Privacy Policy
Last updated: 31 July 2026
This Privacy Policy explains how ELVORIN LTD collects, uses, stores, shares and protects personal data when you use arvosim.com, your ArvoSim Account, Wallet Balance and eSIM Plans. It also explains your rights and how you may raise a privacy request or complaint.
1. About this Privacy Policy
This Privacy Policy explains how ELVORIN LTD collects, uses, stores, shares and protects personal data when you:
- visit arvosim.com;
- create or use an ArvoSim Account;
- add funds to your Wallet Balance;
- purchase or use an eSIM Plan;
- communicate with our support team;
- subscribe to marketing communications; or
- otherwise interact with ArvoSim.
This Policy also explains your rights and how you may raise a privacy request or complaint.
ArvoSim is operated by ELVORIN LTD, company number 17344051, of Dept 6946, 196 High Road, Wood Green, London, United Kingdom, N22 8HH. Email: info@arvosim.com.
For the purposes of applicable data protection law, ELVORIN LTD is generally the controller of the personal data described in this Policy.
In this Policy, "ArvoSim", "we", "us" and "our" refer to ELVORIN LTD.
2. Applicable Data Protection Law
We process personal data in accordance with applicable data protection and privacy legislation, including, where relevant:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Data (Use and Access) Act 2025;
- the Privacy and Electronic Communications Regulations 2003; and
- other applicable privacy, electronic communications and consumer laws.
Additional or different rights may apply depending on where you live.
3. Scope of this Policy
This Policy applies to personal data processed through:
- the ArvoSim Website;
- your ArvoSim Account;
- Wallet Top-Ups and Wallet transactions;
- eSIM Orders and digital delivery;
- installation and activation support;
- customer service communications;
- complaints and refund requests;
- fraud-prevention and security processes;
- cookies and similar technologies; and
- authorised marketing communications.
This Policy does not govern independent third-party websites, applications, mobile networks or services that operate under their own privacy notices.
4. Meaning of Personal Data
"Personal data" means information relating to an identified or identifiable individual.
Information that has been irreversibly anonymised so that an individual can no longer reasonably be identified is not personal data.
Information that has merely been pseudonymised or associated with a technical identifier may still be personal data where it can reasonably be linked back to an individual.
5. Personal Data We Collect
The personal data we collect depends on how you use ArvoSim.
5.1 Account and identity data — we may collect full name; Account username or identifier; email address; password in encrypted or hashed form; country or region; preferred language; preferred currency; Account creation date; Account status; communication preferences; and information used to verify Account ownership.
5.2 Contact data — we may collect email address; billing contact details; correspondence address where required; telephone number where voluntarily provided; support contact preferences; and details contained in communications with us.
5.3 Order and eSIM data — we may collect Order number; selected destination; selected eSIM Plan; data allowance; validity period; Plan price; date and time of Order; Order status; delivery status; activation status; Plan expiry information; refund or cancellation status; eSIM or provisioning identifiers; QR-code delivery records; network or provider reference numbers; and limited usage information required to determine whether an eSIM has connected or consumed data. We do not use the content of your internet traffic for advertising purposes.
5.4 Wallet and transaction data — we may collect Wallet Top-Up amount; Wallet Balance; Wallet transaction history; currency; payment date and time; transaction status; payment reference; refunds; payment reversals; Chargebacks; promotional credits; closing-balance calculations; and invoice or receipt information.
5.5 Payment and authentication data — payments are processed through third-party payment providers. We do not store your full payment-card number or card security code on ArvoSim systems. We may receive limited payment information such as card brand; last four digits of the card; expiry month and year; tokenised payment reference; payment status; transaction identifier; card issuer country; billing country; authorisation result; 3D Secure authentication result; fraud or risk indicators; and refund or Chargeback information.
5.6 Device and technical data — we may collect IP address; browser type and version; device type; device manufacturer and model; operating system and version; language and time-zone settings; screen or browser characteristics; device identifiers made available to the Service; approximate location derived from IP address; referring page or website; pages viewed; session information; login records; error logs; security logs; cookie identifiers; and information necessary to investigate eSIM compatibility, installation or activation issues. We do not normally collect precise GPS location through the Website.
5.7 Network and service-usage data — to deliver and support an eSIM, we may receive or process limited information from connectivity providers or mobile network operators, including eSIM provisioning status; activation status; connection time; destination network; technical network identifiers; data-consumption records; remaining allowance; Plan expiry status; fault or error codes; and other information needed to provide, troubleshoot or verify the Service.
5.8 Customer support and communications data — when you contact us, we may collect the content of your request; email correspondence; attachments; screenshots; device information; installation or connection details; complaint information; refund requests; records of troubleshooting; internal support notes; dates and times of communications; and the outcome of the request. You should not send full card details, card security codes, passwords, authentication codes or unnecessary sensitive information to customer support.
5.9 Marketing and preference data — where marketing is used, we may collect marketing consent; date and method of consent; communication preferences; unsubscribe requests; previous marketing interactions; email delivery or opening information where permitted; and records required to honour an objection or unsubscribe request.
5.10 Fraud, security and compliance data — we may collect or generate information concerning suspected unauthorised Account access; unusual payment activity; repeated failed payments; payment risk indicators; device or IP inconsistencies; multiple Accounts; Chargebacks; refund abuse; sanctions screening; prohibited-jurisdiction concerns; breaches of our Terms or Acceptable Use Policy; and investigations, restrictions or Account suspensions.
5.11 Information from cookies and similar technologies — we may use cookies; local storage; session storage; pixels; software development kits; log files; and similar technologies. Further information is provided in the Cookie Policy.
6. Special Category Data
ArvoSim does not normally request or require special category data such as information concerning health; racial or ethnic origin; religion; political opinions; trade-union membership; genetics; biometrics used for identification; or sexual orientation.
Please do not provide such information unless it is genuinely necessary for a specific request.
If you voluntarily provide sensitive information, we will process it only where an appropriate legal basis and any required additional legal condition apply.
7. How We Collect Personal Data
7.1 Directly from you — for example, when you create an Account; update Account information; complete a Wallet Top-Up; place an eSIM Order; request support; submit a refund request; request Account closure; make a complaint; exercise a data protection right; or subscribe to marketing.
7.2 Automatically — we may collect technical and usage data when you visit the Website; sign in; navigate between pages; submit a transaction; interact with emails; use cookies or similar technologies; or encounter a technical error.
7.3 From service providers and business partners — we may receive personal data from payment providers; card issuers and card networks; 3D Secure authentication providers; eSIM and connectivity providers; mobile network operators; hosting and infrastructure providers; email-delivery providers; analytics providers; fraud-prevention providers; and customer support systems.
7.4 From public or official sources — where necessary for legal compliance, security or fraud prevention, we may receive information from Companies House; sanctions lists; regulatory or law-enforcement sources; courts; public records; or other legally available sources.
8. Purposes and Lawful Bases
We process personal data only where we have an appropriate lawful basis. The lawful basis depends on the purpose and context of the processing.
8.1 Providing the Account and Service — to register and maintain your Account, authenticate access, display your Wallet Balance, process eSIM Orders, deliver QR codes, provide installation information, activate or manage eSIM Plans, provide support, process cancellations and refunds, and close Accounts. Lawful basis: performance of a contract or steps taken at your request before entering into a contract.
8.2 Processing Wallet Top-Ups and payments — to process Top-Ups, perform 3D Secure authentication, record Wallet credit, issue receipts, process refunds, investigate payment errors, handle reversals and Chargebacks, and maintain accurate financial records. Lawful bases: performance of a contract, compliance with legal obligations and our legitimate interests in operating secure and accurate payment systems.
8.3 Delivering and managing eSIMs — to issue the correct eSIM Plan, send the QR code, verify delivery, enable provisioning, check activation and usage, troubleshoot connectivity, determine whether an eSIM is unused, investigate faults, and provide replacements or refunds. Lawful bases: performance of a contract and our legitimate interests in providing, supporting and improving the Service.
8.4 Customer support and complaints — to respond to enquiries, troubleshoot issues, investigate complaints, reconsider decisions, keep users informed, provide remedies, and maintain records of the outcome. Lawful bases: performance of a contract, compliance with legal obligations and our legitimate interests in resolving disputes and improving customer service.
8.5 Fraud prevention and security — to detect unauthorised payments, prevent Account takeover, identify suspicious activity, protect users and the Service, investigate abuse, enforce applicable policies, secure systems, and establish, exercise or defend legal claims. Lawful bases: our legitimate interests and compliance with legal obligations where applicable.
8.6 Legal, tax and regulatory compliance — to maintain accounting and tax records, respond to lawful requests, comply with court orders, comply with sanctions and other legal restrictions, meet consumer-protection obligations, investigate legal claims, and demonstrate compliance. Lawful basis: compliance with legal obligations and, where relevant, our legitimate interests in protecting and exercising legal rights.
8.7 Service administration — to send Order confirmations, QR-code delivery emails, Wallet confirmations, security alerts, Plan-related notices, support responses, refund updates, material policy changes and other essential service communications. These are transactional communications and are not direct marketing.
8.8 Website security and performance — to keep the Website operational, detect errors, prevent malicious activity, maintain Account sessions, measure performance, diagnose outages, protect infrastructure, and improve reliability. Lawful bases: our legitimate interests and, where required for non-essential technologies, consent.
8.9 Analytics and improvement — subject to applicable cookie and consent requirements, we may process usage and interaction data to understand how the Website is used, identify navigation problems, measure feature performance, improve the user experience, develop new features, and assess demand for destinations and Plans.
8.10 Direct marketing — we may process contact and preference data to send marketing concerning ArvoSim products, offers or travel connectivity. Lawful bases: consent or, where legally permitted, legitimate interests and the applicable customer soft opt-in rules. You may unsubscribe at any time.
9. When Providing Data Is Required
Certain information is required to create an Account, process a Wallet Top-Up, place an Order or deliver an eSIM.
If you do not provide required information, we may be unable to create or maintain the Account; authenticate access; process payment; credit the Wallet; fulfil an Order; deliver the QR code; investigate a fault; process a refund; or comply with a legal obligation.
Optional information will be identified where practical.
10. Legitimate Interests
Where we rely on legitimate interests, those interests may include operating and improving ArvoSim; protecting Accounts and transactions; preventing fraud and abuse; maintaining accurate Wallet records; securing systems; responding to users; enforcing our Terms; managing business risk; recovering amounts lawfully owed; defending legal claims; preventing duplicate or fraudulent refunds; and understanding Website performance.
Before relying on legitimate interests, we consider whether the processing is necessary; whether a less intrusive method is available; the nature of the data; the user's reasonable expectations; the potential effect on the user; and appropriate safeguards.
You may have the right to object to processing based on legitimate interests.
11. Consent
Where we rely on consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
Consent may be used for non-essential cookies; certain analytics; certain electronic marketing; optional communications; or another use where genuine choice and control are provided.
We do not rely on consent where personal data is objectively necessary to provide a service you requested and another lawful basis is more appropriate.
12. Payments and 3D Secure
Wallet Top-Ups may be subject to payment authentication, including 3D Secure.
During payment processing card details are entered into or transmitted to the payment provider's secure payment environment; the payment provider and card issuer may process authentication and fraud-prevention data; ArvoSim may receive the authentication result, payment status and limited payment metadata; the card issuer may request a one-time password, banking-app approval or biometric confirmation; and a transaction may be delayed or declined where authentication or fraud checks are unsuccessful.
ArvoSim does not control the authentication method chosen by your card issuer. Full card numbers and card security codes are not stored on ArvoSim systems.
13. eSIM Providers and Mobile Networks
To provide an eSIM, we may share necessary information with eSIM provisioning providers; connectivity platforms; roaming partners; mobile network operators; and technical support providers.
The information shared will be limited to what is reasonably necessary to create or allocate the eSIM; provision the selected Plan; confirm activation; measure data consumption; investigate faults; prevent abuse; and provide the purchased connectivity.
A mobile network operator may process network, device and location information independently under applicable telecommunications laws and its own privacy notice.
Depending on the processing activity, an eSIM provider or network operator may act as our processor; a separate controller; or another party with independent legal responsibilities.
14. Cookies and Similar Technologies
We use strictly necessary technologies to operate the Website; keep users signed in; secure Accounts; prevent fraud; maintain Wallet sessions; remember essential selections; and complete transactions.
Subject to consent requirements, we may also use technologies for preferences; analytics; performance measurement; error monitoring; and service improvement.
Non-essential cookies and similar technologies will not be used before valid consent where consent is legally required. You may withdraw or change your cookie preferences through the available consent tool.
Further information is provided in the Cookie Policy.
15. Marketing Communications
We may send marketing emails only where permitted by applicable law. We may rely on your consent; or the customer soft opt-in where we obtained your details during a sale or genuine sales enquiry, market similar products or services, and provided a clear opportunity to opt out.
Every marketing email will provide an unsubscribe method. You may also object by contacting info@arvosim.com.
Unsubscribing from marketing will not prevent us from sending essential communications concerning your Account; Wallet transactions; Orders; eSIM delivery; security; refunds; complaints; or changes affecting the Service.
We may retain limited suppression information after an unsubscribe request so that we do not contact you again for marketing.
16. How We Share Personal Data
We may share personal data with the following categories of recipients:
- Payment providers — for payment processing, 3D Secure authentication, fraud prevention, refunds, reversals, Chargebacks and transaction reconciliation.
- eSIM and connectivity providers — for eSIM provisioning, network access, activation, usage verification, technical support, replacements and fault investigation.
- Hosting and infrastructure providers — for Website hosting, database hosting, cloud storage, content delivery, backups, cybersecurity and system monitoring.
- Communications providers — for transactional email delivery, QR-code delivery, support communications, security notifications and authorised marketing.
- Analytics and error-monitoring providers — where permitted, for Website analytics, error detection, performance monitoring, service improvement and aggregate reporting.
- Professional advisers — lawyers, accountants, auditors, tax advisers, insurers and consultants, where reasonably necessary.
- Authorities and legal recipients — where reasonably necessary to comply with law, respond to a court order, cooperate with a regulator, respond to law enforcement, comply with tax obligations, enforce our Terms, prevent fraud, protect users, or establish, exercise or defend legal claims.
- Business transfers — if ArvoSim or relevant business assets are reorganised, sold, merged or transferred, personal data may be disclosed to potential purchasers, investors, professional advisers and the acquiring organisation, subject to confidentiality and purpose-limitation requirements.
17. Processors
Where a service provider processes personal data on our behalf, we require appropriate contractual protections.
Depending on the circumstances, these may require the processor to act only on documented instructions; maintain confidentiality; implement appropriate security; assist with individual rights; notify us of security incidents; control sub-processors; delete or return data when services end; and demonstrate compliance.
18. No Sale of Personal Data
We do not sell personal data.
We do not provide personal data to unrelated third parties in exchange for payment so that they may independently market their products to you.
We also do not permit eSIM or network providers to use data supplied solely for Order fulfilment for unrelated advertising on our behalf.
19. International Data Transfers
ArvoSim provides international travel connectivity and may use providers located in different countries. Personal data may therefore be transferred to, stored in or accessed from countries outside the United Kingdom.
Before making a restricted international transfer, we will use an appropriate transfer mechanism where required, which may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses;
- another approved safeguard;
- binding corporate rules;
- a legally permitted exception; or
- another mechanism recognised by applicable law.
Where appropriate, we will also assess the legal and practical risks of the transfer; complete a transfer risk assessment; apply contractual protections; limit the information transferred; use encryption or pseudonymisation; restrict access; and apply supplementary safeguards.
You may contact us for further information about the safeguards relevant to your personal data.
20. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.
20.1 Account information is normally retained while the Account remains active. After Account closure, relevant Account data may be retained for a limited period where required for financial reconciliation, fraud prevention, complaint handling, legal claims, enforcement of our Terms or compliance with law.
20.2 Orders, Wallet transactions and payment records may generally be retained for at least six years from the end of the relevant financial year or for another period required by applicable tax, accounting or legal obligations.
20.3 eSIM provisioning and usage records may be retained for as long as reasonably required to provide the Plan, verify usage, resolve technical issues, process refunds, investigate fraud, handle disputes and meet provider or legal requirements.
20.4 Support and complaint records may be retained for a reasonable period after the matter is closed.
20.5 Fraud and security records may be retained where necessary to protect Accounts, prevent repeated abuse, investigate incidents, establish legal claims and meet payment-provider or legal requirements.
20.6 Marketing information is retained until you withdraw consent, unsubscribe, object, the information is no longer accurate, or we no longer have a lawful reason to use it.
20.7 Cookie retention periods are described in the Cookie Policy and consent tool.
20.8 Records of privacy requests and our response may be retained for a reasonable period to demonstrate compliance.
20.9 Deleted information may remain temporarily in secure backups until those backups are overwritten or deleted under the applicable backup schedule.
21. Anonymisation and Aggregation
We may anonymise or aggregate information for analytics; service planning; destination-demand analysis; performance measurement; security research; statistical reporting; and product improvement.
We will take reasonable steps to ensure that anonymised information cannot be used to identify an individual. If information can still reasonably be linked to a person, we will continue to treat it as personal data.
22. Data Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access; accidental loss; misuse; alteration; destruction; unlawful disclosure; and other unlawful processing.
Measures may include encryption in transit; access controls; authentication controls; least-privilege access; password hashing; secure hosting; logging and monitoring; staff confidentiality obligations; provider due diligence; system updates; incident-response procedures; backup controls; and fraud-prevention measures.
No internet-based system can be guaranteed to be completely secure. You are responsible for keeping your password and email Account secure and for notifying us promptly of suspected unauthorised access.
23. Personal Data Breaches
If a personal data breach occurs, we will investigate the incident; take reasonable containment and recovery measures; assess the likely risk to individuals; document the incident; notify relevant service providers where necessary; notify the Information Commissioner's Office where required; and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Any notification may include practical steps that affected users can take to reduce potential harm.
24. Automated Processing and Fraud Screening
We may use automated tools to identify unusual payment activity; assess transaction risk; detect Account abuse; identify multiple Accounts; prevent unauthorised payments; protect the Website; and prioritise transactions for review.
Automated screening may result in additional authentication; a temporary delay; a request for further information; temporary restriction of a transaction; or referral for manual review.
ArvoSim Orders are manually processed. We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects on users without an applicable legal basis and appropriate safeguards.
Where such automated decision-making applies, you may have the right to receive meaningful information about the processing; express your point of view; contest the decision; and request human involvement.
25. Children
The Service is intended for persons aged 18 or over. We do not knowingly permit children to create Accounts or complete Wallet Top-Ups.
If we become aware that personal data has been collected from a child in circumstances where it should not have been collected, we will take appropriate steps to delete or restrict that information.
A parent or guardian who believes that a child has provided personal data may contact info@arvosim.com.
26. Account Closure and Data Deletion
An Account cannot currently be closed through a self-service function. To request Account closure, email info@arvosim.com from the email address associated with the Account.
Before closure, we may need to verify Account ownership; complete or cancel pending Orders; return eligible Wallet funds; resolve disputes; investigate suspected fraud; and retain information required by law.
Account closure does not mean that every record will be immediately deleted. We may retain information where necessary for tax and accounting, payment reconciliation, fraud prevention, Chargeback handling, complaint resolution, legal claims, regulatory compliance or another lawful purpose.
Data that is no longer required will be deleted, anonymised or securely restricted.
27. Your Data Protection Rights
Depending on the circumstances and applicable law, you may have the following rights:
- Right to be informed — to receive clear information about how we process your personal data.
- Right of access — to request confirmation that we process your personal data, a copy of the relevant data, and supplementary information.
- Right to rectification — to ask us to correct inaccurate personal data or complete incomplete information.
- Right to erasure — to request deletion of personal data in certain circumstances (subject to legal exceptions).
- Right to restrict processing — to request that we temporarily restrict use of personal data in certain circumstances.
- Right to data portability — where processing is based on consent or contract and carried out by automated means, to request certain data in a structured, commonly used and machine-readable format.
- Right to object — to object to processing based on legitimate interests.
- Right to object to direct marketing — an absolute right to object to the use of your personal data for direct marketing.
- Right to withdraw consent — where processing is based on consent, to withdraw that consent at any time.
- Rights concerning automated decisions — where applicable, relating to solely automated decisions that produce legal or similarly significant effects.
- Right to complain — directly to ArvoSim and to the Information Commissioner's Office.
28. Exercising Your Rights
To exercise a data protection right, contact info@arvosim.com. Please clearly describe your request and include sufficient information to identify the relevant Account or data.
We may request reasonable proof of identity where necessary to protect personal data against unauthorised disclosure. We will not ordinarily charge a fee.
A reasonable fee may be charged, or a request may be refused, where permitted by law because a request is manifestly unfounded or excessive.
We will respond without undue delay and normally within one calendar month after receiving a valid request. Where permitted by law, the period may be extended for complex or multiple requests, and we will inform you of any extension and the reasons for it.
Some rights are not absolute and may be subject to legal exemptions.
29. Data Protection Complaints
You may raise a complaint if you believe that we used your personal data unfairly or unlawfully; failed to keep it secure; retained it for too long; disclosed it improperly; failed to correct or delete it; failed to respond properly to a rights request; or otherwise failed to comply with data protection law.
Complaints should be sent to info@arvosim.com. Please include your name; the email address associated with your Account; a clear description of the complaint; relevant dates; any Order or transaction reference; copies of relevant correspondence; and the outcome you are seeking.
We will provide a clear method for submitting a complaint; acknowledge receipt within 30 days; take appropriate steps to investigate; request additional information where reasonably necessary; keep you informed about material progress; and communicate the outcome without undue delay.
30. Complaints to the ICO
You have the right to complain to the UK Information Commissioner's Office.
We encourage you to contact us first so that we have an opportunity to investigate and resolve the matter, but you are not required to obtain our permission before contacting the ICO.
The ICO's current contact information is available through its official website.
31. Third-Party Websites and Applications
The Website may contain links to third-party websites; mobile network operators; payment services; device manufacturers; support materials; or applications.
Those third parties process personal data under their own terms and privacy notices. We are not responsible for the privacy practices of independent third parties.
You should review the relevant privacy information before providing personal data to them.
32. Changes to this Policy
We may update this Policy to reflect changes to the Service; new payment or connectivity providers; changes to data-processing activities; security developments; changes to law; regulatory guidance; or changes to our business operations.
The updated version will be published on arvosim.com with a revised "Last updated" date.
Where a change materially affects how we use personal data, we will provide reasonable notice before the new processing begins where required. Continued use of the Service does not replace consent where consent is legally required.
33. Contact Information
Questions, privacy requests and data protection complaints may be directed to ELVORIN LTD, company number 17344051, Dept 6946, 196 High Road, Wood Green, London, United Kingdom, N22 8HH.
Email: info@arvosim.com. Website: arvosim.com.