Privacy Policy

Effective from 1 January 2026 · Last updated 13 September 2026

This Privacy Policy explains how RND20 ("RND20", "we", "us", or "our") collects, uses, stores, and shares information when you use the RND20 mobile application and related services (the "Service").

1. Data Controller

The data controller for the Service is:

DynAgro s.r.o.
IČO: 284 606 77
Address: Lesní 100, 252 28 Vonoklasy, Czech Republic
Email: hello@webnik.cz
Website: rnd20.eu

2. Information We Collect

We collect only the information necessary to provide and improve the Service:

Heart rate is health data and may constitute special-category personal data under Article 9 GDPR. RND20 processes it only on your Apple devices, for the workout feature you explicitly enable, and does not receive it on RND20 servers.

3. How We Use Information and Legal Basis

We use your information for the following purposes and on the following legal bases:

4. Analytics and Notifications

Our website and, where enabled, our mobile and web app use our self-hosted Umami analytics service at s.ventosi.com to understand page visits and product usage. Events describe actions such as starting a workout or opening the Pro screen. App event properties are limited to platform, app surface, app version and build number; screen dimensions and language are also sent. We do not include your RND20 account identifiers, name, email, workout scores, friend identities, payment transaction identifiers or HealthKit samples in these analytics payloads.

The analytics service receives network requests and their connection information. We do not use it for advertising profiles or cross-company advertising tracking. Our website and web-app trackers respect the browser's Do Not Track signal. Notification engagement described below is recorded separately from Umami and is linked to your account.

RND20 offers workout reminders, friend-request alerts and workout-reaction alerts. The app requests your device's notification permission; new accounts have all three in-app notification preferences enabled by default. Device permission is still required for alerts. Change each category independently in Profile → Notifications, or turn off notifications in your device settings. Reminder timing uses your timezone and recent workout times, not GPS location.

We store delivery scheduling, related friend-request or reaction identifiers, provider responses and notification opens to deliver alerts, troubleshoot failures and understand engagement. Social delivery records can be created when a request or reaction occurs, before checking whether an alert will be sent. Turning off alerts does not delete your underlying social activity or existing records.

For workout reminders, we also record a workout start within two hours after opening a reminder and completion of that workout. This helps assess reminder engagement; it does not establish that a reminder caused a workout. We do not use this attribution for friend-request or reaction alerts. Operational test notifications are identified separately from ordinary engagement measurements.

Turning off a category cancels its pending alerts and prevents ordinary future alerts in that category. Turning off all three categories deactivates registered notification devices. An alert already handed to Apple may still arrive. Notification payloads contain generic text, a random notification identifier and an app destination; they do not contain sender identities, workout scores, round counts, heart rate or HealthKit samples. Device tokens are encrypted in our database and are not sent to Umami.

5. Sharing of Information

We do not sell your personal information. We may share information with:

For iOS notifications, RND20 sends your device notification token, generic alert text and a random notification identifier directly to Apple's Apple Push Notification service (APNs). Expo is not a notification delivery provider. Android push delivery is not enabled in the current release. Apple may process notification information outside the European Economic Area. Contact us at hello@webnik.cz for information about the processing locations and international-transfer arrangements applicable to your data.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Specifically:

7. Your Rights

Under the GDPR and applicable data protection laws, you have the right to:

8. How to Exercise Your Rights

You may exercise any of the above rights by emailing us at hello@webnik.cz. We will respond without undue delay and no later than 30 days after receiving your request. In complex cases, we may extend this period by two months and will inform you accordingly.

9. Children's Privacy

The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children under that age. If you believe we have collected data from a child, please contact us so we can delete it.

10. Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is completely secure.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available on this page with the date of the last update. For material changes, we will notify you via email if you have provided one.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at hello@webnik.cz