Atlayo Privacy Policy
Last updated: 21 July 2026 · Effective: 21 July 2026
This Privacy Policy explains how Atlayo Overseas s.r.o. (“Atlayo”, “we”) processes personal data when you use the Atlayo app, optional saved payment cards, Atlayo ID, and related services. Atlayo Overseas s.r.o. (company ID 29645433) is the data controller for processing described here unless stated otherwise. The parent company of the Atlayo group is Atlayo spol. s r.o.
1. Summary
- We collect data needed to run chat, calls, optional saved payment cards, account security and mini-apps.
- Sensitive permissions (camera, microphone, contacts, location, NFC) are requested only when you use a related feature.
- One-to-one and group message content is encrypted in transit; server-side storage is limited to delivery, sync and safety features you enable.
- We do not sell your personal data.
- EU/EEA users have GDPR rights — see section 10 and the EU Addendum.
2. Who we are
Data controller: Atlayo Overseas, Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic
Company ID: 29645433
Parent company: Atlayo spol. s r.o. (Atlayo group)
Email: privacy@atlayo.com
Data Protection Officer: dpo@atlayo.com
3. Data we collect
3.1 Account and profile
- Mobile number or approved login identifier, display name, profile photo, Atlayo ID, language preference.
- Optional: bio, region, custom ringtones and notification settings.
3.2 Communications
- Messages, media, files, voice notes and call metadata (participants, time, duration) needed to deliver the Service.
- Read receipts and typing indicators when enabled.
- Reported content and abuse reports you submit.
3.3 Contacts and social graph
- If you use contact matching, phone contacts you choose to upload (hashed where possible).
- Friends list, group membership, block list.
3.4 Location
- Precise or approximate location only when you share live location, send a map pin, or use location-based mini-apps with consent.
3.5 Saved payment cards
- If you choose to save a card, we store tokenised payment-method identifiers (not full card numbers), card brand and last four digits, and your save/remove preferences.
- Our payment infrastructure partner tokenises card data under its own privacy notices. Atlayo does not operate a wallet, stored balance, or peer-to-peer payments.
- When a mini-app requests card autofill, we share only the minimum token data needed after you grant permission — the mini-app’s own payment provider processes the transaction.
3.6 Device and usage
- Device model, OS version, app version, IP address, push token, crash logs, feature usage and security logs.
- QR/NFC interaction logs for contact sharing and login.
3.7 Mini-apps
- Mini-app open events, permission grants, and data shared with developers per your consent.
3.8 Support
- Information you provide when contacting support or exercising privacy rights.
4. How we use data
We use personal data to:
- Create and manage your account and authenticate sessions.
- Deliver messages, calls, notifications and sync across devices.
- Store and manage tokenised saved payment cards when you opt in; honour autofill permissions you grant to mini-apps.
- Run Compass, attribute mini-app usage, and enforce developer rules.
- Improve reliability, debug crashes and measure aggregated performance.
- Detect spam, abuse, security incidents and illegal content.
- Comply with law and respond to valid legal requests.
- Send service announcements; marketing only with consent where required.
5. Legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service you request | Contract (Art. 6(1)(b)) |
| Security, fraud prevention, abuse handling | Legitimate interests (Art. 6(1)(f)) / Legal obligation |
| Saved payment cards (tokenisation and autofill) | Contract (Art. 6(1)(b)) / Consent for mini-app autofill (Art. 6(1)(a)) |
| Optional features (location, contacts, marketing) | Consent (Art. 6(1)(a)) — withdraw anytime in Settings |
| Analytics with pseudonymous data | Legitimate interests, balanced against your rights |
6. Sharing and processors
We share personal data only as needed:
- Service providers (hosting, SMS verification, push delivery, analytics, customer support) under data-processing agreements.
- Payment tokenisation providers — to securely store card tokens when you save a card.
- Mini-app developers — only data you approve on the permission screen.
- Other users — profile elements and content you choose to make visible.
- Authorities — when required by law; see Law Enforcement Guidelines.
- Corporate transactions — merger or acquisition, subject to confidentiality and continued protection.
We do not sell personal data to advertisers or data brokers.
7. International transfers
We store and process data primarily in the European Union. If data is transferred outside the EU/EEA, we use appropriate safeguards such as Standard Contractual Clauses (2021/914) and transfer impact assessments where required.
8. Retention
- Account data: for the life of the account plus limited period after deletion for backups and legal holds.
- Messages: until you delete them, leave a group, or delete your account; server copies removed per deletion schedule.
- Saved card tokens: until you remove the card or delete your account, plus limited backup period.
- Security logs: generally up to 12 months unless needed for investigations.
9. Security
We use encryption in transit (TLS), access controls, monitoring, and staff training. No method of transmission or storage is 100% secure; please use a strong device lock and report suspected compromise promptly.
10. Your rights
If GDPR applies, you may have the right to:
- Access, rectify, erase, restrict or object to processing.
- Data portability for data you provided in structured form.
- Withdraw consent without affecting prior lawful processing.
- Lodge a complaint with your supervisory authority — see the EU Addendum.
Exercise rights via in-app Settings → Privacy or email privacy@atlayo.com. We may verify your identity before responding.
11. Minors
Atlayo is not directed at children under 16 in the EU/EEA without parental consent. See our Children's Privacy Statement.
12. Mini-app developers
Developers are independent controllers or processors for data they collect in mini-apps. We require contractual privacy commitments and provide users permission controls.
13. Cookies and similar technologies
The Atlayo website and Developer Portal may use essential cookies and local storage for login sessions and preferences. Non-essential analytics cookies are used only with consent where required (e.g. ePrivacy / GDPR).
14. Changes
We will post material changes here and in the app. If changes require new consent under law, we will obtain it before applying the change to your data.
15. Contact & DPO
Atlayo Overseas s.r.o.
Company ID: 29645433
VAT ID: CZ29645433
File C 152275 at the Regional Court in Brno
Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic
Parent company: Atlayo spol. s r.o. (Atlayo group)
Privacy requests: privacy@atlayo.com
DPO: dpo@atlayo.com