Data Processing Addendum
The Article 28 terms under which Esimbit processes your shoppers’ personal data on your instructions, as your processor.
Metinler tamam ama henüz hukuki incelemeden geçmedi; bu yüzden yürürlükte değil ve arama motorlarına kapalı.
Bu belge İngilizce yayımlanmıştır. Bağlayıcı metin İngilizce sürümdür.
Which of us is the controller
Two different relationships run through the same product, and the difference decides who answers for what. For your shoppers’ personal data — everything that arrives through your storefront — you are the controller and we are your processor: you decide why it is held and what happens to it, and we act on your instructions. For your own account data — your company and contact details, your team’s logins, your plan and billing state, what you do in the panel — Esimbit is the controller in its own right, we decide those purposes ourselves, and the Privacy Policy describes them. This addendum governs the first relationship only.
This addendum is between you (the reseller named on the Esimbit account) and LOKUM TECH LLC ("Esimbit", "we"), registered at 8 The Green, Suite A Dover, DE 19901. It takes effect when your subscription starts and lasts as long as we hold personal data for you.
We are not a joint controller with you, and we do not use your shoppers’ data for our own purposes. We do not profile them, we do not market to them, we do not sell or share their data with anyone for anyone else’s purposes, and we do not use it to train anything.
One honest exception, stated so nobody finds it later: we count orders and stores against your plan’s limits and bill you on those counts. What we use is the number, not who bought what.
What we process, and for how long
The subject matter is the operation of your storefronts and your reseller workspace. The nature of the processing is storing, organising, transmitting, displaying back to you, and erasing personal data. The purpose is running the service you subscribed to: taking an order, having the eSIM issued by the provider you connected, delivering it to the buyer, reporting its usage, and letting you support the people who bought it. Annex 1 sets this out in full.
Processing runs continuously for as long as your subscription is live, and then for as long as it takes to return or delete the data under the section on deletion below.
The categories of data subject and of personal data are in Annex 1. They are short because the product asks for little: a storefront checkout collects one email address, because the eSIM has to be delivered somewhere, and there is no free-text field for anyone to put anything else in.
The platform has no field for special category data under Article 9 and none for criminal offence data under Article 10. Do not load either into it — there is nowhere appropriate to put it, and this addendum is not written for it.
Your instructions
We process your shoppers’ personal data only on your documented instructions. Your instructions are this addendum, the Terms of Service, and what you actually do with the product.
- Connecting an eSIM provider or a payment gateway instructs us to send that provider what a purchase requires.
- Publishing a store instructs us to take orders through it and to deliver eSIMs to the addresses buyers give.
- Refunding an order, resending a delivery email, or retrying fulfilment in the panel instructs us to do exactly that.
- Anything else — an extract, a correction, a deletion, a bulk change — is an instruction you send us in writing.
Written instructions outside the product go to [email protected] from an owner or admin on the account. We may ask you to confirm one before we act on it, because an instruction to delete or export somebody’s records is worth being sure about.
If law requires us to process data beyond your instructions, we will tell you before we do it, unless that same law forbids us from telling you. If we think an instruction breaks data protection law we will say so and may pause that processing until it is resolved. Saying so is not legal advice — you are the controller, and the decision stays yours.
You decide what your storefront asks for and what you tell your shoppers. We supply the software and the privacy text for the platform’s side; the shopper-facing notice at your store is yours to give.
Who at Esimbit can see it
Everyone we allow near personal data — employees and contractors alike — is under a written duty of confidentiality that continues after their engagement ends. Access is limited to the people who need it to run and support the service, and is removed when they leave or change role.
Concretely: our staff backoffice, the only Esimbit staff screen there is, shows tenants, plans, subscriptions, the status of your provider connections and a record of platform actions taken on your account. It has no screen that lists your shoppers, their orders or their eSIMs. Staff are also a separate realm from your team — nobody at Esimbit holds a role inside your workspace, and there is no impersonation feature.
Which staff may reach production data directly, on whose approval, and how that access is logged and reviewed is set out under access control on the Security page. As with the security measures below, it is stated there and not repeated here: one text kept current beats two that drift apart.
Security measures
We keep appropriate technical and organisational measures under Article 32. They are described mechanism by mechanism on the Security page, which is the operative description and is not repeated here — one text that is kept current beats two that drift apart. We will not change those measures in a way that materially weakens protection while this addendum is in force.
Two measures matter enough to this relationship to state here. No card number ever reaches our servers: a storefront checkout redirects the buyer to your gateway’s own hosted page. And the provider and gateway credentials you connect are encrypted by the application before storage and never returned to any browser — the panel shows only the last four characters.
Independent certifications and audit reports: None. No independent certification or third-party audit is held — see the Security page.
Security is shared. We secure the platform; you choose which credentials to connect and how narrowly they are scoped, who on your team can sign in and with what role, and what your store sells and to whom.
Sub-processors
You give us general authorisation to engage sub-processors. The ones engaged today are in Annex 2. Each is bound by written terms imposing data protection obligations no weaker than these, and we remain fully liable to you for what they do.
We will tell you before adding or replacing a sub-processor, by email to your account contact, at least 30 days in advance. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service and stop paying for it from the date it stops; that is the remedy, and neither of us can veto the other into a corner.
Your own eSIM providers and your own payment gateway are not our sub-processors. You hold those accounts, you agreed those contracts, and we call their APIs on your instruction with the keys you connected. They are yours to assess, list in your own records, and terminate.
Nothing runs in your shoppers’ browsers from a third party. No analytics, no tag manager, no advertising pixel, no session replay, no in-page error reporter, no third-party script of any kind in the page — fonts and flag icons are served from our own hosts. The one exception is a logo you point at a host we do not run, which the browser then fetches from that host. This is about what loads in the browser, not about what sits in front of the site: the proxy and security network that carries every request to your storefront is a sub-processor, and it is listed in Annex 2.
Requests from your shoppers
Your shoppers’ requests belong to you. The storefront carries your name and the delivery email replies to your support address, so in practice they will reach you first. If one reaches us instead, we will not answer it on the merits: we will tell the person to contact you and pass the request to you if we can tell which store it concerns.
We help you answer, taking into account the nature of the processing and what is available to us. Much of it you can already do yourself: the panel finds a buyer by email address and shows their orders, their eSIMs and the usage readings we hold, and a shopper with a store account can see and correct their own name, email, language and notification settings.
What is not self-serve is erasure, restriction and a portable export — the product has no button for any of them. We do those by hand on your written instruction and confirm in writing when they are done. Our target turnaround for assistance is 5 working days, which needs to leave you inside your own one-month deadline.
Erasing a buyer’s records can break the order they are still travelling on: the eSIM stays live at your provider, but nobody will be able to look it up, top it up or be told it is running out. Say what you want kept.
Breaches, and help with Articles 32 to 36
If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay, and in any event within 72 hours of confirming it. Notice goes to your account contact by email, so keep that address current and reachable — it is the only channel we have.
The notice will describe the nature of the breach, the categories and approximate number of data subjects and records involved as far as we can tell, the likely consequences, the measures we have taken or propose, and a contact who can answer follow-up questions. If we cannot establish all of it at once, we send what we have and follow up rather than waiting.
You decide whether a breach has to be reported to a supervisory authority or to your shoppers, and you make that report. We will not notify a regulator or your shoppers on your behalf unless you instruct us in writing to do so.
We also give you reasonable help with your obligations under Articles 32 to 36 — security of processing, breach notification, data protection impact assessments and prior consultation — by supplying the information about how the platform works that you cannot get for yourself. The Security page, this addendum and its annexes are written to answer most of it without anyone having to ask.
Suspected security problems, from either side, go to [email protected].
Deletion and return at the end
When the service ends, you choose: we return a copy of the personal data we hold for you, or we delete it. Tell us which within 30 days of the end of your subscription. Absent an instruction we keep it for 365 days after the account is closed and then delete it.
Two things survive that. Where you tell us a record must be kept to meet a legal duty of yours — order and payment records most often — we keep it for 2 years rather than deleting it, and you tell us when that duty ends. Server and access logs age out on their own cycle, 365 days.
Deletion happens in the live systems first. Copies inside backups are not picked out individually; they disappear as those backups are rotated, after 30 days. Until then they stay protected by the same measures and are not used for anything.
The platform has no automated deletion today: no soft deletes, no scheduled pruning, no retention job. Every period in this addendum is a policy that a person applies. Treat it as a commitment we keep by hand, and hold us to it in writing.
Information and audits
We make available the information you need to show that Article 28 is being met. In practice that is a written answer to your security or privacy questionnaire, the Security page, the annexes below, and — for actions taken on your account by our staff — an extract from the record we keep of them.
We allow for and contribute to audits and inspections carried out by you or an auditor you mandate. The practical terms — notice, frequency, scope, who bears the cost, and what an auditor has to sign — are Once in any twelve months, on 30 days’ written notice, during business hours, at your cost, and limited to the systems that process your data. Where a written questionnaire satisfies your obligation, we answer that instead.. If we ever hold an accepted third-party report that answers the same questions, we can offer that instead, and you can still ask for more.
We will redact anything that would expose another customer’s data, or security detail that would make the platform easier to attack. Everything else is answerable.
International transfers
Production runs at AWS, in Frankfurt, Germany (eu-central-1). Annex 2 gives the location of each sub-processor.
Where processing under this addendum involves transferring personal data out of the EEA or the United Kingdom, the transfer is made under the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), with the UK International Data Transfer Addendum where UK data is involved, together with whatever supplementary measures the transfer assessment calls for. Those terms take precedence over this addendum to the extent they conflict.
Transfers to your own eSIM providers and your own gateway are a separate matter. Connecting them instructs us to send data wherever their API is, under your contract with them and your assessment of it. We cannot tell you where they hold it; ask them.
If you or your shoppers are in Turkey
KVKK (Law 6698) applies alongside the GDPR and is not covered by it. You are the veri sorumlusu, the data controller; we are the veri işleyen, the data processor. Under Article 12 the security duty falls on both of us together, and we are jointly and severally liable with you for the measures taken.
- Article 10: your shoppers get an aydınlatma metni from you, in Turkish, before their data is collected. It names you as controller, not us.
- Article 11: the rights list is not identical to the GDPR’s — it includes being told whether data was processed, asking who it was transferred to at home and abroad, and asking for compensation for damage caused by unlawful processing.
- Article 13: requests come to you in writing or by the registered electronic means Turkish law recognises, and are answered within thirty days, free unless the answer has a real cost.
- VERBİS: registering, and keeping the entry current, is yours if you are in scope. We cannot do it for you.
Transfers abroad follow Article 9 as amended by Law 7499: an adequacy decision, or a standard contract notified to the Authority within five business days of signature, or one of the other listed safeguards, or an exception. Which route applies to your shoppers’ data is your decision as controller. The route relied on for processing under this addendum is a standard contract under KVKK Article 9(5), notified to the Personal Data Protection Authority within five business days of signature.
Our Turkish representative, where one is required, is [email protected]. The product is available in English, Turkish and Arabic; a Turkish notice for your shoppers is still yours to write.
How this fits with the rest
This addendum forms part of the Terms of Service. Where the two conflict about personal data processed on your behalf, this addendum wins. On everything else — the subscription, fees, liability, termination — the Terms apply, and the limits of liability in the Terms apply to this addendum too.
One tension is named here rather than left to be found. The Turkey section records that under Article 12 of the KVKK the security duty falls on both of us and that liability for it is joint and several. That liability is imposed by law, not agreed between us, so the limits in the Terms reach it only as far as that law allows them to.
The Privacy Policy describes what we do as a controller, for our own purposes. It does not qualify anything here, and this addendum does not qualify it.
We may update this addendum where the law, the platform or the sub-processor list changes. Changes that affect your rights get notice to your account contact before they take effect. This addendum is governed by Delaware, United States, with the courts of Delaware, United States deciding disputes — without limiting where a data subject or a supervisory authority may bring a claim.
Published in English only. If we ever issue a translation, the English text is the one that applies.
Contact
| Subject | Address |
|---|---|
| Instructions under this addendum, and data-subject requests | [email protected] |
| Security incidents and vulnerability reports | [email protected] |
| Contract notices | [email protected] |
| Role | Who |
|---|---|
| Data protection officer | No data protection officer is appointed; data-protection questions go to [email protected]. |
| EU representative (Article 27) | [email protected] |
| Turkish representative | [email protected] |
LOKUM TECH LLC, 4872118, 8 The Green, Suite A Dover, DE 19901.
Annex 1 — Details of the processing
| Required detail | For this service |
|---|---|
| Subject matter | Operating your storefronts and your reseller workspace so that eSIMs can be sold, delivered and supported. |
| Duration | The life of your subscription, then the deletion or return process above. Order and eSIM records you tell us to keep for a legal duty of yours are kept for 2 years; logs for 365 days. |
| Nature of the processing | Collection, storage, organisation, display back to you, transmission to the providers you connected, sending email, and erasure. |
| Purpose | Taking an order, having the eSIM issued by your provider, delivering it to the buyer, reporting usage back to them and to you, supporting the purchase, and handling refunds you instruct. |
| Categories of data subject | People who buy from your storefronts; people who hold a customer account at one of your stores; people to whom a buyer has an eSIM delivered. |
| Personal data — checkout | The delivery email address, the order record (order number, package, amount, currency, status, timestamps, refunds) and the language chosen. |
| Personal data — customer accounts | Name where given, email address, password hash, language, notification preferences, and the order history tied to them. |
| Personal data — eSIMs | The identifiers of the eSIM issued for the buyer, including the ICCID, and the data-usage readings we pull from your provider with the time each was taken. |
| Personal data — technical | Server and access logs generated by requests to your storefront, which can include IP address and user agent. |
| Data loaded by you | Store name, support address, branding and pricing you configure. Little of it is personal data, but a support address often names a person. |
| Special category data | None. The platform has no field for Article 9 or Article 10 data and asks for none. |
| Payment card data | None reaches us. The buyer enters card details on your gateway’s own hosted page; we pass an amount and a reference and learn only whether the payment succeeded. |
| Frequency | Continuous, for as long as a store of yours is published and taking orders. |
If you start using the platform for something outside this annex, it is a change of instruction. Tell us, so the annex stops being true of the wrong thing.
Annex 2 — Sub-processors
The sub-processors engaged for the processing described in Annex 1. Each entry names who it is, what it is for, and where the processing takes place.
| Sub-processor | Purpose | Location |
|---|---|---|
| AWS | Running the production systems and holding everything stored by the service | Frankfurt, Germany (eu-central-1) |
| Postmark | Sending the eSIM to the buyer, plus verification codes, password resets and service notices | United States |
| Sentry | Receiving diagnostic detail from server errors so failures can be found and fixed. Nothing of the kind runs in the browser | European Union (Frankfurt) |
| Cloudflare, whose bot-protection cookies (__cf_bm, and cf_clearance after a challenge) may be set on this domain | Proxying and filtering all storefront traffic, terminating TLS, and bot protection | Global edge network; a request is served from the location nearest the visitor |
This list is the whole of it. There is no analytics vendor, no advertising or marketing platform, no session replay and no support-chat vendor.
The proxy row is worth reading twice, because that provider sees more of your shoppers than the others. Every request to one of your storefronts reaches us through it: it terminates the encrypted connection, inspects the request to tell people from automated traffic, and passes the visitor’s IP address on to us. It stores nothing of the service itself, but all of your shoppers’ traffic passes through it.
Your own eSIM providers and your own payment gateway are deliberately absent. You contract with them directly and we call them with the keys you connected, so they belong in your records of processing, not in ours.