← Back to homeLegal

Privacy Policy

Effective: 29 June 2026 · Version 2.0
Supersedes the previous version effective 1 June 2024.

1. Introduction

This Policy explains how personal data is processed in the mobile application Aerial Hoop Flow ("App"), in compliance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Sb.

2. Data Controller

DataOps, s.r.o.
IČO: 19550731 · DIČ: CZ19550731
Registered office: U Školičky 1148, 253 01 Hostivice, Czech Republic
Registered: Městský soud v Praze, file No. C 388314
Statutory body: Eva Martínová, Managing Director
Contact: info@wearedataops.cz
DPO: not appointed — the scope of processing does not require one under Art. 37 GDPR.

3. What Data We Collect

Account data: email address, username, password (hashed/encrypted, stored in Google Firebase Authentication). If you sign in with Google or Apple, we receive basic profile data from that provider (in particular email, name, and possibly a profile photo, which may be carried over to your profile in the App).

User content: photos you upload, personal notes, Flow names, music links.

Usage & technical data: device type, operating system, app usage events and performance data (via Firebase / Google Analytics and Performance), approximate location derived from your IP address (Google Analytics), and standard logs.

We do not collect special-category ("sensitive") data within the meaning of Art. 9 GDPR (e.g. health, racial/ethnic origin, political opinions).

4. Purposes & Legal Bases

PurposeLegal basis (Art. 6 GDPR)
Creating and operating your account; providing the App's features (catalogue, Flows, sharing)Performance of a contract — Art. 6(1)(b)
Security, abuse prevention, app stability and improvement (logs, analytics)Legitimate interest — Art. 6(1)(f)
Compliance with legal obligations (responding to lawful requests)Legal obligation — Art. 6(1)(c)
Marketing communication (planned)Consent — Art. 6(1)(a)

5. Subscriptions & Payments

Premium subscriptions are purchased through the Apple App Store or Google Play. Payment is processed by Apple/Google; we do not store or see your payment-card data. Subscription status is managed via RevenueCat on our behalf. DataOps does not issue invoices — payments and their records are handled by Apple / Google / RevenueCat under their own terms.

6. Recipients & Processors

We use the following processors/recipients, who process data on our behalf under data-processing terms:

  • Google / Firebase — authentication, database (Firestore), file storage, cloud functions, analytics and performance. (Google Ireland / Google LLC)
  • RevenueCat — subscription management.
  • Apple App Store / Google Play — payment processing and app distribution.
  • Google Sign-In / Apple Sign-In — optional login.

We do not sell personal data. We disclose data to others only where required by law or to protect our legal rights.

7. International Transfers

The App is available worldwide. Some processors (e.g. Google/Firebase) may process data on servers outside the EEA (in particular the United States). Such transfers are safeguarded by Standard Contractual Clauses (SCCs) and/or the EU-U.S. Data Privacy Framework, in line with Chapter V GDPR.

8. Retention

  • Account data & user content: kept while your account is active.
  • On account deletion (Profile → Delete Account): all your data — email, username, login times, uploaded photos — is permanently deleted from our servers.
  • Logs: retained for a limited period (Firebase defaults, ~30 days).
  • Accounting/tax documents: DataOps does not issue invoices — payments and their records are handled by Apple / Google / RevenueCat under their own terms.

9. Cookies & Tracking

The App uses only technically necessary mechanisms (e.g. Firebase Authentication session/local storage). We do not use advertising cookies or third-party ad tracking.

10. Your Rights

Under the GDPR you have the right to:

  • access your data (Art. 15);
  • rectification (Art. 16);
  • erasure (Art. 17) — also via in-app Delete Account;
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing (Art. 21);
  • withdraw consent at any time, where processing is based on consent.

To exercise these rights, contact info@wearedataops.cz. We may verify your identity before acting on a request.

Right to complain: You may lodge a complaint with the supervisory authority:
Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz.

11. Security

We protect your data with HTTPS/TLS encryption, password hashing, and Firestore security rules. In the event of a personal-data breach, we notify the supervisory authority within 72 hours where required (Art. 33 GDPR).

12. Children

The App is rated 9+, is freely available, and may be used by children. A parent or legal guardian is responsible for a minor's use of the App and for any purchases, and should be aware of and supervise that use. We do not knowingly collect more data than is necessary to operate the service.

13. User-Generated Content & Sharing

Content you upload and choose to share (e.g. a Flow shared with your trainer or a friend) becomes visible to those users. You are responsible for what you upload and share. See the Terms of Use.

14. Content Ownership

The App's catalogue content (position photographs and videos), which may feature live individuals including the developer and colleagues, is the property of DataOps, s.r.o. and may not be downloaded, distributed, or used without explicit permission.

15. Changes to This Policy

We may update this Policy to reflect changes in our processing or the law. Material changes will be posted in the App and at the public URL, with reasonable prior notice where required.

16. Contact

Questions or requests regarding your personal data: info@wearedataops.cz.