1. Who decides about your data
The school where you train is the data controller: it decides what data it asks for, what it uses it for, and for how long, within what the law allows. DojoPro is the data processor: we provide the software and process the data on the school's instructions.
DojoPro processes the data the school enters only to provide the service to it, on its behalf and on its instructions: to host it, back it up, protect it and support you when you ask. We do not sell it, we do not pass it on, and we do not use it for advertising, to train models or for any purpose of our own. The only thing we use is aggregated, anonymised metrics that identify no one.
In practice this means that if you want to access, correct or delete your data, you ask your instructor or your school: they handle it or, when needed, contact our team, which carries it out. If you write to us directly at the address in the footer, we pass it to your school the same day and tell you we did.
The relationship between the school and DojoPro is set out in our Data processing agreement, which is public and part of this same set of documents.
2. What data we process
We ask for what a school needs to run, and nothing beyond it. The ordinary data is:
- Student identity and contact details: name, email address, phone number.
- Date of birth. It is the fact that makes every rule about minors enforceable: without it, the system cannot tell a seven-year-old from a forty-year-old.
- Identity and contact details of at least one guardian when the student is a minor, plus the declared relationship (mother, father, legal guardian, other).
- Class attendance, and belt and level progression.
- Tuition, payments, dates and payment receipts.
- Training objectives, chosen from a fixed list (self-defence, fitness, competition, discipline, stress relief, community, weight loss, fun). There is no free-text field.
- Emergency contact and the people authorised to collect the student.
- Messages with the school's staff and posts in the location's forum.
Account data: if you have portal access, we also hold your username, the hash of your password (never the password itself) and your profile picture.
3. What we only process with your explicit consent
Some data is not collected merely because someone enrolled. Each item is asked for separately, starts as NO, and can be withdrawn at any time without losing your place in class.
- Health data: allergies, medical conditions, medication, injuries, physician and authorisation for emergency care. This is sensitive data (art. 7 Ley 25.326). The step is skippable: leave it blank and the registration still completes, with no health data stored at all.
- Internal image use: a profile photo visible to the school's staff inside the system.
- External image use: publication on the school's social media, non-commercial.
The two image checkboxes are separate on purpose. Schools tend to treat them as one thing and families do not: agreeing that the school may keep a photo on file is not the same as agreeing that it may post it on Instagram.
4. What we never ask for
Neither in a form field nor in free text: racial or ethnic origin, religion, political or philosophical opinions, trade-union membership, sexual orientation or sex life, criminal records.
Nor biometric data of any kind. There is no face-recognition, fingerprint or voice check-in, and there will not be. If we ever automate attendance, it will be with a rotating QR code or a PIN, which solve the same problem without creating an irreversible fact about a child.
The system's free-text fields (instructor notes, progress observations, reason for an absence) are labelled so staff do not record health, family or legal information there. If it appears anyway, we treat it with the same care as special-category data.
5. What each piece of data is used for, and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Enrolling the student and running the relationship with the school | Identity, contact, date of birth, location | Performance of the contract (with the guardian, where the student is a minor) |
| Recording attendance, belts and progress | Attendance, belt, level, assessments | Performance of the contract |
| Charging and crediting tuition | Amounts, dates, receipts | Performance of the contract and accounting duties |
| Announcing class changes, cancellations and school events | Contact details, class enrolment | Performance of the contract |
| Acting in a training emergency | Health data, emergency contact | Explicit consent, and vital interests where the person cannot consent |
| Showing a photo on the student's record | Image | Consent (internal use) |
| Publishing photos or video on the school's social media | Image | Consent (external use) |
| Hosting the data in the United States (section 13) | All data in the system | Express consent (art. 12 Ley 25.326) |
| Sending promotions or commercial news | Contact details | Prior opt-in consent, and never to minors |
6. Minors
Anyone under 18 needs a guardian on file, verified by the school. That adult grants or withdraws the health and image consents, and exercises the rights listed below.
Acceptance of this notice and of the Terms, and consent to hosting the data in the United States (section 13), are also given for the minor by their guardian: at enrolment, the adult who enrols them; afterwards, when a new version requires it, the adult whose link the school has verified and who has full authority over the child. A minor with their own portal access is not asked.
Requests about a minor's data — access, correction or erasure — are made by their guardian, who listens to the child's own view and gives it weight according to their age and maturity (Ley 26.061, arts. 3 and 24).
A minor does not create their own account at enrolment. From age 14, the guardian may grant them portal access to see their classes, attendance and progress. When that happens we tell the child on first sign-in, in plain words: the guardian still sees everything, including their messages. Watching someone without their knowledge is wrong, and it also fails the transparency duty.
A minor can never edit their health data, change who their guardian is, or touch payments.
At 18 the person decides for themselves. The school has to ask them to re-affirm their consents in their own name and to choose which adults keep access; in the meantime they can ask the school at any point to remove an adult's access. When in doubt, less access, not more.
Minors' data is never used for commercial or advertising purposes.
7. How we record consent
Every decision — granting, refusing or withdrawing — is stored as a new record, with the date, who took it, in what capacity (yourself, a guardian, or school staff entering a signed paper form) and the exact version of this notice that was on screen at the time.
Acceptance of this notice and of the Terms, and consent to hosting the data in the United States (section 13), are recorded the same way: each separately, per person, with the version that was accepted.
We never modify or delete an earlier record. Withdrawing adds a new entry; the previous one stays, because it is the evidence that what was done until that day was lawful. Withdrawal is not retroactive, but it stops the use going forward.
When we change this notice materially, earlier consents keep pointing at the old version — which is exactly how we know who has to be asked again. The next time those people sign in, we show them a screen asking them to accept the new version before they can keep using the app.
To withdraw a consent, ask the school, or write to the address in the footer. It has to be as easy as granting it, and it is.
8. How long we keep each thing, and how to ask for erasure
You can ask at any time for your data to be deleted. Ask your instructor or your school: they contact our team, which carries it out. If you write to us directly at the address in the footer, we pass it to your school the same day. The request is resolved within 5 business days of the school receiving it. We keep only what the law requires us to keep — accounting records and consent records — plus the access log that shows how your data was handled, and we tell you what was kept and why. Backups delete themselves when our database provider's retention period runs out, and are not restored selectively. If the student is a minor, the request comes from their guardian, who listens to the child's own view.
What is deleted depends on what is being removed:
- A student. Deleted on the spot: the health record, instructor notes, progress assessments, the people authorised to collect them, their files (payment-receipt images, the fitness certificate, the profile photo and message attachments), the messages they sent and received, and their forum replies and topics; a topic others have already answered is emptied and loses its author. The guardian's details are deleted too when they have no other child at any school and no account of their own. Name, email, phone and date of birth are replaced by an identity-free marker. Deleting a student from the school's roster is this same, complete erasure.
- What is kept of an erased student: payments, anonymised and without their free-text notes (amounts, dates and statuses), for 10 years; attendance and belt history, without their name, until its period runs out; invoices and receipts already issued, exactly as issued, because they are tax documents and carry the student's name; and, in full, the consent records (including scanned paper forms), the access log and the record of the erasure itself. It does not reach what other people wrote about the student, nor the guardian's own messages: those expire after 24 months or are deleted at the request of whoever wrote them.
- An account. Our team deletes it. The profile photo, messages and their attachments, forum posts and open sessions are deleted, and the user is anonymised, with no way to sign in again. If the account is a student's, the erasure above applies. If it is a guardian's, their links to the children and their pickup authorisations are deleted and their details anonymised; the children's records are untouched, and if a child is left without a guardian, the school follows up. If it is an instructor's, their logo, class assignments, branch memberships and pay settings are deleted, and what they were paid is kept, anonymised and without its notes, for 10 years. If they have a DojoPro subscription that could still charge — active, paused, or with its MercadoPago sign-up unfinished — we first cancel it at MercadoPago, and the deletion does not go on until MercadoPago confirms; then any payer data we had stored is deleted, and the subscription history (amounts, dates and statuses) is kept for 10 years without identifying anyone.
- A whole school. Our team deletes it, always after handing the school a full copy of its data. First the staff's DojoPro subscriptions that could still charge are cancelled at MercadoPago, as in an account deletion, and nothing else is deleted until MercadoPago confirms. Then every student is erased as described above; the accounts of guardians left with no child and of staff who worked only at that school are deleted; and so is all of the school's content: classes, events, announcements, products, plans, forum and invitations. Each branch remains as an empty, closed record. Payments are kept anonymised and without their free-text notes, and consent records in full, for 10 years; issued invoices and receipts, as issued.
| Data | Retention | Why |
|---|---|---|
| Health record and fitness certificate | Deleted on departure, with a 90-day grace period | There is no reason to keep a former student's allergies |
| Instructor notes and progress assessments | 24 months | Free text, highly sensitive, of little value once cold |
| Reasons given for an absence | 12 months | They age out fast and often contain health information |
| Attendance and belt history | 5 years | It is the one thing a returning student actually needs |
| Payments (amounts and dates) | 10 years | Commercial record-keeping duty (art. 328 CCyC, Argentina) |
| Attached payment receipts | 24 months | The image is not the record; the ledger entry is |
| Messages and forum posts | 24 months | — |
| Consent records | 10 years, never deleted | They are the evidence that everything else was lawful |
| Access log (who opened or changed which data, and when) | 24 months | It lets us reconstruct who saw or changed a piece of data |
| Sessions and sign-in data | 90 days | — |
The periods in the table run from the day the student leaves the school, except for absence reasons, receipts, messages, sessions and the access log, which run from the day each record was created. When a period runs out, the system purges that data on its own, every day, including its files: receipt images, message attachments, and the fitness certificates of people who left more than 90 days ago.
9. Who we share it with
We do not sell personal data, and we do not hand it to third parties for advertising. Ever.
The infrastructure providers we need in order to run the service are listed — with their role, the category of data they touch and their region — on the Subprocessors page. That list is versioned: we give notice before adding one.
Beyond that, we only disclose data when a competent authority requires it through a valid legal route, and in that case we tell the school unless the law forbids it.
10. Your rights, and how fast we answer
You can request access to your data, its rectification, its update, its erasure, restriction of or objection to certain processing, and portability of what you provided. Where the student is a minor, the guardian exercises these rights.
We answer within the deadlines of Ley 25.326: 10 calendar days for access (art. 14) and 5 business days for rectification, updating or erasure (art. 16).
You make the request to your instructor or your school, which is the controller: they handle it or, when needed, contact our team, which carries it out. The deadlines run from the day the school receives the request. If you write to us directly at the address in the footer, we pass it to your school the same day and confirm that it arrived.
If you get no answer in time, or the answer does not satisfy you, you may complain to the Agencia de Acceso a la Información Pública (AAIP), the supervisory authority under Ley 25.326.
11. Security and incidents
Passwords are stored hashed (bcrypt), and every read of a student's record passes through a single permission check: school staff see their students, an instructor sees their own, a student sees themselves, and a guardian sees their child — the health record only once the school has verified the relationship in person.
Payment receipts, fitness certificates, scanned consent forms and message attachments live in private storage, reachable only through short-lived signed links issued after a permission check. Profile pictures and the school's and instructors' logos, on the other hand, are stored at a public address: it is long, hard to guess and not listed anywhere, but anyone who has the link can see the image.
DojoPro's team runs the platform, so it has technical access to every school's data, health records included. It only goes into a school's data to give the support that school asked for, to deal with a security problem, or to meet a legal obligation. Every read of a health record made through the application is logged with who made it and when, including reads by DojoPro staff.
If a security incident affecting personal data occurs, we notify the school without undue delay, with what we know, so it can tell the people affected and, where appropriate, the AAIP. Argentine law sets no deadline for that notification today; our commitment to the school does not wait for one.
12. Cookies and analytics
We use no advertising cookies and no third-party tracking cookies. The only cookies we set are the ones the application needs: the session cookie that keeps you signed in, and the one that remembers which location you are looking at.
We measure aggregate site usage with Vercel Analytics, which works without cookies and builds no profiles of individuals. If we ever add a tool that does use cookies, it will appear here, on the subprocessor list, and with advance notice.
13. International transfers
Data is hosted in the United States: the database with Neon, on Amazon Web Services (region us-east-1), and the application and files with Vercel. That is an international transfer under art. 12 of Ley 25.326, and the United States is not among the countries the Argentine authority considers to offer an adequate level of protection (Disposición DNPDP 60-E/2016).
That is why the transfer rests on your express consent (art. 12 of Ley 25.326 and its regulation in Decreto 1558/2001). We ask for it when you sign up and, if you already had an account, on a screen shown when you sign in, together with acceptance of this notice and of the Terms. It is recorded per person and per version of this notice. If the student is a minor, their guardian gives it (section 6); a minor with their own portal access is not asked.
In addition, DojoPro has signed a data processing agreement with each provider, which binds it to process the data only on our instructions and to protect it. Those agreements are an additional safeguard; they do not replace your consent. Each provider is detailed on the Subprocessors page.
DojoPro cannot provide the service without hosting the data in the United States. If you do not give your consent on that screen, you are signed out and your answer is recorded; if you change your mind, sign in again and accept. You can withdraw it at any time by asking your school or writing to the address in the footer; since the service cannot run without that hosting, withdrawing it means you stop using DojoPro. If you also want your data deleted, ask your instructor or school, who take it to our team (section 8).
14. Changes to this notice
Every version of this notice has an identifier and an effective date, both printed above. A material change — a new purpose, a new subprocessor, a longer retention period — is announced before it takes effect and, where it applies, means asking for consent again: when you sign in we show you a screen asking you to accept the new version, and you cannot keep using the app until you answer.
Wording or translation fixes that do not change meaning do not create a new version; they are mentioned in the next one that does.