VEYA · Operated by TELEflash GmbH
Privacy Policy
This policy explains which personal data TELEflash GmbH processes when you use VEYA, why we process it, and the rights you have under the General Data Protection Regulation (GDPR).
Last updated 8 September 2026
1. Who is responsible for your data
The controller responsible for the processing of personal data on this website and in connection with the VEYA service is TELEflash GmbH, TELEflash GmbH, Mainzer Landstraße 69, 60329 Frankfurt am Main, Germany. VEYA is a brand of TELEflash GmbH and not a separate company.
Data-protection enquiries can be sent to the contact channel listed in our Imprint.
2. Which data we process
We process the following categories of personal data:
- Order data
- The mobile number to be topped up, the selected country and operator, the top-up amount, the order ID and the status of the order. If you choose to provide an email address so that we can send you a receipt, that address as well. We do not ask for your name.
- Technical data
- IP address, browser type and version, device type, operating system, language settings, the pages you visit, timestamps of requests and security-related log entries (for example failed requests or rate-limit events).
- Communication data
- The content of messages you send to us, for example support requests or refund enquiries, together with the contact details you use.
- Payment data
- Payment is handled by an external payment provider. Card numbers, security codes and similar payment credentials are entered on the provider's page and are not stored by VEYA. We receive from the provider a confirmation of whether the payment succeeded, a payment reference and, depending on the provider, limited information such as the payment method type or a masked identifier.
- Cookie and preference data
- Your cookie-consent choices, your theme preference and the last country you selected. See the Cookie Policy.
We do not intentionally collect special categories of personal data (such as health data or data revealing political opinions) and ask that you do not send us such data.
3. Why we process your data
We process personal data for the following purposes:
- to receive, process and deliver your top-up order, including transmitting the mobile number and amount to the operator or top-up supplier;
- to send you the order confirmation, delivery confirmation and any notice of a failed transaction;
- to handle support requests, complaints and refund requests;
- to detect and prevent fraud, misuse and security incidents, and to protect our systems;
- to comply with legal obligations, for example commercial and tax record-keeping and cooperation with competent authorities where required by law;
- to operate, maintain and improve the website and, where you have consented, to measure how the website is used.
4. Legal bases
We rely on the following legal bases under Article 6(1) GDPR:
- Article 6(1)(b) — performance of a contract
- Processing of order data, communication data and payment confirmations to conclude and perform the top-up contract with you and to respond to your requests in connection with it.
- Article 6(1)(c) — legal obligation
- Retention of transaction records to meet commercial and tax record-keeping duties, and disclosure of data where we are legally required to do so.
- Article 6(1)(f) — legitimate interests
- Processing of technical data and security logs to keep the website and service secure, to detect and prevent fraud and abuse, to defend legal claims and to ensure the technical operation of the site. Our legitimate interest lies in operating a secure and reliable service; we balance this against your interests and rights.
- Article 6(1)(a) — consent
- Setting of optional analytics or marketing cookies and any related processing. Consent is requested through the cookie banner and can be withdrawn at any time under Cookie Settings.
Providing order data is necessary to place an order; without it we cannot deliver a top-up. Providing consent for optional cookies is voluntary.
5. Who receives your data
We share personal data only where necessary for the purposes described above. Recipients include:
- Payment provider
- [PAYMENT PROCESSOR NAME] processes your payment. Payment details entered on its page are processed by the provider under its own privacy notice. We exchange the order reference, amount and payment status with the provider.
- Mobile operators and top-up suppliers
- To deliver a top-up we transmit the mobile number, operator, amount and an order reference to the relevant operator or to the top-up supplier through which we reach that operator.
- Hosting and infrastructure providers
- Our website and systems are hosted by service providers who process data on our behalf under data-processing agreements in accordance with Article 28 GDPR.
- Email delivery providers
- Service providers used to send order confirmations and support replies on our behalf.
- Authorities and advisers
- Public authorities, courts, and professional advisers where disclosure is required by law or necessary to establish, exercise or defend legal claims.
We do not sell personal data and do not share it with third parties for their own marketing purposes.
6. International transfers
Where possible we use service providers located in the European Union or the European Economic Area. If personal data is transferred to a country outside the EEA, we ensure that appropriate safeguards are in place, such as an adequacy decision of the European Commission or standard contractual clauses approved by the Commission, supplemented by additional measures where necessary. You can request further information about the safeguards used by contacting the contact channel listed in our Imprint.
7. How long we keep your data
We keep personal data only for as long as it is needed for the purposes for which it was collected and for as long as statutory retention periods require.
- Order and transaction data is retained for the duration of the contract and thereafter for the retention periods imposed by commercial and tax law.
- Technical logs and security data are retained for a limited period necessary to ensure security and investigate incidents, after which they are deleted or anonymised.
- Support communications are retained for as long as needed to resolve the request and to document its outcome.
- Cookie-consent records are kept for the lifetime of the consent cookie described in the Cookie Policy.
Data that is no longer needed is deleted or anonymised, unless a legal obligation or a pending dispute requires longer retention.
8. Your rights
Subject to the conditions set out in the GDPR, you have the right to:
- obtain access to the personal data we hold about you (Article 15);
- have inaccurate data rectified (Article 16);
- have your data erased (Article 17);
- have processing restricted (Article 18);
- receive the data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller (Article 20);
- object to processing based on legitimate interests, on grounds relating to your particular situation (Article 21);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).
To exercise these rights, contact the contact channel listed in our Imprint. We may need to verify your identity before responding. We respond within the time limits set by the GDPR, normally within one month.
10. Automated decision-making
We may use automated checks to identify orders that show indications of fraud or abuse, for example unusual ordering patterns or mismatches between the information provided. Such checks may cause an order to be delayed or referred for manual review. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. If you believe an order was declined incorrectly, you can contact the support contact listed in our Imprint and ask for a review by a member of our team.
12. Security
We apply technical and organisational measures appropriate to the risk in order to protect personal data against unauthorised access, loss, alteration and disclosure. These include encrypted connections (TLS) between your browser and our servers, access controls, logging of security-relevant events and the separation of payment processing to a specialised provider. No system can be guaranteed to be completely secure; if you suspect a security problem, please contact the contact channel listed in our Imprint.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our processing, our service providers or the law. The current version is always available on this page, and the date of the most recent update is shown at the top. Where a change materially affects you, we will draw your attention to it in an appropriate way.
14. Contact
TELEflash GmbH, TELEflash GmbH, Mainzer Landstraße 69, 60329 Frankfurt am Main, Germany.
Data-protection enquiries can be sent to the contact channel listed in our Imprint. Questions about an order can be sent to the support contact listed in our Imprint. Full company details are available in the Imprint.