Privacy Policy
Last updated: March 24, 2026
1. Introduction
Simsima ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we manage your personal data when you visit our website (www.simsima.io) or use our mobile application, regardless of where you access them from. It also details your privacy rights and how the law protects you.
2. Data Controller
Under the General Data Protection Regulation (GDPR), the data controller responsible for your personal data is:
- Name: Dimitri MORVAN BRAHIM (trading as Simsima)
- NIF: Z2036651Y
- Registered address: Carrer Lepant - 08013 Barcelona, Spain
- Email: [email protected]
- Supervisory Authority: Agencia Española de Protección de Datos (AEPD) — www.aepd.es
3. The Data We Collect About You
Personal data, or personal information, means any information about an individual from which that person can be identified. We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:
- Identity Data: includes your first name, last name, username, or a similar identifier.
- Contact Data: includes your billing address, email address, and telephone numbers.
- Financial Data: includes your payment card details (processed securely by our payment providers).
- Transaction Data: includes details about payments to and from you, and other details of products and services you have purchased from us.
- Technical Data: includes your internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
- Usage Data: includes information about how you use our website, products, and services.
4. Legal Basis for Processing
Under the GDPR, we must have a valid legal basis for processing your personal data. The legal bases we rely on are:
- Contract Performance (Art. 6(1)(b)): Processing your orders, delivering eSIM profiles, managing your account, and processing payments through Stripe.
- Legitimate Interests (Art. 6(1)(f)): Improving our services, fraud prevention, ensuring network security, and providing customer support via Crisp Chat.
- Legal Obligation (Art. 6(1)(c)): Complying with tax, accounting, and regulatory requirements under Spanish and EU law.
- Consent (Art. 6(1)(a)): Sending marketing communications, placing analytics cookies (Google Analytics 4, PostHog), and enabling functionality cookies (Crisp Chat). You may withdraw your consent at any time.
5. How We Use Your Personal Data
We will only use your personal data when legal regulations allow us to do so. Most commonly, we will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation.
- Marketing Communications: With your explicit consent, we may send you information about our services, offers, and updates. You can opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email or by contacting us at [email protected].
6. Disclosures of Your Personal Data
We share your personal data only with trusted third-party processors who assist us in operating our services. We ensure that all processors comply with GDPR requirements through appropriate contractual agreements.
- Stripe (USA/EU): Payment processing for card payments, Apple Pay, Google Pay, Alipay, and WeChat Pay.
- Google Analytics 4 (USA): Website analytics and performance monitoring (with your consent).
- PostHog (USA/EU): Product analytics and user behavior analysis (with your consent).
- Crisp (EU): Live chat customer support (with your consent).
- eSIM network operators: Delivery and activation of eSIM profiles as required to fulfill your order.
- Legal authorities: When required by law or regulatory obligations.
7. International Data Transfers
Some of our third-party service providers are based outside the European Economic Area (EEA). When we transfer your personal data outside the EEA, we ensure appropriate safeguards are in place:
- We rely on the European Commission's Standard Contractual Clauses (SCCs) as the legal mechanism for transferring personal data to processors in the United States and other non-EEA countries.
- We verify that our processors maintain adequate data protection measures consistent with GDPR standards.
- You may request a copy of the safeguards in place by contacting us at [email protected].
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies. We use a cookie consent banner that allows you to manage your preferences. Cookies are grouped into the following categories:
- Strictly Necessary Cookies: Essential for the website to function properly. These cannot be disabled.
- Analytics Cookies: Help us understand how visitors interact with our website. These include Google Analytics 4 and PostHog, and are only activated with your consent.
- Functionality Cookies: Enable features like our Crisp live chat support. These are only activated with your consent.
- You can manage your cookie preferences at any time by clicking the cookie settings link in the footer of our website. Our mobile application does not use cookies.
9. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. Additionally, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a legitimate business need to know. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Agencia Española de Protección de Datos (AEPD) within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
10. Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
11. Your Rights Under GDPR
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): You have the right to request that we correct any inaccurate personal data we hold about you.
- Right to Erasure (Art. 17): You have the right to request that we delete your personal data, subject to certain legal exceptions.
- Right to Restriction of Processing (Art. 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent (Art. 7): Where we rely on your consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Rights Related to Automated Decisions (Art. 22): You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Simsima does not currently engage in automated decision-making.
- To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es.
12. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you believe we may have collected data from a child, please contact us at [email protected].
13. Third-Party Links
Our website and application may contain links to third-party websites or services that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We encourage you to review the privacy policy of every site you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will update the date at the top of this policy and, where appropriate, notify you by email. Your continued use of our services after any changes constitutes your acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or want to make a complaint, please contact us at: Email: [email protected] Postal address: Carrer Lepant - 08013 Barcelona, Spain You also have the right to lodge a complaint with the Spanish Data Protection Authority: Agencia Española de Protección de Datos (AEPD) Website: www.aepd.es Postal address: C/ Jorge Juan, 6, 28001 Madrid, Spain