Legal information

Privacy Policy

Service preview: purchases, eSIM delivery and electronic support are not enabled. Service terms describe the intended offering and will be reviewed before commercial launch. No regulatory authorisation or VAT status is asserted.

Last updated: 11 September 2026

1. Who is the controller?

The controller for personal data processed through the Utelenet eSIM website and customer relationship is:

BELL UGT LTD Registration no.: HE 445888 Registered office: Alexandreias 2-4, Bridge Tower, Flat/Office 3A, 3013 Limassol, Cyprus Trading brand: Utelenet Contact: our contact details

This Privacy Policy explains how we process personal data when you browse the website, create an account, buy or use an eSIM, request support, submit a complaint, exercise privacy rights or interact with our communications.

Current preview website

The current website is hosted by Hetzner in Germany. It stores region and privacy preferences on your device and uses normal web-server access/security logs. Checkout, sign-in and request forms are local demonstrations: no order, payment, email or form submission is sent to a backend. Analytics, advertising, chat, payment and eSIM provisioning integrations are not installed. The sections below describe service-related processing that may apply when those services are enabled; this policy will be reviewed before that happens.

2. Personal data we may process

Depending on how you use the service, we may process:

  • identity and contact data, such as name, email address, telephone number, billing address and country;
  • account data, such as account identifier, authentication information and account preferences;
  • order and contract data, such as order number, purchased plan, destination, price, tax information, order status, consent records and refund history;
  • payment-related data, such as payment status, transaction reference, payment method type and limited billing data received from a payment provider. Full card details are normally processed directly by the payment provider where the checkout is designed that way;
  • eSIM and provisioning data, such as ICCID, EID, IMSI or other profile/network identifiers where technically necessary and available to us;
  • service and usage metadata, such as activation status, data allowance, data volume, timestamps, serving network, country/region and technical session information to the extent needed for service delivery, billing, troubleshooting, fraud prevention or legal obligations;
  • device and technical data, such as IP address, device type, operating system, browser, language, diagnostic data and security logs;
  • support and communications data, including emails, chat/support content, screenshots or troubleshooting information you choose to provide;
  • identification or verification data where subscriber identification is required by applicable law;
  • cookie and consent data, including your cookie preferences and records showing when consent was given, refused or withdrawn;
  • marketing preference data, where you separately choose to receive marketing.

We do not intentionally collect more data than is reasonably necessary for the relevant purpose.

3. Where data comes from

We may obtain personal data:

  • directly from you;
  • automatically from your device or browser;
  • from payment service providers;
  • from telecommunications, roaming, platform or infrastructure providers involved in delivering the service;
  • from fraud-prevention or security providers;
  • from public authorities where legally required.

4. Purposes and legal bases

Performing the contract

We process data to accept and manage orders, deliver eSIM profiles, activate and operate connectivity, provide account functions, measure plan usage, provide customer support, process refunds and administer the contractual relationship. The legal basis is performance of a contract or steps taken at your request before entering into a contract.

Legal obligations

We process data where necessary to comply with tax, accounting, consumer, electronic communications, subscriber-identification, anti-fraud, sanctions, regulatory or other legal obligations applicable to us.

Legitimate interests

Where permitted, we process limited data for legitimate interests such as website and network security, fraud prevention, abuse detection, service diagnostics, improving support, protecting legal claims and maintaining reliable business operations. We assess those interests against your rights and expectations.

Consent

We rely on consent where required, including for non-essential cookies/trackers and certain direct marketing. Consent may be withdrawn at any time without affecting processing that was lawful before withdrawal.

5. Service providers and recipients

We may disclose personal data only as reasonably necessary to categories of recipients such as:

  • mobile network, roaming, telecommunications and eSIM infrastructure providers;
  • cloud hosting, software, customer-support and technical service providers;
  • payment processors and financial institutions;
  • fraud-prevention, security and identity-verification providers;
  • analytics or marketing providers where you have given the required consent;
  • professional advisers, auditors and insurers where necessary;
  • tax, regulatory, law-enforcement, judicial or other public authorities where disclosure is legally required.

Our public Privacy Policy uses categories of recipients rather than disclosing confidential supplier relationships. This does not reduce our obligation to enter into appropriate data-protection arrangements with processors or to provide further information where required by law.

6. International data transfers

Some service providers or telecommunications networks may process data outside the European Economic Area. Where EU/EEA data-protection law requires a transfer safeguard, we use a lawful transfer mechanism, such as:

  • an adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses and, where required, supplementary measures;
  • another lawful transfer mechanism available under applicable data-protection law.

You may contact us for information about the safeguards relevant to your personal data, subject to lawful confidentiality restrictions.

7. Retention

We keep personal data only for as long as necessary for the purpose for which it was collected and for applicable legal, accounting, tax, telecommunications, dispute and limitation periods.

Retention periods differ by data type. For example, order and invoice records may need to be retained for statutory accounting/tax periods; technical and security logs are normally kept for a shorter period unless needed for an investigation; consent records may be retained as evidence of your choices; and data connected to a complaint or legal claim may be kept until the matter and relevant limitation period are resolved.

We will document specific retention periods in our internal retention schedule. We do not publish invented fixed periods where the applicable requirement has not been verified.

8. Security

We use technical and organisational measures appropriate to the risk, which may include access controls, encryption in transit, credential protection, logging, supplier controls, backup/availability measures and procedures for security incidents. No online system can be guaranteed to be completely secure.

9. Automated decisions

We may use automated signals to help detect fraud, payment abuse or security threats. We will not make a decision based solely on automated processing that produces legal or similarly significant effects on you unless a lawful basis and required safeguards apply. If such processing is introduced, we will provide the required information.

10. Marketing

Service messages relating to an order, security, activation, plan usage or support are not marketing and may be sent where needed to perform the contract.

Marketing messages are sent only where legally permitted. Where consent is required, it is separate from acceptance of the Terms and may be withdrawn at any time.

11. Cookies and similar technologies

Strictly necessary cookies or local storage may be used without consent where permitted because they are required to provide the service you request. Analytics, advertising or other non-essential technologies are not activated before the required consent. See our Cookie Policy and consent preference centre.

12. Your rights

Subject to applicable conditions and exceptions, you may have the right to:

  • obtain information about our processing;
  • access your personal data;
  • correct inaccurate or incomplete data;
  • request erasure;
  • request restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing is based on consent;
  • object to direct marketing;
  • receive safeguards relating to certain automated decisions;
  • lodge a complaint with a competent data-protection authority.

To exercise a right, contact our contact details with the subject "Data Rights Request". We may request proportionate information to verify your identity before acting on a request.

13. Children

The online store is intended for persons able to enter into a purchase contract. Where a minor will use an eSIM, the purchaser remains responsible for the order and any legally required subscriber registration. We do not knowingly use children’s personal data for behavioural advertising.

14. Complaints to a data-protection authority

You may lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence, place of work or the place of the alleged infringement.

Our lead Cyprus authority may include the Office of the Commissioner for Personal Data Protection, Cyprus. Website: https://www.dataprotection.gov.cy/. Public contact details published by the authority include commissioner@dataprotection.gov.cy.

We encourage you to contact us first at our contact details so we can try to resolve the issue.

15. Changes to this Privacy Policy

We may update this Policy to reflect changes in the service, law or processing practices. Material changes will be communicated where required. The current version and effective date will remain available on the website.

Support request

Describe the issue and we reply by email within one working day.

This is a demo: the form sends nothing.