Privacy Policy
Last updated: —
Introduction
This privacy policy (“Notice”) is intended to inform you about how your Personal Data will be handled by Roamjoy (“Roamjoy”, “we”, “us” or “our”) and sets out the information including personal information detailed below relating to you or which you provide to us (“Personal Data”) that will be collected and processed by Roamjoy and/or on its behalf by its third party service providers when you contact us through our channels, such as our application, website or, once you have contracted for our services. We are required to give you this information, including to inform you about your data protection rights, under the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
Roamjoy takes its data protection obligations seriously and will never share personal data with any third parties without the proper legal basis. We are committed to compliance with data protection and privacy regulations globally, including GDPR, UK data protection laws, and relevant privacy frameworks in North America, Australia, and Latin America, with privacy by design integrated into all our services.
Roamjoy as data controller
Roamjoy is committed to respecting your fundamental right to the protection of your Personal Data and this Notice is intended to inform you about the processing of your Personal Data by us.
Types of Personal Data we process about you
| Category of Personal Data | Details |
|---|---|
| Website Usage and Device Data: When you visit our application, or our website. | Your visits and interactions with our website including which webpages you visit, time and date of access, what you click on, when you perform these actions; your device data including your IP address, location data, device type and language, browser type and other related information; and any linked websites that you access through the website. Most of this Personal Data is collected using cookies on the Website. |
| Customer Data: When you purchase an eSIM or data plan. | Full name; title; country of residence; current location; residential address; network provider; telephone number; payment information; e-mail address; device type (e.g. make and model); a copy of your passport, driving licence or similar documentation for identification (where necessary); and other details relating to you when you interact with us regarding the purchase of an eSIM. |
Sources of your Personal Data
During the course of our contractual relationship with you or when you visit our website or application, we will collect Personal Data either: (1) directly from you, or (2) indirectly from third parties (for example, once you have contracted for our services, through our affiliates or travel agencies).
Purpose and legal basis for processing
We have set out in the table below the key context (“Legal Basis”) on which we process your Personal Data. We also explain how (“Nature of Processing”) and why (“Purposes”) we obtain and collect your Personal Data.
| Legal Basis | Nature of Processing and Purposes | Categories of Personal Data |
|---|---|---|
| Compliance with a Legal Obligation | Roamjoy may process your Personal Data where it is necessary to comply with legal obligations to which we are subject under European Union and/or applicable laws, including but not limited to safeguarding and complying with law enforcement requests. | Customer Data, Website Data |
| Performance of a Contract |
| Customer Data, Website Data |
| Legitimate Interest |
| Customer Data, Website Data |
With whom do we share Personal Data?
Depending on the Purpose for which we process your Personal Data, we may share such Personal Data with some or all of the following recipients to the extent necessary:
- Roamjoy internal/intra-group entities: internal departments and services (such as our sales department, marketing department or IT department).
- Telecommunications service providers: service providers located in the appropriate jurisdiction for which the eSIM service was purchased.
- Regulatory authorities and law enforcement agencies: where we are under a duty to disclose or share your Personal Data in order to comply with any legal or regulatory obligation or request, such as the Revenue Commissioners, Department of Social Protection, the Data Protection Commission, Workplace Relations Commission, the Irish courts, An Garda Síochána or any other applicable authorities.
- Third party advisors and professionals: professional advisors who provide professional services to us (e.g. consultants, legal advisors).
- Third party service providers: we engage third party suppliers who may process your Personal Data on our behalf for the above Purposes. These include administrative services, advertising and communication services, corporate social responsibility services, maintenance services, physical security services, archiving, custody, storage and digitalisation services, document removal and destruction services, back-office services, and IT services.
Our network carriers only process the minimal technical information needed for the service to function, such as the IMSI (International Mobile Subscriber Identity), the MSISDN (mobile number identifier), and the IP addresses used to establish the connection. This information is standard in all mobile services worldwide and is necessary for routing traffic and enabling connectivity.
Our network partners only access technical data required for connectivity and cannot see details such as names, emails, payment information, or browsing activity. All communications use end-to-end encryption (HTTPS, SFTP, SSH), ensuring data remains encrypted in transit. We implement data minimisation principles and maintain strict partner agreements to prevent linking internet traffic to identifiable individuals.
International data transfers
Users resident in the European Union should note that your Personal Data will be transferred to certain recipients (mainly our external service providers) who are located outside the European Economic Area (“EEA”) in countries with laws and practices that do not contain equivalent data protection rights for your Personal Data (e.g. Thailand, Colombia). Where such transfers occur, we ensure that appropriate safeguards are in place by ensuring that: (a) transfers do not occur without our prior written authority; and (b) that an appropriate transfer mechanism, such as Module 2 of the Standard Contractual Clauses (as approved by the European Commission) or an adequacy decision of the European Commission, is in place to protect your Personal Data. If you would like to find out more about any transfers which affect your Personal Data, please contact us at support@roamjoy.com.
Your data protection rights
| Right | Further information |
|---|---|
| Right of access | You have the right to request a copy of the Personal Data held by Roamjoy about you and to access the Personal Data which we hold about you. |
| Right to object | You have a right to object at any time to the processing of your Personal Data where Roamjoy processes your Personal Data on the legal basis of pursuing its legitimate interests. |
| Right to rectification | You have the right to have any inaccurate Personal Data which Roamjoy holds about you updated or corrected. |
| Right to erasure | In certain circumstances, you may also have your Personal Data deleted. For example, if you exercise your right to object and Roamjoy does not have an overriding reason to process your Personal Data or if we no longer require your Personal Data for the purposes set out in this Notice. |
| Right to restriction of processing | You have the right to ask Roamjoy to restrict processing your Personal Data in certain cases, including if you believe that the Personal Data we hold about you is inaccurate or if our use of your Personal Data is unlawful. |
| Right to data portability | You may request Roamjoy to provide you with your Personal Data which you have given Roamjoy in a structured, commonly used and machine-readable format. |
| Right to lodge a complaint | You have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or in the place where an alleged infringement occurred. The relevant supervisory authority in Ireland is the Data Protection Commission. |
| Right to object to automated decision-making | You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We may not be able to comply with this request where the processing is necessary to enter or perform our contract with you or when the processing is authorised under a law to which we are subject. |
How long we retain your Personal Data
In general, we will store your Personal Data in accordance with our obligations under applicable Irish and European Union laws and/or for as long as we have a relationship with you plus a reasonable period of time after that. Your Personal Data will be stored as long as necessary in light of the purpose(s) for which it was obtained. The criteria used to determine the retention periods include:
- The length of the contractual relationship plus 7.5 years from the date of termination.
- Whether retention is prudent in light of Roamjoy's legal position (such as with respect to statutes of limitations, litigation or regulatory investigations).
- Whether there is a legal obligation to which Roamjoy is subject.
- 6 months for connection history and call recording.
Roamjoy retains customer data only for as long as necessary to provide the service and comply with legal obligations. Once this period ends, the data is securely deleted or anonymised, in line with GDPR.
Children’s Personal Data
Roamjoy understands the importance of safeguarding the Personal Data of children, which we consider to be an individual under the age of 18 in Ireland or the equivalent age as specified by law in your jurisdiction.
Children under the age of 18 are prohibited from using Roamjoy’s services. We do not knowingly collect (or knowingly allow any third party to collect) Personal Data from persons under the age of 18. If we become aware that Personal Data has been collected from a person under the age of 18, we will delete this Personal Data and terminate that individual’s account as quickly as possible.
Contacting us about your data
Roamjoy has a Data Protection Officer in accordance with applicable laws. If you have any questions about the information detailed in this Notice or would like to exercise your data protection rights, please contact our Data Protection Officer at support@roamjoy.com.
Updates to this Notice
We will make best efforts to keep this Notice up to date. This Notice will be regularly reviewed and may be amended and updated from time to time as necessary. Any updates to this Notice will be posted to this section of the website.
This Notice is drafted in the English language. In the event that there is a conflict between this English language version of the Notice and any translated copies of the Notice, the English version shall prevail.