Privacy Policy
Last updated: 26 September 2026
This policy explains how Nordic Travel eSIM ("we") processes personal data in the eSIM sales, dealer and customer services offered through nordictravelesim.com, under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where it applies, the EU General Data Protection Regulation ("GDPR"). The data controller is the company whose details appear below.
Company details
- Brand
- Nordic Travel eSIM
- Registered name
- To be added once incorporation is complete
- Address
- To be added once incorporation is complete
- Tax office / number
- To be added once incorporation is complete
- MERSIS number
- To be added once incorporation is complete
- Contact
- [email protected]
1. What we process
- Identity and contact: name, email address, phone number.
- Dealer application and verification (KYC): company or business details, tax details, address, the documents you upload such as an identity document or trade registry record, and your national identity number (stored encrypted).
- Transactions: orders, the eSIM and top-up packages bought, balance top-ups, account ledger entries, commission records, support tickets.
- eSIM usage: information received from the supplier such as activation status and remaining data.
- Social sign-in: when you sign in with Google, Apple or Facebook, the account identifier, email address, whether that address is verified, and display name the provider sends us. The provider never shares your password with us.
- Technical data: IP address, browser information, session cookies, security and audit logs.
2. Why, and on what legal basis
- To open your account, authenticate you and provide the service — performance of a contract.
- To pass your order to the supplier and deliver the eSIM to you or your customer — performance of a contract.
- To assess dealer applications, verify identity and keep accounting and tax records — legal obligation.
- To prevent fraud and abuse and keep the system secure — legitimate interest.
- To contact you about the service (order, balance and announcement notifications) — performance of a contract and legitimate interest.
3. Who we share it with
We do not sell your data. We use the following only as far as needed to provide the service:
- eSIM and mobile top-up suppliers — to fulfil your order.
- Hosting and email providers — to run the system and deliver notifications.
- Cloudflare — bot protection (Turnstile) on sign-in and form screens.
- Google, Apple and Meta (Facebook) — only if you choose to sign in with them.
- Public authorities — where the law requires it.
4. International transfers
Some of our service providers may operate servers outside Türkiye. Such transfers are made in line with Article 9 of KVKK and, where applicable, the GDPR.
5. How long we keep it
We keep your data while your account is open and afterwards for as long as the law requires (for example the statutory retention periods for accounting and tax records). After that it is deleted, destroyed or anonymised.
6. Cookies
We only use cookies the service needs to work: sign-in cookies that keep your session open and a language cookie that remembers your choice. We use no advertising or tracking cookies.
7. Your rights
You may ask whether we process your data and for a copy of it, ask what it is used for and who it has been shared with, have it corrected or deleted, object to decisions made solely by automated means, and seek compensation for unlawful processing. Under the GDPR you may also restrict or object to processing, ask for data portability, and complain to your supervisory authority.
8. How to make a request
Email [email protected] from the address registered on your account. We answer within 30 days at no charge. The steps to have your data deleted are set out separately on the Data Deletion page.
9. Changes
We may update this policy as the service changes. The current version is always published on this page, with the date of the last update at the top.