Privacy Policy
What Esimbit does with the personal data of resellers and visitors to esimbit.com — and what it deliberately does not do.
النصوص مكتملة لكنها لم تمرّ بعد بمراجعة قانونية، فهي غير سارية ومحجوبة عن محركات البحث.
يُنشر هذا المستند بالإنجليزية. النص الإنجليزي هو النسخة المعتمدة.
Who this policy covers
This policy explains what LOKUM TECH LLC ("Esimbit", "we") does with personal data on esimbit.com: the marketing site, and the reseller panel you sign in to. For everything described here, we are the controller — we decide why the data is held and what happens to it.
If you bought an eSIM from a store built on Esimbit, this is not your policy. Each store publishes its own privacy notice, and the reseller who runs that store is the controller for your order. Read the notice on the store you bought from.
We still hold that shopper data, because the store runs on our software. We hold it on the reseller’s instructions, as their processor, and what we may do with it is set by the Data Processing Addendum rather than by this policy.
| Detail | Value |
|---|---|
| Controller | LOKUM TECH LLC |
| Registered address | 8 The Green, Suite A Dover, DE 19901 |
| Registration | 4872118 |
| Privacy contact | [email protected] |
What we collect, and where it comes from
Most of this you type in yourself. The rest arrives because you used the service, or because Stripe told us your subscription changed.
| What | Specifically | Where it comes from |
|---|---|---|
| Account details | Company name, your name, your work email, your chosen language, and your password — kept only as a hash, never as text we could read. | You, at signup and whenever you edit your profile. |
| Your team | Each member’s name, email, language and role, and when they were last active. For an invitation that has not been accepted: the email address, the role offered, who sent it, and when it expires. | You and your colleagues, in the panel. An invited person’s address reaches us from whoever invited them. |
| Subscription state | Your plan, billing interval, trial end date, subscription status, and the Stripe identifiers that point at your record there. | You, when you choose a plan; Stripe, when your subscription starts, renews, fails or ends. |
| Support correspondence | What you write to us and what we write back, including anything you attach. | You, when you get in touch. |
| Marketing-form leads | Your email address, which form it came from, and your language. | You, if you ask to be notified or ask for a demo. Nothing else on the marketing site collects anything. |
| Server logs | Your IP address, the time, what was requested, and what our server answered. | Automatically, whenever a browser or a client calls our servers. |
We never see your card number. Subscribing sends you to Stripe’s own hosted checkout page, and the card details you type there go to Stripe, not to us. What comes back is a status and a reference.
Separately from personal data, your workspace holds the provider and payment-gateway keys you connect. Those are your secrets, not your identity: they are encrypted at rest, used only to call those services on your behalf, and never returned in full — the panel is sent only the last four characters of a stored key, so that you can tell two connections apart. The Data Processing Addendum and the Security page describe how they are handled.
Why we process it, and on what legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Create your workspace, sign you in, and run the panel | This is the service you asked for. | Performance of a contract (GDPR Art 6(1)(b)). |
| Charge your subscription, run your trial, and handle renewal and failed payments | You subscribed, and we have to bill you correctly. | Performance of a contract (Art 6(1)(b)). |
| Keep invoices, tax records and accounting entries | The law requires us to keep them, whatever either of us would prefer. | Legal obligation (Art 6(1)(c)). |
| Send service email: password resets, verification codes, invoices, and notices about your account | You cannot use the account without them. These are not marketing and you cannot unsubscribe from them while the account is open. | Performance of a contract (Art 6(1)(b)). |
| Answer your support messages | You asked us a question. | Performance of a contract (Art 6(1)(b)), or our legitimate interest in helping people who write to us (Art 6(1)(f)). |
| Email an invitation to a colleague you added | An account that only one person can reach is not much use to a company. | Our legitimate interest, and the inviting company’s, in letting a team share one workspace (Art 6(1)(f)). |
| Keep server logs, block abuse, and investigate faults | To keep the service standing up and to work out what went wrong when it does not. | Our legitimate interest in a secure, working service (Art 6(1)(f)). |
| Email you after you fill in a "notify me" or demo form | You asked to hear from us. | Your consent (Art 6(1)(a)), which you can withdraw at any time. |
| Answer a lawful request from a court or a regulator | We have no choice. | Legal obligation (Art 6(1)(c)). |
Where we rely on a legitimate interest, you can object, and we will stop unless we can show grounds that override yours. Where we rely on consent, withdrawing it is one email and costs you nothing else — the account carries on as before.
Things we do not do: we do not sell personal data, we do not share it for anyone else’s advertising, we do not build profiles of you, and we make no automated decision that produces a legal effect for you or similarly significantly affects you.
Where the data lives
The production database and its backups are in Frankfurt, Germany (eu-central-1).
Some suppliers in the list above operate outside that region, so data reaches them there. Where a transfer leaves the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s standard contractual clauses, with the UK addendum where the UK is involved, plus whatever additional measures the transfer needs. Transfers out of Turkey are covered separately below.
You can ask us for a copy of the safeguards that apply to a specific transfer by writing to [email protected].
How long we keep it
Nothing in the platform deletes itself: there is no automatic expiry, no scheduled cleanup and no background job that removes old records. Every period below is a decision the operator makes and then has to carry out.
| What | Kept for |
|---|---|
| Your account and profile, after the account is closed | 365 days after the account is closed |
| Subscription, invoice and accounting records | 7 years, as tax and accounting law requires |
| Support correspondence | 24 months after the request is closed |
| A marketing-form lead that never became an account | 12 months, or until you ask us to delete it |
| Server and access logs | 365 days |
Pending team invitations are an exception: each one carries its own expiry date, set when it is sent, and it stops being usable then. You can revoke one earlier from the panel.
Where a record has to be kept for tax or accounting reasons, we keep it for that reason alone and do not go on using it for anything else.
Security
Passwords are stored as hashes. Provider and gateway credentials are encrypted at rest. Traffic to the site and to our API is encrypted in transit. Access to production is limited to the people who need it to do their jobs.
The Security page describes the controls in more detail and gives the address for reporting a vulnerability. We would rather hear about a problem from you than not hear about it.
Your rights under the GDPR
If the GDPR applies to you, you can ask us to do any of the following.
- Confirm whether we hold data about you, and give you a copy of it.
- Correct anything inaccurate, or complete anything that is missing.
- Erase data where we no longer have a good reason to hold it.
- Restrict what we do with it while a dispute about it is being sorted out.
- Give you the data you provided in a portable, machine-readable form, or send it to someone else where that is technically feasible.
- Stop processing you object to, where we relied on a legitimate interest.
- Withdraw a consent you gave. That does not undo what we did while the consent stood.
Some of this is faster to do yourself: your name, email and language are editable in the panel, and you can change your password there. For everything else, write to [email protected]. We may have to check who you are before we act, which for an account holder normally means writing from the address on the account.
The GDPR gives us one month to answer. We can extend that by two further months if the request is complex, and if we do, we will tell you within the first month and say why. Requests are free unless one is manifestly unfounded or excessive.
Turkey: your rights under the KVKK
This section is the aydınlatma — the notice Article 10 of Law No. 6698 requires us to give you when we collect your data. The data controller (veri sorumlusu) is LOKUM TECH LLC, at 8 The Green, Suite A Dover, DE 19901. Our representative in Turkey is [email protected]. What we collect, why, and who we share it with are the same as the sections above.
Article 11 gives you a list of rights that is not the same list as the GDPR’s, so it is set out here in its own terms rather than folded into the section above. You may:
- learn whether we process your personal data at all;
- request information about it if we do;
- learn the purpose we process it for, and whether it is used in line with that purpose;
- learn who we transfer it to, in Turkey or abroad;
- have it corrected if it is incomplete or wrong;
- have it erased or destroyed where the conditions in Article 7 are met;
- require that a correction, erasure or destruction is notified to the third parties we transferred the data to;
- object to a result reached against you purely by automated analysis of your data;
- claim compensation if unlawful processing has caused you damage.
The eighth right has nothing to bite on here: we run no automated analysis that produces a decision about you. We list it because Article 11 lists it, not because we do it.
Turkey: how to apply, and transfers abroad
Article 13 sets how to ask. Apply to us in writing, or by any other method the Personal Data Protection Board has approved, at [email protected] or at the address above. Say what you want and give us enough to identify you. We will answer within thirty days at the latest, and free of charge — unless answering has a cost of its own, in which case we may charge the fee in the Board’s tariff.
If we refuse, if our answer does not satisfy you, or if we do not answer in time, you can complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) within thirty days of learning our answer, and in any case within sixty days of the date you applied to us.
Your data may be transferred abroad, because some of the suppliers listed above operate outside Turkey. Since the amendments made by Law No. 7499, such transfers rest on an adequacy decision by the Board, on an appropriate safeguard such as a standard contract notified to the Board within five business days of signature, or on one of the case-by-case exceptions in Article 9, including your explicit consent. The route we rely on is a standard contract under KVKK Article 9(5), notified to the Personal Data Protection Authority within five business days of signature.
This policy is published in English only, including this section. That is a deliberate choice: one authoritative text avoids the situation where a translation and an original quietly say different things. If you would rather correspond in Turkish, write to us in Turkish.
Children
Esimbit is a business tool sold to companies that resell eSIMs. It is not designed for children, not marketed to them, and not something a child would have a reason to sign up for. We do not knowingly collect data from children.
If you believe a child has given us personal data, write to [email protected] and we will delete it. As elsewhere on this platform, deletion is done by hand rather than by a scheduled job.
Changes to this policy
When this text changes, we publish the new version with a new date at the top. The date is the honest signal: if it has not moved, nothing has changed.
If a change materially affects what we do with your data, we will email account holders before it takes effect, so that anyone who disagrees has the chance to close their account first.
Contacting us, and complaining about us
| For | Write to |
|---|---|
| Anything about your personal data, and any request under this policy | [email protected] |
| Legal notices | [email protected] |
| Reporting a security problem | [email protected] |
| Our Data Protection Officer | No data protection officer is appointed; data-protection questions go to [email protected]. |
| Our EU representative (GDPR Art 27) | [email protected] |
Please come to us first. Most of what goes wrong is something we can fix faster than a regulator can ask us to.
You do not have to, though. If the GDPR applies to you, you can complain to the supervisory authority where you live, where you work, or where you think the problem happened. Our lead supervisory authority is Esimbit has no establishment in the EU, so no single lead supervisory authority applies; you may complain to the authority where you live, where you work, or where the problem happened.. In Turkey, the authority is the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).