Privacy Notice
Effective from: 3 October 2026
This notice explains what personal data we collect when you use needasim.com (the "Website"), buy an eSIM or contact us, why we use it, and the rights you have. It is provided under Article 13 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information ("Infotv.").
1. Who is responsible for your data
The controller of your personal data is:
- Nagy Norbert József E.V. (Nexuscode), sole trader
- Hungarian tax number: 57631336-1-36
- Email: hello@nexuscode.hu
- Phone: +36 30 269 7632
("we", "us", "our"). Please send any privacy question or request to the email address above.
2. In short
- You do not need an account. We only ask for an email address to send you your eSIM.
- We never see or store your card details. Payments are handled by Viva.
- We do not share personal data with our eSIM supplier.
- We only use Google's advertising cookies if you agree. We may report a purchase to Google from the order confirmation page even without your consent, but without cookies (see 3.5).
- We do not sell your personal data.
3. What we collect, why, on what legal basis and for how long
3.1. Orders, payment and delivery of your eSIM
- Data: your email address; order details (destination, number of days, number of eSIMs, amount and currency, order number and internal order ID, Website language, timestamps, order and delivery status, technical event log); eSIM details (activation code and QR code, ICCID, and status information from our eSIM supplier, such as whether the eSIM has been installed or is in use); payment details we receive from Viva (transaction ID, payment status, the name entered on the payment page, the country that issued your card, and, if we do not already have it, the email address given to Viva). We never receive your full card number or other card data.
- Why: to take your order, check your payment, make your eSIM available on your order page and by email, keep you informed about your order, handle guarantee claims and refunds, and notify our team of sales internally. On your order page we use your browser's user agent to show the installation option that suits your phone; we do not store it.
- Legal basis: performance of our contract with you, or steps you ask us to take before entering into it (Article 6(1)(b) GDPR). We need your email address to deliver your eSIM; without it, you cannot buy.
- How long: for completed orders, 5 years after delivery (the general limitation period under section 6:22 of the Hungarian Civil Code); for orders that were never paid, 30 days after the order was created, after which we delete them automatically. Data supporting our accounting records is kept as described in 3.2.
3.2. Invoicing and accounting
- Data: the details that must appear on invoices and accounting records (for example name, what you bought, the amount and the date).
- Why: to meet our invoicing and accounting obligations.
- Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR) under Hungarian Act CXXVII of 2007 on VAT and Act C of 2000 on Accounting.
- How long: 8 years (section 169(2) of the Hungarian Accounting Act).
3.3. Customer support, guarantee claims and complaints
- Data: what you give us (for example your name, email address or phone number; on WhatsApp, your phone number, profile name and profile picture), your order number, the content of your messages or complaint, and our reply.
- Why: to answer your questions, troubleshoot, handle guarantee and warranty claims, and deal with complaints.
- Legal basis: performance of our contract with you (Article 6(1)(b) GDPR); for complaints, compliance with a legal obligation (Article 6(1)(c) GDPR and section 17/A of Hungarian Act CLV of 1997 on Consumer Protection).
- How long: complaints and our replies for 3 years (section 17/A(7) of the Consumer Protection Act); other support messages (email and WhatsApp) for 1 year after the case is closed.
3.4. Security and fraud prevention
- Data: IP address, browser and device information (user agent), time of the request and the page requested, recorded in our hosting provider's server logs. When you start a payment, we also briefly use your IP address, without saving it to our database, to block excessive repeated attempts.
- Why: to keep the Website and the payment process secure, prevent misuse and find errors.
- Legal basis: our legitimate interests in running a secure, reliable website and preventing fraud (Article 6(1)(f) GDPR). You can ask us for information about our balancing test.
- How long: up to 30 days.
3.5. Measuring our Google ads
- Click identifier: if you arrive by clicking a Google ad, the link may contain a click identifier (gclid, gbraid or wbraid). If you then buy, we store this identifier with your order so that we can tell which ad led to the purchase.
- Google tag and cookies, with your consent: we only load Google's tag (gtag.js) on the Website's pages if you click "Accept" in the cookie bar. Google may then set cookies in your browser and record your purchase as a conversion.
- The order confirmation page: when your order page is opened within 24 hours of payment, Google's tag loads even without your consent and reports the purchase to Google (our internal order ID as the transaction ID, the amount and the currency). If you have not consented, the tag runs in the "denied" state of Google's Consent Mode v2: it does not set or read cookies, although, like any request on the internet, the request includes technical data such as your IP address and browser details. We do not send Google the unique address of your order page. If you have consented, we also place a marker in your browser's local storage so that the purchase is not counted twice (see section 4); without your consent we store nothing in your browser.
- Enhanced conversions: if this feature is switched on and you have consented in the cookie bar, Google's tag passes your order email address to Google in hashed (one-way encoded) form together with the conversion.
- Legal basis: for the Google tag and cookies on the Website's pages, your consent (Article 6(1)(a) GDPR and section 155(4) of Hungarian Act C of 2003 on Electronic Communications). For storing the click identifier and the cookieless report from the confirmation page: our legitimate interest in knowing which of our ads lead to purchases (Article 6(1)(f) GDPR); in this case nothing is stored in or read from your browser. For the local-storage marker and enhanced conversions: your consent.
- Withdrawing consent: you can withdraw your consent at any time: click "Cookie settings" at the bottom of any page to open the cookie bar again and choose "Reject" (deleting the needasim.com cookies in your browser has the same effect). Withdrawing consent does not affect processing carried out before.
- How long: for Google's cookies, see section 4; we keep click identifiers together with your order (see 3.1).
- Recipient: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), an independent controller for conversion tracking and our processor for enhanced conversions.
3.6. Cookies needed for the Website to work
- Data: the content of the
ns_lang,ns_consentandns_admincookies listed in section 4. - Why: to remember your language and your cookie choice, and to keep our staff signed in.
- Legal basis: these cookies are strictly necessary for the service you request, so we do not ask for consent; the legal basis is our legitimate interest (Article 6(1)(f) GDPR).
- How long: see section 4.
4. Cookies and similar technologies
ns_lang– remembers the language you chose (only set if you switch language). Lasts 1 year. Strictly necessary.ns_consent– remembers whether you accepted or rejected advertising cookies. Lasts 180 days. Strictly necessary.ns_admin– keeps our staff signed in to the admin area; never set for visitors. Lasts 12 hours. Strictly necessary.ns_conv_…(local storage, not a cookie) – set on the order confirmation page to record that the purchase has already been reported to Google, so it is not counted twice. Only set with your consent. Stays until you clear your browser data.- Google advertising cookies (for example
_gcl_au) – Google Ads conversion measurement. Lifetime set by Google, typically up to 90 days. Only with your consent.
5. Who we share your data with
Processors (acting on our behalf and on our instructions):
- Vercel Inc. (440 N Barranca Avenue #4133, Covina, CA 91723, USA) – hosting and running the Website, server logs.
- Neon, LLC (part of the Databricks group, USA) – database service. Database location: the European Union (Frankfurt, Germany).
- Plus Five Five, Inc. (Resend) (USA) – sending order emails and our internal notifications.
- Our invoicing software provider – issuing invoices.
- Our accountant – bookkeeping.
- Google Ireland Limited – for enhanced conversions (see 3.5).
Independent controllers (responsible for their own processing):
- Vivabank Single Member Banking S.A. (Viva.com) (18-20 Amarousiou Chalandriou Str., 15125 Marousi, Greece) – payment processing. We pass on the amount, the order description, our internal order ID, your email address and the Website language; you give your card details directly to Viva. Viva acts as a controller when meeting its obligations under payment services and anti-money-laundering law; see Viva's privacy notice on viva.com.
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) – Google Ads conversion measurement (see 3.5).
- WhatsApp Ireland Limited – if you contact us on WhatsApp; WhatsApp is an independent controller for its own service.
Our eSIM supplier and mobile networks:
- ESIM ACCESS LIMITED (Hong Kong) – supplies the eSIM profiles. It receives only our internal order ID and the plan ordered, never personal data. We receive the eSIM's activation code, ICCID and status from it.
- When you use the eSIM, the local mobile networks in the destination (the partner networks shown on the product page) and our eSIM supplier process the technical data needed to provide the connection (for example SIM and device identifiers, connection and traffic data) under their own responsibility.
Authorities: we may disclose data to authorities where the law requires it (for example at the request of a court, the police or the tax authority).
6. Transfers outside the EU
6.1. Vercel Inc., Neon, LLC, Plus Five Five, Inc. (Resend) and Google LLC also process data in the United States. According to their own statements, Vercel, the Databricks group (including Neon, LLC) and Resend participate in the EU-U.S. Data Privacy Framework, which is covered by the European Commission's adequacy decision (EU) 2023/1795 (Article 45 GDPR). In addition, and wherever the Framework does not apply, transfers are based on the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (Article 46 GDPR).
6.2. We do not transfer any personal data to our eSIM supplier in Hong Kong.
7. Security
7.1. The Website only works over an encrypted (HTTPS) connection, card data goes only to Viva, and our admin area is password-protected.
7.2. Your order page has a unique, hard-to-guess address. Anyone who has the link can see your order details (for example your email address and QR code), so please do not share it.
8. Your rights
8.1. You have the right to:
- access your personal data and receive information about how we use it (Article 15 GDPR);
- have inaccurate data corrected (Article 16);
- have your data erased when we no longer need it and the law does not require us to keep it (Article 17);
- restrict how we use your data (Article 18);
- receive the data you gave us on the basis of consent or contract, processed by automated means, in a structured, machine-readable format, or have it sent to another controller (data portability, Article 20);
- object to processing based on our legitimate interests (Article 21);
- withdraw your consent at any time (Article 7(3)).
8.2. We do not make automated decisions about you, including profiling.
8.3. We will reply to your request without undue delay and within one month at the latest. We may extend this by two further months where necessary, in which case we will let you know (Article 12(3) GDPR).
9. Complaints and remedies
9.1. If you think we have breached your data protection rights, you can complain to the Hungarian supervisory authority, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH):
- Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Postal address: 1363 Budapest, Pf. 9., Hungary
- Phone: +36 1 391 1400
- Email: ugyfelszolgalat@naih.hu
- Website: https://naih.hu
9.2. You can also complain to the data protection authority of the EU country where you live or work (Article 77 GDPR).
9.3. You can also go to court (Article 79 GDPR). In Hungary you may bring the case before the regional court (törvényszék) for your place of residence or stay (section 23(3) of the Infotv.).
9.4. We would appreciate the chance to sort out your concern first, so please feel free to contact us before you turn to an authority or a court.
10. Changes to this notice
10.1. We may update this notice if the way we process data or the law changes. The current version is always available on the Website, with its effective date shown at the top.