Privacy Policy
Effective as of 30 August 2026The controller of your personal data is Továrna na absolutno s.r.o., Company ID (IČO): 243 83 171, with its registered office at Korunní 2569/108, 101 00 Prague 10, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague under file no. C 439513 (hereinafter referred to as "Takyo" or "we"). Through this Privacy Policy we inform you about the processing of your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act No. 110/2019 Coll., on the Processing of Personal Data, Act No. 480/2004 Coll., on Certain Information Society Services, and other applicable legal regulations governing the protection of personal data.
Takyo is a mobile application for iOS and Android and a website (www.takyo.cz), accessible through a single user account. In the app you will find prepared dates, questions, games, and other content for couples.
If you have any questions regarding the protection of your personal data, you can contact us at ola@takyo.cz. We are not required to appoint a Data Protection Officer under Art. 37 GDPR.
01 What personal data we process and why
The personal data we process depends on how you use Takyo.
A. User account
You register and log in to Takyo exclusively through a Google or Apple account; we do not offer registration by email and password (your Google/Apple account password never reaches us). From your chosen login provider, we obtain and further process:
- your email address — used as the account identifier and for communicating with you,
- your name — to address you within the app,
- your profile photo, if provided to us by the login provider (typically Google; Apple does not provide a photo); we display it in your profile.
We also maintain technical data related to your account: the date your account was created, the date of your last login, and which login provider (Google/Apple) you use.
Providing this data is a contractual requirement — a registered account cannot be created without it. If you don't want to provide it, you can use Takyo in guest mode: in this mode we do not collect your email, name, or profile photo; we keep records of app usage (see below) for guests too, but only under an anonymous technical identifier.
The legal basis for this processing is performance of a contract (Art. 6(1)(b) GDPR).
B. Guest account
You can also use Takyo without registering, as a guest. In that case, we process only a random technical identifier (UUID) and the technical data listed above (date created, last login); the identifier is not linked to your name, email, or any other data that would allow us to directly identify you.
The legal basis for this processing is performance of a contract (Art. 6(1)(b) GDPR).
C. Use of app content
So that we can display the app correctly and return you to where you left off, we process, in connection with your account:
- onboarding progress — the steps you completed during initial setup, so we don't have to walk you through them again and can guide you toward suitable content,
- content progress — which dates, questions, or games you've opened, which step you're on, and whether you've completed them; this lets us mark content as in progress or completed and avoid offering you again what you've already done,
- referrals — every user has a unique referral code they can share with others; if someone enters your code, we process information about who entered the code, whose code was used, and what reward each party received, solely so that we can correctly grant the rewards.
This data is used exclusively for the operation of the app.
The legal basis for this processing is performance of a contract (Art. 6(1)(b) GDPR).
D. Purchases and payments
Content is purchased on a one-time basis — you purchase a specific content package, not a recurring subscription. Payments are processed by external payment service providers, the Apple App Store and Google Play. These providers process your payment details (card number, etc.) under their own privacy policies; we do not have access to this data and do not store it.
On our side, we retain only:
- purchase data — payment confirmation, transaction ID, the purchased package, and the purchase date, so that we can grant you access to the purchased content,
- accounting records — documents we are required to archive under accounting and tax regulations.
The legal basis for processing purchase data is performance of a contract (Art. 6(1)(b) GDPR); for accounting records, compliance with a legal obligation (Art. 6(1)(c) GDPR).
Technical operation and security
When you use Takyo, we automatically process technical data necessary for its operation, security, and troubleshooting:
- access logs — IP address, timestamp of access, requested URL, and status code,
- device information — device type, operating system, and app version,
- application operational logs — error logs and request logs used for diagnostics and app stability.
Information about the use of cookies is governed separately in our Cookie Policy.
The legal basis for this processing is our legitimate interest in ensuring the secure and functional operation of the app (Art. 6(1)(f) GDPR).
02 Recipients of personal data
To operate and secure Takyo, we use the third-party services listed below. Processing of personal data with these providers is governed contractually in accordance with Art. 28 GDPR, through data processing terms that form part of their terms of service. We do not disclose or sell your data to anyone for their own purposes.
Supabase (USA; servers in the EU — Ireland and Germany)
- Services: database, backend, authentication, and app hosting
- Link: Privacy Policy
Apple (USA, Ireland)
- Services: Sign in with Apple, payments via the App Store
- Link: Privacy Policy
Google (USA, Ireland)
- Services: Sign in with Google, payments via Google Play
- Link: Privacy Policy
Sentry (Functional Software, Inc., USA; servers in the EU — Germany)
- Services: application error and crash monitoring
- Link: Privacy Policy
Plausible Analytics (Plausible Insights OÜ, Estonia; servers in the EU, Germany)
- Services: website traffic measurement for takyo.cz with no cookies, no IP addresses stored, and no cross-site tracking
- Link: Privacy Policy
If we are required to disclose data by law or by a decision of a competent authority, public authorities may also be recipients.
Transfers of data outside the EU/EEA
Your data is primarily processed within the European Union — data is stored on servers in Ireland and Germany. Some providers, however, are based in the USA, and in connection with their services, data may be transferred outside the EU/EEA. These transfers take place in accordance with the GDPR, on the basis of:
- the European Commission's adequacy decision under the EU-US Data Privacy Framework — applicable to Apple and Google,
- Standard Contractual Clauses (SCCs) approved by the European Commission — applicable to Supabase and Sentry.
In addition to this legal basis, we implement appropriate technical and organizational measures to protect your data — communication between the app and our servers is encrypted, data is pseudonymized where appropriate, and access to it is limited to what is necessary.
03 Marketing and service communications
In connection with the operation of Takyo, we may send you service messages — for example, purchase confirmations, notice of account deletion, or notification of changes to our terms or this Policy. These messages do not constitute marketing communications, and sending them is part of providing the service.
In addition, we may occasionally send you news about our own services by email — in particular news about the app, new dates, questions and games, or promotions and pre-sales of content packages. We send these communications on the basis of the statutory exception for existing customers (Section 7(3) of Act No. 480/2004 Coll.); we will never send you third-party offers, and we do not share your email with anyone for marketing purposes.
You can opt out of these updates at any time — with a single click on the unsubscribe link included in every such email, or by writing to ola@takyo.cz. Opting out has no effect on your account or on the lawfulness of processing carried out before your objection.
04 How long we retain personal data
We retain your personal data only for as long as necessary for the purpose for which we received it, so that we can meet your needs or fulfil our legal obligations.
Overview of retention periods:
- User account and related data — for as long as the account exists. Upon its deletion, without undue delay and no later than within 30 days, we delete the personal data associated with registration (email, name, profile photo) and anonymize the remaining data by assigning it a new random identifier, so that it can no longer be linked to you.
- Guest account — we retain the guest technical identifier (a random UUID) for as long as you actively use it; after 30 days of inactivity, we automatically delete it, or anonymize it by assigning a new random UUID. Clearing your device cache or uninstalling the app will cause you to lose access to the account from your device sooner, but the record itself remains stored on our servers until this period elapses. In both cases, the data can no longer be linked to a specific device or person.
- Records of app usage (onboarding and content progress, referrals) — for as long as the account exists, and thereafter in anonymized form.
- Technical and operational logs — access and operational logs at Supabase, 7 days from creation; error logs at Sentry, 30 days from creation.
- Accounting and tax records — 10 years from the date of the transaction, pursuant to accounting and tax legislation.
- Email for sending newsletters — for as long as the account exists, or until you opt out of receiving newsletters.
In exceptional cases we may retain data for longer if required by law, by a decision of a public authority, or if necessary to resolve a legal dispute. Once the reason for retention ceases to exist, we will delete the data without undue delay.
05 Your rights
We want you to be in control of your data. Under the GDPR, you have the following rights:
- Access — you may request information about what data we process about you and obtain a copy of it.
- Rectification — you may request correction of inaccurate data or completion of incomplete data.
- Erasure — you may request deletion of your data if there is no longer a reason for its processing. We cannot carry out erasure if we need the data to comply with a legal obligation or to defend legal claims. You may also delete your account, including all data, at any time directly in the app.
- Restriction of processing — you may request that we temporarily stop using your data, for example if you dispute its accuracy.
- Data portability — you may request an export of the data you provided to us, in a machine-readable format.
- Objection — you may object to processing based on legitimate interest, including the sending of newsletters. Once we receive your objection, we will reassess the processing, or stop sending newsletters, as applicable.
- Withdrawal of consent — if any processing were to take place on the basis of your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Not to be subject to automated decision-making — Takyo does not use automated decision-making that would have legal effects on you or similarly significantly affect you, nor do we create advertising profiles based on your data.
You may exercise your rights by sending a request from the email address to which the personal data relates, to ola@takyo.cz. We will respond to your request without undue delay, and no later than within 30 days; in more complex cases we may extend this period by a further two months, of which we will inform you. Exercising your rights is free of charge; we may only charge a reasonable fee or refuse a request in the case of manifestly unfounded or excessive requests.
If you believe that we are processing your data in violation of applicable law, you have the right to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic; phone: +420 234 514 111; email: posta@uoou.cz; www.uoou.cz). You may also lodge a complaint with the supervisory authority in another EU member state; a list of authorities can be found on the website of the European Data Protection Board. We would, however, appreciate the opportunity to address your concerns directly first.
06 Final provisions
We may update this Policy from time to time — for example when adding new features or changing service providers. We will inform you of material changes in the app or by email; the current version is always available at www.takyo.cz. The effective date of the current version is stated in the header of this document.
Takyo is intended for persons who have reached the age of 16; if you live outside the European Economic Area, the United Kingdom, and Switzerland, the minimum age is 13. We do not knowingly process the personal data of persons below this age; if we discover that such processing has occurred, we will delete the data without undue delay.
The processing of personal data and this Policy are governed by the laws of the Czech Republic and directly applicable European Union law, in particular the GDPR.
This Policy is drawn up in the Czech and English languages; in the event of any discrepancy between the language versions, the Czech version shall prevail.