Travel eSIM

Vereinbarung zur Auftragsverarbeitung

Datenschutz

Zu diesem Dokument

Das folgende Dokument enthält die Bestimmungen von Mindszi Technologies Ltd, handelnd unter eSIM Copilot, für diesen Dienst. Der bereitgestellte Rechtstext ist auf Englisch.

PostFinance Travel eSIM Data Processing Agreement

Mindszi Technologies Ltd is the company behind this service. eSIM Copilot is our brand. We are registered in England and Wales, company number 15524190, at 128 City Road, London EC1V 2NX, United Kingdom.

Last updated: 29 September 2026

Parties: Mindszi Technologies Ltd, trading as eSIM Copilot (company number 15524190, 128 City Road, London EC1V 2NX, United Kingdom) ("Mindszi") and the Customer.

This agreement forms part of the PostFinance Travel eSIM Terms and Conditions between the parties and governs Mindszi's processing of personal data, as Processor for business accounts and as independent Controller for platform operations.

1. Definitions

1.1 "Data Protection Laws" means all applicable data protection and privacy laws, including the Swiss Federal Act on Data Protection (FADP), the EU GDPR (2016/679), the UK GDPR and the Data Protection Act 2018.

1.2 "Personal Data", "Data Subject", "Processing", "Processor", "Controller" and "Supervisory Authority" have the meanings given in the GDPR, and the equivalent meanings under the FADP.

1.3 "Subprocessor" means any third party engaged by Mindszi to process Personal Data.

2. Subject matter

2.1 This agreement governs Mindszi's Processing of Personal Data: (a) as Processor on behalf of the Customer for business accounts on PostFinance Travel eSIM; and (b) as independent Controller for platform operations including account security, analytics, billing and compliance.

3. Roles of the parties

3.1 The parties agree that:

(a) for business accounts, the Customer is the Controller and Mindszi is the Processor;

(b) for individual accounts, Mindszi is the Controller and the PostFinance Travel eSIM Privacy Policy applies;

(c) for platform-level activities such as account management, billing, fraud detection and security monitoring, Mindszi acts as independent Controller.

3.2 PostFinance AG is not a party to this agreement.

4. Instructions

4.1 Where acting as Processor, Mindszi shall only process Personal Data on documented instructions from the Customer, unless required to do otherwise by law.

4.2 The Customer instructs Mindszi to process Personal Data for the purposes described in the Agreement and this DPA.

5. Confidentiality

5.1 Mindszi shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality.

6. Security measures

6.1 Mindszi shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • encryption of Personal Data at rest and in transit
  • access control measures
  • incident detection and response procedures
  • regular security assessments

7. Subprocessing

7.1 The Customer authorises Mindszi to engage the Subprocessors listed at the end of this DPA.

7.2 Mindszi maintains the list of Subprocessors in this document.

7.3 Mindszi shall ensure that Subprocessors are bound by written agreements imposing data protection obligations no less protective than this DPA.

7.4 Mindszi shall notify the Customer of any intended addition or replacement of a Subprocessor and give the Customer an opportunity to object.

8. Data transfers

8.1 Mindszi shall not transfer Personal Data outside the UK, the EEA or Switzerland unless appropriate safeguards are in place, such as standard contractual clauses recognised by the FDPIC, the EU standard contractual clauses, the UK International Data Transfer Addendum, or a recognised adequacy decision or framework.

9. Data subject rights

9.1 Mindszi shall assist the Customer, by appropriate technical and organisational measures, in meeting the Customer's obligation to respond to requests from Data Subjects exercising their rights.

10. Data breach

10.1 Mindszi shall notify the Customer without undue delay after becoming aware of a Personal Data Breach.

10.2 The notification shall include the information the Customer reasonably requires to meet its own obligations under the Data Protection Laws, including any notification to the FDPIC.

11. Deletion or return of data

11.1 On termination of the Agreement, Mindszi shall, at the Customer's choice, delete or return all Personal Data, unless the law requires otherwise.

12. Audit rights

12.1 Mindszi shall make available all information necessary to demonstrate compliance with this DPA.

12.2 The Customer may conduct audits, including inspections, provided that at least 30 days' written notice is given, audits take place during normal business hours, and they do not interfere unreasonably with Mindszi's operations.

13. Liability

13.1 Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.

14. Governing law

14.1 This DPA is governed by the laws of England and Wales, consistent with the PostFinance Travel eSIM Terms and Conditions.

Categories of personal data processed

Each category below is Personal Data because it is held against an identified customer account. A device model or a data volume would not identify anyone on its own.

  • First name
  • Last name
  • Email address
  • MSISDN (mobile number)
  • ICCID (SIM identifier, where linked to an individual)
  • EID (device eSIM identifier, where linked to an individual)
  • Device make and model, in some cases
  • Job title and department, where the Customer provides them
  • Mobile plan order and assignment information
  • Credit or debit payment information (if provided)
  • Connection and usage data, including data volumes and the countries and networks used
  • Support and chat messages, and delivery metadata

Subprocessors and locations

SubprocessorPurposeRegion
AWSPlatform cloud servicesEU
Auth0End user authenticationEU
StripePayment processingUK and EU
DatadogLoggingEU
SendGridEmail communicationsEU
PostHogProduct analyticsEU
Google (Google Analytics)Website analyticsEU and US
TwilioSMS and WhatsApp messagingUK and EU

AI subprocessors

SubprocessorPurposeRegion
AWS (Amazon Bedrock)Model inference for the AI assistant, inside Mindszi's private AWS account in the EUEU

The model providers behind Bedrock do not receive inputs or outputs, and no customer content is used to train models. No tracing or evaluation tool sits outside the tenant.

Data transfers

Personal data for PostFinance Travel eSIM is stored at rest in the EU. Our team in the UK administers and supports the service and has access to it. AI inference for this service runs on Amazon Bedrock inside Mindszi's private AWS account in the EU, so prompts and completions remain in the EU. Where a transfer to the US is needed for payments or website analytics, it relies on the EU standard contractual clauses, the UK International Data Transfer Addendum and, for data from Switzerland, the FDPIC-recognised clauses or the Swiss-US Data Privacy Framework where the provider is certified.

AI model training

Mindszi does not permit AI subprocessors to use customer content for model training or fine-tuning. For PostFinance Travel eSIM the assistant runs in Amazon Bedrock, where inputs and outputs are not shared with the model providers and are not used to train models, and we do not opt into any data-sharing, fine-tuning or feedback-driven training programme.

Contact

CompanyMindszi Technologies Ltd, trading as eSIM Copilot, 128 City Road, London EC1V 2NX, United Kingdom
Emailprivacy@mindszi.com
Data Protection OfficerMichael Moorfield