Security Certified

Privacy Policy

Last updated: June 01, 2026

1. Data Controller & Data Protection Officer

The data controller for all personal data processed through the Viberest B2B Partner Portal is LLC Vaperi, a Limited Liability Company registered in Georgia (Identification Code: 433102484), with registered address at Tsminda Dedopali Ketevan Ave, 0144 Tbilisi, Georgia. German VAT ID: DE338190653. Our designated Data Protection Officer (DPO) is Ilia Tskhvediani, reachable at info@llc-vaperi.de for all data privacy inquiries, GDPR rights requests, and legal correspondence. For general support, partners may contact info@viberest.com.

2. Data We Collect

We collect the following categories of data from B2B partner accounts: (a) Registration data — full name, business email address, company name, and operational country; (b) Billing metadata — payout method details (IBAN, PayPal email, USDT wallet address), deposit history, commission ledger entries, and transaction timestamps; (c) eSIM telemetry — technical activation parameters such as mobile network MNC/MCC codes, eSIM profile generation timestamps, and bandwidth capacity identifiers required for profile provisioning; (d) Security and session data — hashed authentication credentials, OTP verification logs, OAuth tokens (Google), and active session identifiers. Plain-text passwords are never stored. All authentication credentials are irreversibly hashed using industry-standard algorithms.

3. eSIM & End-User Privacy

When partners trigger eSIM profile generation via the wholesale portal or API webhooks, Viberest processes only the minimal technical parameters required for profile configuration. We do not collect, store, or analyze the actual browsing traffic, private data payloads, or personal credentials of your retail end-users. eSIM activation logs contain only technical provisioning metadata (activation timestamp, operator code, data capacity) and are used exclusively for quality assurance and network troubleshooting. LLC Vaperi does not profile, monetize, or share end-user behavioral data. Partners remain independently responsible for their own privacy obligations toward their retail customers under applicable local laws.

4. Data Retention Periods

We retain personal data only as long as necessary for the purposes stated in this policy or as required by law: (a) Partner account data — retained for 5 years following account closure or termination; (b) Transaction and ledger logs — retained for 7 years to comply with tax and financial record-keeping obligations under Georgian and EU law; (c) Session tokens and authentication logs — retained for 30 days, automatically purged upon expiry; (d) eSIM telemetry and activation logs — aggregated and anonymized after 90 days; (e) Support correspondence — retained for 3 years. Upon verified deletion request, personal identifiers are purged within 30 business days, subject to mandatory retention obligations.

5. Third-Party Data Processors

LLC Vaperi shares partner data only with trusted third-party processors under binding Data Processing Agreements (DPAs): Stripe Inc. (payment checkout processing, PCI-DSS Level 1 certified); Wise Payments Limited (international payout disbursements); Amazon Web Services (AWS) (encrypted cloud hosting and database infrastructure); MongoDB Atlas (encrypted database storage); Google Analytics (anonymous platform usage telemetry — no personal identifiers transmitted); Tawk.to Inc. (partner support chat widget). We do not sell, rent, or disclose partner contact information or lead data to third-party marketers, telemarketers, or data brokers.

6. International Data Transfers

As an internationally operating platform, some partner data may be transferred to and processed in countries outside the European Economic Area (EEA), including Georgia and the United States. All such international transfers are conducted in strict compliance with GDPR Chapter V, including the use of Standard Contractual Clauses (SCCs) approved by the European Commission where applicable. Data stored on AWS infrastructure is subject to AWS's EU GDPR compliance framework and SOC 2 Type II certification. Partners in the EU/EEA retain full rights under GDPR regardless of where data is physically processed.

7. Your Rights Under GDPR

Depending on your jurisdiction, you hold the following rights regarding your personal data: Right of Access (Art. 15 GDPR) — obtain a copy of all data we hold about you; Right to Rectification (Art. 16) — correct inaccurate data; Right to Erasure (Art. 17) — request deletion of your data, subject to retention obligations; Right to Data Portability (Art. 20) — receive your data in a structured, machine-readable format; Right to Object (Art. 21) — object to processing based on legitimate interests; Right to Restriction (Art. 18) — limit how we use your data during a dispute. To exercise any of these rights, email info@llc-vaperi.de with your account email and the specific request. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (DPA).

GDPR or Data Inquiry?

Our compliance officer will resolve it.

Contact Security