address and payment details are never disclosed to a mobile network operator.
Analytics
We use a self-hosted analytics system running on our own infrastructure. Because no third party receives the data, there is no sub-processor to list. This was a deliberate choice.
Advertising and tracking technology
There is nothing to list here because we use none. Specifically, we do not use Google Analytics, Google Ads, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, X/Twitter conversion tracking, Pinterest Tag, Reddit Pixel, or any comparable advertising or cross-site tracking technology.
Professional advisers
Our lawyers, accountants, auditors and insurers may receive personal data where it is necessary for them to advise us — for example in defending a legal claim or completing a statutory audit.
They are not listed as sub-processors because they act as independent controllers subject to their own professional obligations, and because the disclosure is occasional and specific rather than systematic. They are bound by professional confidentiality duties in every case.
Questions
Write to contact@banxs.com.
If you are a business customer conducting vendor due diligence and need documentation beyond this page — a completed security questionnaire, a copy of the transfer safeguards for a specific supplier, or a countersigned Data Processing Agreement — say so and we will provide what we can.
Banxs Technologies EOOD (trading as Skybyte) · Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria · EIK 206285017 · VAT BG206285017 · Registered with the Bulgarian Registry Agency · Data protection contact: contact@banxs.com
Version 2.0