Privacy Policy
Effective: July 9, 2026
Version: 1.1
1. Who processes your data
The controller of personal data is:
Matheo Academy s.r.o.
Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
Company ID: 29537126
Registered file: C 151267, Regional Court in Brno
Contact e-mail: hello@matheo.academy
2. What data we process
Depending on how you use our services, we process the following categories of data:
Identification and contact data: name, surname, e-mail address, and optionally the name of a school or organisation.
Payment data: subscription details (type, duration, payment method) and billing details. We do not process payment card details ourselves. Invoices are issued via the Fakturoid service and payment is made by bank transfer; if card payment is available, it goes through the Stripe secure payment gateway, which acts as a separate controller.
App usage data: records of which exercises a child has completed, results, progress, and time spent in the app. This data is used to show progress to parents and teachers, and to adapt content to the child’s level.
Technical data: IP address, device type, browser, language, and information about visiting the website (cookies: see the separate Cookies Policy).
Communication: the content of e-mails you send us (questions, support, feedback).
3. Purposes and legal bases of processing
We process your data for the following purposes:
Providing the service (legal basis: performance of a contract under Article 6(1)(b) GDPR)
- Creating and managing the user account
- Granting access to subscription content
- Tracking a child’s progress in the apps
- Communication regarding the service
Accounting and tax obligations (legal basis: compliance with a legal obligation under Article 6(1)(c) GDPR)
- Issuing invoices and storing accounting records
Improving the service (legal basis: legitimate interest under Article 6(1)(f) GDPR)
- Analysing app usage in an aggregated, anonymised form
- Aggregated analysis of website traffic (Cloudflare Web Analytics, cookie-less)
- Resolving technical problems and improving the user experience
Marketing (legal basis: consent under Article 6(1)(a) GDPR)
- Sending news about apps and content, only with your consent, which you may withdraw at any time.
4. How long we keep the data
- Active account data: for the duration of the subscription and 12 months after it ends, to allow a return without loss of progress
- Accounting records: 10 years under Act No. 235/2004 Coll. on VAT
- Communication: up to 3 years from the last contact
- Marketing consent: until it is withdrawn
After these periods, the data is securely deleted or irreversibly anonymised.
5. To whom we transfer the data
We pass data only to processors who help us run the service, and always with appropriate contractual arrangements (processing agreement, technical and organisational measures):
- Hosting and infrastructure providers (Cloudflare Workers)
- Database and authentication (Supabase): account data is stored in the EU
- Invoicing service (Fakturoid)
- Transactional e-mail delivery (Resend): invitations, password resets, invoices
- Payment gateway (Stripe): only when paying by card
- Tools for e-mail communication and support
- Analytics (Cloudflare Web Analytics): aggregated and anonymous traffic measurement without cookies and without identifying visitors (see Cookies).
Some processors may be located outside the EU/EEA (especially in the USA). In such cases we require GDPR safeguards, Standard Contractual Clauses of the European Commission, or other equivalent instruments.
We never sell your data to third parties for advertising purposes.
6. Protection of children
Our apps are designed for primary-school children. We take this responsibility seriously:
- A user account with Matheo Academy is always created by a legal guardian or a school. A child under 15 does not create one on their own.
- We follow the principle of data minimisation; from children we collect only the data necessary for learning to function (name or nickname, exercise results).
- We do not store location, photographs, or biometric data.
- We do not perform behavioural profiling for advertising purposes.
- We do not use children’s data for marketing.
If you discover that we are processing a child’s data without the legal guardian’s consent, contact us at hello@matheo.academy. We will remove it without undue delay.
7. Your rights
In relation to your personal data, you have the following rights under GDPR:
- Right of access: to know what data we process about you
- Right to rectification: to have inaccurate data corrected
- Right to erasure: to have data deleted, if no other legal reason for keeping it applies
- Right to restriction of processing in certain situations
- Right to data portability: to receive your data in a structured, machine-readable format
- Right to object to processing based on legitimate interest
- Right to withdraw consent at any time, where processing is based on consent (withdrawal has no retroactive effect)
- Right to lodge a complaint with a supervisory authority: the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), www.uoou.cz
To exercise these rights, contact us at hello@matheo.academy. We will handle your request without undue delay, no later than 30 days.
8. Security
We process data with appropriate technical and organisational safeguards: encrypted connection (HTTPS), secure storage, restricted access for authorised persons only, regular backups, and system updates.
9. Changes to the policy
We may update this policy from time to time. The current version is always available on this page with the effective date stated. If substantial changes occur, we will notify you by e-mail.
10. Contact
For any questions regarding the processing of personal data, contact: