Atlayo
Legal hub Terms EU Addendum
← All legal documents

Atlayo Privacy Policy

Last updated: 21 July 2026 · Effective: 21 July 2026

This Privacy Policy explains how Atlayo Overseas s.r.o. (“Atlayo”, “we”) processes personal data when you use the Atlayo app, optional saved payment cards, Atlayo ID, and related services. Atlayo Overseas s.r.o. (company ID 29645433) is the data controller for processing described here unless stated otherwise. The parent company of the Atlayo group is Atlayo spol. s r.o.

Contents
  1. Summary
  2. Who we are
  3. Data we collect
  4. How we use data
  5. Legal bases (GDPR)
  6. Sharing and processors
  7. International transfers
  8. Retention
  9. Security
  10. Your rights
  11. Minors
  12. Mini-app developers
  13. Cookies and similar tech
  14. Changes
  15. Contact & DPO

1. Summary

  • We collect data needed to run chat, calls, optional saved payment cards, account security and mini-apps.
  • Sensitive permissions (camera, microphone, contacts, location, NFC) are requested only when you use a related feature.
  • One-to-one and group message content is encrypted in transit; server-side storage is limited to delivery, sync and safety features you enable.
  • We do not sell your personal data.
  • EU/EEA users have GDPR rights — see section 10 and the EU Addendum.

2. Who we are

Data controller: Atlayo Overseas, Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic
Company ID: 29645433
Parent company: Atlayo spol. s r.o. (Atlayo group)
Email: privacy@atlayo.com
Data Protection Officer: dpo@atlayo.com

3. Data we collect

3.1 Account and profile

  • Mobile number or approved login identifier, display name, profile photo, Atlayo ID, language preference.
  • Optional: bio, region, custom ringtones and notification settings.

3.2 Communications

  • Messages, media, files, voice notes and call metadata (participants, time, duration) needed to deliver the Service.
  • Read receipts and typing indicators when enabled.
  • Reported content and abuse reports you submit.

3.3 Contacts and social graph

  • If you use contact matching, phone contacts you choose to upload (hashed where possible).
  • Friends list, group membership, block list.

3.4 Location

  • Precise or approximate location only when you share live location, send a map pin, or use location-based mini-apps with consent.

3.5 Saved payment cards

  • If you choose to save a card, we store tokenised payment-method identifiers (not full card numbers), card brand and last four digits, and your save/remove preferences.
  • Our payment infrastructure partner tokenises card data under its own privacy notices. Atlayo does not operate a wallet, stored balance, or peer-to-peer payments.
  • When a mini-app requests card autofill, we share only the minimum token data needed after you grant permission — the mini-app’s own payment provider processes the transaction.

3.6 Device and usage

  • Device model, OS version, app version, IP address, push token, crash logs, feature usage and security logs.
  • QR/NFC interaction logs for contact sharing and login.

3.7 Mini-apps

  • Mini-app open events, permission grants, and data shared with developers per your consent.

3.8 Support

  • Information you provide when contacting support or exercising privacy rights.

4. How we use data

We use personal data to:

  • Create and manage your account and authenticate sessions.
  • Deliver messages, calls, notifications and sync across devices.
  • Store and manage tokenised saved payment cards when you opt in; honour autofill permissions you grant to mini-apps.
  • Run Compass, attribute mini-app usage, and enforce developer rules.
  • Improve reliability, debug crashes and measure aggregated performance.
  • Detect spam, abuse, security incidents and illegal content.
  • Comply with law and respond to valid legal requests.
  • Send service announcements; marketing only with consent where required.

5. Legal bases (GDPR)

PurposeLegal basis
Providing the Service you requestContract (Art. 6(1)(b))
Security, fraud prevention, abuse handlingLegitimate interests (Art. 6(1)(f)) / Legal obligation
Saved payment cards (tokenisation and autofill)Contract (Art. 6(1)(b)) / Consent for mini-app autofill (Art. 6(1)(a))
Optional features (location, contacts, marketing)Consent (Art. 6(1)(a)) — withdraw anytime in Settings
Analytics with pseudonymous dataLegitimate interests, balanced against your rights

6. Sharing and processors

We share personal data only as needed:

  • Service providers (hosting, SMS verification, push delivery, analytics, customer support) under data-processing agreements.
  • Payment tokenisation providers — to securely store card tokens when you save a card.
  • Mini-app developers — only data you approve on the permission screen.
  • Other users — profile elements and content you choose to make visible.
  • Authorities — when required by law; see Law Enforcement Guidelines.
  • Corporate transactions — merger or acquisition, subject to confidentiality and continued protection.

We do not sell personal data to advertisers or data brokers.

7. International transfers

We store and process data primarily in the European Union. If data is transferred outside the EU/EEA, we use appropriate safeguards such as Standard Contractual Clauses (2021/914) and transfer impact assessments where required.

8. Retention

  • Account data: for the life of the account plus limited period after deletion for backups and legal holds.
  • Messages: until you delete them, leave a group, or delete your account; server copies removed per deletion schedule.
  • Saved card tokens: until you remove the card or delete your account, plus limited backup period.
  • Security logs: generally up to 12 months unless needed for investigations.

9. Security

We use encryption in transit (TLS), access controls, monitoring, and staff training. No method of transmission or storage is 100% secure; please use a strong device lock and report suspected compromise promptly.

10. Your rights

If GDPR applies, you may have the right to:

  • Access, rectify, erase, restrict or object to processing.
  • Data portability for data you provided in structured form.
  • Withdraw consent without affecting prior lawful processing.
  • Lodge a complaint with your supervisory authority — see the EU Addendum.

Exercise rights via in-app Settings → Privacy or email privacy@atlayo.com. We may verify your identity before responding.

11. Minors

Atlayo is not directed at children under 16 in the EU/EEA without parental consent. See our Children's Privacy Statement.

12. Mini-app developers

Developers are independent controllers or processors for data they collect in mini-apps. We require contractual privacy commitments and provide users permission controls.

13. Cookies and similar technologies

The Atlayo website and Developer Portal may use essential cookies and local storage for login sessions and preferences. Non-essential analytics cookies are used only with consent where required (e.g. ePrivacy / GDPR).

14. Changes

We will post material changes here and in the app. If changes require new consent under law, we will obtain it before applying the change to your data.

15. Contact & DPO

Atlayo Overseas s.r.o.
Company ID: 29645433
VAT ID: CZ29645433
File C 152275 at the Regional Court in Brno
Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic

Parent company: Atlayo spol. s r.o. (Atlayo group)
Privacy requests: privacy@atlayo.com
DPO: dpo@atlayo.com

© 2026 Atlayo spol. s r.o. Legal hub