ZÁSADY ZPRACOVÁNÍ OSOBNÍCH ÚDAJŮ
Aplikace Věrňák, účinné od 21. 7. 2026
1. ÚVODNÍ USTANOVENÍ
1.1. Správcem osobních údajů je společnost Neoncode.app s.r.o., IČO: 24629553, se sídlem Gajdošova 2277/11, Moravská Ostrava, 702 00 Ostrava (dále jen „správce“).
1.2. Tyto zásady informují uživatele aplikace Věrňák a webové administrace Můj podnik (dále společně jen „Aplikace“) o tom, jaké osobní údaje správce zpracovává, za jakým účelem, na jakém právním základě, jak dlouho je uchovává a jaká práva subjektům údajů náleží podle nařízení (EU) 2016/679 (dále jen „GDPR“) a zákona č. 110/2019 Sb.
1.3. Aplikaci užívají dvě skupiny osob, pro které se zpracování zčásti liší. Uživatelem se rozumí fyzická osoba, která sbírá věrnostní body a uplatňuje benefity. Podnikem se rozumí podnikatel, který provozuje vlastní věrnostní program. Osoba, která přijímá body a benefity jménem Podniku (obsluha), je z pohledu ochrany údajů Uživatelem.
1.4. Kontakt ve věcech ochrany osobních údajů: hello@neoncode.app.
2. ÚDAJE UŽIVATELŮ
2.1. Správce zpracovává o Uživateli tyto údaje:
2.1.1. jméno a příjmení, za účelem vedení účtu a zobrazení obsluze při uplatnění benefitu, na základě plnění smlouvy podle čl. 6 odst. 1 písm. b) GDPR, po dobu trvání účtu;
2.1.2. e-mailovou adresu, za účelem přihlášení, vedení účtu a technické podpory, na základě plnění smlouvy, po dobu trvání účtu;
2.1.3. datum narození, za účelem ověření věkové hranice 15 let pro funkci sledování a oznámení podle čl. 4, na základě plnění právní povinnosti podle čl. 6 odst. 1 písm. c) GDPR ve spojení s čl. 8 GDPR, po dobu trvání účtu;
2.1.4. stav věrnostních bodů a benefitů, za účelem provozu věrnostního programu, na základě plnění smlouvy, po dobu trvání účtu.
2.2. Datum narození správce používá výhradně k ověření, zda je Uživateli alespoň 15 let, což je podmínka pro udělení souhlasu s funkcí sledování a přijímání oznámení podle čl. 4. Správce nevyužívá datum narození k profilování ani k jiným účelům.
2.3. Profilový obrázek z účtu Google nebo Apple si zobrazuje pouze Aplikace v zařízení Uživatele, která si jej při přihlášení načítá přímo od těchto služeb. Správce profilový obrázek neukládá na své servery ani jej jinak nezpracovává.
2.4. Při přihlášení prostřednictvím služeb Google nebo Sign in with Apple získává správce z těchto služeb e-mailovou adresu a jméno Uživatele.
3. CO O UŽIVATELI VIDÍ PODNIK
3.1. Při uplatnění benefitu zobrazí Aplikace obsluze Podniku jméno Uživatele a stav jeho věrnostních bodů a benefitů u daného Podniku. Tyto údaje slouží výhradně k ověření nároku na benefit. Obsluha nemá možnost zobrazit žádné další údaje Uživatele ani se prokliknout na jeho detail.
3.2. Podnik nezískává přístup k databázi Uživatelů ani k jejich seznamu a nemůže Uživatele prostřednictvím Aplikace kontaktovat.
3.3. Statistiky ve webové administraci Můj podnik jsou Podniku dostupné výhradně v podobě agregovaných čísel a grafů, například údaje o počtu uplatněných benefitů za den. Osobní údaje Uživatelů, jejich jména ani jednotlivé identifikátory se ve statistikách nezobrazují.
3.4. Správcem údajů podle čl. 3.1 zůstává správce. Podnik je ve všeobecných obchodních podmínkách zavázán užít tyto údaje pouze k ověření nároku a nezaznamenávat je ani nezpracovávat pro vlastní účely.
4. SLEDOVÁNÍ PODNIKU A OZNÁMENÍ
4.1. Uživatel může v detailu Podniku označit Podnik jako sledovaný. Tímto výslovným úkonem uděluje souhlas s přijímáním oznámení týkajících se daného Podniku, jako jsou novinky, nabídky a nové benefity. Sledování nevzniká automaticky přijetím věrnostního bodu ani uplatněním benefitu.
4.2. Právním základem tohoto zpracování je souhlas podle čl. 6 odst. 1 písm. a) GDPR a § 7 zákona č. 480/2004 Sb., o některých službách informační společnosti.
4.3. Funkce sledování a oznámení je dostupná pouze Uživatelům starším 15 let, neboť souhlas s doručováním oznámení nezletilého vyžaduje podle čl. 8 GDPR tuto věkovou hranici.
4.4. Správce v souvislosti se sledováním zpracovává vazbu mezi účtem Uživatele a sledovaným Podnikem a token zařízení pro doručení oznámení. Tyto údaje zpracovává po dobu trvání sledování; zrušením sledování vazba zaniká.
4.5. Uživatel nemá přehled sledovaných Podniků; sledování konkrétního Podniku může kdykoli vypnout v detailu daného Podniku, případně vypnout veškerá oznámení přímo v Aplikaci nebo v nastavení operačního systému. Odvoláním souhlasu není dotčena zákonnost zpracování před jeho odvoláním.
4.6. Oznámení odesílá správce na základě obsahu zadaného Podnikem. Podnik nezískává informaci o tom, kteří Uživatelé jej sledují, ani k nim nemá přístup; obsah oznámení nastavuje pouze globálně pro celý okruh sledujících a ve své administraci vidí pouze agregovaný počet sledujících. Podnik proto není v souvislosti s oznámeními zpracovatelem ani společným správcem.
4.7. Umožňuje-li to tarif Podniku, může být sledujícímu Uživateli doručeno automatické oznámení na základě jeho vlastního chování, například blížící se dokončení věrnostní karty nebo končící platnost kupónu, tzv. chytré oznámení. Výběr adresátů provádí automatizovaně správce; Podnik nastavuje pouze obsah a spouštěcí podmínku a nedozví se, komu bylo oznámení doručeno. Právní základ je shodný s čl. 4.2.
4.8. Doručení oznámení na zařízení Uživatele technicky zajišťují služby Apple Push Notification service a Firebase Cloud Messaging, uvedené v seznamu zpracovatelů v čl. 6.
5. BLUETOOTH A POLOHA
5.1. Aplikace vyžaduje přístup k modulu Bluetooth a k polohovým službám zařízení.
5.2. Oprávnění k poloze je vyžadováno operačními systémy iOS a Android jako nezbytný technický předpoklad pro skenování okolních zařízení Bluetooth Low Energy a navázání komunikace s určeným zařízením obsluhy. Není užíváno k určení polohy Uživatele.
5.3. Údaje o geografické poloze ani seznamy naskenovaných okolních zařízení Bluetooth nejsou odesílány na servery správce, nejsou nikde trvale ukládány a nedochází k žádnému sledování pohybu Uživatele.
6. ÚDAJE PODNIKŮ
6.1. U Podniků správce zpracovává identifikační a fakturační údaje, kterými jsou obchodní firma nebo jméno, sídlo, IČO, případně DIČ, kontaktní e-mail a telefon a jméno kontaktní osoby.
6.2. Právním základem je plnění smlouvy podle čl. 6 odst. 1 písm. b) GDPR a plnění právních povinností v oblasti účetnictví a daní podle čl. 6 odst. 1 písm. c) GDPR.
6.3. Údaje Podniku správce zpracovává po dobu trvání předplatného a následně 90 dnů, po kterou si Podnik může vyžádat export dat. Daňové doklady a související údaje správce uchovává 10 let od konce příslušného zdaňovacího období podle zákona o účetnictví a zákona o dani z přidané hodnoty.
6.4. Údaje o platební kartě zadává Podnik přímo v prostředí platební brány Comgate, a.s., která s nimi nakládá podle bezpečnostního standardu PCI-DSS Level 1. Správce k číslu karty nemá přístup a neukládá je; pracuje pouze s platebním identifikátorem (tokenem).
7. PŘÍJEMCI A ZPRACOVATELÉ
7.1. K údajům mají přístup pouze pověření zaměstnanci správce a prověření zpracovatelé.
7.2. Zpracovateli a příjemci osobních údajů jsou:
7.2.1. Hetzner Online GmbH (Německo), zajišťující hosting a ukládání dat;
7.2.2. Google Ireland Limited (Irsko), zajišťující autentizaci prostřednictvím Google Auth a doručování oznámení prostřednictvím Firebase Cloud Messaging;
7.2.3. Apple Inc. (USA), zajišťující autentizaci prostřednictvím Sign in with Apple a doručování oznámení prostřednictvím Apple Push Notification service;
7.2.4. Comgate, a.s. (Česká republika), zajišťující zpracování plateb Podniků;
7.2.5. Zoho Corporation B.V., zajišťující odesílání transakčních e-mailů prostřednictvím služby Zoho Mail.
7.3. Osobní údaje jsou uloženy výhradně na serverech v rámci Evropského hospodářského prostoru. Přenos ke společnosti Apple Inc. do Spojených států amerických probíhá na základě standardních smluvních doložek podle čl. 46 GDPR.
7.4. Správce může být povinen předat údaje orgánům veřejné moci, stanoví-li tak zákon.
8. DOBY UCHOVÁNÍ
8.1. Údaje k účtu Uživatele správce zpracovává po dobu trvání účtu. Po zrušení účtu jsou data bez zbytečného odkladu nenávratně smazána.
8.2. Údaje o sledování Podniku správce zpracovává po dobu trvání sledování; zrušením sledování zanikají.
8.3. Údaje k účtu Podniku správce zpracovává po dobu trvání předplatného a následně 90 dnů.
8.4. Daňové doklady správce uchovává 10 let.
8.5. Údaje o poloze a naskenovaných zařízeních Bluetooth se neukládají vůbec.
9. PRÁVA SUBJEKTU ÚDAJŮ
9.1. Subjekt údajů má právo požadovat přístup ke svým osobním údajům, jejich opravu, výmaz, tzv. právo být zapomenut, omezení zpracování, právo na přenositelnost údajů a právo vznést námitku proti zpracování.
9.2. Uživatel může svůj účet a data kdykoli kompletně smazat přímo v nastavení Aplikace.
9.3. Byl-li udělen souhlas, zejména se sledováním Podniku, má subjekt údajů právo jej kdykoli odvolat, aniž je tím dotčena zákonnost zpracování před odvoláním.
9.4. Subjekt údajů má právo podat stížnost u dozorového úřadu, kterým je Úřad pro ochranu osobních údajů, se sídlem Pplk. Sochora 727/27, 170 00 Praha 7, internetová adresa www.uoou.gov.cz.
9.5. Žádosti a dotazy lze směřovat na e-mail hello@neoncode.app.
10. ZMĚNY TĚCHTO ZÁSAD
10.1. Správce může tyto zásady aktualizovat. O podstatných změnách bude informovat prostřednictvím Aplikace nebo e-mailem.
10.2. Tyto zásady jsou účinné od 21. 7. 2026.
Právně závazné je pouze toto české znění. Anglická verze níže je neoficiální překlad pro pohodlí čtenáře.
English version
This English version is an unofficial translation provided for convenience only. Only the Czech version above is legally binding.
PRIVACY POLICY
Věrňák application, effective from 21 July 2026
1. INTRODUCTORY PROVISIONS
1.1. The controller of personal data is Neoncode.app s.r.o., Company ID: 24629553, registered office at Gajdošova 2277/11, Moravská Ostrava, 702 00 Ostrava (hereinafter the “controller”).
1.2. This policy informs users of the Věrňák application and the Můj podnik web administration (hereinafter jointly the “Application”) about what personal data the controller processes, for what purpose, on what legal basis, how long it retains it, and what rights data subjects have under Regulation (EU) 2016/679 (hereinafter “GDPR”) and Act No. 110/2019 Coll.
1.3. The Application is used by two groups of persons, for whom the processing partly differs. A User means a natural person who collects loyalty points and redeems benefits. A Business means an entrepreneur who operates its own loyalty program. A person who accepts points and benefits on behalf of a Business (staff) is, from the perspective of data protection, a User.
1.4. Contact for personal-data matters: hello@neoncode.app.
2. USER DATA
2.1. The controller processes the following data about a User:
2.1.1. first name and surname, for the purpose of maintaining the account and displaying it to staff upon redemption of a benefit, on the basis of performance of a contract under Article 6(1)(b) GDPR, for the duration of the account;
2.1.2. email address, for the purpose of login, account maintenance and technical support, on the basis of performance of a contract, for the duration of the account;
2.1.3. date of birth, for the purpose of verifying the age limit of 15 for the following and notification function under Article 4, on the basis of compliance with a legal obligation under Article 6(1)(c) GDPR in conjunction with Article 8 GDPR, for the duration of the account;
2.1.4. the status of loyalty points and benefits, for the purpose of operating the loyalty program, on the basis of performance of a contract, for the duration of the account.
2.2. The controller uses the date of birth solely to verify whether a User is at least 15 years old, which is a condition for granting consent to the following and notification function under Article 4. The controller does not use the date of birth for profiling or for any other purpose.
2.3. A profile picture from a Google or Apple account is displayed only by the Application on the User’s device, which loads it directly from those services on login. The controller does not store the profile picture on its servers or otherwise process it.
2.4. When logging in through the Google or Sign in with Apple services, the controller obtains from those services the User’s email address and name.
3. WHAT A BUSINESS SEES ABOUT A USER
3.1. Upon redemption of a benefit, the Application displays to the Business’s staff the User’s name and the status of their loyalty points and benefits with the given Business. This data serves solely to verify entitlement to the benefit. The staff have no ability to display any other data of the User or to click through to their detail.
3.2. A Business does not obtain access to the database of Users or to a list of them and cannot contact Users through the Application.
3.3. In the Můj podnik web administration, statistics are available to a Business solely in the form of aggregated figures and charts, for example data on the number of benefits redeemed per day. Users’ personal data, their names and individual identifiers are not displayed in the statistics.
3.4. The controller remains the controller of the data under Article 3.1. Under the terms of service, a Business is bound to use this data only to verify entitlement and not to record it or process it for its own purposes.
4. FOLLOWING A BUSINESS AND NOTIFICATIONS
4.1. A User may mark a Business as followed in the Business detail. By this explicit act, they grant consent to receiving notifications relating to the given Business, such as news, offers and new benefits. Following does not arise automatically upon accepting a loyalty point or redeeming a benefit.
4.2. The legal basis for this processing is consent under Article 6(1)(a) GDPR and Section 7 of Act No. 480/2004 Coll., on certain information-society services.
4.3. The following and notification function is available only to Users over 15 years of age, as consent to the delivery of notifications to a minor requires this age limit under Article 8 GDPR.
4.4. In connection with following, the controller processes the link between the User’s account and the followed Business and the device token for delivering the notification. It processes this data for the duration of following; cancelling the following ends the link.
4.5. A User does not have an overview of followed Businesses; they may switch off the following of a particular Business at any time in the detail of the given Business, or switch off all notifications directly in the Application or in the operating system settings. The withdrawal of consent does not affect the lawfulness of processing before its withdrawal.
4.6. Notifications are sent by the controller based on the content entered by the Business. The Business does not obtain information about which Users follow it, nor does it have access to them; it sets the content of a notification only globally for the entire audience of followers and, in its administration, sees only the aggregated number of followers. Therefore, in connection with notifications, the Business is neither a processor nor a joint controller.
4.7. Where the Business’s tariff allows it, a following User may be delivered an automatic notification based on their own behaviour, for example an upcoming completion of a loyalty card or an expiring coupon, a so-called smart notification. The selection of recipients is performed automatically by the controller; the Business sets only the content and the triggering condition and does not learn to whom the notification was delivered. The legal basis is the same as in Article 4.2.
4.8. The delivery of a notification to the User’s device is technically ensured by the Apple Push Notification service and Firebase Cloud Messaging, listed among the processors in Article 6.
5. BLUETOOTH AND LOCATION
5.1. The Application requires access to the Bluetooth module and to the device’s location services.
5.2. The location permission is required by the iOS and Android operating systems as a necessary technical prerequisite for scanning nearby Bluetooth Low Energy devices and establishing communication with the designated staff device. It is not used to determine the User’s location.
5.3. Data on geographic location and lists of scanned nearby Bluetooth devices are not sent to the controller’s servers, are not permanently stored anywhere, and no tracking of the User’s movement takes place.
6. BUSINESS DATA
6.1. For Businesses, the controller processes identification and billing data, namely the business name or name, registered address, Company ID (IČO), where applicable VAT ID (DIČ), contact email and phone, and the name of the contact person.
6.2. The legal basis is performance of a contract under Article 6(1)(b) GDPR and compliance with legal obligations in the area of accounting and taxes under Article 6(1)(c) GDPR.
6.3. The controller processes a Business’s data for the duration of the subscription and thereafter for 90 days, during which the Business may request an export of the data. The controller retains tax documents and related data for 10 years from the end of the relevant tax period under the Accounting Act and the Value Added Tax Act.
6.4. Payment-card data is entered by the Business directly in the environment of the payment gateway Comgate, a.s., which handles it in accordance with the PCI-DSS Level 1 security standard. The controller has no access to the card number and does not store it; it works only with a payment identifier (token).
7. RECIPIENTS AND PROCESSORS
7.1. Only authorized employees of the controller and vetted processors have access to the data.
7.2. The processors and recipients of personal data are:
7.2.1. Hetzner Online GmbH (Germany), providing hosting and data storage;
7.2.2. Google Ireland Limited (Ireland), providing authentication through Google Auth and notification delivery through Firebase Cloud Messaging;
7.2.3. Apple Inc. (USA), providing authentication through Sign in with Apple and notification delivery through the Apple Push Notification service;
7.2.4. Comgate, a.s. (Czech Republic), providing the processing of Business payments;
7.2.5. Zoho Corporation B.V., providing the sending of transactional emails through the Zoho Mail service.
7.3. Personal data is stored solely on servers within the European Economic Area. The transfer to Apple Inc. in the United States of America takes place on the basis of standard contractual clauses under Article 46 GDPR.
7.4. The controller may be obliged to hand over data to public authorities where the law so provides.
8. RETENTION PERIODS
8.1. The controller processes data on a User’s account for the duration of the account. After cancellation of the account, the data is irretrievably deleted without undue delay.
8.2. The controller processes data on the following of a Business for the duration of the following; it ceases upon cancellation of the following.
8.3. The controller processes data on a Business’s account for the duration of the subscription and thereafter for 90 days.
8.4. The controller retains tax documents for 10 years.
8.5. Data on location and scanned Bluetooth devices is not stored at all.
9. RIGHTS OF THE DATA SUBJECT
9.1. A data subject has the right to request access to their personal data, its rectification, erasure (the “right to be forgotten”), restriction of processing, the right to data portability and the right to object to processing.
9.2. A User may completely delete their account and data at any time directly in the Application settings.
9.3. If consent was granted, in particular to following a Business, the data subject has the right to withdraw it at any time, without this affecting the lawfulness of processing before withdrawal.
9.4. A data subject has the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), registered office at Pplk. Sochora 727/27, 170 00 Prague 7, website www.uoou.gov.cz.
9.5. Requests and questions may be directed to the email hello@neoncode.app.
10. CHANGES TO THIS POLICY
10.1. The controller may update this policy. It will inform of material changes through the Application or by email.
10.2. This policy is effective from 21 July 2026.
