Privacy Policy
Last updated: 29 July 2026
1. Who We Are
Valkara ("we", "us", "our") is operated by TechniSK s. r. o., a company registered in the Slovak Republic (Company ID: 55109357, Tax ID: 2121871059, VAT ID: SK2121871059), with registered office at Severná 1502/2, 974 01 Banská Bystrica. Contact: privacy@valkara.app
TechniSK s. r. o. is the controller of the personal data described in this policy within the meaning of Art. 4(7) GDPR. This policy covers the website at valkara.app and the Valkara mobile app for Android and iOS, and it is the whole of it — there is no second, internal policy that says something different. Where we say "we do not", we mean we do not do it at all, not that we do it in a way we have chosen not to describe.
Two things are worth knowing before you read the rest, because they shape everything else. First, Valkara works without an account: the core of the app is local to your device, and you can use it having given us nothing. Second, the sensitive data stays on your device — health, fitness, location, your quests and anything you write are stored in the app's own storage and are not uploaded to our servers. What follows explains, honestly and in detail, the narrow set of things that do reach us.
If you only want to know about cookies, jump to section 3. The short answer is that we set none.
2. What Data We Collect
Account Data
- Email address (required for registration)
- Warrior name / username (chosen by you)
- Password (hashed — never stored in plain text)
- Account role (tester / user / admin)
- Early adopter status and registration date
- Referral source (if you registered via a referral link)
Health & Fitness Data
Collected only with your explicit permission, only on the mobile app:
- Steps, distance, floors climbed, heart rate, HRV, resting heart rate
- Sleep data (duration and quality)
- VO2 Max (if available from your device)
- Body weight, body fat percentage, lean/muscle mass and BMI (manual entry, smart scale or health app)
- Calories burned (calculated via MET formula using your weight)
- Age, gender and height (used to estimate your biological age and calorie figures)
Sourced from Apple HealthKit (iOS), Google Health Connect (Android), or manual entry within the app. All health and fitness data is processed and stored locally on your device, and is used only to calculate your biological age and in-app attributes. None of it is uploaded to our servers. If you use the optional social features, only your game stats (such as level and XP) can appear to other warriors; no heart rate, weight, sleep figure or other health metric is transmitted to us, so there is nothing for us to publish even by mistake.
You may see settings in the app for who can view "Health & vitals" or "Body metrics" on your profile. Those controls currently govern nothing, because no such data reaches our servers to be governed. They exist because an opt-in cloud-sharing feature is planned, and we would rather show you the control early than add it quietly later.
Our commitment, stated so you can hold us to it: health and fitness data will not be uploaded unless you switch it on yourself, for that specific category, having been told plainly what it means — and we will update this policy and notify you before such a switch exists, not after. It will never be on by default, never bundled into another setting, and never a condition of using anything. If you would like to be certain it can never happen, do not grant the health permission at all: the rest of the app works without it.
Location Data
Collected only with your explicit permission, only on the mobile app, and only while you are actively recording an outdoor activity session. We use your device location to measure distance, route and pace during a training session. Location is not tracked in the background, is never used for advertising, and is not shared with third parties. You can revoke location access at any time in your device settings.
Microphone and Motion Sensor (sleep monitoring)
Valkara's sleep mode is started by you, for one night at a time, and it ends when you end it or when the wake time you set arrives. While it runs, and only while it runs, the app may use two sensors on your device:
- The microphone — only if you switch it on for that night, and only after the app has explained what it does. It is used to measure how loud the room is, so that snoring and the rhythm of your breathing can be found. No recording is kept. The recorder writes to a scratch file because the operating system offers no other way to read a sound level; that file is replaced every five minutes and deleted immediately, is never opened by the app, and is erased if the app is closed or crashes mid-night. What is written down is a row of numbers per minute: how loud the minute was, how many sound events stood above the room's own quiet, and whether they came at the pace of a breath. No audio is stored, and no audio is transmitted — not to us, not to anyone. There is no speech recognition and no attempt to identify what is being said or who is speaking.
- The accelerometer (motion sensor, which needs no permission on either platform) — used to tell a phone lying still from a phone being held, so that minutes you spent awake with the phone in your hand are not counted as sleep. It records only how much the device moved. It cannot see, and does not record, which app you were using.
Both are processed entirely on your device, and the per-minute figures they produce are stored there in the app's own storage. None of it is uploaded to our servers, and none of it is used for advertising or shared with third parties. You can erase any night from the sleep report, decline the microphone and still use sleep mode, or not use sleep mode at all — the rest of the app is unaffected. On Android, a notification from your system shows whenever the microphone is in use, and your phone's own recording indicator is visible on both platforms.
Profile Photo (optional)
If you choose to set a profile photo, the app accesses your camera or photo library with your permission. The photo is stored locally on your device and is not uploaded to our servers.
What You Write to Other Warriors
If you use the optional social features, the direct messages, guild wall posts and kudos you send are stored on our servers so that the person on the other end can read them. That is the whole purpose, and there is no way around it — a message nobody can retrieve is not a message.
They are not end-to-end encrypted. We say so plainly rather than letting you assume otherwise: they are encrypted in transit and protected at rest by database access controls, but we hold the keys, which means we are technically capable of reading them. We do not. There is no scanning, no profiling, no automated classification, no advertising use, and no human at Valkara browsing conversations. The only circumstances in which anyone here would read a message are a specific report about that specific content, or a lawful order we are obliged to comply with — both described in section 13 of our Terms of Service.
Treat them as you would any ordinary messaging app that is not end-to-end encrypted: fine for arranging a training session, wrong for anything you would not want a court order to reach. Deleting your account deletes these messages for both sides — see our account deletion page for what that means for the other person.
App Usage Data
- Quest completions and streaks
- XP, levels, and attribute progress
- Training session logs
- Achievement records
- Shadow program progress
Device Data
- Device type and OS version
- App version
- Push notification token (notifications only)
- IP address and basic technical logs (recorded by our authentication provider, Supabase, for security and abuse prevention)
Website Data
- Registration and login events
- Referral link usage
- Website analytics — see below
Website Analytics (cookieless)
We measure how the website is used so we can see where visitors get stuck. Neither method uses cookies, and neither identifies you or follows you across other websites. There are two:
Our own measurement. For each interaction we record only: the event (for example a page view, opening the registration form, or starting a download), the page path, the referring website's domain (not the full address), any campaign or affiliate code in the link you arrived through, and whether your screen is phone-, tablet- or desktop-sized. Interactions are grouped by a random identifier created in your browser tab, stored in sessionStorage, and deleted when you close that tab. It is not linked to your account, your email or your IP address.
Vercel Web Analytics. Our hosting provider also provides aggregated visitor statistics — page views, referrers, countries, browsers and devices. It is cookieless and stores nothing on your device; visitors are counted using a temporary identifier derived from request data that rotates daily and cannot be traced back to a person or linked across sites. We see only aggregate counts, never individual visitors. The same provider's Speed Insights feature measures anonymous page-performance timings (how fast pages load) to help us keep the site fast; it likewise sets no cookies and identifies no one.
If your browser sends a Do Not Track or Global Privacy Control signal, our own measurement records nothing at all.
Legal basis: legitimate interest in understanding and improving our own website (Art. 6(1)(f) GDPR). For the separate question of whether storing anything on your device requires consent, see section 3 below.
In-App Crash and Failure Reports
When something in the app breaks — it crashes, or it tells you that an action could not be completed — the app records what went wrong so it can be fixed. This is on by default and you can switch it off in Settings → Version Info → "Report crashes and failures".
Each report contains: the error message and its technical stack trace, a short trail of the steps the app took immediately beforehand (for example award XP → level up → open celebration), the screen it happened on, the app version, your device type and OS version. It does not contain your name, your email, your account, your quests or anything you have written.
Reports are grouped by a reporting identifier — a random value created on your device, not derived from anything about you, and shown to you in Settings → Version Info. It exists so that one fault can be counted across the devices it affects, and so that you can erase your own reports whenever you like: in the app under Settings → Version Info → "Delete my reports", or on our report deletion page without signing in to anything. Switching the reporting off does the same. Reports are written on your device first and sent later, so the app works offline and nothing waits on a network request.
Legal basis: legitimate interest in keeping Valkara working and secure (Art. 6(1)(f) GDPR). You may object at any time using the switch above, which also deletes any reports still waiting to be sent.
3. Cookies, Local Storage and Similar Technologies
Valkara sets no cookies whatsoever — not on the website, not in the app. We run no advertising, no ad network, no social plug-ins, no cross-site tracking, no fingerprinting, and no third-party tag manager. Nothing we store is ever read by another website, sold, or shared for marketing.
We do use two ordinary browser storage areas, and the law requires us to tell you about them in full even where they need no consent. This is the complete list — there is nothing else:
| Name | Where | What it holds | Purpose | Lifetime |
|---|---|---|---|---|
sb-…-auth-token |
localStorage | Your Supabase sign-in token | Keeps you signed in on the dashboard so you are not asked for your password on every page. Set only after you sign in. | Until you sign out or clear your browser storage |
va_sid |
sessionStorage | A random identifier, generated in your browser | Groups the page views of one visit together so we can count visits rather than clicks. Not derived from anything about you or your device. | Deleted when you close the tab |
va_engaged |
sessionStorage | The value 1 |
Records that this visit has already been counted as a real human visit, so automated crawlers do not inflate our figures and you are not counted twice. | Deleted when you close the tab |
referred_by |
sessionStorage | The referral or affiliate code from the link you clicked | Remembers, for the duration of your visit, who referred you, so that the reward you were promised is actually credited when you register. | Deleted when you close the tab |
Why we do not show you a cookie banner
Storing anything on your device is governed by Art. 5(3) of the ePrivacy Directive (2002/58/EC), in Slovakia § 109(8) of Act No. 452/2021 Coll. on electronic communications. It requires that you always be informed — which is the purpose of the table above — and that you consent, unless the storage is strictly necessary to provide a service you yourself asked for. Every item above falls inside that exemption, and we have deliberately built them so that they do:
- The sign-in token exists only because you asked to be signed in, and does nothing else. This is the textbook example of strictly necessary storage.
- The referral code is stored only when you arrive through a referral or affiliate link, and exists solely to deliver the reward that link promised you. It is not used to profile you, is not read on any other site, and is discarded when your visit ends.
- The two measurement values are for first-party audience measurement only. They are generated by us, sent only to us, never combined with any other data set, never used to track you across sites or sessions, never used for advertising or profiling, and never shared with a third party. They produce aggregate statistics about our own pages and nothing else. This is the narrow audience-measurement exemption recognised by the European Data Protection Board and by national supervisory authorities, and we hold ourselves to every one of its conditions.
We are aware that some regulators take a stricter view of analytics storage than others. We would rather be safe than clever, so you also have an unconditional way out that works before you have to trust any of the above: if your browser sends a Do Not Track or Global Privacy Control signal, our measurement never runs at all — no identifier is created, no storage is written, no data is sent. You can also block or clear all site storage in your browser settings; the website continues to work, and only your ability to stay signed in is affected.
If we ever introduce storage that is not strictly necessary — an advertising pixel, a cross-site tag, a third-party analytics script — we will ask for your consent first, through a banner that makes refusing exactly as easy as accepting, and we will not set it unless and until you agree. We have no plans to do so.
The mobile app stores its data in its own private application storage on your device, not in cookies. See section 2 for what that data is.
4. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Provide app and website functionality | Contract (Terms of Service) |
| Calculate biological age | Contract + Consent |
| Send push notifications | Consent |
| Apply early adopter pricing | Contract |
| Process referrals and affiliate commissions | Contract |
| Improve the product | Legitimate interest |
| Find and fix crashes and failures in the app | Legitimate interest (switchable off) |
| Manage subscriptions | Contract |
| Comply with legal obligations | Legal obligation |
We do not sell your data. We do not share it with advertisers. We have never done so and will not begin without telling you first.
No automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22 GDPR, and we do not profile you for advertising. Your level, XP and biological age are calculated arithmetically from what you yourself log; they are features of the product you are using, they decide nothing about you outside the app, and no human or automated judgement about you is made or shared on their basis.
Do you have to give us this data?
Only an email address and a password are required, and only if you want a cloud account — the app's core features work with no account at all. Everything else is optional: if you do not grant health, location, camera or notification permissions, those specific features simply do not operate, and nothing else about the product changes. There is no statutory obligation on you to provide any of it.
5. Where Your Data Is Stored
- Account, authentication and public profile data (email, warrior name, level, XP): Supabase, on AWS infrastructure in Frankfurt, Germany (eu-central-1) — inside the European Union
- Optional social data (leaderboards, guilds and guild wall posts, mentorships, community quests, kudos, feedback): Supabase — only if you choose to use those features
- Direct messages between warriors: Supabase, in the same Frankfurt region. Stored so the person you wrote to can read them, and deleted when either of you deletes their account. See below for who can read them.
- Everything else — your character, quests, goals, tasks, attribute history, health and training data: stored locally on your device (SQLite), never uploaded to our servers
- Crash and failure reports: Supabase (same Frankfurt region), in their own table, never joined to your account
- Payments: when subscriptions are active, they are made as in-app purchases (IAP) through the Apple App Store and Google Play, which act as merchant of record — we never see or store your card details. Valkara is currently free during the testing period.
6. International Data Transfers
Our own database and authentication run on Supabase in Frankfurt, Germany (AWS eu-central-1), so your account data, your public profile and your crash reports are stored inside the European Union. We name the region rather than saying "an EU region" because a claim you cannot check is not worth much.
Some of the providers we depend on are established in the United States, or may process limited data there in the course of operating a global service. Where that happens, the transfer is covered by one or both of the following safeguards under Chapter V GDPR:
- the EU–US Data Privacy Framework, where the provider is certified under it (an adequacy decision of the European Commission, Art. 45 GDPR); and
- Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR), together with the provider's supplementary technical measures.
| Provider | What may leave the EEA | Safeguard |
|---|---|---|
| Vercel (hosting, aggregate analytics) | Request metadata needed to serve the page; aggregate statistics | SCCs / Data Privacy Framework |
| Expo (push delivery, app updates) | Device push token, app-update requests | SCCs / Data Privacy Framework |
| Apple (APNs, App Store) | Device push token; purchase data handled by Apple as merchant of record | SCCs / Data Privacy Framework |
| Google (FCM, Google Play, Health Connect) | Device push token; purchase data handled by Google as merchant of record. Health Connect data stays on your device and is not sent to Google by us. | SCCs / Data Privacy Framework |
| Resend (email delivery) | Your email address and the text of a service email we send you | SCCs / Data Privacy Framework |
Your health, fitness and location data is not part of any of this: it never leaves your device in the first place. You may request a copy of the relevant safeguards at privacy@valkara.app.
7. Data Retention
| Data type | Retention |
|---|---|
| Cloud account & public profile data | Kept while your account is active |
| On-device data (character, quests, health, training) | Stays on your device until you delete it in the app or uninstall — we cannot access or remove it remotely |
| Inactive accounts | Automatically deleted after 2 years with no sign-in |
| When you delete your account | Cloud data is erased immediately; any residual backups are purged within 30 days |
| Crash and failure reports | Deleted after 1 year. A rare fault can take months to explain, which is why these outlive usage data. Erased sooner on request — quote the reporting identifier from Settings → Version Info |
| A registration you started but never confirmed | Deleted after 30 days. You never became a user, so there is nothing to justify keeping the address longer |
| Affiliate applications we do not take forward | Deleted within 12 months of the decision |
| Website measurement events | Deleted after 14 months. They contain no personal data and no identifier that survives your browser tab |
8. Your Rights (GDPR)
If you are in the EU/EEA or the UK, you have the right to:
- Access (Art. 15) — request a copy of your personal data and of the information in this policy
- Rectification (Art. 16) — correct inaccurate or incomplete data
- Erasure (Art. 17) — delete your account and all associated data via our account deletion page
- Restriction of processing (Art. 18) — have us hold your data without using it, for example while a dispute about its accuracy is resolved
- Portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format, or have it sent directly to another provider where technically feasible
- Object (Art. 21) — object at any time to processing based on legitimate interest, including the crash reporting and the website measurement described above
- Withdraw consent (Art. 7(3)) — at any time, for any consent-based processing. Withdrawal does not affect the lawfulness of what was processed before you withdrew.
To exercise any right: privacy@valkara.app. Exercising them is free and we will not ask you why. We will respond within one month of your request, as Art. 12(3) GDPR requires; if a request is exceptionally complex we may extend this by up to two further months, and we will tell you within that first month if we do. We will not charge a fee or refuse a request unless it is manifestly unfounded or excessive, and if we ever take that position we will explain it in writing and tell you how to challenge it.
Your right to complain
If you believe we have handled your data unlawfully, you can complain to a supervisory authority at any time — you do not have to contact us first, although we would like the chance to put it right. Our lead supervisory authority is:
Úrad na ochranu osobných údajov Slovenskej republiky
Hraničná 12, 820 07 Bratislava 27, Slovak Republic
dataprotection.gov.sk · statny.dozor@pdp.gov.sk · +421 2 3231 3214
You may equally complain to the supervisory authority of the EU/EEA country where you live or work, or where you think the problem occurred. If you are in the UK, that is the Information Commissioner's Office (ico.org.uk). You also have the right to an effective judicial remedy under Art. 79 GDPR.
Data protection officer
We are a small company and our processing does not meet the conditions in Art. 37(1) GDPR that would require us to appoint a data protection officer — we do not monitor people on a large scale, and the health data the app handles stays on your device rather than being processed by us. Privacy questions are handled directly by the company at privacy@valkara.app, and that address reaches a person who can act on them. If that ever changes, we will name a data protection officer here.
One of these is worth spelling out, because crash reports are not tied to your account:
- Deleting your crash reports — do it yourself, instantly, in either place: Settings → Version Info → "Delete my reports" in the app, or on our report deletion page using the reporting identifier shown on that same screen. No account and no sign-in are required — Valkara can be used without an account, so neither can the right to erase. Switching "Report crashes and failures" off does the same thing on its way out. Deleting your account does not remove these reports, because the two were never linked. If you no longer have the identifier — you uninstalled the app and kept no backup — then nothing connects those reports to you any more, and they are deleted automatically within a year regardless; under Art. 11 GDPR we are not required to gather more data in order to identify them, and we will not, because that would defeat the point of keeping them unlinked.
9. Health Data (Special Category)
Health and fitness data is a special category of personal data under Art. 9 GDPR, and we treat it as the most sensitive thing the app touches.
The design decision that matters most is this: we never receive it. It is read on your device, calculated on your device and stored on your device, in the app's own private storage. It is not transmitted to our servers, not backed up to them, not visible to us in any support tool, and not included in any analytics or crash report. If our servers were breached tomorrow, no health data of yours would be in them, because none is there.
Within the app it is processed on the basis of your explicit consent under Art. 9(2)(a) GDPR, given through your device's own health permission prompt, and used only to show you your own figures and to calculate your biological age and in-app attributes. It is never used for advertising, never sold, never shared with third parties, and never used to make any decision about you.
You can withdraw that consent at any moment by revoking Apple HealthKit or Google Health Connect access in your device settings; the features that depend on it stop, the rest of the app carries on, and you can delete the data already held by deleting it in the app or uninstalling. If you use the optional social features, only game statistics such as level and XP can appear to other users — no heart rate, weight, sleep figure or other health metric is sent to us at all, so none can be shown. See section 2 for what would have to change before that were ever untrue, and the commitment we have made about it.
10. Affiliate and Referral Data
If you refer other users, or take part in the affiliate program for creators and publishers:
- We store your referral identifier (your warrior name) and the code of anyone whose registration is attributed to you
- We record which referrals were confirmed, so that rewards and commissions can be calculated
- Legal basis: performance of the contract you entered into by joining the programme (Art. 6(1)(b) GDPR)
If you apply to the affiliate program
The application form on our affiliate page collects your name, email address, platform, audience size range and content type. We use it for one thing: deciding on your application and contacting you about it. Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR).
It is not used for marketing, not shared with anyone, and not linked to any Valkara user account you may also hold. Applications we do not take forward are deleted within 12 months; applications that are approved are kept for as long as you remain an affiliate, and then for the period our tax and accounting law requires for the payments made to you. You can ask us what we hold, or ask for erasure, at privacy@valkara.app.
No commission data is shared with anyone. Valkara is free during the testing period, no subscription revenue exists yet, and consequently no affiliate payouts have been made and no payment provider has been engaged. When payouts begin, we will name the provider in this policy and in the table in section 12 before any of your data reaches it, and we will notify affiliates of the change. We would rather leave this paragraph awkwardly specific than list a placeholder recipient you cannot check.
11. Children
Valkara is not directed at children and is not intended for anyone under 16. Slovakia has set the age of consent for information society services at 16 under Art. 8 GDPR, and we apply that limit to every user regardless of country rather than operating a lower threshold anywhere.
We ask you to confirm your age at registration and we do not knowingly collect data from anyone below it. We do not profile users by age, and we do not advertise to anyone.
If you are a parent or guardian and believe a child has created an account, write to privacy@valkara.app. You do not need to prove anything or fill in a form: tell us the account and we will suspend it immediately, delete it and its data, and confirm to you in writing when it is done. If we discover such an account ourselves, we do the same without waiting to be asked.
12. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Supabase | Authentication, database | supabase.com/privacy |
| Apple App Store | In-app purchases / subscriptions (iOS) | apple.com/legal/privacy |
| Google Play | In-app purchases / subscriptions (Android) | policies.google.com |
| Apple HealthKit | Health data (iOS) | apple.com/privacy |
| Google Health Connect | Health data (Android) | policies.google.com |
| Vercel | Website hosting & cookieless aggregate web analytics | vercel.com/legal/privacy-policy |
| Expo (EAS) | Push notification delivery, over-the-air app updates, and hosting the Android APK — the "Download APK" link on our home page redirects to expo.dev, so your IP address and browser reach them when you download the beta build | expo.dev/privacy-explained |
| Apple APNs / Google FCM | Push notification delivery to your device | apple.com/legal/privacy · policies.google.com |
| Resend | Delivery of service emails we send you directly — currently only replies about a bug report you submitted. Your email address and the message reach them for that purpose. Account confirmation and password-reset emails do not go through Resend; those are sent by Supabase. | resend.com/legal/privacy-policy |
Each of these acts as our processor under Art. 28 GDPR, or as an independent controller for its own platform (Apple and Google in respect of App Store and Google Play purchases), under a written agreement. This table is exhaustive: we use no advertising network, no data broker, no customer-data platform and no third-party analytics or session-recording service. There is no affiliate payment provider in this table because we have not engaged one — see section 10.
13. Push Notifications and Email
Push notifications
We send push notifications only with your explicit permission. You can disable them at any time in your device settings. Notification tokens are not used for any other purpose.
Notifications are delivered through Expo's push service and, at the device level, Apple Push Notification service (APNs) on iOS or Google Firebase Cloud Messaging (FCM) on Android. A device push token is shared with these providers solely to deliver your notifications.
We do not send marketing email. There is no newsletter, no promotional campaign, no "we miss you" sequence, and your address is never given, sold or rented to anyone for their own use. If that ever changes we will ask you to opt in first, separately, and you will be able to leave with one click.
The only messages we send are the ones the service itself requires:
| When | Legal basis | |
|---|---|---|
| Confirm your address | Once, when you register | Performance of the contract (Art. 6(1)(b)) |
| Password reset | Only when you ask for one | Performance of the contract |
| Reply about a bug report or feedback you sent us | When we have an answer for you | Performance of the contract |
| Material changes to these terms or this policy, and security incidents affecting you | Rarely, and only when there is something you need to know | Legal obligation (Art. 33/34 GDPR) or legitimate interest |
None of these are marketing, so none carry an unsubscribe link — you cannot opt out of being told that your password was reset or that your data was breached, and it would not be in your interest to. If you want no email from us at all, delete your account and there will be none.
Registration and password emails are sent by Supabase; replies about bug reports are sent through Resend. Both appear in the table in section 12.
14. Security
- Encrypted connections (HTTPS/TLS) on all data in transit
- Supabase Row Level Security — enforced at the database, so an account can read only its own rows even if the client is tampered with
- Passwords hashed with bcrypt — we cannot read your password, and neither can anyone who obtains the database
- Access to production data restricted to the people who need it to run the service
- The most sensitive data — health, fitness, location, your quests and notes — is kept off our servers entirely, which is the strongest security measure available for it
If something goes wrong
No security measure is absolute, and we will not claim otherwise. If a personal data breach occurs, we will notify the Slovak supervisory authority within 72 hours of becoming aware of it as Art. 33 GDPR requires, and we will tell you directly and without undue delay where the breach is likely to result in a high risk to your rights, as Art. 34 requires. We will tell you what happened, what data was involved and what you should do, in plain language and without waiting until we have a comfortable explanation.
15. Changes to This Policy
We will notify you of material changes by email and by in-app notification, before they take effect wherever that is possible, and the "Last updated" date at the top always reflects the most recent revision. If a change would newly require your consent — a new purpose, a new category of data, a new recipient — we will ask for that consent separately and will not rely on your silence. For changes that do not require consent, continuing to use the Service after we have notified you indicates acceptance; if you would rather not accept, you can delete your account at any time on our account deletion page.
16. Contact
Privacy questions: privacy@valkara.app
Account & data deletion: use our account deletion page — sign in and delete your account and data instantly, no request or waiting needed.
TechniSK s. r. o.
Company ID: 55109357 · Tax ID: 2121871059 · VAT ID: SK2121871059
Severná 1502/2, 974 01 Banská Bystrica
Slovak Republic