We use cookies to understand how you use our site. You can accept or decline non-essential analytics.
Zetexa carries traveller identity, payment and network traffic across 180+ countries. This page documents exactly how that is protected — the certifications we hold, the controls behind them, who processes your data, and what happens when something goes wrong.
Zetexa Global Private Limited is a registered MVNO delivering local connectivity in Canada, the UK and the USA, and operates under telecom authorisations in each market it serves.
An eSIM is a credential. It authenticates you onto a stranger's network in a country whose laws you have not read. That asymmetry is why we treat provisioning security, data minimisation and regulatory standing as product features rather than paperwork.
We ask for what a purchase and a provisioning event genuinely need. No passport uploads to buy a data plan, no silent profiling to sell you a second one.
Zetexa is a registered MVNO in Canada, the UK and the USA, and works only with licensed host operators elsewhere. Regulatory standing is part of the product.
An eSIM profile is a cryptographic credential. Ours is encrypted for a single eUICC, redeemable once, and killable from support the moment a phone goes missing.
Every claim on this page names the artefact behind it. If a report is confidential we say so; if we are not certified against a standard, we do not print its logo.
Each entry names the standard, what it actually covers at Zetexa, and how you can verify it. Where a report is confidential we say so instead of implying otherwise.
Card capture, storage and settlement are handled by PCI DSS certified payment providers. No primary account number or CVV is stored on Zetexa infrastructure, keeping our cardholder-data environment minimal by architecture.
Our control set is mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality. The report is shared with enterprise customers and partners rather than published.
Lawful bases are documented per purpose, transfers rely on Standard Contractual Clauses, and data subject rights are handled within 30 days. A Data Processing Addendum is available for business customers.
California residents can access, delete, correct and port their data, and opt out of the sharing of personal information for cross-context behavioural advertising. We do not sell personal data.
As an Indian-incorporated data fiduciary, Zetexa provides notice and consent for the processing it performs, honours correction and erasure requests, and maintains a grievance channel at support@zetsim.com.
Consumer eSIM provisioning runs on GSMA-accredited SM-DP+ platforms using the GSMA certificate hierarchy for mutual authentication between device and server.
US local connectivity is delivered as a registered mobile virtual network operator over licensed host networks, subject to FCC rules on consumer disclosure and network use.
Canadian local plans are offered as a registered telecommunications service provider, delivered over licensed Canadian host networks under CRTC obligations.
Indian operations are conducted under Department of Telecommunications authorisation, including the subscriber and lawful-access obligations that apply to services offered in India.
Open any control to read what it does and what evidence sits behind it. Search to jump straight to a topic — encryption, retention, provisioning, access reviews.
Security is owned, written down and reviewed on a schedule — not improvised per incident.
We collect the minimum needed to sell, provision and support an eSIM — and we do not sell traveller data.
Card data does not live on Zetexa systems. It is captured, tokenised and settled by certified providers.
Provisioning follows the GSMA Remote SIM Provisioning architecture. Every profile is bound to one device.
Standard, boring, well-understood protections applied consistently across every environment.
Fewest people, least privilege, shortest time — with a record of who did what.
Changes are reviewed, dependencies are watched, and outsiders are invited to look.
Severity is set by customer impact. A traveller who cannot get data is an incident.
Zetexa Global Private Limited is the data controller. We collect the minimum needed to sell you an eSIM, provision it and support it — and we do not sell traveller data.
eSIM delivery is the part of our service most people never see. It runs on the GSMA Remote SIM Provisioning architecture, and every step is cryptographically bound to one device.
When you buy, our provisioning partner prepares a profile on a GSMA-accredited SM-DP+ platform and issues an activation code tied to it. The credential itself never travels in your email — only the pointer to it does.
On download, the eUICC in your phone and the provisioning server authenticate each other through the GSMA certificate hierarchy. The profile is then encrypted specifically for that chip, so it cannot be installed anywhere else.
Once the profile lands, the activation code and matching ID are spent. A shared screenshot provisions nothing. If the handset is lost, support disables the profile so the remaining data cannot be used.
Severity is assigned on customer impact, not on internal convenience. A traveller who cannot get data is an incident, not a ticket.
Monitoring, partner alerts or a customer report opens an incident. Anyone at Zetexa can raise one; nobody needs permission to escalate.
An incident lead is assigned and severity is set on customer impact — provisioning failures and data exposure outrank internal inconvenience.
Access is cut, credentials rotated and affected paths isolated. Preserving evidence runs in parallel with stopping the bleeding.
Confirmed personal data breaches go to the supervisory authority without undue delay and within 72 hours where GDPR applies, and to affected individuals when the risk requires it.
A blameless review produces a timeline, contributing factors and corrective actions with named owners and due dates, tracked alongside product work.
Every third party below is contracted, assessed before onboarding and limited to the purpose stated. The current authoritative register is available on request.
Public documents are one click away. Confidential material — audit reports, penetration test summaries, the live subprocessor register — is released under NDA to customers and partners.
We do not sell personal data. We do use marketing and advertising partners to run campaigns, and where you live may give you the right to tell us not to share your information for targeted advertising — email support@zetsim.com and we will apply that preference.
Customer and order data sits with our commerce and support providers in their operating regions, protected by contractual transfer safeguards. Network traffic is carried in the destination country by the licensed local operator, which is what makes a local plan local. The subprocessor table above names each party and its region.
A profile is cryptographically bound to the single eUICC that downloaded it, and the activation code is single-use. Once installed, a copy of the QR is useless. If your device is lost, contact support and we disable the profile.
No. Card data is captured and stored by PCI DSS certified payment providers. Zetexa sees a token, the last four digits and the transaction result — never the full card number or CVV.
SOC 2 is the framework our control set is mapped to, and the report is shared with customers and partners under NDA rather than published. Where we are not certified against a standard we say so on this page instead of displaying a badge.
Email support@zetsim.com with your company, the document you need and any deadline. Standard requests — DPA, security overview, subprocessor register, insurance summary — are usually turned around within five business days.
Your account data is deleted or de-identified on verified request. Transaction, invoice and tax records are kept for the period the law requires in the relevant jurisdiction, then removed on the normal retention cycle.
Report a suspected vulnerability to support@zetsim.com with SECURITY in the subject line. We acknowledge reports, keep you updated while we investigate, and will not pursue good-faith researchers who avoid privacy violations, service disruption and data destruction.