Privacy Policy
GigaXeSIM – Privacy Policy
For international customers whose confirmed billing country is outside the Republic of Croatia and Singapore
25.08.2026.
1. Controller
For customers covered by the international GigaXeSIM service, the controller is Proximus Tech Investments Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422. Privacy and data-protection enquiries, including requests for the attention of the Data Protection Officer, should be sent to [email protected]. Where applicable data-protection law requires Proximus to appoint a representative in a jurisdiction, the representative’s contact details will be made available on the Platform.
2. Personal data we process
· identity and contact data;
· account and authentication data;
· order, billing and transaction data;
· payment-related metadata made available by the payment service provider, such as payment status, fraud/risk signals and the country associated with the card or other electronic payment instrument; Proximus does not store the full card number where it is processed by the payment service provider;
· technical data such as IP address, device, browser, operating system and security logs;
· eSIM and service data including ICCID, IMSI where necessary, installation status, activation status and usage records;
· customer-support and complaint communications;
· strictly necessary technical identifiers or storage used to operate, authenticate and secure the Platform.
3. Purposes and legal bases
We process personal data only for specified purposes connected with the international GigaXeSIM service. These purposes include creating and managing the user account; entering into and performing the contract; processing orders and payments; delivering, activating and supporting eSIMs and data packages; maintaining transaction and accounting records; preventing fraud and unauthorised transactions; protecting accounts and the Platform; resolving complaints; complying with legal and regulatory obligations; and establishing, exercising or defending legal claims. Under the Singapore PDPA, Proximus relies on consent and/or the applicable statutory exceptions and permissions. Where the GDPR or a similar law applies, the corresponding legal bases may include performance of a contract, compliance with a legal obligation, Proximus’s legitimate interests in fraud prevention, security and protection of legal claims, and consent where consent is required. Proximus does not currently use international customer account data for newsletters or unsolicited email marketing. If optional marketing or non-essential analytics are introduced later, they will be carried out only on an appropriate legal basis and with consent where required.
4. Recipients and processors
International customer identity, account and order data are accessible to Proximus and to DIGICOM d.o.o. in Croatia solely as Proximus’s operational service provider/data processor (and, where the Singapore PDPA terminology applies, data intermediary) for administration and support of the GigaXeSIM Platform. DIGICOM does not use international customer data for its own marketing or other independent purposes. The authorised payment service provider processes the payment data and payment-risk information necessary to complete and secure the transaction and may act as an independent controller for parts of that processing under its own legal obligations. Connectivity and roaming partners may process technical eSIM/network identifiers and usage records necessary to provide connectivity, but Proximus does not provide them with customer identity or account data unless this is necessary for the service or required by law. Personal data are not sold to third parties.
5. International transfers
The international GigaXeSIM service is operated across more than one country. Proximus may access and manage relevant customer data from Singapore, while DIGICOM d.o.o. may access the same Platform administration system from Croatia solely to provide operational administration and support to Proximus. Payment service providers and connectivity partners may also process the limited data necessary for their functions in the countries in which they operate. Proximus applies the safeguards required by applicable data-protection law to such cross-border access and transfers. In particular, transfers from Singapore are handled in accordance with the Singapore PDPA Transfer Limitation Obligation, and where the GDPR or another transfer regime applies, Proximus uses an applicable valid transfer mechanism and supplementary safeguards where required. Further information about relevant safeguards may be requested at [email protected].
6. Retention
Account-profile and operational data are retained while the user maintains an active GigaXeSIM account and for as long as they are needed to provide the service. If an account shows no login, purchase, activation or other service activity for 18 consecutive months, Proximus may delete or anonymise the account-profile data that are no longer required. Transaction, accounting, tax, fraud-prevention, security, complaint and legal-claim records may be retained for a longer period where required or justified by applicable law or a continuing business or legal purpose. eSIM and service records are retained only for as long as reasonably necessary for service delivery, troubleshooting, fraud prevention and legal obligations, after which they are deleted or anonymised where appropriate.
7. User rights
Depending on applicable law, users may have rights to request access to and correction of personal data, deletion or restriction of processing, portability, objection to certain processing, withdrawal of consent and complaint to a competent data-protection authority. Under the Singapore PDPA, applicable rights include access and correction and the ability to withdraw consent, subject to statutory limits and exceptions. Where the GDPR applies, users may also have the rights provided by Articles 15–22 GDPR, including the right to object to processing based on legitimate interests and an unconditional right to object to direct marketing if such marketing is carried out. Requests should be sent to [email protected]. Proximus may request information reasonably necessary to verify the requester’s identity and will respond within the time limits required by applicable law.
8. Cookies and similar technologies
The Platform may use strictly necessary cookies or similar technical storage required for login, account security, checkout, fraud prevention and core website functions. Proximus does not currently use non-essential analytics or advertising cookies for the international GigaXeSIM service. If non-essential analytics, advertising or similar technologies are introduced in the future, users will be informed and consent will be requested before use wherever required by applicable law.
9. Security
We use risk-based technical and organisational measures designed to protect personal data, including access controls, account protection, security logging, role-based operational access and contractual safeguards with service providers and data processors. Proximus assesses suspected personal-data breaches and notifies the relevant authority and affected individuals where notification is required by the Singapore PDPA, the GDPR or another applicable law. These obligations apply to Proximus as a Singapore organisation regardless of whether the affected customer is a Singapore citizen.
10. Singapore payment-instrument restriction
The international GigaXeSIM service does not accept payment instruments issued by financial institutions in Singapore. The payment service provider checks the country associated with the card or other electronic payment instrument and may block the transaction on that basis. This check is used to enforce the Singapore payment restriction and for fraud prevention. GigaXeSIM does not separately collect citizenship documents or treat the payment-instrument country as proof of a user’s citizenship.
11. Changes
We may update this Policy to reflect changes in law, services, technologies or processing. Material changes will be published on the Platform and additional notice will be provided where required. A change to this Policy does not by itself create a new legal basis for a materially different use of personal data already collected; where a new purpose requires additional notice or consent, Proximus will provide that notice or obtain that consent before the new processing begins. Previous versions may be retained for compliance and audit purposes.

