Privacy Policy
Effective Date: April 9, 2025
Last Updated: April 9, 2025
Conekt.ai, Inc. (“Company”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, and protect personal data in connection with our enterprise software and cellular connectivity services. It applies in accordance with the General Data Protection Regulation (GDPR) and ISO/IEC 27001:2022.
1. Who We Are
We provide enterprise software platforms and cellular data management tools (including SIM/eSIM provisioning, usage monitoring, and billing) to businesses. These services are delivered via a secure, web-based portal.
Conekt.ai, Inc. acts as:
• A Data Controller for information about our enterprise clients and users of our portal (e.g., account admins, billing contacts).
• A Data Processor for end-user data (e.g., SIM assignments, device identifiers, network traffic metadata) processed on behalf of our enterprise clients under a Data Processing Agreement (DPA).
2. What This Policy Covers
This policy covers:
• Visitors to our website
• Enterprise customers using our platform and portal
• Information processed on behalf of enterprise clients as part of service delivery
It does not cover personal data collected independently by our clients using our platform — they remain responsible as data controllers of that data.
3. What Data We Collect
Category
Examples
Controller or Processor
Client Contact Data
Name, email, company, phone number
Controller
Portal Account Data
Username, access logs, IP addresses, permissions
Controller
Billing Data
Payment history, invoicing, tax ID
Controller
Connectivity Data
SIM/eSIM identifiers, device IMEI, data usage
Processor
End-User Metadata
Assigned phone numbers, usage logs, timestamps
Processor
We do not intentionally collect special category data (e.g., health, biometric).
4. Legal Bases for Processing (GDPR)
We process personal data under the following lawful bases:
• Contractual necessity – Managing accounts, delivering services
• Legitimate interest – Fraud prevention, service improvement
• Legal obligation – Telecom/data retention regulations
• Consent – For optional communications or cookie usage
For data processed on behalf of clients, we rely on their legal basis and act as their processor.
5. How We Use Personal Data
We use personal data to:
• Create and manage enterprise customer accounts
• Provision and monitor cellular connectivity
• Authenticate users and authorize access
• Provide technical and billing support
• Analyze service usage trends (aggregated and anonymized)
We process end-user data strictly under clients’ instructions and do not use it for our own purposes.
6. Subprocessors and Third Parties
To deliver our services, we engage subprocessors under GDPR-compliant agreements. These may include:
• Cloud infrastructure providers (e.g., AWS, Azure)
• Telecom connectivity partners
• Payment processors
• Email and support platforms
A full list of current subprocessors is available upon request or in your Data Processing Agreement.
7. International Data Transfers
If we transfer data outside the EEA or UK, we use appropriate safeguards such as:
• Standard Contractual Clauses (SCCs)
• Transfers to countries with adequacy decisions
• Additional technical and organizational measures
8. Security Measures (ISO/IEC 27001:2022)
We maintain an ISO/IEC 27001-certified Information Security Management System (ISMS) that includes:
• Encryption in transit and at rest
• Role-based access control (RBAC)
• Multi-factor authentication
• Security incident response plans
• Annual audits and penetration testing
9. Data Retention
We retain:
• Enterprise account data for the duration of the business relationship plus 3 years for legal compliance
• End-user connectivity logs in accordance with applicable telecom/data retention laws or client instructions
After the retention period, data is securely deleted or anonymized.
10. Data Subject Rights (GDPR)
If you are a user or contact of our platform (Controller relationship), you may:
• Access or update your data
• Request deletion or restriction
• Object to processing
• Request data portability
• Withdraw consent at any time
If you are an end-user of a client organization, please contact your organization (data controller) to exercise your rights.
11. Cookies and Analytics
We use:
• Essential cookies – For authentication and portal functionality
• Optional analytics cookies – Only with user consent (when applicable)
Full details are in our Cookie Policy.
12. Changes to This Policy
We may revise this policy to reflect legal or service changes. You’ll be notified of material changes via the portal or email.
13. Contact Information
Data Protection Officer (DPO)
Conekt.ai, Inc.
3830 Valley Centre Dr. STE 705402, San Diego, CA 92130
Phone: (888) 799-9666
You also have the right to file a complaint with your local Data Protection Authority.