Privacy Policy of the Heatmapa Mobile Application

of heatmapa s.r.o., with its registered office at Pod vinohradem 211/7, Braník, 147 00 Prague, Czech Republic, Company ID (IČO): 244 19 010, registered in the Commercial Register kept by the Municipal Court in Prague under file No. C 440662, e-mail: support@heatmapa.com (the "Controller")

This English translation is provided for convenience only. The Czech version of this Privacy Policy is the authoritative and legally binding version (Article 14.2).

Download PDF

I. Introductory Provisions

1.1This privacy policy (the "Policy") contains information on the processing of personal data of users of the Heatmapa mobile application (the "Application" and the "User") provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation, "GDPR") and with Act No. 110/2019 Coll., on Personal Data Processing, as amended.
1.2The Policy supplements the Terms of Use of the Heatmapa mobile application and applies to all processing of personal data carried out by the Controller in connection with the operation of the Application. The Policy applies to all Users regardless of the manner in which they use the Application, i.e. both to Users who merely browse the content of the Application and to Users who create content, perform administration of a Venue or Event, or use paid services.
1.3Given the nature of the Application, the essence of which is the display of Users' locations, the Controller pays increased attention to the processing of location data; detailed rules are set out in Article V of the Policy.

II. Identity and Contact Details of the Controller

2.1The controller of personal data is heatmapa s.r.o., identified in the heading of this Policy. The Controller may be contacted in matters of personal data processing at the e-mail address support@heatmapa.com.
2.2The Controller has not appointed a data protection officer, as it is not subject to this obligation under Article 37 GDPR.

III. Categories of Personal Data Processed

3.1The Controller processes personal data provided to it by the User and personal data generated by the use of the Application, to the following extent:
3.2The Controller does not process special categories of personal data within the meaning of Article 9 GDPR. The User acknowledges that location data and Check-ins may indirectly reveal information about their habits and interests; the Controller therefore handles them with an increased level of protection in accordance with this Policy.

IV. Purposes and Legal Bases of Processing

4.1Personal data are processed for the following purposes and on the following legal bases:
4.2The provision of registration data, including the nickname and profile photograph, is a contractual requirement; without them, the contract on the use of the Application cannot be concluded or performed. The provision of location data and access to contacts is entirely voluntary; failure to provide them only results in the non-functionality of those parts of the Application that depend on them.

V. Location Data

5.1The User grants access to the device's location in the settings of their device, including the choice of accuracy and access mode. The User is entitled to switch off location sharing at any time in the settings of the device or in the settings of the Application, thereby withdrawing the consent under Article 4.1(b) of the Policy; the lawfulness of processing prior to the withdrawal of consent is not affected. Switching off location sharing is the only privacy setting available in the Application.
5.2The User's location and Check-ins are visible exclusively to Users with whom the User has mutually confirmed friendship. The User's precise location is not public and is not made available to Venues or Organisers; only aggregate and anonymised statistics may be made available to them.
5.3The current location is processed on an ongoing basis for the purpose of displaying the map and friend functions. The history of the precise location is retained only for the period necessary for the functioning of the Application and for ensuring its security, for a maximum of 30 days; after this period it is deleted or anonymised. Check-ins are retained for the duration of the user account or until deleted by the User.
5.4The use of the Application for stalking or monitoring other persons is prohibited and constitutes grounds for blocking the account; in serious cases, the Controller will report the matter to law enforcement authorities.

VI. Recipients of Personal Data

6.1The following are made available to other Users: the User's profile (name or nickname, profile photograph, links to social networks), their location and Check-ins (exclusively to Users with whom they have mutually confirmed friendship), data on participation in Events and on followed Venues (likewise exclusively to confirmed friends) and the content published by the User in the Application.
6.2The Controller may make personal data available, to the necessary extent, to the following categories of recipients:
6.3The Controller shall provide the current list of processors upon request sent to the e-mail address support@heatmapa.com.
6.4The Controller has concluded personal data processing agreements under Article 28 GDPR with all processors. The Controller does not sell personal data or transfer them to third parties for their own marketing purposes.
6.5The Controller is entitled to create from personal data aggregate, statistical and anonymised data, i.e. data that cannot be attributed to a specific User or any other identified or identifiable natural person, even retrospectively with the use of additional information. Data anonymised in this way do not constitute personal data within the meaning of the GDPR (Recital 26 GDPR) and their processing is not governed by the GDPR. The Controller is entitled to use anonymised and aggregated data without restriction, including their use for commercial purposes and their disclosure to third parties, whether for consideration or free of charge, in particular in the form of aggregate statistics on footfall and use of the Application provided to Venues and Organisers. Article 6.4 of the Policy remains unaffected; Users' personal data are not the subject of any trade.

VII. Transfers of Personal Data to Third Countries

7.1Some processors may process personal data outside the European Economic Area, in particular in the United States of America. Such a transfer is based on a European Commission adequacy decision under Article 45 GDPR (the EU-U.S. Data Privacy Framework, where the recipient is certified), or on standard contractual clauses under Article 46(2)(c) GDPR, supplemented where appropriate by additional safeguards.

VIII. Retention Period of Personal Data

8.1Personal data are retained only for the period necessary to fulfil the purpose of the processing, in particular as follows:

IX. Automated Processing and Profiling

9.1The Application personalises the displayed content and recommendations based on the User's location, preferences and previous interactions; recommendations may be generated algorithmically, including with the use of artificial intelligence. This does not constitute automated individual decision-making with legal or similarly significant effects within the meaning of Article 22 GDPR.
9.2Paid highlighting of Venues and Events is always clearly recognisable in the Application.

X. Rights of the Data Subject

10.1In connection with the processing of personal data, the User has the following rights:
10.2The rights under Article 10.1 of the Policy may be exercised by e-mail at support@heatmapa.com. The Controller shall handle the request without undue delay, at the latest within one month of its receipt; in justified cases, this period may be extended by a further two months, of which the applicant will be informed. For the purpose of protecting personal data, the Controller is entitled to verify the identity of the applicant before handling the request.

XI. Security of Personal Data

11.1The Controller has adopted appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or destruction within the meaning of Article 32 GDPR, in particular encryption of data transmission, storage of passwords exclusively in cryptographic form, access management based on the principle of least privilege and regular security updates.
11.2The User acknowledges that no data transmission over the internet can be absolutely secured. The User is obliged to protect their login credentials and device and to report any suspected misuse of their account to the Controller without undue delay.

XII. Processing of Data of Persons Under 18 Years of Age

12.1The Application is intended exclusively for persons over 18 years of age; fulfilment of the age condition is based on the date of birth provided upon registration and the User's declaration. The Controller does not knowingly process personal data of persons under 18 years of age. If the Controller discovers that a user account has been created by a person under 18 years of age, it will cancel the account and delete the related personal data, unless prevented from doing so by a legal obligation.

XIII. Cookies and Similar Technologies

13.1The Application may use device identifiers, third-party software development kits (SDKs) and similar technologies necessary for its functioning, security and analytics. Technologies that are not necessary for the provision of the service are used exclusively on the basis of the User's consent, which may be managed in the settings of the Application or the device.

XIV. Final Provisions

14.1The Controller is entitled to update this Policy, in particular in the event of a change in the scope of the services provided, the range of processors or legal regulations. The User will be notified of material changes in the Application or by e-mail before they take effect. The current version of the Policy is available in the Application and at heatmapa.com/privacypolicy and heatmapa.cz/privacypolicy.
14.2This Policy is drawn up in the Czech language. Any translation into another language is for information purposes only; the Czech version is the authoritative version.
14.3This Policy enters into effect on 23 July 2026.