1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
Avelis Technologies UG (haftungsbeschränkt)
Winterhuder Weg 29
22085 Hamburg, Germany
Email: support@withavelis.com
Represented by: Eyüp Alikilic
For any questions regarding data protection, please contact us at the address above or by email at support@withavelis.com.
We have not appointed a data protection officer, as we are not legally required to do so. Please direct all data protection enquiries to support@withavelis.com. Our full company details are available in our Legal Notice.
2. General Principles
We process the personal data of our users only to the extent necessary to provide a functional website and our content and services. Processing of personal data is generally based on one of the following legal bases:
- Art. 6(1)(a) GDPR – consent of the data subject
- Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures
- Art. 6(1)(c) GDPR – compliance with a legal obligation
- Art. 6(1)(f) GDPR – legitimate interests of the controller
3. Categories of Data Collected
3.1 Account and Order Data
When creating a customer account (optional) or placing an order, we process:
- First and last name
- Email address
- Billing address / country of residence
- Phone number (optional)
- Payment data (transmitted directly to the payment service provider; we do not store complete card data ourselves)
- Order history, purchased eSIM packages, activation status
3.2 Usage and Device Data
When you visit our website, the following data is collected automatically:
- IP address (anonymised where technically possible)
- Date and time of access
- Pages visited and click paths
- Browser type and version, operating system
- Referrer URL
This data is stored in server log files and deleted after a maximum of [30] days, unless statutory retention obligations apply.
3.3 Communication Data
When you contact us via email, chat, or contact form, we process your name, email address, and the content of your enquiry for the purpose of processing and responding to it.
4. Purposes and Legal Bases
4.1 Performance of a Contract (Art. 6(1)(b) GDPR)
- Processing of one-time purchases, subscriptions, and top-ups
- Delivery of the eSIM QR code by email and via the browser activation link
- Management of the optional customer account
- Handling customer enquiries, complaints, and refund requests
- Sending transactional emails (order confirmation, activation instructions, invoices)
4.2 Legitimate Interests (Art. 6(1)(f) GDPR)
- Improving our website and service offering
- Fraud prevention and abuse detection
- IT security and system monitoring
- Direct marketing to existing customers for similar products (unless objected to)
- Statistics and market research in anonymised form
4.3 Consent (Art. 6(1)(a) GDPR)
- Email newsletter (double opt-in process)
- Push notifications (browser or app)
- SMS marketing
- WhatsApp marketing communications
- Non-essential cookies and tracking tools (incl. Google Ads Conversion Tracking)
Consent may be withdrawn at any time with effect for the future (see Section 11).
4.4 Legal Obligation (Art. 6(1)(c) GDPR)
- Retention of invoices and tax-relevant records (§ 147 AO: 10 years)
- Providing information to authorities and courts on a statutory basis
5. Payment Service Providers
We use the following external service providers for payment processing. The transmission of payment data required for processing is carried out on the basis of Art. 6(1)(b) GDPR. The service providers process your data as independent controllers in accordance with their own privacy policies.
Stripe — Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (for EU customers). Stripe processes credit card and payment data. Privacy policy →
PayPal — PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Privacy policy →
Apple Pay — Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland. Apple Pay transmits only tokenised payment data; Apple does not see purchase details or full card numbers. Privacy policy →
Google Pay — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy →
Shopify Payments — Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (Shopify Payments for Europe). Shopify processes transaction and customer data for payment processing. Privacy policy →
6. Marketing Communications
6.1 Email Newsletter
If you have expressly subscribed to our newsletter (double opt-in), we process your email address to send you product information, offers, and news. Legal basis: Art. 6(1)(a) GDPR. You may unsubscribe at any time via the unsubscribe link in every email or informally by emailing support@withavelis.com.
6.2 Transactional Emails to Existing Customers
Existing customers may receive emails about similar products on the basis of § 7(3) UWG in conjunction with Art. 6(1)(f) GDPR, provided they did not object at the time of purchase. Objection is possible at any time (see Section 11).
6.3 Push Notifications
We send browser or app push notifications only with your express consent (Art. 6(1)(a) GDPR). You may revoke your consent at any time via your browser or device settings.
6.4 SMS Marketing
We send SMS messages containing marketing content only if you have given your express consent (Art. 6(1)(a) GDPR). To unsubscribe, reply with "STOP" or email support@withavelis.com.
6.5 WhatsApp Communications
We send WhatsApp marketing messages only with your express consent (Art. 6(1)(a) GDPR). Please note that WhatsApp (Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) processes metadata and phone numbers when using WhatsApp Business. For more information: whatsapp.com/legal/privacy-policy.
WhatsApp messages related to your order (e.g. activation links, status updates) are sent on the basis of Art. 6(1)(b) GDPR where you have provided WhatsApp as your preferred contact channel. To opt out of WhatsApp marketing, reply with "STOP" or send an email to support@withavelis.com.
WhatsApp support button. Our website offers a floating "WhatsApp support" button. Before you are forwarded, we show a short form (reason for contact, and optionally your name, destination, device, order number or email). These details are not stored on our servers; they are only used to pre-fill the message, and the chat is opened in WhatsApp exclusively after you actively confirm and tap the button. From that moment, the message content and metadata are processed by WhatsApp / Meta Platforms Ireland Limited, which may involve a transfer to third countries (Art. 44 et seq. GDPR). Legal basis: your consent (Art. 6(1)(a) GDPR) and, for existing orders, Art. 6(1)(b) GDPR. The button loads no third-party script and sets no cookies. If you prefer not to use WhatsApp, you can always contact us at support@withavelis.com.
7. Cookies and Tracking
7.1 General
Our website uses cookies and similar technologies. Technically necessary cookies are set on the basis of § 25(2) TTDSG. For all other cookies, we obtain your consent via our cookie banner (§ 25(1) TTDSG in conjunction with Art. 6(1)(a) GDPR). You can adjust your cookie preferences at any time via the "Cookie Settings" link in the footer of our website.
7.2 Google Ads Conversion Tracking
We use Google Ads Conversion Tracking provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This enables us to measure which users visit our website after clicking on a Google ad and complete a transaction (conversion).
When an ad is clicked, a cookie is placed on your device. This cookie contains a unique identifier that allows Google and us to recognise whether you have visited a specific page on our website after clicking the ad. We do not receive any personal information identifying the visitor.
Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TTDSG.
- Google Privacy Policy: policies.google.com/privacy
- Opt-out: adssettings.google.com
Data may be transferred to the USA in connection with Google services. Google is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023).
7.3 Plausible Analytics (cookieless)
We use Plausible Analytics, a privacy-friendly web analytics service provided by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. All data is processed and stored exclusively on servers within the European Union.
Plausible does not set any cookies, does not use browser fingerprinting and does not collect or store personal data or cross-site identifiers. Only aggregated statistics are recorded, such as page URL, referrer, device type, browser, operating system and country. Your IP address is used solely to derive the country and is never stored. The data cannot be used to identify you or to track you across websites.
Purpose: measuring and improving the reach, performance and usability of our website. Legal basis: Art. 6(1)(a) GDPR (consent). We only load the Plausible script after you have accepted the "Analytics" category in our cookie banner; if you withdraw that consent, the script is removed and no further measurement takes place.
- Plausible Data Policy: plausible.io/data-policy
7.4 Microsoft Clarity (session replay and heatmaps)
We use Microsoft Clarity, a web analytics service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity records aggregated usage behaviour such as heatmaps, clicks, scroll depth and session recordings in order to detect usability problems.
Clarity sets the first-party cookies _clck (1 year) and _clsk (1 day). We operate Clarity with text and input masking enabled, so the content you type — for example name, email address, order number or payment details — is not recorded.
Purpose: analysing and improving the usability of our website. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TTDSG (consent). Clarity is only loaded after you have accepted the "Analytics" category in our cookie banner; if you withdraw that consent, the script is removed, the Clarity cookies are deleted and no further measurement takes place. Microsoft may process data outside the EU, in particular in the United States. Microsoft Corporation is certified under the EU-US Data Privacy Framework and additionally applies the EU Standard Contractual Clauses.
- Microsoft Privacy Statement: privacy.microsoft.com/privacystatement
8. Disclosure of Data to Third Parties
We do not disclose your personal data to third parties unless in the following cases:
- Payment service providers (see Section 5) for payment processing
- Network partners in the destination country for the technical provision of the eSIM connection (only technically necessary data such as IMSI/MSISDN; no disclosure of name, email, or payment data)
- Email delivery service providers (Resend, Mailgun) for sending transactional and marketing emails
- SMS service providers for SMS delivery, where you have provided a mobile number for this purpose
- WhatsApp Business Solution Providers for WhatsApp delivery, where you have chosen WhatsApp as a contact channel
- Push notification service providers, where you have enabled push notifications
- Authorities and courts where we are legally required to provide information
- Legal and tax advisors within the scope of legally permissible representation
All processors engaged by us are bound by a data processing agreement (DPA) pursuant to Art. 28 GDPR.
9. International Data Transfers
Some of our service providers (in particular Stripe, Google, Meta/WhatsApp) process data outside the European Economic Area (EEA), particularly in the United States. We ensure an adequate level of data protection is maintained through:
- European Commission adequacy decisions (e.g. the EU-US Data Privacy Framework for certified US companies)
- EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
- Your express consent in individual cases (Art. 49(1)(a) GDPR)
For further information on the transfer mechanisms used, please contact us at support@withavelis.com.
10. Retention Periods
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations:
- Customer account data: until the account is deleted by the user, plus a [30]-day backup period
- Order data and invoices: 10 years (§ 147 AO, § 257 HGB)
- Order data without tax relevance: up to 3 years after the end of the contract year (limitation periods under § 195 BGB)
- Server log files: [30] days
- Marketing consents (incl. double opt-in log): for the duration of the subscription plus 3 years (for evidence and documentation purposes)
- Contact enquiries: 3 years from receipt of the enquiry
11. Your Rights as a Data Subject
You have the following rights under the GDPR:
Right of Access (Art. 15 GDPR) — You may request information about the data stored about you, its origin, recipients, and purpose of processing.
Right to Rectification (Art. 16 GDPR) — You may request the correction of inaccurate or incomplete data.
Right to Erasure (Art. 17 GDPR) — You may request the deletion of your data, provided no statutory retention obligations apply.
Right to Restriction of Processing (Art. 18 GDPR) — You may request that we restrict processing, for example if you contest the accuracy of the data.
Right to Data Portability (Art. 20 GDPR) — You may request that we provide your data in a structured, commonly used, and machine-readable format.
Right to Object (Art. 21 GDPR) — You may object at any time to the processing of your data based on legitimate interests (Art. 6(1)(f) GDPR), in particular to processing for direct marketing purposes. The objection may be made informally.
Withdrawal of Consent (Art. 7(3) GDPR) — You may withdraw consent at any time with effect for the future (unsubscribe link in emails, "STOP" via SMS/WhatsApp, cookie settings, or email to support@withavelis.com).
Right to Lodge a Complaint (Art. 77 GDPR) — You have the right to lodge a complaint with a data protection supervisory authority. In Germany, the competent authority is generally the data protection authority of your federal state. A list of German supervisory authorities is available at bfdi.bund.de.
12. Data Security
We implement technical and organisational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorised persons. Our website uses SSL/TLS encryption (indicated by the padlock symbol in the address bar). Access to personal data is restricted to authorised employees.
13. Minors
Our services are directed exclusively at persons aged 18 and over. We do not knowingly collect personal data from persons under the age of 18. If we become aware that a minor has submitted data, we will delete it without delay.
14. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy as necessary to comply with current legal requirements or to reflect changes to our services. The current version is always available at withavelis.com/privacy. In the event of material changes, we will notify you by email or by means of a prominent notice on our website.
Last updated: 2026-06-01
