Last updated: 24 August 2026. This Policy explains how SAS Clyb processes personal data across the eSIMDual website, web app, iOS and Android applications, customer and partner areas, APIs and support channels.
1. Data controller and contact
The controller is SAS Clyb, 4 rue des Roquettes, 49500 Segré-en-Anjou Bleu, France. Privacy requests may be sent to contact@esimdual.com. This Policy should be read with the Terms of Service and cookie preferences.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email, telephone number, username, language, country, authentication and account status | You, authentication providers and account administrators |
| Orders and payments | Plans, eSIM identifiers, activation and usage status, top-ups, amounts, currency, invoices, wallet records and payment references; full card data is handled by the payment provider | You, payment providers, eSIM and network suppliers |
| Device and technical | App version, operating system, device or installation identifier, IP address, time zone, security logs, diagnostics, cookie choices and push tokens | Your device, browser, APNs, Firebase and our systems |
| Calls and communications | Internet number, participants, call reference, direction, time, duration, rate, status, device token, conversation and message identifiers, delivery state, encrypted payloads, sender display name and the limited notification preview | You, other users and telecommunications or notification infrastructure |
| Content and community | Profile, contacts you choose to synchronise, posts, stories, reviews, place submissions, reports, support messages, files, images and voice notes | You and other users |
| VPN and location-related data | VPN account/profile, selected endpoint, connection diagnostics and session metadata; destination chosen, approximate IP location or precise location only when you enable a feature that requests it | You, your device and VPN infrastructure |
| Verification and partner data | KYC status and required evidence, business identity, website, tax and billing information, API tokens, webhooks, reseller orders and audit events | You, verification providers, public registers and partner administrators |
3. Why we use data and legal bases
- Contract: create and secure the account; deliver eSIM, VPN, calling, messaging, community, travel, support, partner and payment functions; measure usage and provide customer service.
- Legal obligation: accounting, tax, sanctions, lawful requests, fraud or telecom obligations and handling data-rights requests.
- Legitimate interests: secure systems, prevent abuse and fraud, diagnose incidents, improve reliability, moderate content, measure service performance and defend legal claims, after balancing your rights.
- Consent: optional cookies, marketing where required, contacts, precise location, camera, microphone, photos, notifications and other device permissions. You can withdraw consent in the app, browser or device settings.
4. Encrypted messages and call confidentiality
Supported complete message content and attachments are end-to-end encrypted between participating devices. Our servers route encrypted payloads and process the minimum metadata needed for delivery, synchronisation, anti-abuse, device management and support. For text-message alerts, the sender’s device separately provides a cleaned notification preview limited to 120 characters. We send that preview and the sender’s display name through APNs or Firebase; voice notes, files and view-once media use a translated category instead of content. The preview is therefore outside the end-to-end encrypted message body and may be visible to the push provider or on the lock screen; encryption keys are never included. Audio and video media are not recorded by eSIMDual unless a separate, explicit feature and notice says otherwise.
5. Notifications and app wake-up
We register separate alert and VoIP tokens where supported. APNs or Firebase receives the token and a limited payload so the operating system can display a message or incoming-call interface and wake the app. A message alert may contain the sender’s display name and the limited preview described above; a call payload may contain a call reference, display name or number and audio/video indicator. You can change lock-screen preview and notification permissions in the device settings, but disabling notifications may prevent alerts or incoming calls when the app is closed.
6. VPN, permissions and location
VPN traffic necessarily passes through the selected VPN infrastructure. We process account, server, connection and limited diagnostic data required to authenticate, operate, secure and troubleshoot the service; tunnel content is not used to build advertising profiles. Microphone, camera, photos, files, contacts, Bluetooth, notifications and location are accessed only after the relevant device permission and for the function you request. Contacts may be normalised or matched to help find eSIMDual users; do not upload contacts without authority.
7. Payments, identity checks and automated controls
Payment providers process payment credentials under their own privacy terms; eSIMDual receives transaction status and references. Verification providers may process identity documents and biometric or liveness checks when legally or operationally required. Automated fraud, security, device-limit or eligibility checks may block or hold an operation. Where a decision produces a significant legal effect, you may request human review and provide additional information.
8. Community, travel guide, blog and public data
Content marked public can be seen, shared or indexed by others. Visibility, block, delete and report tools help control it, but copies may remain with recipients or search engines. Travel data can combine public, licensed and user-contributed sources. Reports are reviewed by moderators. Blog reading may generate ordinary web analytics and cookie data according to your preferences.
9. Recipients and service providers
Data is shared only as needed with authorised SAS Clyb staff; hosting, security, email, support and analytics providers; eSIM and mobile network suppliers; VPN and telecommunications infrastructure; payment and KYC providers; Apple APNs and Google Firebase; mapping, weather, travel and media providers; professional advisers; resellers administering their own customers; and competent authorities where legally required. We do not sell personal data.
10. International transfers
Some networks and technology providers operate outside the European Economic Area. Where personal data is transferred internationally, we rely on an adequacy decision, approved standard contractual clauses, another lawful safeguard or a statutory derogation, and apply additional technical or organisational measures when appropriate.
11. Retention
We keep data only for the purpose and period required, using the following criteria:
- account and service data for the active relationship, then a restricted period needed for claims, fraud prevention and legal duties;
- orders, invoices and payment evidence for applicable accounting and tax periods;
- eSIM, call, VPN, delivery and security metadata for the operational, billing, dispute and security period appropriate to that record;
- encrypted messages and user content until deletion, expiry, account closure or the feature’s retention rule, subject to recipient copies and rotating backups;
- KYC data for the period required by the relevant verification, anti-fraud or legal obligation;
- support and moderation records while the case is active and for a proportionate follow-up or defence period;
- invalid push tokens and obsolete technical data are removed or anonymised through lifecycle and housekeeping processes.
12. Security and breaches
We use access controls, encryption in transit, encryption at rest where appropriate, isolated credentials, monitoring, backups and least-privilege procedures. No system is risk-free. You must protect devices, codes and credentials. We investigate suspected breaches and notify authorities or affected people where legally required.
13. Cookies and similar technologies
Strictly necessary cookies support sessions, security, language and checkout. Optional analytics, personalisation or marketing technologies are used only under the applicable consent rules. You can review or withdraw preferences from the cookie interface and browser settings; necessary cookies cannot be disabled without affecting the service.
14. Your rights
Subject to the GDPR and applicable law, you may request access, rectification, erasure, restriction, portability and objection; withdraw consent; define instructions regarding data after death where French law applies; and request human review of an applicable automated decision. We may verify identity and may retain data where law or overriding grounds require it. You may lodge a complaint with the CNIL or your local supervisory authority.
15. Children, changes and questions
The services are not directed at children who cannot lawfully contract or consent to the relevant processing. A parent or guardian should contact us if a child provided data without valid authorisation. We may update this Policy as services or law change and will provide suitable notice of material changes.
Privacy contact: contact@esimdual.com.