Graba SIM Privacy Policy

Last updated: 27 April 2025

This Privacy Policy explains how Graba Mobile Ltd ("Graba SIM", "we", "us") collects, uses, discloses and protects your personal data when you interact with our websites, apps and connectivity services.

  1. Who We Are
    Controller: Graba Mobile
    Data-Protection Lead: [email protected]
  2. The Data We Collect
    CategoryExamplesSource
    Account dataName, email, password (hashed), country, preferred currencyDirectly from you
    Transaction dataOrder number, plan code, amount, currency, payment statusFrom you and payment processor
    eSIM profile dataICCID, EID, activation code, QR-code URL, usage statistics, status eventsFrom our eSIM Access API partner
    Device & log dataIP address, device type/OS, browser, time zones, diagnostic logs, crash reportsAutomated
    Marketing preferencesNewsletter opt-in/out, cookies, tracking pixelsDirectly from you
    Support dataTickets, chat transcripts, screenshots you provideDirectly from you
    We do not intentionally collect special-category (sensitive) data nor data of children under 16.
  3. Purpose & Lawful Basis
    PurposeLawful basis (UK GDPR Art. 6)
    Account creation & plan deliveryContract performance
    Payment processing & fraud preventionContract performance; Legitimate interest
    Network provisioning & real-time usage notificationsContract performance
    Customer support & troubleshootingContract performance; Legitimate interest
    Service improvement & analyticsLegitimate interest
    Marketing emails & push notificationsConsent
    Compliance with legal obligations (e.g. HMRC, telecoms regulations, law-enforcement requests)Legal obligation
  4. Sharing Your Data
    We share data only where necessary and under written agreements:
    • Payment processors (PCI-DSS compliant)
    • eSIM profile supplier (eSIM Access) and local carrier partners for network onboarding
    • Cloud hosting, email and customer-support platforms
    • Professional advisers (lawyers, accountants, auditors)
    • Authorities where required by law or enforceable request
    We never sell your personal data.
  5. International Transfers
    Some partners operate outside the UK/EEA. Where we transfer data internationally, we rely on:
    • Adequacy decisions (e.g. UK–US Data Bridge)
    • Standard Contractual Clauses (SCCs) or UK Addendum
    Copies of safeguards can be requested via [email protected].
  6. Retention
    Account & transaction records – 6 years after your last purchase (statutory limitation).
    Diagnostic & analytics logs – up to 24 months.
    Marketing opt-out records – indefinitely to honour suppression.
    We securely delete or anonymise data when retention ends.
  7. Security
    We employ industry-standard measures: TLS encryption, firewalls, strict access controls, regular penetration tests and 24 / 7 monitoring. No system is 100 % secure; you are responsible for keeping your credentials confidential.
  8. Your Rights
    Under UK GDPR/UK DPA 2018 you can:
    • Access, rectify or erase your data
    • Restrict or object to processing
    • Port data to another provider
    • Withdraw consent at any time (marketing)
    • Lodge a complaint with the UK Information Commissioner (ico.org.uk)
    Contact [email protected] to exercise your rights. We aim to respond within one calendar month.
  9. Marketing & Cookies
    We send newsletter or promotional messages only with your explicit consent. You may unsubscribe at any time via the link in each email or through your account settings.
    Cookies and similar technologies are used to remember preferences, perform analytics and deliver personalised ads. For details, please see our separate Cookie Notice.
  10. Automated Decision-Making
    We do not engage in automated decision-making that produces legal or similarly significant effects.
  11. Children
    Our Services are not directed to persons under 16. If we learn that a child has provided personal data we will delete it promptly.
  12. Changes to this Policy
    Updates will be posted on our website and, where appropriate, notified by email. The effective date is at the top of the document.
  13. Contact
    Questions or concerns? Email [email protected].

© 2025 Graba Mobile. All rights reserved.