1. Scope and controller
This policy applies to priesim.com, the PRIeSIM applications and the eSIM service. The controller is PRCONNECT SH.P.K., with the address and registration number below. Travel insurance is separate; if enabled, policy data is handled under the separate insurance privacy notice and PRISIG documents.
2. Data categories and sources
- Account: email, optional name, user identifier, language, password hash and session state.
- Order: package, price, discount, status, payment reference, legal consents, invoice data and, for gifts, recipient email and sender name.
- eSIM: supplier identifier, ICCID, QR/LPA, status, usage, network and expiry where provided.
- Payment: the displayed bank/PSP holds the full card data. We receive payment status, provider/transaction references, card type or masked/last-four data where returned, and anti-fraud signals. Only when the checkout offers it and you separately choose “Save this card” may we retain a ProCard/Paysera KS recurring token encrypted at rest, its keyed fingerprint, provider/card type, last four digits, and the consent time/version and source order. We do not retain the full card number or CVC/CVV.
- Crypto: only when the option is displayed and selected, NOWPayments receives data for its hosted checkout: email where available, order reference and description, fiat amount/currency, selected crypto/network, return/callback details and payment status. PRCONNECT does not provide a customer wallet, exchange or custody service.
- Support and AI: messages and free text, screenshots, diagnosis, complaint/refund details and relevant account, order and eSIM status. Screenshots may be received by human or email support; the in-app AI chat currently sends only text to Anthropic. Before that transmission, recognised email addresses, bearer tokens, LPA/activation data, ICCIDs and passwords are redacted, and no more than the 30 most recent conversation messages are included. Unusual text formats may contain data the filter does not recognise, so do not include passwords, full card details, QR/LPA, activation codes or wallet secrets. Internal AI business summaries may include aggregate order count and spend, but not customer email.
- Device, language and security: IP, user-agent, platform/app version, time, requested URL, limited errors, push token and rate-limit/integrity/anti-abuse signals. For initial language routing, the server infers country from the IP using a local country database; it does not use precise GPS for this purpose. A manual language choice and browser language may then take priority.
- Measurement and optional choices: marketing/notification choices, 1–5 feedback, browser analytics identifiers, campaign parameters and partner code. New product events recorded from 1 September 2026 may include event type, package, destination, amount/method and a pseudonymous event identifier, but not a user or order ID. Some earlier operational events may retain those links until deletion under the 13-month schedule below. Browser analytics requires Analytics consent; limited server operational measurement uses the legitimate-interest basis below.
- Affiliate click before consent: when a partner link is opened, before you make your cookie choices, we create a limited server-side record containing the affiliate ID, the landing path without query parameters or fragments and, where available, the referring host. It contains no device cookie, user ID, order ID or purchase attribution. We process it on the basis of legitimate interests for aggregate measurement and abuse prevention, and delete the raw record after 13 months. We set
pa_refand use it for commission attribution only after you consent to the Affiliate category.
Data comes from you, your device/browser, our eSIM/network partners, the displayed payment provider, NOWPayments only when selected, Apple/Google services and referring partners.
3. Purposes and legal bases
- Contract/pre-contract steps: account, price, payment, supply, QR, top-up, invoice and support.
- Legal obligation: accounting, tax, refunds, complaints, sanctions and authority requests.
- Legitimate interests: security, fraud prevention, legal claims, service diagnostics, unconsented server-side operational product measurement, support and service reliability, subject to necessity and balancing.
-
Consent: optional feedback/direct marketing and Consent v2’s independent Analytics, Marketing and Affiliate choices, plus the separate saved-card choice where offered. Analytics covers Google Analytics, including GA4 purchase measurement; Marketing covers Google Ads and Meta conversion reporting; Affiliate covers
pa_ref. The v2 record lasts 180 days unless changed sooner. Consent can be withdrawn for future processing.
4. Named recipients and service providers
- Hetzner: server hosting, storage and network infrastructure.
- eSIM/network partners: eSIM package provisioning, ICCID/QR/LPA delivery, status, network, usage and top-up operations.
- ProCard/Paysera KS and Paysera: card payment initiation, authentication, settlement, fraud checks, callbacks and refunds; card data is handled on their payment systems.
- NOWPayments: hosted crypto checkout and payment status only when that option is displayed and selected.
- Microsoft 365: transactional and support email.
- Apple and Google: social sign-in where selected, APNs/FCM push delivery, DeviceCheck/Play Integrity and related app services.
- Anthropic: AI-assisted customer support and internal business summaries as described above.
- Google Tag Manager, Google Analytics and Google Ads; Meta Pixel: browser measurement, advertising and conversion reporting. Neither Google Tag Manager nor a vendor tag makes a request before the relevant choice, and there is no noscript tracking fallback. Analytics consent enables Google Analytics, including GA4 purchase measurement. Separate Marketing consent enables Google Ads and Meta conversion reporting. PRIeSIM does not send customer email or an email hash as enhanced-conversion data.
These providers may act as our processor/service provider or, for parts of their service, as an independent controller under their own notice. Card networks, local mobile operators, professional advisers, auditors and authorities receive data only where necessary. Affiliate partners receive aggregate reporting; the referral cookie itself is described in the Cookie policy.
5. AI-assisted support
Anthropic output assists support or internal analysis; staff can review or take over. PRIeSIM does not use it to make a solely automated decision producing legal or similarly significant effects. The in-app AI chat currently sends only text to Anthropic; screenshots may be handled by human or email support and are not sent through this route. Recognised email, bearer-token, LPA/activation, ICCID and password patterns are redacted before transmission, and the sent conversation history is capped at 30 messages; internal AI summaries do not contain customer email. Do not submit secrets or unrelated sensitive information because a filter may not recognise every text format. The contracted configuration determines the applicable transfer mechanism and any no-training or retention setting; contact us for the configuration applying at the time.
6. International transfers
Some named providers may process outside Kosovo or the EEA. Under Articles 44–50 of Kosovo Law No. 06/L-082, a transfer must rely, as applicable, on an adequacy decision, appropriate contractual safeguards with enforceable rights, or another lawful ground, together with proportionate technical and organisational measures. Contact us for the mechanism, processing location and a copy or summary of safeguards applying to a particular recipient and route.
7. Retention
- The active account is kept until account closure, deletion request or service closure. Self-service deletion currently anonymises the core user row and scrubs saved-card credentials and eSIM QR/LPA data, but it is not a guarantee that every related record is erased immediately.
- Orders, invoices, minimum payment references, complaints and refund/dispute records are kept only for the accounting, tax and legal-claim periods applicable to the relevant record category; contact us for the criterion applied to a particular record.
- The usable saved-card token is kept until removal, consent revocation or feature shutdown; removal cryptographically scrubs it. A disabled audit stub and minimum consent evidence may remain for security and legal claims.
- Support conversations and AI-related prompt history currently have no separate automatic fixed expiry; they are kept with the support record until deletion/manual cleanup or a legal-claim criterion applies.
affiliate_clicksdoes not store user or order IDs. Newproduct_eventsfrom 1 September 2026 do not store those IDs; some earlier rows may contain them. Raw rows in both categories are deleted after 13 months. Browser analytics also follows the Cookie policy.- Fraud-prevention IP/email/user signals are HMAC-pseudonymised and the short-term ledger is cleaned after about 48 hours. Caddy access logs omit query strings, mask IPv4 to /24 and IPv6 to /48, and are kept for 14 days. PRIeSIM operational job logs are also kept for 14 days.
pa_refis configured for up to 90 days, depending on the partner; Google Analytics cookies may last up to two years. New database and environment backups are encrypted with AES-256 and active sets are intended to be retained for 14 days. Legacy plaintext sets created before this change are access-restricted and not used for routine recovery pending verified encrypted replacement and secure deletion. Backups are used only for recovery. See the Cookie policy.
8. Your rights
You may request access and a copy, correction, deletion, restriction, objection and, where applicable, portability. You may withdraw consent without affecting earlier lawful processing and object to direct marketing. We normally respond without undue delay and within one month; where the law permits a two-month extension because of complexity or volume, we inform you within the first month and give reasons. We may verify identity and explain any lawful exception.
Profile → My data and the account deletion page start the current self-service anonymisation flow; they do not by themselves prove deletion of all orders, support or AI history, suppression records or backups. New pseudonymous events are not linked to a user/order ID; older rows that may contain such links follow the 13-month schedule above. Send a rights request to info@priesim.com for access/export, restriction, objection or complete erasure assessment. You may complain to Kosovo’s Information and Privacy Agency or seek a judicial remedy. We do not sell personal data.
9. Children, security and changes
The service is for persons able to contract or authorised by a guardian. We use encryption in transit, access controls, hashed passwords, session revocation and rate limiting. No system is risk-free. Material changes are published with a new version and date.
Company details
Registered address: Bulevardi Bill Clinton, Nr. 2 SU.2, 10000 Prishtinë, Kosovë
Business registration number: 811410448
Email: info@priesim.com
Phone/WhatsApp: +383 48 441 256
Web: priesim.com