Eydost eSIM Privacy Policy
This policy explains how Nurtel Elektrik MMC ("Eydost eSIM", "we", "us") collects, uses, discloses, and retains personal data when you use the Eydost eSIM app in ChatGPT or our related eSIM ordering and support services.
1. Who controls your data and how to contact us
Nurtel Elektrik MMC is the controller of the personal data described in this policy. For privacy questions or to exercise a privacy right, email info@eydost.com. Include enough information for us to identify the relevant ChatGPT app interaction or order. We may ask you to verify your identity before fulfilling a request.
2. Scope and the role of OpenAI
When you invoke Eydost eSIM in ChatGPT, ChatGPT sends the information needed for the selected tool to our MCP server and displays the result returned by us. OpenAI separately processes your ChatGPT account, conversation, device, and app-interaction data under OpenAI's own terms and privacy policy. Your ChatGPT privacy settings, retention, training choices, and deletion controls are managed by OpenAI and do not automatically delete records that Eydost must keep for an order or legal obligation. You can disconnect the app in ChatGPT settings at any time.
3. Data we collect
- ChatGPT app identity and context: a privacy-preserving identifier derived from the ChatGPT subject or session value, session ID, language/locale, and source channel. We hash the ChatGPT identifier before using it as the customer identifier in our backend.
- Messages and support content: messages you submit to the assistant, inferred intent, selected actions, assistant responses, prompts and responses used with our AI provider, and related diagnostic metadata.
- Package and order data: destination/country, package code and slug, plan type, duration, referral code, order and transaction IDs, order status, price, currency, discounts, and fulfillment status.
- Optional contact and checkout data: name, email address, phone number, and language when you provide them to create a payment checkout or obtain support.
- Payment records: checkout identifier and URL, amount, currency, provider status, transaction references, and payment-provider request/response records. Payment-card numbers, CVVs, and card credentials are entered directly with the payment provider and are not collected or stored by Eydost eSIM.
- eSIM and usage data: ICCID, provider transaction number, QR-code or installation URL, activation code, SM-DP+ address, APN, PIN/PUK where supplied, activation status, plan allowance, data used and remaining, and expiry time.
- Technical and security data: request timestamps, IP address and HTTP/server logs that may be processed by our hosting and security infrastructure, error records, fraud/abuse signals, and redacted operational logs.
Please do not place sensitive information in free-text messages unless it is necessary for the service.
4. ChatGPT MCP tools: inputs, outputs, and uses
| Tool | Inputs we receive | Outputs returned to ChatGPT | Why we use the data |
|---|---|---|---|
assistant_message | Message, optional session ID and language; pseudonymous ChatGPT identity and locale | Assistant answer, session ID, inferred intent, action results and suggested actions | Answer questions, recommend packages, provide support, and maintain conversation context |
list_packages | Country/region code and optional package filters | Package names/codes, plan attributes, availability and sale prices | Search and compare available eSIM plans |
create_order | Country, package identifiers, plan type/duration, optional referral code, name and language; pseudonymous ChatGPT identity | Order ID/status, selected package, price, currency, discount and transaction reference | Create and administer the requested order, prevent fraud, and support fulfillment |
list_my_orders / get_order | Pseudonymous ChatGPT identity and, for a single order, order ID | Orders owned by that identity, including status, package and price details | Show and support the user's own orders |
start_payment | Order ID and optional name, email, phone and language | Payment session identifier, checkout URL and status | Create or retrieve a secure hosted checkout with our payment provider |
list_my_esims / get_order_esim | Pseudonymous ChatGPT identity and, where applicable, order ID | Owned eSIM records and installation credentials such as QR/activation details | Deliver and manage purchased eSIMs |
get_usage | Internal eSIM ID and pseudonymous ownership identity | Allowance, usage, remaining data, status and expiry | Provide plan-usage information |
list_topups | Internal eSIM ID and pseudonymous ownership identity | Compatible top-up packages and prices | Show top-ups available for the user's eSIM |
create_topup_order | Internal eSIM ID, package code and pseudonymous ownership identity | Top-up order ID, status, price and related order information | Create, administer and fulfill a requested top-up |
5. How and why we use data
- Provide package search, recommendations, orders, checkout, eSIM delivery, usage and top-up functions.
- Authenticate ownership and prevent one ChatGPT user from viewing another user's orders or eSIM credentials.
- Process payments, fulfill purchases, provide customer support, and communicate service messages.
- Maintain service reliability, troubleshoot errors, secure the service, prevent abuse and fraud, and keep appropriate audit records.
- Meet accounting, tax, consumer-protection, sanctions, legal-process and other applicable obligations.
Where applicable, our legal bases include performing a contract or taking steps at your request; complying with legal obligations; our legitimate interests in operating, securing, supporting and improving the service; and consent where the law requires it. We do not use ChatGPT app data for targeted advertising and do not sell personal data.
6. Who receives data
- OpenAI: receives tool outputs so ChatGPT can display them and processes your ChatGPT interaction under OpenAI's policies.
- Google Gemini: may receive assistant messages, conversation context and relevant service data needed to generate an answer or classify a request. We do not intentionally send payment-card credentials.
- eSIM Access: receives package/order references, provider transaction references, plan information, and eSIM identifiers required to search, provision, top up and report usage.
- United Payment: receives order reference, amount, currency, language and any optional name, email or phone you provide to create and verify hosted checkout. United Payment—not Eydost—collects your card details.
- Infrastructure and professional service providers: hosting, database, cache, networking, security, logging, customer support, accounting and legal providers process data only as needed to provide their services to us.
- Authorities or transaction parties: we may disclose information where required by law, to protect rights and safety, investigate fraud, enforce agreements, or complete a corporate transaction subject to appropriate safeguards.
If you separately use Eydost through WhatsApp or Telegram, Meta or Telegram will process those communications under their own policies. ChatGPT app activity is not automatically sent to those channels merely because those integrations also exist.
7. Retention
- Conversation and assistant logs: retained for up to 180 days, then message text, AI prompts/responses and logged payload content are deleted or irreversibly redacted. A minimal deletion/audit record may remain where needed to demonstrate compliance and prevent abuse.
- Uncompleted orders and checkout sessions: retained while needed to complete, troubleshoot or secure the transaction, and then deleted or de-identified when no longer reasonably necessary, unless a longer period is required for disputes, fraud prevention or law.
- Completed orders, payments, invoices and fulfillment records: normally retained for up to seven years after the transaction to meet accounting, tax, warranty, dispute, fraud-prevention and legal obligations.
- eSIM installation and usage records: retained while the eSIM is active and afterward with the related transaction record where needed for delivery, support, disputes and legal obligations. We restrict access because installation credentials can be sensitive.
- Security logs: retained for the period reasonably necessary to detect, investigate and prevent security incidents and abuse, normally no longer than 12 months unless an incident or legal obligation requires longer.
When a retention period expires, we delete, redact, de-identify or securely isolate the data, subject to backups and legal holds.
8. Your choices and rights
- Choose not to provide optional name, email or phone information unless checkout or support requires it.
- Disconnect Eydost eSIM through ChatGPT's app settings to stop future tool access.
- Ask us to access, export, correct or delete your Eydost data; restrict or object to certain processing; or withdraw consent where processing relies on consent.
- Complain to your applicable data-protection authority.
Send requests to info@eydost.com. State that the request concerns the Eydost eSIM ChatGPT app and provide the relevant order ID or pseudonymous account details if available. Rights are not absolute: we may retain transaction information required by law or needed to establish, exercise or defend legal claims. To manage data held by OpenAI in your ChatGPT account, use OpenAI's own privacy and account controls.
9. International processing
Our providers may process data in countries other than your own. Where required, we use contracts and other safeguards intended to protect data transferred internationally. Contact us for more information about safeguards relevant to your data.
10. Security
We use access controls, transport encryption, secret redaction, ownership checks, restricted admin access, logging and other organizational and technical safeguards. No system is completely secure; protect eSIM QR codes and activation credentials as you would other account credentials.
11. Children
The service is not directed to children under 13, and we do not knowingly collect their personal data. Contact us if you believe a child has provided data.
12. Automated assistance
AI may classify requests and recommend packages, but users choose whether to create an order or proceed to payment. We do not use the app to make decisions producing legal or similarly significant effects solely by automated means.
13. Changes to this policy
We may update this policy when our tools, providers or legal obligations change. We will publish the revised policy here with a new effective date and provide additional notice where required.