1. Who we are and scope of this policy
eSimerge LTD ("eSimerge", "we", "our", or "us") is a company incorporated in England & Wales with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom. We operate the eSimerge wholesale eSIM platform (the "Platform"), including the websites at esimerge.com and its subdomains, the partner portal, the developer portal, the public APIs, our transactional email and notification systems, and the support channels that surround them (collectively, the "Services").
This Privacy Policy explains the categories of personal data we collect about partners, the people who work for our partners, visitors to our websites, applicants to our partner programme, end users of eSIMs we provision, and people who contact our support or commercial teams. It explains why we collect that data, how we use it, who we share it with, how long we keep it, where it is stored, the safeguards we apply, and the rights you have under applicable data-protection law including the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation ("EU GDPR"), the UK Data Protection Act 2018, and the Privacy and Electronic Communications Regulations ("PECR"). For privacy enquiries, contact contact us.
2. Our role: controller and processor
For data we collect directly about our partners, partner staff, applicants, and website visitors, eSimerge acts as the data controller. For data that flows through the Platform as a result of partner activity (for example, end-user identifiers, activation events, and usage metadata generated when an eSIM provisioned by you is used by your customer), eSimerge generally acts as a processor on behalf of the partner, who is the controller for that data. Where we are a processor, our handling of personal data is governed by the Data Processing Addendum ("DPA") available on request.
3. Categories of personal data we collect
3.1 Account and identity data
- Full name, business email, job title, telephone number.
- Hashed password and authentication metadata (e.g., MFA enrolment, last login).
- Profile preferences, language, time zone, notification settings.
3.2 Partner and KYC/KYB data
- Legal entity name, registration number, registered and trading addresses.
- Beneficial ownership information, directors, authorised signatories.
- Tax identification numbers (VAT, EIN, equivalents).
- Copies of identity documents, proof of address, telecommunications licences, and bank statements where required for onboarding or anti-money-laundering compliance.
- Sanctions, politically-exposed-person, and adverse-media screening results.
3.3 Billing and transaction data
- Wallet top-ups, invoices, credit notes, statements, refund records.
- Payment-method metadata (last four digits, card brand, expiry, billing country) — full card numbers are tokenised by our PCI-DSS-compliant payment processors and never stored by us.
- Bank account details where you choose to pay or be refunded by transfer.
3.4 Operational and usage data
- Orders, plan SKUs, activation codes (ICCID, EID, LPA string), allocation timestamps.
- Aggregate usage volumes, attach/detach events, country and Carrier of attachment, session start and end times.
- API request logs, webhook delivery logs, idempotency keys.
- Support tickets, chat transcripts, call recordings (where notified in advance), and the metadata of any document you upload.
3.5 Technical and security data
- IP address, user agent, device type, operating system, browser fingerprint hash.
- Session identifiers, audit logs, access logs, anomaly-detection signals.
- Cookies and similar technologies (see section 9).
3.6 Marketing and communications data
- Subscription status for newsletters, product updates, and partner announcements.
- Open and click metadata on transactional and marketing emails (used to improve deliverability and content relevance).
- Records of correspondence with our commercial, support, and legal teams.
4. Sources of personal data
We obtain personal data from the following sources:
- Directly from you when you apply to the partner programme, register, use the Services, or contact us.
- From your employer or principal when they invite you as an authorised user.
- From our payment processors when you fund a Wallet or receive a refund.
- From Carriers and aggregators reporting activation, usage, and fraud signals on eSIMs we provisioned for you.
- From identity-verification, sanctions, and adverse-media screening providers used for KYC/KYB and AML checks.
- From publicly available sources (e.g., company registries, sanctions lists, your public website).
- From our analytics, error-reporting, and security-monitoring tools.
5. Purposes and legal bases
We process personal data only where we have a lawful basis under UK GDPR / EU GDPR. The principal purposes and legal bases are:
- Performance of a contract: creating and maintaining your account, accepting and fulfilling orders, provisioning eSIMs, managing your Wallet, issuing invoices, providing support, and otherwise delivering the Services.
- Legitimate interests: securing the Platform; preventing fraud, abuse, and bypass-fraud schemes; debugging and improving the Services; assessing partner risk; conducting business analytics; pursuing or defending legal claims; sending business-to-business marketing that is relevant to your role; identifying you as a Partner in our marketing where you have not objected.
- Compliance with a legal obligation: tax, accounting, regulatory reporting, KYC/KYB, AML, CTF, sanctions screening, lawful intercept obligations to the extent applicable, and responding to validly issued government requests.
- Consent: non-essential cookies and similar technologies, optional analytics, marketing to individuals who are not business contacts of a partner, and any other processing for which consent is required by law. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
6. Recipients, processors, and subprocessors
We share personal data with the following categories of recipients:
- Tier-1 mobile network operators and aggregators to reserve, provision, activate, and operate eSIM profiles, and to receive usage and fraud-control signals.
- Cloud infrastructure providers (compute, storage, content delivery, edge security, observability) that host the Platform.
- Payment service providers and acquiring banks for Wallet top-ups, refunds, settlement, and reconciliation.
- Email, SMS, and notification providers for transactional messages and partner alerts.
- Customer-support tooling for ticketing, chat, and knowledge-base operations.
- Identity-verification, sanctions, and AML screening providers.
- Professional advisors (lawyers, accountants, auditors, insurers) under confidentiality obligations.
- Tax, regulatory, and law-enforcement authorities where we are legally required, or where we believe in good faith that disclosure is necessary to protect rights, property, or safety.
- Acquirers or successors in the event of a merger, acquisition, financing, reorganisation, or sale of assets, in which case we will require equivalent protection of personal data.
We do not sell personal data. An up-to-date subprocessor list is available on request and is appended to the DPA we sign with partners that require one.
7. International transfers
We are based in the United Kingdom. Some of our processors operate in the European Economic Area, the United States, and other jurisdictions. Where personal data is transferred outside the UK or EEA to a country that has not received an adequacy decision, we rely on appropriate safeguards including the UK International Data Transfer Addendum ("UK IDTA"), the EU Standard Contractual Clauses ("SCCs"), and supplementary technical and contractual measures. Copies of the relevant transfer mechanisms are available on request.
8. Retention
We retain personal data only for as long as we have a lawful purpose to do so. Indicative retention periods are:
- Account data: for the life of the account and up to 24 months after closure, for dispute resolution and reactivation.
- KYC/KYB and AML records: at least 5 years after the end of the partner relationship, as required by anti-money-laundering law.
- Billing, invoicing, and tax records: up to 7 years (longer where local tax law requires).
- Operational logs (orders, eSIM events): typically 24–36 months, then aggregated or deleted.
- Security and audit logs: 12–24 months.
- Support tickets: 24 months after closure.
- Marketing data: until you unsubscribe or after 24 months of inactivity, whichever comes first.
At the end of the applicable retention period we delete or irreversibly anonymise the data, except where retention is required by law or is necessary for the establishment, exercise, or defence of legal claims.
9. Cookies and similar technologies
We use a small number of cookies and equivalent storage mechanisms. These fall into the following categories:
- Strictly necessary: session management, authentication, security tokens, load balancing, and consent state. These cannot be disabled.
- Functional: remembering your language, theme, and dashboard preferences.
- Analytics: measuring traffic and feature usage on an aggregated basis, where permitted by your consent.
- Security: bot detection, anomaly detection, and fraud prevention.
Where required by law, non-essential cookies are loaded only after you grant consent through our cookie banner. You can change your preferences at any time by clearing your browser cookies or re-opening the cookie banner from the footer of any page.
10. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you and obtain a copy.
- Rectify data that is inaccurate or incomplete.
- Erase data where there is no overriding legal basis for us to keep it.
- Restrict processing in certain circumstances, for example while we verify a rectification request.
- Object to processing based on legitimate interests, including direct marketing.
- Port data you provided to us to another controller, in a structured, commonly used, machine-readable format.
- Withdraw consent at any time where consent is the legal basis.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not currently make such decisions about you).
- Lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office ("ICO") at ico.org.uk.
To exercise any right, email contact us. We may need to verify your identity before responding and will reply within the statutory deadline (one month for UK/EU GDPR requests, extendable by two further months for complex requests).
11. Security
We maintain administrative, technical, and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These include encryption in transit (TLS), encryption at rest for sensitive datastores, role-based access control with least-privilege defaults, multi-factor authentication for privileged operators, environment isolation between production and non-production, audit logging, vulnerability management, penetration testing, secure software-development-lifecycle practices, and incident-response procedures. No system is perfectly secure; please report any suspected vulnerability or incident immediately to contact us.
12. Children
The Services are offered to businesses and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can delete it.
13. Automated decision-making and profiling
We use automated tools for fraud detection, risk scoring, and anti-abuse controls. These tools may flag transactions or accounts for human review but do not, without human intervention, produce legal effects on you. Where you disagree with the outcome of a review, you may request a manual reconsideration by writing to contact us.
14. Third-party links and integrations
The Services may link to or integrate with third-party websites and tools (for example documentation portals, payment-processor checkout pages, or our partners' own systems). This Privacy Policy does not apply to those third parties. Please review their own privacy notices before providing personal data.
15. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services. The "Effective" date at the top of this page reflects the latest revision. Material changes will be communicated through the partner portal or by email. We encourage you to review this page periodically.
16. Contact
For any privacy question, complaint, or rights request, contact contact us, or write to eSimerge LTD, Data Protection, 128 City Road, London, EC1V 2NX, United Kingdom.
This document is provided as a plain-language template and does not constitute legal advice. Please have qualified counsel review before relying on it in production. Questions? Contact us.