1. Scope and controller
This policy applies to the eSIM service on priesim.com and the PRIeSIM applications. The controller is PRCONNECT Sh.p.k., Prishtina, Republic of Kosovo. Privacy contact: info@prconnect-ks.com.
Travel health insurance is separate and currently disabled. If it is enabled, policy data will be handled under the separate insurance privacy notice and PRISIG documents, not under this general eSIM description.
2. Data we process
- Account: email, optional name, user identifier, language preference and password hash.
- Orders: package, price, status, payment reference, legal consents and support communications.
- eSIM: ICCID, status, QR/LPA, usage and expiry when supplied by the provider.
- Product measurement: only after consent, limited events such as destination, package selection, checkout or installation start, platform and a randomly generated identifier stored as a hash. We do not send email, name, phone number, token, ICCID, QR/LPA or free text in these events.
- Security/diagnostics: IP address, browser/device, time, page path without query/hash, limited errors and anti-abuse logs.
We do not store the full card number, CVV or wallet credentials. We do not use advertising identifiers or track users across applications.
3. Why we process data and the legal basis
- Contract: registration, payment, supply, QR delivery, status, invoicing and support.
- Legal obligation: accounting, taxes, refunds, complaints and requests from authorities.
- Legitimate interests: security, fraud prevention and minimal diagnostics, following a proportionality assessment.
- Consent: email reminders/offers and non-essential cookies; you may withdraw consent without affecting earlier processing.
4. Recipients and transfers
Data is shared only where necessary with: technical eSIM partners for supplying and administering the service; the bank or payment service provider for payment; the email provider; the hosting provider; advisers/auditors and authorities where required by law. They receive only the data necessary for their role.
Some providers may process data outside Kosovo/the EEA. Where required, we use contracts and appropriate safeguards and assess the country/recipient. You may request information about the applicable safeguards.
5. Retention periods
The account is retained until deletion; QR credentials are removed or anonymised when the account is deleted, except where needed for an active matter. Minimum order/invoice data is retained for the applicable financial/tax period. Security and diagnostic logs are kept only as long as needed for investigation and stability. Marketing consent is retained until withdrawn and as evidence for as long as required by law.
6. Your rights
You may request access, a copy, correction, deletion, restriction, objection and, where applicable, data portability. You may withdraw consent and object to direct marketing at any time. You can delete the account in the app under Profile → My data or on the Account deletion page.
For a complaint, please contact us first; you also have the right to contact the Information and Privacy Agency.
7. Cookies, children and decision-making
Essential cookies/storage are used for the session, security and preferences. Analytics or marketing is enabled only after consent. See the Cookie policy. The service is offered to persons able to enter into a contract or with a guardian's authorisation. We do not make solely automated decisions with legal effect and we do not sell data.
8. Security and contact
We use encryption in transit, access controls, hashed passwords, session revocation and request rate limiting. No system is risk-free; incidents are handled in accordance with legal obligations.