MyMFA / Privacy
Privacy
policy.
What data MyMFA uses, why it needs it and how you can request its deletion.
Effective and last updated: 15 September 2026
1. Who we are and what this policy covers
MyMFA is developed and the mymfa.cz and mymfa.eu websites are operated by MyOffice s.r.o., company registration no. 29188997, U viaduktu 881/21f, Chrlice, 643 00 Brno, Czech Republic. Contact for privacy questions and deletion requests: info@myoffice.cz.
This policy applies to MyMFA for Android, the iOS app in development, the related authentication service and this website. It describes the current Android pilot and the iOS client in development. Feature availability differs: Android supports local OTP codes and QR scanning; the current iOS prototype does not. Push notifications are not integrated into the current clients. We will update this policy before releasing a version that changes how data is processed.
For business sign-ins, your organisation generally determines the purposes and rules of processing as the data controller. MyOffice may provide operation and support as its processor under a contract and instructions. MyOffice acts as controller for its own website, communications with you and its own test operations. Your organisation's administrator can explain the specific rules for its environment.
2. What data is processed
OTP codes on your phone — Android
When you add an OTP account, the app stores its label, any name or email included in that label, the issuer, secret key and parameters for generating one-time codes. This information is stored in encrypted local storage. MyMFA does not send it to our servers or the account provider. Codes are calculated on your phone. Using a code to sign in to another service is subject to that service's rules.
Device pairing and business authentication
During pairing, the app sends a one-time pairing code, a device label and a public cryptographic key. The server creates a device identifier and an access token. The app keeps the token in protected storage; the server keeps a verification hash of it. The private signing key remains protected on the device.
During authentication, the app receives from the server the organisation and user identity, identifiers for the business account, target system, device, challenge, attempt and session, the expiry time and challenge security parameters. It sends back the challenge identifier, approval or rejection, the entered verification number and a digital signature. The server processes the authentication status and security events. The mobile app does not request or transmit your business account password.
Camera and biometrics
Android requests camera access when you want to scan a QR code. The image is decoded locally; the app does not save it as a photo or send it to a server. The contents of a pairing code may then be used for pairing as described above. You can deny or revoke camera permission in system settings and paste the link manually.
Biometric verification is handled by Android or iOS. MyMFA does not receive fingerprints, facial images or biometric templates. The system allows a protected operation after successful verification. The Android pilot requires supported strong biometrics; the iOS client in development uses system user verification. Protected features cannot be used without the required verification.
Operational data, website and support
When a network connection is made, the server processes the IP address and technical HTTP request data. Operational and security logs may include the time, requested address, request result and client information. When you contact support, we process your email address, message and any information you choose to provide.
The mymfa.cz and mymfa.eu websites do not use analytics or advertising cookies, tracking pixels or forms. Fonts and images are loaded from the website itself. The apps contain no advertising, analytics or automatic third-party crash reporting tools. They do not read contacts, SMS, microphone input, location or the device advertising identifier. FCM and APNs push notification services are not integrated into the apps.
3. Why we use data
Data is used to create and manage pairing, calculate local OTP codes, verify and secure sign-ins, prevent abuse, resolve operational issues and handle your requests. We do not use it for advertising profiles or sell it.
Depending on the circumstances, MyOffice's own processing relies on performance of a contract or steps before entering into one, legitimate interests in service security and handling requests, or a legal obligation. For business accounts, your organisation determines the applicable legal basis. An operating system permission does not itself replace a legal basis under the GDPR.
The authentication system automatically checks whether an approval is valid and correct and may deny access. If you experience problems, contact your organisation's administrator, who can investigate and arrange another approved sign-in method. The service does not create advertising or behavioural profiles.
4. Who can access data
Business authentication data is available to authorised administrators in your organisation and operations or support staff to the extent necessary for their tasks. If a contracted supplier is involved, it may process data only for the agreed purpose, with appropriate protection and confidentiality and under the controller's instructions. Competent authorities may receive data where required by law.
Google Play and the Apple App Store independently process data relating to store accounts, distribution and use of their services under Google's privacy policy and Apple's privacy policy. MyMFA does not send them OTP account contents or approval challenges through advertising or analytics SDKs.
For business deployments, your organisation's controller provides information about the specific hosting, suppliers and any transfers outside the European Economic Area. If the controller arranges such transfers, it must meet the GDPR requirements, for example through an adequacy decision or appropriate contractual safeguards.
Protection in transit and at rest
The app communicates with approved authentication servers over HTTPS with certificate validation. Signing keys are protected by system storage on the device; Android uses an encrypted vault, and the iOS client uses Keychain and Secure Enclave. Automatic app data backup is disabled in the Android pilot; the iOS client does not use iCloud pairing synchronisation. Access to server data is restricted to authorised people.
5. How long we retain data
- Local OTP accounts: until you remove them in the app or clear the app's data in Android. MyMFA automatic cloud backup is not enabled.
- Pairing: local data is retained while the pairing is in use; server registration must be revoked by an administrator. Uninstalling the app alone does not revoke server registration. On iOS, you cannot rely on uninstallation to remove all Keychain items.
- Authentication challenges in the current pilot: a challenge is valid for 90 seconds. Its record becomes eligible for removal from the active state 24 hours after expiry and is removed on subsequent server processing. This rule does not apply to separate audit logs or backups.
- Security audit logs: the default period is 90 days from the event to investigate unauthorised access and handle incidents.
- Routine operational and web logs: 30 days from creation unless required to handle a specific security incident or covered by the regulated regime described below.
- Operational backups of MyMFA data: no more than 30 days from backup creation. After deletion from the active system, data may remain in a separate backup until this period ends. Backups are used only for recovery; previous deletions and access revocations are reapplied during restoration. A security log archive follows its own retention period, not the operational backup period.
- Support communications: while the request is being handled and for 12 months after it is closed.
We set these default periods for MyMFA operations provided by MyOffice. In deployments subject to the higher-obligation regime under Czech cybersecurity law, security and relevant operational logs within the prescribed scope are retained for 18 months from the event, unless a reason for longer retention is documented. This is a specific rule under Section 22(5)(c) of Czech Decree No. 409/2025 Coll.; it does not automatically apply to all data, backups or MyMFA deployments. Where another organisation operates the service, that organisation determines and communicates the specific periods.
At the end of the applicable period, data is deleted or irreversibly anonymised. Only data needed for a specific incident, legal claim or legal obligation may be retained longer, to the extent necessary and while that reason remains. The need for such retention is reviewed on an ongoing basis.
When handling a deletion request, the controller also considers related records and backups. If some data must be retained, you will be told why and for how long, or the criteria used to determine that period. Revoking a device does not automatically delete all historical records.
6. Deleting data and cancelling pairing
MyMFA does not create a separate consumer account with MyOffice. It stores local OTP accounts and allows device registration for existing business access. Follow the procedure for the data you want to delete:
- OTP account on Android: in the Codes section, select the account's Delete account action (in Czech: Odstranit účet) and confirm removal. You can also clear all local data in the system app settings. First arrange an alternative way to sign in to the affected services.
- Business device registration and related server data: ask your organisation's administrator to revoke the registration and delete MyMFA data. You can also contact info@myoffice.cz with the subject “MyMFA — deletion request”. You can submit a request without having the app installed.
Include your organisation, account identifier or contact email, and whether you want to cancel pairing, delete data or both. Do not send your password, OTP secret, pairing QR code or access token. Where necessary, we will verify your identity in a proportionate way; requests for data controlled by your organisation are handled with its controller. Cancelling pairing does not delete your employer's business account or an account with another service.
We respond to GDPR requests without undue delay, generally within one month. If the law allows an extension due to the complexity or number of requests, we will explain the reasons within that period.
7. Your other rights
Subject to the GDPR, you may request access to your personal data, rectification, erasure, restriction of processing and portability. You may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. Send your request to your organisation's controller or to info@myoffice.cz.
You also have the right to lodge a complaint with the Czech Office for Personal Data Protection or another competent supervisory authority.
8. Children and changes to this policy
MyMFA is intended for account security and business use and is not directed at children. When features, processed data or recipients change, we will update this policy and its revision date. We will communicate material changes in the app or through the service administrator as appropriate to their nature.