Legal document · Personal data protection

Privacy policy

(also the „Policy“)

The purpose of this Policy is to give you comprehensive and comprehensible information about how, to what extent, for what purpose and for how long we process your personal data, which you or another person provided to us when registering in the Mo.one app and in the related contractual relationship, during that relationship, or which we obtained in another lawful way, and to inform you of your individual rights in connection with the processing of personal data we carry out. If anything about the information provided or the description of the processing is unclear to you, contact us using the contact details below and we will be glad to explain the terms and descriptions used.

Unless stated otherwise, the terms and definitions used in this Policy have the meaning set out in our General terms and conditions.

1) CONTROLLER OF PERSONAL DATA

The controller of your personal data is Mo.one a.s., company ID: 020 13 517, with its registered office at Palackého třída 3048/124, Královo Pole, 612 00 Brno, registered in the Commercial Register kept by the Regional Court in Brno under file No. B 9099 (the „We“ or the „Controller“).

Please direct any questions to us by e-mail at: info@mo.one, or by post at: Palackého třída 3048/124, Královo Pole, 612 00 Brno.

The Controller is entitled to transfer the Application or its administration to another entity. In such a case the Controller will ensure that this entity is bound, in administering or processing personal data, at least to the extent of the obligations under this Policy.

2) WHAT DATA ABOUT YOU DO WE PROCESS AND HOW DO WE OBTAIN IT?

The nature of the personal data we process about you depends on the occasion on which the data was obtained, the form in which it was obtained and the purpose for which it is processed. We process different data where you are our client as a Merchant and different data about you where you are a consumer.

The data we process about you:

  • Identification data. In particular your first name, surname, title, sex, date of birth, birth number, residence, nationality, place and country of birth, identity document number, a photocopy of your identity document, signature and politically exposed person status. If you are a business, also the company ID and the address of the registered office or place of business.
  • Contact data. Above all your permanent address, residence, postal address, e-mail address, telephone number and other data allowing us to get in touch with you.
  • Data on the products and services arranged. This is data on which of our services you use.
  • Data from our communication. This means above all records of any telephone conversations, e-mail and other communication or interaction between you and us, and information about the use of our websites and applications, including your IP address.
  • Transaction data. This means in particular the numbers of your bank accounts (which you connect to our Mo.one app) and the balances on those accounts. This is necessary for providing payment initiation services and the account information service.
  • Authentication token (OAuth token). An OAuth token is a security key which, with your consent, allows us to find out the balance of your bank account and display it in the Application, and to initiate payments from your bank account, that is, to provide the payment initiation service. It does not contain your password or sensitive data, it expires automatically and it is protected by encryption. We keep it only for the necessary period.
  • Other data. For example age, data obtained from the internet browser you use or on the basis of storing cookies, or data you provide to us while using the mobile application, including geolocation data.

3) SOURCES OF THE PERSONAL DATA WE PROCESS

We obtain personal data first and foremost directly from you. We also use information you publish about yourself or which we obtain about you from publicly available sources (for example from public lists and registers, internet applications, social networks, websites and other public information sources). We do not carry out profiling.

4) ON WHAT BASIS AND FOR WHAT PURPOSES DO WE PROCESS YOUR DATA?

In most cases we do not need your consent to process your personal data; processing it to the necessary extent is permitted to us directly by legal regulations (above all so that we can provide you with the service you request or fulfil our legal obligations arising from special regulations), and by the pursuit of our legitimate interests. In other cases we process your personal data only on the basis of your prior consent.

Where you communicate with us by e-mail, please note that this is not a secure communication channel. We therefore assume responsibility for the protection of your data only once it is received on our mail server.

We process your personal data on the following legal grounds:

  • Providing services: processing personal data is necessary for providing services through the Mo.one app, including managing user accounts and ensuring communication with users.
  • Performance of a contract: processing is necessary for performing contractual obligations between us and data subjects.
  • Compliance with legal obligations: we process personal data in line with legal regulations, in particular in the areas of accounting, taxes and protection against money laundering.
  • Protection of legitimate interests: processing personal data is necessary to protect the legitimate interests of the Controller, for example in recovering receivables, protecting against fraud or ensuring the security of the Mo.one app.
  • Improving services: the Controller processes data in order to analyse and improve the functionality of the Mo.one app and the user experience.

We process personal data on the following legal bases:

  • Performance of a contract: processing personal data is necessary for performing the contract you concluded with the Controller.
  • Legal obligation: processing personal data is necessary for fulfilling the legal obligations that apply to the Controller.
  • Consent: where consent is required for processing personal data, that consent will be obtained from you in advance and can be withdrawn at any time, without affecting the lawfulness of processing before its withdrawal. Not giving consent, or withdrawing it, has no consequences for the contractual relationship between you and the Controller.
  • Legitimate interests: processing personal data is necessary for the purposes of the legitimate interests of the Controller, where those interests are not overridden by the rights of the data subject.

5) DO YOU HAVE TO PROVIDE US WITH YOUR DATA?

Data for whose processing we need your consent is provided by you voluntarily – you can therefore refuse to provide it without any effect on the contractual relationship between the Controller and you. This concerns above all data processed for marketing purposes.

In cases where we do not require your consent to process personal data, providing the personal data is mandatory. We need your personal data in order to meet our commitments and our obligations arising from legal regulations, or in order to protect our legitimate interests. This concerns above all identification and contact data.

6) PERIOD FOR WHICH PERSONAL DATA IS KEPT

We keep data only for the period strictly necessary to achieve the purposes for which it was collected, or for the period set by the relevant legal regulations. After that period the personal data will be securely erased or anonymised.

7) TRANSFER OF DATA TO THIRD PARTIES AND INTERNATIONAL TRANSFERS

The Controller does not transfer personal data to third parties, except where it is necessary for providing services, complying with legal obligations or protecting rights and property. In those cases personal data may be made available in particular to:

  • providers of technical infrastructure and hosting,
  • banks and other financial institutions in connection with payment services,
  • providers of IT, communication and analytical services,
  • external advisers and auditors, to the necessary extent,
  • public authorities, where required by legal regulation.

If it is necessary to transfer personal data outside the European Union or the European Economic Area, we will ensure that the transfer takes place in line with applicable legal regulations and that an adequate level of protection of personal data is ensured. This may include the use of standard contractual clauses approved by the European Commission.

8) PROTECTION OF PERSONAL DATA

The Controller uses appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and destruction. These measures include appropriate methods of protecting data, access control and regular training in personal data protection.

9) YOUR RIGHTS IN CONNECTION WITH THE PROCESSING OF PERSONAL DATA

  • Right of access: you have the right to request information about what personal data the Controller processes about you and to obtain a copy of that data.
  • Right to rectification: if you find that the personal data the Controller processes about you is inaccurate or incomplete, you have the right to request its rectification.
  • Right to erasure: you have the right to request the erasure of personal data the Controller processes about you, where it is no longer needed for the purposes for which it was collected, or where it has been processed unlawfully.
  • Right to restriction of processing: You have the right to request restriction of the processing of personal data in a situation where:
    • you have contested the accuracy of the personal data (processing will then be restricted for the period we need to verify its accuracy),
    • the processing is unlawful and you do not want erasure,
    • we no longer need the personal data for the purposes of processing, but you require it to establish, exercise or defend your legal claims,
    • you have objected to the processing and it is being verified whether our legitimate grounds for processing override yours.

    Even where processing is restricted, we will still be able to process your personal data in cases where this is needed to establish, exercise or defend our legal claims or to protect the rights of other natural or legal persons, or where we have your consent to the processing in question.

  • Right to data portability: you have the right to receive the personal data you provided to us in a structured, commonly used and machine-readable format and to pass it to another controller.
  • Right to object: you have the right to object at any time to the processing of personal data that is based on the legitimate interests of the Controller.
  • Right to withdraw consent: where the processing of personal data is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

10) AUTOMATED DECISION-MAKING AND PROFILING

The Controller does not carry out automated decision-making, including profiling, that would have legal effects on you or otherwise significantly affect you. If we were to start using automated decision-making, you will be informed in advance and given the opportunity to object or to request human intervention.

11) CHANGES AND UPDATES TO THE POLICY

The Controller reserves the right to change this Policy at any time. In the event of substantial changes we will inform you through the Mo.one app or by e-mail. In your own interest, however, we recommend checking this Policy regularly so that you are informed about how the Controller protects your personal data.

12) CONTACT AND SUBMITTING A COMPLAINT

You can contact us about any questions, comments or complaints concerning the processing of your personal data by e-mail at info@mo.one. Data subjects also have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection (ÚOOÚ), with its registered office at Pplk. Sochora 27, 170 00 Praha 7, company ID 70837627.

13) FINAL PROVISIONS

This Policy takes effect on 6 November 2025 and remains in effect until replaced by a new privacy policy. All changes will be published through the Mo.one app.

Mo.one a.s., with its registered office at Brno, Palackého třída 3048/124, Královo Pole, 612 00 Brno, company ID: 02013517, file No. B 9099 kept by the Regional Court in Brno, mo.one · In effect from 6 November 2025 · PDF version