Privacy Policy - Your Data & Privacy Rights

Last updated: January 2025

01 Overview and Data Controller

This Privacy Policy describes how Abroadmode, operated by Daniel Samer ("we", "us"), collects, uses, shares and protects personal data when you visit our travel connectivity blog.
Abroadmode compares eSIM data plans by destination, breaks down roaming costs, and explains setup. We take part in partner programs run by eSIM providers, handled through affiliate networks such as Impact, which may use tracking technologies to attribute referrals.
We protect your privacy and process your data in line with the applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
Data Controller:
Abroadmode
Operated by Daniel Samer
Am Alefskamp 50
47198 Duisburg
Germany
Email: abroadmode@samer.email
Phone: +49 15225669203
By using the website you confirm that you have read and understood this Privacy Policy.

02 What Data We Collect

We collect personal data from these categories:
Account data:
- Name and username
- Email address
- Password (stored encrypted)
- Profile details you enter yourself
Profile data:
- Profile picture (if uploaded)
- Biography and description
- Settings and preferences
Technical data:
- IP address
- Browser type and version
- Device details
- Operating system
- Time zone and location details
- Cookies and comparable technologies (see the Cookie Policy)
Usage data:
- Pages opened and features used
- Time spent on the website
- Interactions such as clicks, including clicks on referral links
- Source of the visit
Communication data:
- Messages and correspondence with us
- Feedback and support requests
- Answers to surveys
We receive data directly from you, automatically through your use of the website, and in individual cases from third parties (such as social login providers, where used).

03 What We Use Your Data For

We use your personal data for these purposes:
Providing the services:
- Creating and managing your account
- Providing and maintaining our services
- Handling transactions and the messages that go with them
Communication:
- Answering enquiries and support requests
- Sending service-related notices
- Sending marketing messages (only with your consent)
Development:
- Evaluating usage patterns to improve the services
- Building new features
- Analysis and reporting
Security and compliance:
- Protection against fraud and unauthorized access
- Meeting legal obligations
- Enforcing our Terms of Service
Legal bases under the GDPR:
- Contract performance: processing needed for our services
- Consent: processing based on your explicit agreement
- Legitimate interests: processing for our legitimate business interests
- Legal obligation: processing the law requires

04 Sharing Your Data

We do not sell your personal data. Sharing can happen in these cases:
Service providers:
We work with third-party firms that help us run the website, such as:
- Hosting and cloud providers
- Payment services
- Analytics services
- Email service providers
These providers are contractually bound to protect your data and to use it only for the agreed purposes.
Legal reasons:
We may disclose data where needed to:
- Meet legal obligations or valid official orders
- Safeguard our rights, property or safety
- Look into possible breaches of our Terms
- Defend ourselves against legal claims
Corporate events:
In a merger, acquisition or sale of assets, your data can pass to the acquirer. We will inform you about this.
With your consent:
For other purposes we share data only with your explicit consent.

05 How Long We Keep Data

We store personal data only as long as needed for the respective purposes:
Active accounts:
- Account data stays stored while the account exists
- You can request deletion at any time
After account deletion:
- The bulk of the data is deleted within 30 days
- Individual data we keep longer for legal reasons (such as transaction records for tax purposes)
- Anonymized data may be kept for analysis
Concrete periods:
- Account data: lifetime of the account plus 30 days
- Transaction records: 10 years (legal obligation)
- Support correspondence: 3 years
- Server logs: 90 days
We review our retention practice at regular intervals so data is not stored longer than needed.

06 Your GDPR Rights

The General Data Protection Regulation (GDPR) gives you these rights:
1. Access: You can request a copy of your personal data and details about its processing.
2. Rectification: You can have inaccurate or incomplete data corrected.
3. Erasure ("right to be forgotten"): Under certain conditions you can request the deletion of your data.
4. Restriction of processing: You can require us to limit how we use your data.
5. Data portability: On request you receive your data in a structured, common, machine-readable format.
6. Objection: You can object to processing based on legitimate interests or for direct marketing.
7. Withdrawing consent: Where processing rests on consent, you can withdraw it at any time.
8. Complaint: You can lodge a complaint with a supervisory authority if you suspect a violation of your rights.
To exercise these rights, write to abroadmode@samer.email. We answer within 30 days.
Supervisory authority:
The competent authority is the data protection supervisory authority of the German federal state where the operator is established. A directory of all German supervisory authorities is kept by the Federal Commissioner for Data Protection and Freedom of Information: https://www.bfdi.bund.de

07 Cookies and Tracking

To improve your visit we use cookies and comparable technologies. Details on the individual cookies and how to manage them are in our Cookie Policy.
Cookie types:
- Necessary cookies: The website does not work without them
- Analytics cookies: Show us how visitors use the website
You control cookies via:
- Our consent banner
- Your browser settings
- The cookie settings page

08 Protecting Your Data

To protect your personal data we apply appropriate technical and organizational safeguards, including:
Technical:
- Encrypted transmission (TLS/SSL)
- Encryption of sensitive data at rest
- Secure password hashing
- Ongoing security updates and patches
- Firewalls and intrusion detection
Organizational:
- Access to personal data only on a need-to-know basis
- Recurring security training
- Procedures for handling incidents
- Recurring security reviews
No transmission path on the internet is fully secure. We cannot promise absolute security, but we take all reasonable steps to protect your data.
If you suspect a security breach, please contact us straight away.

09 Minors

Our website is not aimed at children under 18. We do not knowingly collect personal data from anyone under 18.
If you are a parent or guardian and suspect your child has sent us data, please get in touch right away. We will delete such data from our systems.
If we discover ourselves that we hold data of a person under 18, we delete it as quickly as possible.

10 Transfers to Third Countries

Your data is processed predominantly within the European Union. For transfers outside the EU or EEA we put suitable safeguards in place:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions of the European Commission
- Other legally recognized transfer instruments
By using the website you acknowledge that your data can be transferred to, stored in and processed in countries outside your country of residence.

11 Updating This Policy

We adjust this Privacy Policy when needed, for instance because of changed procedures or for legal, operational or regulatory reasons.
When we adjust it:
- We update the "Last updated" date above
- For material adjustments we point them out clearly (such as by email or banner)
Read this policy again from time to time to stay informed about how we handle your data.
Continuing to use the website after adjustments take effect counts as acceptance of the new version.

12 Privacy Questions

For questions about this Privacy Policy or our handling of data, you can reach us here:
Daniel Samer
Am Alefskamp 50
47198 Duisburg
Germany
Email: abroadmode@samer.email
Phone: +49 15225669203
For GDPR matters you can additionally contact the competent supervisory authority. The competent authority is the data protection supervisory authority of the German federal state where the operator is established; a directory of all German supervisory authorities is kept by the Federal Commissioner for Data Protection and Freedom of Information at https://www.bfdi.bund.de

Last updated: January 2025