Data Privacy Information for T-Travel – Global eSIM Data Service

The protection of your personal data has a high priority for the Hrvatski Telekom d.d. It is important for us to inform you about what personal data is collected, how it is used and what options do you have in this regard.

1. Purpose of this Privacy Notice

This Privacy Notice explains how Hrvatski Telekom d.d. (“HT”, “we”, “us” or “our”) processes personal data in connection with the T-Travel global eSIM mobile data service (“Service”).

This Privacy Notice supplements the general HT privacy policy and applies to processing activities specific to the Service. Privacy Notice does not expand the scope of any processing beyond what is permitted under the general HT privacy policy.

2. Who is the controller?

The controller for the processing of personal data related to the Service is:

Hrvatski Telekom d.d.
Radnička cesta 21
10000 Zagreb
Croatia

3. What data is collected, how it is used, and how long is it stored?

Categories of personal data

Depending on how the User purchases, activates and uses the Service, we may process the following categories of personal data:

Purposes for data processing

Purchase and contract handling: We process data to enable Users to purchase the Service, receive order confirmation, receive the eSIM Profile and access the purchased Data Package.

eSIM provisioning and service delivery: We process data to provision the eSIM Profile, activate the Service, enable mobile data connectivity, apply package coverage and validity rules, measure data usage and provide access to HT and/or partner mobile networks.

Package management and usage metering: We process data to calculate data usage, apply package priority rules, display remaining allowance and validity, apply Unlimited Package speed management and send or display service-related notifications.

Customer support and complaints: We process data to respond to support requests, troubleshoot technical issues, handle complaints, process refund or withdrawal requests where applicable and communicate with the User about the Service.

Payments and accounting: We process purchase, payment status and billing-related data to support payment processing, order fulfilment, accounting, tax compliance, refunds and chargeback handling. Payment processing may be performed by authorised third-party payment service providers.

Fraud prevention, misuse prevention and network security: We process data to prevent, detect and respond to fraud, payment abuse, misuse of promotional codes, prohibited use, security incidents, network attacks, non-intended use of the Service or other activities that may harm the Service, HT, partner networks, other users or third parties.

Legal and regulatory compliance: We process data where necessary to comply with applicable legal, regulatory, accounting, tax, electronic communications, consumer protection, dispute resolution or authority request obligations.

Promotions and campaign discount: Where promotional codes or campaign discounts are used, we process data necessary to determine eligibility, apply discounts, prevent misuse and administer the relevant campaign.

What are the legal bases for processing?

Depending on the processing activity, the legal basis may be:

Where processing is based on consent, the User may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7 para. 3 GDPR).

Data necessary for providing Service

Providing the email address and country of residence is a contractual requirement necessary for the conclusion of the contract and the provision of the Service. If the User does not wish to provide such data, HT will not be able to enter into the contract for the Service or perform related actions.

Registration – eSIM profile

Registering a User account – eSIM profile, including setting a password, is possible for Users who wish to do so, but is not necessary for the provision of the Service or the conclusion of the contract. Providing a name is voluntary and is not a condition for using the Service.

How long to we keep your data?

We keep personal data only for as long as necessary for the purposes for which it was collected, including service provision, customer support, accounting, legal compliance, dispute resolution, fraud prevention and security.

Retention periods may differ depending on the category of data and applicable legal requirements. For example:

Specific retention periods are defined in accordance with HT’s internal retention rules. taking into account statutory retention requirements under applicable law, including data retention obligations under the applicable law (e.g. Croatian Electronic Communications Act). Once the applicable retention period expires, personal data is deleted or anonymized.

4. Where can I find the information important to me?

This privacy notice provides an overview of the points that apply to HT’s processing of your data in this Service. Further information, including on data privacy in general, is available at https://www.hrvatskitelekom.hr/sigurnost-i-zastita-podataka/privole-i-gdpr

5. Who do I contact if I have questions about the privacy policy at HT?

If you have any questions, please contact our Customer Service or our data privacy officer: osobni.podaci@t.ht.hr

6. What rights do I have?

You have the right to:

  1. to request information on the categories of data processed, the purpose of processing, any recipients of the data, or the planned storage period (Art. 15 GDPR)

  2. to demand the correction or completion of incorrect or incomplete data (Art. 16 GDPR)

  3. to revoke given consent at any time with the effect for the future (Art. 7 para. 3 GDPR)

  4. to object to data processing that is to be carried out on the basis of a legitimate interest, for reasons arising from your particular situation (Art. 21 para 1 GDPR)

  5. in certain cases, within the framework of Art. 17 GDPR, to demand the deletion of data – in particular, insofar as the data are no longer required for the intended purpose or are processed unlawfully, or you have revoked your consent in accordance with c) above or declared an objection in accordance with d) above

  6. under certain conditions, to demand the restriction of data processing, insofar as deletion is not possible or the obligation to delete is disputed (Art. 18 GDPR)

  7. to data portability, i.e. you can receive your data that you have provided to us in a conventional machine-readable format, such as CSV, and transmit it to others if necessary (Art. 20 GDPR)

  8. to lodge a complaint with the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka, AZOP)

7. Who may receive personal data?

Personal data may be shared with or processed by the following categories of recipients where necessary:

We only share personal data where there is an appropriate legal basis and where it is necessary for the relevant purpose.

8. Where will my data be processed?

Your data will be processed in Croatia and other European countries. If data processing takes place in third countries, this will take place insofar as you have expressly consented to this or if it is necessary for our provision of services to you or if it is provided for by law (Art. 49 GDPR). Your data will only be processed in third countries if certain measures are taken to ensure that an adequate level of data protection is in place (e.g. adequacy decision of the EU Commission or so-called suitable safeguards, Art. 46 et seq. GDPR).

9. Automated decision making and profiling

There is no automated decision-making within the meaning of Art. 22 GDPR.

10. Biometric authentication for app login

You may choose to log into the App using biometric authentication features provided by your device (such as Apple Touch ID/Face ID or Android Fingerprint/Face Unlock). Biometric authentication is managed entirely by your device’s operating system. We do not collect, access, process or store your biometric data on our server. Our App only receives confirmation from your device as to whether the authentication was successful.

11. Changes to this Privacy Notice

HT regularly reviews this Privacy Notice and reserves the right to amend it from time to time. The purpose of such amendments is not to reduce your rights, but solely to ensure that this Privacy Notice remains complaint with the applicable legal framework governing the protection of personal data.

Any amendments to this Privacy Notice will be published here in a timely manner and will take effect on the date of publication. However, if any amendment involves a change in the purpose of the data processing, a change in the identity of the data controller, or a change in the way data subject may exercise their rights in relation to data processing, we will inform you in advance by email or through another appropriate means.

Status of Privacy Notice 01.08.2026