01Data Controller
OHA Labs Limited, a company registered in England and Wales (Company No. 17183250), with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ ("we", "us", "our"), is the data controller responsible for your personal data.
For any data protection enquiries, contact us at [email protected].
OHA Labs Limited is registered with the UK Information Commissioner's Office (ICO) as a data controller under registration number ZC137188. Our entry on the ICO public register is verifiable at https://ico.org.uk/ESDWebPages/Entry/ZC137188.
02Information We Collect
We collect the following categories of personal data:
Account Information:
- Email address — required for account creation and eSIM delivery
- Name — optional, for personalising your account
Transaction Data:
- Order history, amounts, and currency
- Payment information — processed securely by our PCI DSS-compliant payment processor; we never store your full card number or security code
- Promotional codes applied to orders
eSIM Data:
- eSIM identifiers (ICCID) and activation details
- Data usage statistics
- Auto top-up configuration and history
Technical Data:
- IP address and browser type — for security and fraud prevention
- Session data — for maintaining your login
- Usage analytics events (pages viewed and interactions) — cookieless; linked to a pseudonymous identifier when you are signed in (see Third-Party Services)
User-Generated Content:
- Product reviews and ratings
- Contact form submissions
Client-Side Data (not sent to our servers):
- Recently viewed products — stored only in your browser's local storage
03Lawful Basis for Processing
We process your personal data on the following legal grounds under UK GDPR:
Contract (Article 6(1)(b)):
- Account data — to provide our service
- Order and payment data — to complete your purchase
- eSIM provisioning — to deliver the product
- Transactional emails — order confirmations and delivery notifications
Legitimate Interest (Article 6(1)(f)):
- IP address and session data — securing our service and preventing fraud and abuse
- Service-quality monitoring and operational notifications — maintaining a reliable service
- Contact form submissions — responding to and managing your enquiry, and preventing abuse of the form
Consent (Article 6(1)(a)):
- Product reviews — you choose to write a review
- Auto top-up — you explicitly enable this feature
We process website usage data (page views, click events, conversion funnels) under legitimate interest to improve our service. This data is collected without cookies or advertising identifiers; for signed-in customers, events are linked to a pseudonymous account identifier.
04How We Use Your Information
We use your personal data to:
- Process and deliver your eSIM orders
- Send order confirmations, eSIM activation details, and support communications
- Prevent fraud and enforce our terms of service
- Improve our website and services
- Comply with legal obligations
05Third-Party Services
We share data with a small number of trusted service providers, each contractually bound to protect your data and — unless stated otherwise below — process it only on our instructions:
Payment Processing:
- A PCI DSS-compliant payment processor handles your card payment on its own secure checkout page. We never receive or store your full card number or security code. For purchases in the EU, it acts as Merchant of Record and is an independent controller for its own legal obligations, such as VAT collection (see the 'Merchant of Record — EU customers' section of our Terms of Service).
Email Delivery:
- A transactional email delivery service sends your order confirmations, eSIM delivery, and account notifications.
Hosting & Infrastructure:
- Cloud hosting, database, and content-delivery providers run our website; our core customer database is held in the United Kingdom.
Service Quality:
- An error-monitoring service helps us detect and fix faults.
eSIM Provisioning:
- We work with an eSIM provisioning partner to deliver your eSIM profiles. We minimise the data shared with this partner: we do not share any direct identifiers such as your name, email address, or phone number. We exchange only a transaction reference, the plan and pricing details, and technical eSIM identifiers — pseudonymous data that can be linked to you only within our own systems.
Analytics:
- A privacy-focused, cookieless analytics service hosted in the EU processes page views and interaction events. If you are signed in, events are linked to a pseudonymous account identifier — never your name, email address, or payment details — so we can understand how our service is used.
Bot Protection:
- An automated bot-protection service safeguards our contact form from spam (it processes a verification token and your IP address).
06International Data Transfers
Your core data (database and cache) is stored in the United Kingdom. Some of our service providers process data outside the UK — in the United States and, for analytics, in the European Economic Area (Germany). Transfers to the EEA are covered by the UK's adequacy regulations. For transfers to other countries, we only transfer your personal data where it is protected by an appropriate safeguard required under UK GDPR, such as the UK International Data Transfer Agreement or Addendum, or Standard Contractual Clauses. You can ask us for more information about the safeguard relevant to a particular transfer by contacting us at [email protected].
07Data Retention
We retain your personal data for the following periods:
- Account data — for as long as your account is active
- Order records — 6 years after the transaction (UK Companies Act 2006, s.386)
- Order security metadata (IP address, device/browser information, card country, card last 4 digits) — 18 months for fraud prevention and chargeback defence (legitimate interest, Article 6(1)(f)), then automatically erased; erased immediately on account deletion
- eSIM records — for the contract duration plus 1 year
- Contact form submissions — 2 years
- Usage analytics events — retained only for a limited period, then deleted
- Authentication tokens, login sessions, and diagnostic logs — kept only for the short period technically necessary for security and service operation, then automatically deleted
When you delete your account, your account profile and contact details are deleted, your email address is anonymised on retained records, and the security metadata attached to your orders (IP address, device/browser information, card country, card last 4 digits) is erased immediately. The financial record of each order and top-up (amount, currency, dates) is kept for 6 years as required by law (UK Companies Act 2006). For accounts you do not delete, that security metadata is automatically erased 18 months after the order — the window in which it may be needed for fraud prevention and chargeback defence (legitimate interest, Article 6(1)(f)) — and is never used for any other purpose.
08Cookies and Local Storage
We use a privacy-focused analytics service in cookieless mode — no analytics cookies are set. If you are signed in, usage events are linked to a pseudonymous account identifier (never your name or email address) to help us improve our service. We do not use advertising cookies or third-party tracking pixels.
- Authentication session cookie — maintains your login (HTTP-only, secure)
- Currency preference cookie — remembers the display currency you choose (functional; not used for tracking)
Local Storage:
We store your recently viewed products in your browser's local storage for convenience. This data never leaves your device and is not sent to our servers.
09Your Rights
Under UK GDPR, you have the following rights:
- Right of Access — You can export the personal data held in your account in machine-readable format (JSON) from your account settings.
- Right to Rectification — You can update your name and profile information in your account settings.
- Right to Erasure — You can permanently delete your account from your account settings. Active eSIMs will be suspended and unused eSIMs will be cancelled. No refunds are issued for active or cancelled eSIMs upon account deletion. The financial record of orders and top-ups is kept for 6 years for legal compliance; the fraud-prevention security metadata attached to them is erased on account deletion and otherwise after 18 months (see Data Retention).
- Right to Restrict Processing — You may request that we limit how we process your data.
- Right to Data Portability — You can download your data in a structured, machine-readable format from your account settings.
- Right to Object — You may object to processing based on legitimate interest.
To exercise any right not available through your account settings, contact us at [email protected]. We will respond within one month.
Right to Complain:
You have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
10Automated Decision-Making
We do not make any decisions based solely on automated processing that produce legal or similarly significant effects on you.
11Children's Data
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at [email protected].
12Data Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), secure authentication, and access controls.
13California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). We do not sell your personal information to third parties. For any enquiries regarding your California privacy rights, please contact us at [email protected].
14Regional Privacy Rights
If you are located in certain jurisdictions, you may have additional rights:
Brazil (LGPD): You have the right to request access, correction, deletion, and portability of your personal data. Contact us at [email protected].
Thailand (PDPA): You have the right to access, correct, and delete your personal data. You may also withdraw consent at any time.
Japan (APPI): You have the right to request disclosure, correction, and deletion of your personal data held by us.
In all cases, exercising your rights under UK GDPR (as described in the 'Your Rights' section above) will also fulfil these regional requirements.
15Language and Contact
This privacy policy is provided in multiple languages for your convenience. In the event of any discrepancy between the English version and any translated version, the English language version shall prevail.
If you have any questions about this privacy policy, please contact us at [email protected].