1. Parties and roles
The school is the controller: it determines the purposes and means of processing. DojoPro is the processor: it processes personal data on the school's behalf and only on its documented instructions, including as regards international transfers.
Permitted processing: DojoPro processes the data only to provide the service to the school, on its behalf and on its instructions: hosting it, backing it up, protecting it and giving the support the school asks for. It does not sell it, does not pass it on, and does not use it for advertising, to train models or for any purpose of its own. It uses only aggregated, anonymised metrics that identify no person and no school.
If DojoPro believes an instruction infringes applicable law, it will tell the school without delay and may suspend that instruction until the point is resolved.
2. Subject matter, duration and scope
| Item | Detail |
|---|---|
| Subject matter | Provision of the DojoPro martial-arts school management software |
| Duration | For as long as the subscription is in force, plus the published retention periods |
| Nature and purpose | Hosting, storage, retrieval, modification and deletion of data in order to manage students, classes, attendance, tuition and communications |
| Categories of data subjects | Students (including minors), guardians, instructors, administrative staff |
| Categories of data | Identity and contact details, date of birth, attendance, technical progression, financial and payment data, messages and posts, and — only with explicit consent — health data and images |
3. Division of obligations
| Obligation | Owner |
|---|---|
| Lawful basis for enrolling and processing a student's data | The school |
| Collecting guardian consent | The school, through the interface we provide |
| Verifying the guardian relationship | The school |
| Asking for acceptance of the current texts and express consent to the transfer to the United States | DojoPro, at sign-up and on a screen that blocks access until it is answered; each adult gives it and, for a minor, the adult who enrols them or, on that screen, their verified guardian |
| Answering access, rectification and erasure requests | The school, which receives the request and passes erasure requests to DojoPro; DojoPro carries them out, and forwards to the school the same day any request it receives directly |
| Deciding what data is entered, what it is used for and who on staff has access, and the use the school's staff make of the data, on and off the platform | The school |
| Telling the people affected by a breach and, where appropriate, the supervisory authority | The school; DojoPro notifies the school without undue delay |
| Database security, backups and access control | DojoPro |
| Purging data when the published retention periods run out | DojoPro, automatically and daily |
| Registering the database in the Registro Nacional de Bases de Datos, where required | Each party, for its own database |
4. Confidentiality
Every member of DojoPro staff with access to personal data is bound by a confidentiality duty that survives the end of their employment or engagement, in line with arts. 9 and 10 of Ley 25.326. Platform-level access is reserved to the people on a closed list, and revoked when they leave that role.
That access is technically broad: it reaches every school's data, health records included. DojoPro uses it only for support the school asks for, to deal with a security problem, or to meet a legal obligation. Every read of a health record made through the application goes into the audit log, including reads by DojoPro staff.
5. Security measures
Technical and organisational measures in place today:
- Encryption in transit (TLS) across the application and to the database.
- Passwords stored as bcrypt hashes; never in clear text.
- Payment receipts, fitness certificates, scanned consent forms and message attachments in private storage, reachable only through short-lived signed links issued after a permission check. Profile pictures and the school's and instructors' logos are stored at a public address that is hard to guess but visible to anyone who has the link.
- A single visibility gate per student, crossed by every read of the health record and the sensitive data hanging off it.
- Role- and location-scoped access: staff see their school, an instructor their own group, a student only themselves, and a guardian their child — the health record only on a verified link.
- Isolation between schools at the query level, with scope filters applied on the server and never in the browser.
- An append-only audit log: every read and change of a health record, every guardian access to a minor's data — granted or refused —, every change to a guardian link, and every data export or erasure is recorded with who and when.
- Sessions that expire after 24 hours of inactivity; a role change, a revoked guardian link or an erasure invalidates the affected sessions within minutes.
- An automatic daily purge of data whose retention period has run out, including its files.
- Backups managed by the database provider, with point-in-time recovery.
Committed improvements not yet implemented, stated here because a school deserves to know before signing: column-level encryption of the health record, and tools for a school to export or delete all of its data by itself (today DojoPro's team does it from the admin area, on request).
6. Subprocessors
The school gives general authorisation for the subprocessors published on the Subprocessors page. DojoPro imposes on them by contract obligations no less strict than those in this agreement, and remains liable to the school for their performance.
Any addition or change is announced at least 30 days in advance, with a right to object on reasoned grounds and, where no reasonable alternative exists, a right to terminate without penalty.
7. Assistance to the controller
DojoPro assists the school, as far as reasonable and taking into account the nature of the processing, to: handle data subject requests; meet its security, breach-notification and impact-assessment duties; and provide the information needed to demonstrate compliance.
If a data subject contacts DojoPro directly, we do not answer on our own account: we forward the request to the school without delay — the same day we receive it — and tell the person we did. The statutory deadlines run from the day the school receives the request.
When the school passes us an erasure request — for a student, an account or the whole school — DojoPro's team carries it out, and we tell the school what was deleted, what was kept and why.
8. Security incidents
DojoPro will notify the school without undue delay — targeting 24 hours — from becoming aware of an incident affecting personal data processed on its behalf.
The notification will contain what is known at the time: the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken and a contact for follow-up. Information is completed as the investigation progresses.
Argentine law sets no deadline today for telling the authority or the people affected about a breach. What is communicated, and to whom, is the school's decision as controller; our commitment to notify it without undue delay is there so it can act in time.
9. International transfers
Data is hosted in the United States: the database with Neon, on AWS (us-east-1), and the application and files with Vercel. This is an international transfer under art. 12 of Ley 25.326, to a country that is not among those the Argentine authority considers to offer an adequate level of protection (Disposición DNPDP 60-E/2016). The transfer rests on each data subject's express consent (art. 12 of Ley 25.326 and its regulation in Decreto 1558/2001). DojoPro asks for it at sign-up and, from anyone who already had an account, on a screen that blocks access until they answer, together with acceptance of the current texts, and records it per person and per version of the texts. For a minor it is given by their guardian: the one who enrols them and, on that screen, the one whose link the school has verified and who has full authority; a minor with their own access is not asked. The service cannot be provided without that hosting: whoever does not consent is signed out, and if they ask for their data to be deleted, the request follows the path in section 7. The data processing agreements DojoPro has signed with each provider, which require them to process the data only on our instructions and with security measures, are an additional safeguard. DojoPro has not yet signed with them the model contract for international transfers for the provision of services approved by that Disposición (Annex II); it is assessing it, within the pending legal review, as a safeguard complementary to consent, and will tell the school if it signs it. The school, as controller, has to tell its students and families that their data is hosted in the United States; the Privacy notice and the consent screen already say so.
10. Audit
DojoPro will make available to the school the information needed to demonstrate compliance with this agreement and will allow audits, including inspections, by the school or an auditor it appoints, on reasonable notice, during business hours, once a year unless an incident justifies another, and subject to confidentiality.
11. Return and deletion
On termination the school chooses between the return of its data in a structured, commonly used format, or its deletion, and may ask for either up to 90 days after cancellation. DojoPro's team carries out either one from the admin area, within 30 days of the request, and a deletion always starts by handing the school a full copy of its data. Absent instruction, DojoPro deletes the data from active systems 90 days after cancellation.
What the law requires us to keep is excepted — payments, anonymised and without their free-text notes, and consent records, for 10 years; issued invoices and receipts, as issued — and is kept for the statutory period and for that purpose only. Each branch remains as an empty, closed record those records point to. Before deleting anything, DojoPro cancels at MercadoPago the school staff's subscriptions that could still charge and waits for its confirmation. Backups are managed by the database provider: they delete themselves when its retention period runs out and are not restored selectively.
12. Term and precedence
This agreement applies from a school's onboarding and for as long as data is processed on its behalf. Where it conflicts with the Terms of service on a data-protection matter, this agreement prevails.
A school that needs a signed copy, or a negotiated version of this text, can ask us at the address in the footer.