Privacybeleid
Laatst bijgewerkt: Mei 2026
Inhoud
- 1. Inleiding
- 2. Informatie over de verwerkingsverantwoordelijke
- 3. Persoonsgegevens die wij verzamelen
- 4. Bronnen van je persoonsgegevens
- 5. Rechtsgrondslag voor verwerking
- 6. Gegevens delen en ontvangers
- 7. Internationale gegevensoverdrachten
- 8. Jouw gegevensbeschermingsrechten
- 9. Bewaartermijnen
- 10. Persoonsgegevens van kinderen
- 11. Cookies en trackingtechnologieën
- 12. Contactinformatie
- 13. Privacyrechten Californie (CCPA/CPRA)
- 14. Brazil Privacy Rights (LGPD)
- 15. Japan Privacy Rights (APPI)
- 16. Canada Privacy Rights (PIPEDA)
- 17. India Privacy Rights (DPDP Act)
- 18. Additional Regional Privacy Rights
- 19. AI and Machine Learning
- 20. Referral Program Privacy
1. Introduction
Dit privacybeleid ("Kennisgeving") legt uit hoe Future Syncs Limited, VK, handelend onder de naam HelloRoam ("HelloRoam", "wij", "ons" of "onze") omgaat met je persoonsgegevens. Het geldt voor informatie die je zelf verstrekt of die wij verzamelen wanneer je contact met ons opneemt, onze app gebruikt, onze website bezoekt of onze diensten koopt.
Op grond van de Algemene Verordening Gegevensbescherming (EU) 2016/679 ("AVG") en de Britse AVG zijn wij verplicht je deze informatie te verstrekken, inclusief details over je gegevensbeschermingsrechten.
Voldoet HelloRoam aan de wetgeving voor gegevensbescherming?
HelloRoam neemt gegevensbescherming serieus en deelt je persoonsgegevens nooit met derden zonder een geldige wettelijke grondslag. Wij voldoen aan de AVG, de Britse wetgeving voor gegevensbescherming en privacykaders in Noord-Amerika, Australië en Latijns-Amerika. Privacy by design is in alle onze diensten ingebouwd.
We run Data Protection Impact Assessments when we start new services or data processing that may pose a high risk to your rights.
2. Data Controller Information
De verwerkingsverantwoordelijke voor deze Kennisgeving is Future Syncs Limited, VK, handelend onder de naam HelloRoam. HelloRoam is verantwoordelijk voor je persoonsgegevens.
Company:Future Syncs Limited
Brand:HelloRoam (een merk van Future Syncs Limited)
Address:Londen, Verenigd Koninkrijk
Company Registration:15950168
Email:help@helloroam.com
HelloRoam zet zich in voor de bescherming van je persoonsgegevens. In deze Kennisgeving leggen wij precies uit hoe wij die verwerken.
3. Personal Data We Collect
Wij verzamelen en verwerken de volgende categorieën persoonsgegevens:
| Categorie | Voorbeelden |
|---|---|
| Identiteitsgegevens | Voornaam, achternaam, gebruikersnaam of vergelijkbare identificator, aanhef, geboortedatum |
| Contactgegevens | E-mailadres, telefoonnummer, factuuradres, afleveradres |
| Financiële gegevens | Betaalkaartgegevens (verwerkt door onze betaaldienstverlener), bankrekeninggegevens |
| Transactiegegevens | Informatie over betalingen aan en van jou, details van de producten en diensten die je bij ons hebt gekocht |
| Technische gegevens | IP-adres, inloggegevens, browsertype en -versie, tijdzone-instelling en locatie, browserplug-intypes en -versies, besturingssysteem en platform, apparaat-ID's |
| Profielgegevens | Gebruikersnaam en wachtwoord, aankopen of bestellingen, interesses, voorkeuren, feedback en antwoorden op enquêtes |
| Gebruiksgegevens | Informatie over hoe je onze website, producten en diensten gebruikt, inclusief eSIM-activatiegegevens en dataverbruikspatronen |
| Marketinggegevens | Je voorkeuren voor het ontvangen van marketing van ons en derden, en je communicatievoorkeuren |
4. Sources of Your Personal Data
Wij verzamelen je persoonsgegevens uit de volgende bronnen:
Directe interacties
Je verstrekt ons identiteits-, contact- en financiële gegevens wanneer je formulieren invult of contact met ons opneemt via telefoon, e-mail of andere kanalen. Dit omvat ook gegevens die je deelt bij het aanmaken van een account, het kopen van een abonnement, het abonneren op onze nieuwsbrief, deelname aan een actie of het geven van feedback.
Geautomatiseerde technologieën
Wanneer je onze website en app gebruikt, kunnen wij automatisch technische gegevens verzamelen over je apparaat, surfgedrag en patronen. Dit doen wij via cookies, serverlogboeken en vergelijkbare technologieën.
Derde partijen
Wij kunnen persoonsgegevens ontvangen van derden, waaronder aanbieders van analyses, advertentienetwerken, zoekinformatieleveranciers, betaal- en bezorgdiensten en identiteitsverificatiediensten.
5. Legal Basis for Processing
Wij gebruiken je persoonsgegevens alleen als de wet dat toestaat. Dit zijn de meest voorkomende situaties:
Uitvoering van overeenkomst
Wanneer wij een overeenkomst met je moeten uitvoeren of zijn aangegaan.
Gerechtvaardigde belangen
Wanneer het noodzakelijk is voor onze gerechtvaardigde belangen (of die van een derde partij) en jouw belangen en fundamentele rechten daarvoor niet zwaarder wegen.
Wettelijke verplichting
Wanneer wij moeten voldoen aan een wettelijke of regelgevende verplichting.
Toestemming
Wanneer je toestemming hebt gegeven voor de verwerking van je persoonsgegevens voor een of meer specifieke doeleinden.
Recht om toestemming in te trekken
Wij gebruiken je persoonsgegevens alleen als de wet dat toestaat. Dit zijn de meest voorkomende situaties:
6. Data Sharing & Recipients
Wij kunnen je persoonsgegevens delen met de volgende categorieën ontvangers:
Dienstverleners
Bedrijven die namens ons diensten leveren, waaronder betalingsverwerking, gegevensanalyse, e-mailbezorging, hosting, klantenservice en marketingondersteuning.
Netwerkpartners
Mobiele netwerkaanbieders en eSIM-leveranciers die onze connectiviteitsdiensten mogelijk maken.
Professionele adviseurs
Advocaten, bankiers, accountants en verzekeraars die juridische, financiële en adviesdiensten verlenen.
Regelgevende instanties
Overheidsinstanties, toezichthouders, wetshandhavingsinstanties, rechtbanken en andere autoriteiten wanneer de wet dat vereist.
Normen voor gegevensbescherming
Wij eisen van alle derde partijen dat zij de beveiliging van je persoonsgegevens respecteren en deze conform de wet behandelen. Wij staan verwerkers niet toe je gegevens voor eigen doeleinden te gebruiken. Zij mogen die alleen verwerken voor de specifieke doeleinden die wij hebben bepaald.
Our Data Processors
We share your data with these trusted service providers. Each one has a data processing agreement with us.
| Verwerker | Doel |
|---|---|
| Stripe | Payment processing. Card details go directly to Stripe and are never stored on our servers. |
| Supabase | User authentication and account management. |
| Google Analytics (GA4) | Website usage analytics. Only active after you give consent. |
| Google Ads | Conversion tracking for advertising. Only active after you give consent. |
| Google Tag Manager | Tag management for analytics and marketing scripts. |
| Meta (Facebook Pixel) | Marketing analytics and conversion tracking. Only active with marketing consent. |
| Microsoft Clarity | Behavioral analytics and session recordings to improve user experience. Only active with analytics consent. |
| Sentry | Error monitoring and performance tracking. Personal data is automatically redacted. |
| VWO (Visual Website Optimizer) | A/B testing to help us improve the website experience. |
| Vercel | Website hosting, analytics, and performance monitoring. |
| Rewardful | Affiliate referral tracking. Stores a referral token for 90 days when you arrive via an affiliate link. |
We have Data Processing Agreements in place with all processors listed above.
Affiliate Partners
When you arrive through an affiliate link, we share a referral token with Rewardful to attribute your purchase and calculate rewards. This data is kept for 90 days.
7. International Data Transfers
Wij kunnen je persoonsgegevens overdragen aan landen buiten het Verenigd Koninkrijk en de Europese Economische Ruimte (EER). Wanneer wij dit doen, treffen wij waarborgen om te zorgen dat je gegevens hetzelfde beschermingsniveau krijgen.
• Overdrachten naar landen die door de Europese Commissie of de Britse overheid als adequaat worden beschouwd voor gegevensbescherming.
• Gebruik van specifieke contracten die zijn goedgekeurd door de Europese Commissie of de Britse overheid (standaardcontractbepalingen).
• Overdrachten aan in de VS gevestigde aanbieders die gecertificeerd zijn onder het EU-VS Data Privacy Framework.
Neem contact op over overdrachten
Neem contact met ons op via help@helloroam.com als je meer informatie wilt over de specifieke waarborgen die wij treffen bij de overdracht van je persoonsgegevens buiten het VK of de EER.
Transfer Mechanisms by Processor
Stripe, Google, Meta, Microsoft, Sentry, VWO, and Vercel transfer data to the United States under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Supabase processes data in the US under SCCs. For UK-origin transfers, we use the UK International Data Transfer Agreement (IDTA) alongside SCCs.
8. Your Data Protection Rights
Je hebt de volgende rechten op grond van de wetgeving inzake gegevensbescherming:
Recht op inzage
Je kunt een kopie opvragen van de persoonsgegevens die wij over je bewaren.
Recht op rectificatie
Je kunt ons vragen onjuiste informatie te corrigeren of onvolledige gegevens aan te vullen.
Recht op wissing
Je kunt ons vragen je persoonsgegevens te wissen, onder bepaalde voorwaarden.
Recht op beperking van verwerking
Je kunt ons vragen de verwerking van je persoonsgegevens te beperken, onder bepaalde voorwaarden.
Recht van bezwaar
Je kunt bezwaar maken tegen de verwerking van je persoonsgegevens, onder bepaalde voorwaarden.
Recht op gegevensoverdraagbaarheid
Je kunt ons vragen de gegevens die wij bewaren over te dragen aan een andere organisatie of rechtstreeks aan jou, onder bepaalde voorwaarden.
Toestemming intrekken
Je kunt toestemming op elk moment intrekken wanneer wij je gegevens op basis van toestemming verwerken.
Klacht indienen
Je kunt een klacht indienen bij een toezichthoudende autoriteit.
We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
Hoe je je rechten uitoefent
Neem contact op via help@helloroam.com om een van bovenstaande rechten uit te oefenen. Er zijn geen kosten verbonden aan het opvragen van je gegevens of het uitoefenen van je rechten. Wij kunnen een redelijke vergoeding vragen als je verzoek duidelijk ongegrond, herhaaldelijk of buitensporig is.
9. Data Retention
Wij bewaren je persoonsgegevens alleen zo lang als nodig, ook voor eventuele wettelijke, boekhoudkundige of rapportageverplichtingen.
Bij het bepalen van bewaartermijnen kijken wij naar de hoeveelheid en gevoeligheid van de gegevens, het risico op schade door onbevoegd gebruik, het doel waarvoor wij ze verzameld hebben, of wij dat doel op een andere manier kunnen bereiken en de toepasselijke wettelijke vereisten.
| Category | Retention Period |
|---|---|
| Accountgegevens | Gedurende de looptijd van je account plus 6 jaar na sluiting |
| Transactiegegevens | 7 jaar vanaf de transactiedatum |
| Marketingvoorkeuren | Tot je je afmeldt of 3 jaar inactiviteit |
| Technische gegevens en gebruiksgegevens | 13 maanden na verzameling |
10. Children's Personal Data
Onze diensten zijn bedoeld voor personen van 16 jaar en ouder. Wij verzamelen bewust geen persoonsgegevens van kinderen onder de 16 jaar. Ben je ouder of voogd en denk je dat je kind gegevens met ons heeft gedeeld, neem dan direct contact met ons op.
Als wij ontdekken dat wij persoonsgegevens van een kind hebben verzameld zonder toestemming van een ouder, verwijderen wij deze onmiddellijk uit onze systemen.
Mededeling voor ouders
Als je denkt dat wij gegevens van of over een kind onder de 16 jaar hebben, neem dan direct contact met ons op via help@helloroam.com.
12. Contact Information
Neem contact met ons op als je vragen hebt over dit privacybeleid of de verwerking van je gegevens:
Recht om een klacht in te dienen
Neem contact met ons op als je vragen hebt over dit privacybeleid of de verwerking van je gegevens:
13. Privacyrechten Californie (CCPA/CPRA)
Als je in Californie woont, geven de California Consumer Privacy Act (CCPA) en de California Privacy Rights Act (CPRA) je specifieke rechten over je persoonsgegevens. In dit gedeelte leggen we die rechten uit en hoe je ze kunt gebruiken.
HelloRoam verkoopt geen persoonsgegevens zoals gedefinieerd onder de CCPA.
Persoonsgegevens die wij verzamelen
Wij verzamelen de volgende categorieen persoonsgegevens van inwoners van Californie:
- Identificatiegegevens: naam, e-mailadres en accountgegevens
- Apparaatinformatie: apparaattype, besturingssysteem en ID's voor eSIM-activatie
- Betalingsinformatie: factureringsgegevens die veilig worden verwerkt door onze betalingsprovider
- Gebruiksgegevens: hoe je onze website en app gebruikt
- Internetactiviteit: IP-adres, browsertype en bezochte pagina's
Recht op inzage
Je kunt ons vragen welke persoonsgegevens wij over jou hebben verzameld, waar die vandaan komen, waarom we ze hebben verzameld en met wie we ze delen.
Recht op verwijdering
Je kunt ons vragen de persoonsgegevens die wij van je hebben verzameld te verwijderen. Er gelden enkele uitzonderingen, zoals wanneer we de gegevens nodig hebben om een transactie te voltooien of een wettelijke verplichting na te komen.
Recht op opt-out
Je kunt ons vragen je persoonsgegevens niet te verkopen of te delen. HelloRoam verkoopt geen persoonsgegevens, dus dit recht is standaard al gewaarborgd.
Recht op gelijke behandeling
Wij behandelen je niet anders en weigeren je geen diensten omdat je ervoor kiest je privacyrechten in Californie uit te oefenen.
Hoe je een CCPA-verzoek indient
Om een van de bovenstaande rechten uit te oefenen, stuur je een e-mail naar help@helloroam.com. Vermeld je naam, e-mailadres en een beschrijving van je verzoek. Je kunt ook namens een andere persoon een verzoek indienen als je daarvoor schriftelijke toestemming hebt of een volmacht bezit.
Verificatieprocedure
We moeten je identiteit verifiëren voordat we je verzoek kunnen verwerken. We vragen je het e-mailadres te bevestigen dat aan je account is gekoppeld en kunnen aanvullende informatie opvragen om je identiteit te bevestigen. We reageren binnen 45 dagen op je verzoek. Als we meer tijd nodig hebben, laten we je dat weten.
14. Brazil Privacy Rights (LGPD)
Brazil's Lei Geral de Proteção de Dados (LGPD) applies to HelloRoam when we process personal data from individuals in Brazil. This section explains your rights and how we handle your data under Brazilian law.
Legal Bases Under LGPD
We process your personal data based on your consent, to perform a contract with you, to meet a legal obligation, or to serve our legitimate interests. We tell you the applicable legal basis at the time we collect your data.
Your Rights Under LGPD
- Confirmation that we process your personal data and access to a copy of it.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data.
- Portability of your personal data to another service provider.
- Deletion of personal data processed with your consent.
- Information about which public and private entities we share your data with.
- Information about your option to deny consent and the consequences of doing so.
- Withdrawal of consent at any time, free of charge.
- Review of decisions made by automated means that affect your interests.
Data Protection Officer
Our Data Protection Officer handles privacy matters for Brazilian residents. Contact them at help@helloroam.com with the subject line "LGPD Request." We will respond within the timeframes required by Brazilian law.
If you believe we have not handled your data correctly, you have the right to file a complaint with Brazil's national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.
15. Japan Privacy Rights (APPI)
Japan's Act on Protection of Personal Information (APPI) applies when we process personal data from individuals in Japan. We handle your data in line with APPI requirements and the guidelines issued by Japan's Personal Information Protection Commission (PPC).
Purpose of Data Use
We use your personal data to process eSIM orders, manage your account, provide customer support, send service notifications, and improve our platform. We will not use your data for other purposes without notifying you first.
Cross-Border Transfers
Your personal data is transferred to and stored in the United Kingdom. The UK has been recognized as providing an adequate level of personal data protection by the European Commission. We apply equivalent safeguards for transfers under APPI.
Your Rights Under APPI
- Disclosure of the personal data we hold about you.
- Correction of any inaccurate personal data.
- Cessation of use or deletion of your personal data where it is no longer needed.
- Cessation of provision of your personal data to third parties.
To exercise your rights or to submit a complaint, email us at help@helloroam.com. You may also contact the Personal Information Protection Commission (PPC) at ppc.go.jp.
16. Canada Privacy Rights (PIPEDA)
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies to HelloRoam's handling of personal information from Canadian residents. We follow the fair information principles that PIPEDA requires.
How We Apply PIPEDA Principles
- Accountability: We are responsible for all personal information under our control and have designated a privacy contact to oversee compliance.
- Consent: We collect, use, or disclose your personal information only with your knowledge and consent, except where the law permits otherwise.
- Limiting Collection: We collect only the information we need for the identified purposes.
- Accuracy: We keep your personal information as accurate, complete, and up to date as necessary.
- Safeguards: We protect your personal information with security appropriate to its sensitivity.
Your Rights Under PIPEDA
- Access to the personal information we hold about you.
- Challenge the accuracy and completeness of your information and request corrections.
- Withdraw consent for non-essential data collection at any time.
To make a privacy request, email us at help@helloroam.com. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
17. India Privacy Rights (DPDP Act)
India's Digital Personal Data Protection Act 2023 (DPDP Act) applies when we process personal data from individuals in India. HelloRoam acts as a Data Fiduciary under this law and processes your data only for clear, lawful purposes.
Your Rights Under the DPDP Act
- Access to a summary of the personal data we process and how we use it.
- Correction and updating of inaccurate or incomplete personal data.
- Erasure of personal data that is no longer necessary for the purpose it was collected.
- Grievance redressal through our dedicated grievance mechanism.
- Nomination of another individual to exercise your rights on your behalf in case of death or incapacity.
As a Data Fiduciary, HelloRoam collects only the personal data needed to provide our eSIM services. We keep it secure, use it only for stated purposes, and delete it when it is no longer needed. We do not process the personal data of children without verifiable parental consent.
To raise a grievance or exercise any DPDP right, email us at help@helloroam.com with the subject line "DPDP Request." We will acknowledge your request within 48 hours and resolve it within the timeframe required by law.
18. Additional Regional Privacy Rights
HelloRoam operates in 185+ countries. In addition to GDPR, CCPA, LGPD, APPI, PIPEDA, and the DPDP Act, the following regional laws may apply to you depending on where you live.
South Africa (POPIA)
South Africa's Protection of Personal Information Act (POPIA) gives you rights to access, correct, and delete your personal data. Cross-border transfers require adequate protection. To exercise your rights or file a complaint, contact us at help@helloroam.com or reach the Information Regulator at inforegulator.org.za.
Thailand (PDPA)
Thailand's Personal Data Protection Act (PDPA) requires your consent for most processing. You have the right to access, correct, delete, and port your data, and to object to processing. To exercise your rights or complain to the Personal Data Protection Committee (PDPC), contact us at help@helloroam.com.
Singapore (PDPA)
Singapore's Personal Data Protection Act (PDPA) requires your consent before we collect, use, or disclose your personal data. You can withdraw consent at any time. We notify affected individuals promptly in the event of a data breach. Contact help@helloroam.com for any PDPA-related request.
Turkey (KVKK)
Turkey's Personal Data Protection Law (KVKK) requires explicit consent for cross-border data transfers. You have the right to know whether your data is processed, access it, request correction or deletion, and object to automated decisions. To submit a request or file a complaint with the KVKK Board, contact us at help@helloroam.com.
Switzerland (nFADP)
Switzerland's revised Federal Act on Data Protection (nFADP) applies to both natural and legal persons. You have the right to access your data, correct inaccuracies, and object to certain processing. We notify the Federal Data Protection and Information Commissioner (FDPIC) of significant data breaches. Contact help@helloroam.com with any nFADP request.
Indonesia (UU PDP)
Indonesia's Personal Data Protection Law (UU PDP) requires your consent for data collection and cross-border transfers. We maintain a designated Data Protection Officer to oversee compliance. To exercise your rights or raise a concern, email help@helloroam.com.
China (PIPL)
China's Personal Information Protection Law (PIPL) requires us to notify you and obtain separate consent before transferring your personal data outside China. We process data from Chinese residents only for the purposes clearly stated at the time of collection. Contact help@helloroam.com for any PIPL-related request.
19. AI and Machine Learning
HelloRoam uses AI tools carefully and only where they improve our service without compromising your privacy. We do not use AI in ways that produce automated decisions with legal or similarly significant effects on individual users.
AI Crawler Access
Our public website content, including eSIM pricing, coverage information, and FAQs, is accessible to AI crawlers. Your account data, personal information, and order history are never exposed to or shared with AI crawlers. We protect all personal data from AI training pipelines.
How We Use AI Internally
We use AI tools to support content research and review customer support quality. These tools process anonymized or aggregated data only. They are not used to make automated decisions about individual users.
HelloRoam does not sell user data to AI companies, data brokers, or any third parties for AI model training purposes.
20. Referral Program Privacy
When you participate in the HelloRoam referral program, we collect limited technical data to attribute referrals accurately and prevent fraud.
Data Collected
- IP address (anonymized after attribution)
- Browser user-agent string
- Device fingerprint (hashed, non-reversible)
Purpose
This data is used solely to attribute referral purchases to the correct referrer, prevent duplicate or fraudulent claims, and calculate referral rewards. We do not use this data for advertising or sell it to third parties.
Data Retention
Referral attribution data is retained for 90 days after the referred purchase. After this period, the data is automatically deleted. Aggregated, non-personal statistics (total referrals, reward amounts) are kept for accounting purposes.
Your Privacy Matters
We care about your data rights. Our practices are transparent, and you can exercise your rights anytime by contacting us at help@helloroam.com.
Related Policies
Questions About This Policy?
Have questions about this Privacy Policy or how we handle your data? We're happy to help.
Download de app. Reis slimmer.
Beheer al je eSIMs, wanneer en waar je wilt.
