As the operator of esimpont.hu we take the protection of your data seriously. This notice is based on Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011 on informational self-determination.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address, (optional) name | Creating an account, signing in (one-time code by e-mail or Google account), contact | Art. 6(1)(b) GDPR — performance of a contract | until the account is deleted |
| Purchase data (plan, price, time), technical eSIM identifiers (ICCID, activation code) | Providing the eSIM service ordered, showing the QR code and usage data | Art. 6(1)(b) GDPR — performance of a contract | until the account is deleted or the service ends |
| Invoicing data (name, address, tax number) | Issuing and keeping invoices | Art. 6(1)(c) GDPR — legal obligation (Hungarian VAT and accounting acts) | 8 years |
| Support messages | Answering questions, handling complaints | Art. 6(1)(b) and (f) GDPR; for complaints, a statutory obligation | 3 years for complaints |
| Chat messages to the automated assistant, and the images you attach in the chat | Automated support answers and quality/error checking. When signed in, limited data about your own order and eSIM helps make the answer accurate. If you are signed in, we keep the conversation linked to your e-mail address so that support can see the history and you do not have to explain everything again. Images can only be attached while signed in; we review the image to answer, and if you ask for human help the agent can see it too. | Art. 6(1)(f) GDPR — legitimate interest (effective support) | full conversation and attached image for 30 days, then automatic deletion |
| Email address for newsletters and offers, the time and source of your consent, and the time of any withdrawal | Sending newsletters and promotional offers (e.g. discounts, refer-a-friend campaigns), and proving that you gave consent — and, if you withdrew it, that we must not send you any more such messages | GDPR Article 6(1)(a) — consent. Consent is voluntary and can be withdrawn at any time, free of charge | until you withdraw your consent. We keep a record of the withdrawal itself afterwards — precisely so that you receive no further such messages |
| Functional browser data (language, currency, theme) | Convenient operation of the website | “strictly necessary” storage — see the Cookie policy | until cleared in the browser |
| Analytics and ad-measurement data (pages visited, referring source, device and browser data, advertising identifiers) | Visitor statistics, plus measuring purchases that come from ads and ad targeting (Google Analytics, Google Ads, Meta, TikTok, Reddit) | Art. 6(1)(a) GDPR — consent, given on the cookie bar and withdrawable at any time | per each provider's own retention period (typically 2–14 months); we collect no new data after withdrawal |
| Our own cookie-free visit measurement (page opened, referring source) | Finding out which pages are useful — stores nothing in your browser and cannot identify you personally | Art. 6(1)(f) GDPR — legitimate interest (improving the service) | aggregated, 12 months |
We send newsletters and promotional offers only if you have given your prior, explicit consent — in your account, on the Notifications tab, using the “Offers & newsletter” switch. The switch is off by default; you can withdraw your consent there at any time, and every such email carries an unsubscribe link at the bottom. Unsubscribing does not affect the emails about your purchases (order confirmation, QR code, data usage alert, invoice): those are not advertising but part of performing the contract, so you keep receiving them. We do not carry out automated decision-makingWe do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR — the advertising platforms' tags may perform targeting in their own systems on the basis of your consent; section 3 below and the Cookie policy explain this.
| Partner | Activity | Data |
|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg) | Hosting and cloud infrastructure (EU data centre, Frankfurt); sign-in management (Amazon Cognito), e-mail sending (Amazon SES) | account data, purchase data |
| eSIM wholesaler (mobile network wholesale partner established in the EU) | Providing the eSIMs and data plans on mobile networks | technical eSIM identifiers (ICCID, activation code); we do not pass on your e-mail address |
| Google Ireland Ltd. — only if you sign in with Google | Sign-in (OAuth) | e-mail address, name (from your Google account, at your initiative) |
| Stripe Payments Europe, Ltd. (Ireland) and its affiliates (Stripe, Inc., USA) | Processing card payments (including Apple Pay / Google Pay / Link) and fraud prevention — your card details are handled solely by Stripe and never reach us. Stripe also acts as an independent controller under its own privacy policy. | name, e-mail address, billing address, transaction data |
| KBOSS.hu Kft. (Számlázz.hu), 1031 Budapest, Záhony utca 7., Hungary | Issuing the electronic invoice, reporting to the Hungarian tax authority and delivering the invoice by e-mail | billing name and address, tax number (if given), e-mail address, purchase data |
| Google Ireland Ltd. (Gemini API) — when you use the automated chat | Generating the chat answers — the messages you type and the recent conversation history are sent to Google's automated service. When signed in we also send the limited context needed for your order. Number sequences that look like a card number are masked automatically; please do not enter card details or special category data. | the messages you type, the history and — when signed in — limited order context |
| Google Ireland Ltd. — Google Analytics 4 and Google Ads · consent only | Visitor statistics (with anonymised IP address), plus measuring purchases that come from ads and ad targeting | visit and device data, advertising identifiers; on purchase, an irreversible hash of the buyer's e-mail address and name to match the conversion — not the address itself |
| Meta Platforms Ireland Ltd. — Meta Pixel · consent only | Measuring and targeting Facebook and Instagram ads | visit and device data, advertising identifiers |
| TikTok Technology Ltd. (Ireland) — TikTok Pixel · consent only | Measuring and targeting TikTok ads | visit and device data, advertising identifiers |
| Reddit, Inc. (USA) — Reddit Pixel · consent only | Measuring and targeting Reddit ads | visit and device data, advertising identifiers |
Data is stored in the European Union. Where data is transferred to a third country — to Reddit, and to the US affiliates of Stripe and Google — we rely on the safeguards in Chapter V GDPR (EU–US Data Privacy Framework or standard contractual clauses). The advertising and analytics providers also act as independent controllers under their own notices.
We handle your data over an encrypted connection (HTTPS/TLS) and store it encrypted. Instead of a password, your account uses a one-time code by e-mail or Google sign-in. Access to our systems is strictly limited, and every user can reach only their own data.
You can submit your request to info@esimpont.hu; we reply within one month at the latest.
If you believe our processing is unlawful, you may lodge a complaint with the Hungarian supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
1055 Budapest, Falk Miksa utca 9–11., Hungary · Postal address: 1363 Budapest, Pf. 9.
Phone: +36 1 391 1400 · E-mail: ugyfelszolgalat@naih.hu · Web: naih.hu
If you are in another EU Member State, you may equally contact the supervisory authority of your habitual residence, and you may also enforce your rights before the court competent for your place of residence.
We may update this notice from time to time (for example when a new processor is engaged). The version in force is always available on this page; we notify registered users of material changes by e-mail.
Last updated: 16 August 2026 · Terms · Cookies · Legal notice