● Brisily
DestinationsFor travel agenciesAPI docsPartner sign inBecome a partner
☰
DestinationsFor travel agenciesAPI docsPartner sign in

Privacy Policy

Last updated: 2026-07-11

This policy explains how Zenetlabs, operating the Brisily service ("Brisily", "we"), processes personal data as controller under the EU General Data Protection Regulation (GDPR) when you use brisily.com, a partner storefront we power, or buy an eSIM from us. Privacy contact: privacy@brisily.com.

1. Data we process

  • Order data: name, email address, phone number, destination, plan, order history.
  • Payment data: processed by Stripe; we receive payment status and a payment reference, never your full card number.
  • eSIM/technical fulfilment data: ICCID, activation status and data-usage totals from our connectivity provider.
  • Attribution data: which partner storefront referred you (a first-party cookie, see the Cookie Policy).
  • Support communications you send us.
  • Website analytics (Google Analytics 4) — only with your consent.
  • Error and performance diagnostics (Sentry) — technical logs that may include IP address and device metadata.

2. Purposes and legal bases (Art. 6 GDPR)

PurposeLegal basis
Selling and delivering your eSIM, sending order emailsContract (Art. 6(1)(b))
Payment processing and fraud preventionContract + legitimate interest (Art. 6(1)(b), (f))
Attributing sales to the travel agency that referred youLegitimate interest (Art. 6(1)(f))
Customer support and order recoveryContract (Art. 6(1)(b))
Tax, accounting and legal obligationsLegal obligation (Art. 6(1)(c))
AnalyticsConsent (Art. 6(1)(a)); withdraw anytime via cookie settings
Service security, error monitoringLegitimate interest (Art. 6(1)(f))

3. Processors and recipients

We share data only with providers needed to run the service, under data-processing agreements:

  • Stripe (payments)
  • Airalo (eSIM provisioning — receives the technical order, not your name)
  • Resend (transactional email delivery)
  • Cloudflare (hosting/CDN), Xata (database hosting, EU region)
  • Sentry (error monitoring, EU region), Google (analytics, with consent)
  • The travel-agency partner whose storefront you bought through (order status for customer care; they never receive your payment details).

4. International transfers

Some providers process data outside the EEA (e.g. USA). Such transfers rely on European Commission adequacy decisions (including the EU–US Data Privacy Framework) or Standard Contractual Clauses.

5. Retention

  • Order and invoice data: as long as Spanish tax and commercial law requires (up to 6 years).
  • Support emails: up to 2 years after the case closes.
  • Analytics: per Google Analytics retention settings (14 months).
  • Attribution cookie: 90 days.

6. Your rights

You have the rights of access, rectification, erasure, restriction, portability, and objection (Arts. 15–21 GDPR), and to withdraw consent at any time without affecting prior processing. To exercise them, write to privacy@brisily.com. You may also complain to the Spanish supervisory authority, the AEPD (www.aepd.es), or to your local supervisory authority.

7. Children

Our services are not directed at children under 16 and we do not knowingly process their data.

8. Changes

We will post any changes to this policy here with a new "last updated" date.

● Brisily

Travel eSIMs for 200+ destinations — built with the travel agencies that take care of your trip.

Product

DestinationsFind your orderAPI docs

Partners

For travel agenciesPartner sign inBecome a partner

Legal

Terms & ConditionsPrivacy PolicyCookie Policy
© 2026 Brisily