PostFinance Travel eSIM Data Processing Agreement
Mindszi Technologies Ltd is the company behind this service. eSIM Copilot is our brand. We are registered in England and Wales, company number 15524190, at 128 City Road, London EC1V 2NX, United Kingdom.
Last updated: 29 September 2026
Parties: Mindszi Technologies Ltd, trading as eSIM Copilot (company number 15524190, 128 City Road, London EC1V 2NX, United Kingdom) ("Mindszi") and the Customer.
This agreement forms part of the PostFinance Travel eSIM Terms and Conditions between the parties and governs Mindszi's processing of personal data, as Processor for business accounts and as independent Controller for platform operations.
1. Definitions
1.1 "Data Protection Laws" means all applicable data protection and privacy laws, including the Swiss Federal Act on Data Protection (FADP), the EU GDPR (2016/679), the UK GDPR and the Data Protection Act 2018.
1.2 "Personal Data", "Data Subject", "Processing", "Processor", "Controller" and "Supervisory Authority" have the meanings given in the GDPR, and the equivalent meanings under the FADP.
1.3 "Subprocessor" means any third party engaged by Mindszi to process Personal Data.
2. Subject matter
2.1 This agreement governs Mindszi's Processing of Personal Data: (a) as Processor on behalf of the Customer for business accounts on PostFinance Travel eSIM; and (b) as independent Controller for platform operations including account security, analytics, billing and compliance.
3. Roles of the parties
3.1 The parties agree that:
(a) for business accounts, the Customer is the Controller and Mindszi is the Processor;
(b) for individual accounts, Mindszi is the Controller and the PostFinance Travel eSIM Privacy Policy applies;
(c) for platform-level activities such as account management, billing, fraud detection and security monitoring, Mindszi acts as independent Controller.
3.2 PostFinance AG is not a party to this agreement.
4. Instructions
4.1 Where acting as Processor, Mindszi shall only process Personal Data on documented instructions from the Customer, unless required to do otherwise by law.
4.2 The Customer instructs Mindszi to process Personal Data for the purposes described in the Agreement and this DPA.
5. Confidentiality
5.1 Mindszi shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality.
6. Security measures
6.1 Mindszi shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- encryption of Personal Data at rest and in transit
- access control measures
- incident detection and response procedures
- regular security assessments
7. Subprocessing
7.1 The Customer authorises Mindszi to engage the Subprocessors listed at the end of this DPA.
7.2 Mindszi maintains the list of Subprocessors in this document.
7.3 Mindszi shall ensure that Subprocessors are bound by written agreements imposing data protection obligations no less protective than this DPA.
7.4 Mindszi shall notify the Customer of any intended addition or replacement of a Subprocessor and give the Customer an opportunity to object.
8. Data transfers
8.1 Mindszi shall not transfer Personal Data outside the UK, the EEA or Switzerland unless appropriate safeguards are in place, such as standard contractual clauses recognised by the FDPIC, the EU standard contractual clauses, the UK International Data Transfer Addendum, or a recognised adequacy decision or framework.
9. Data subject rights
9.1 Mindszi shall assist the Customer, by appropriate technical and organisational measures, in meeting the Customer's obligation to respond to requests from Data Subjects exercising their rights.
10. Data breach
10.1 Mindszi shall notify the Customer without undue delay after becoming aware of a Personal Data Breach.
10.2 The notification shall include the information the Customer reasonably requires to meet its own obligations under the Data Protection Laws, including any notification to the FDPIC.
11. Deletion or return of data
11.1 On termination of the Agreement, Mindszi shall, at the Customer's choice, delete or return all Personal Data, unless the law requires otherwise.
12. Audit rights
12.1 Mindszi shall make available all information necessary to demonstrate compliance with this DPA.
12.2 The Customer may conduct audits, including inspections, provided that at least 30 days' written notice is given, audits take place during normal business hours, and they do not interfere unreasonably with Mindszi's operations.
13. Liability
13.1 Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.
14. Governing law
14.1 This DPA is governed by the laws of England and Wales, consistent with the PostFinance Travel eSIM Terms and Conditions.
Categories of personal data processed
Each category below is Personal Data because it is held against an identified customer account. A device model or a data volume would not identify anyone on its own.
- First name
- Last name
- Email address
- MSISDN (mobile number)
- ICCID (SIM identifier, where linked to an individual)
- EID (device eSIM identifier, where linked to an individual)
- Device make and model, in some cases
- Job title and department, where the Customer provides them
- Mobile plan order and assignment information
- Credit or debit payment information (if provided)
- Connection and usage data, including data volumes and the countries and networks used
- Support and chat messages, and delivery metadata
Subprocessors and locations
| Subprocessor | Purpose | Region |
|---|---|---|
| AWS | Platform cloud services | EU |
| Auth0 | End user authentication | EU |
| Stripe | Payment processing | UK and EU |
| Datadog | Logging | EU |
| SendGrid | Email communications | EU |
| PostHog | Product analytics | EU |
| Google (Google Analytics) | Website analytics | EU and US |
| Twilio | SMS and WhatsApp messaging | UK and EU |
AI subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| AWS (Amazon Bedrock) | Model inference for the AI assistant, inside Mindszi's private AWS account in the EU | EU |
The model providers behind Bedrock do not receive inputs or outputs, and no customer content is used to train models. No tracing or evaluation tool sits outside the tenant.
Data transfers
Personal data for PostFinance Travel eSIM is stored at rest in the EU. Our team in the UK administers and supports the service and has access to it. AI inference for this service runs on Amazon Bedrock inside Mindszi's private AWS account in the EU, so prompts and completions remain in the EU. Where a transfer to the US is needed for payments or website analytics, it relies on the EU standard contractual clauses, the UK International Data Transfer Addendum and, for data from Switzerland, the FDPIC-recognised clauses or the Swiss-US Data Privacy Framework where the provider is certified.
AI model training
Mindszi does not permit AI subprocessors to use customer content for model training or fine-tuning. For PostFinance Travel eSIM the assistant runs in Amazon Bedrock, where inputs and outputs are not shared with the model providers and are not used to train models, and we do not opt into any data-sharing, fine-tuning or feedback-driven training programme.
Contact
| Company | Mindszi Technologies Ltd, trading as eSIM Copilot, 128 City Road, London EC1V 2NX, United Kingdom |
| privacy@mindszi.com | |
| Data Protection Officer | Michael Moorfield |