1. Data controller
The controller deciding why and how your data is processed is SHYP DIGITAL S.R.L. (eSIM Shyp), contact [email protected]. For requests strictly about data protection, use the same email with "GDPR" in the subject.
2. Principles we follow
- we collect only the data we need (minimization);
- we use it only for the purposes we requested it for;
- we keep it accurate and up to date;
- we retain it only as long as necessary;
- we protect it with appropriate technical and organizational measures.
3. Legal basis for processing
- Art. 6(1)(b) – contract performance (eSIM plan delivery);
- Art. 6(1)(c) – legal obligation (invoicing, accounting);
- Art. 6(1)(f) – legitimate interest (security, service improvement);
- Art. 6(1)(a) – consent (marketing, non-essential cookies).
4. Retention period
- Financial documents (invoices, orders): per tax law, usually 10 years.
- Account and contact data: while you're an active customer and a reasonable period after.
- Cookies: per durations in the Cookie policy.
5. Data subject rights
You have the right to access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent anytime. Details are in the Privacy policy.
6. Data transfers
If some partners (e.g. payment processor) process data outside the European Economic Area, we ensure adequate safeguards (standard contractual clauses or European Commission adequacy decisions).
7. How to make a GDPR request
Send an email to [email protected] with "GDPR" in the subject and tell us which right you want to exercise. We may ask for identity confirmation to protect data. We respond within 30 days.
8. Complaints
If you feel we haven't respected your rights, you can complain to the National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro. We'd still prefer you give us a chance to make things right first.