SmartDojoDojo management

SmartDojo

Privacy Policy

How SmartDojo handles personal data in SmartDojo — what we collect, why, who else sees it, and the rights you can exercise.

Last updated10 August 2026

1. Who is responsible

The controller for the data described here is SmartDojo, based in Japan. For any question about this policy, or to exercise a right, write to privacy@smartdojo.net.

Our representative in the European Union under article 27 GDPR is to be appointed. We have not appointed a Data Protection Officer, as we are not required to; privacy@smartdojo.net reaches the person who is accountable for this policy.

This policy applies to the SmartDojo application, the public site and the reference syllabus. It forms part of our Terms of Use.

2. Which hat we wear — controller or processor

SmartDojo holds two different kinds of personal data, and the law treats them differently:

  • Your account and your use of the Service — we decide why and how it is processed, so we are the controller. This policy is our notice to you under articles 13 and 14 GDPR.
  • The people a dojo records — its members, their ranks, their attendance, their dues — the dojo decides why and how, so the dojo is the controller and we are its processor. We touch that data only on the dojo's instructions.

For that second category, sections 3 to 9 of this policy are the data processing agreement required by article 28(3) GDPR between the dojo and us: they set out the subject matter, duration, nature and purpose of the processing, the categories of data and of data subject, and our obligations. We process only on documented instructions (the dojo's use of the Service, plus anything it asks us in writing), we bind everyone with access to confidentiality, we apply the measures in section 8, we engage the sub-processors listed in section 6 and tell dojos before adding one, we help with data-subject requests and with breach notification, we delete or return the data at the end as described in section 7, and we make available the information needed to demonstrate all of it.

A dojo is responsible for having a lawful basis for what it records about its members and for telling them about it. We cannot do that for a dojo, and a dojo should not assume this policy does it.

3. What we collect

  • Account data — first and last name, email address, a hashed password (never the password itself), your language and display settings, the dojos you belong to and your role in each, and your account status.
  • Dojo data — everything a dojo records: members and their contact details, ranks, gradings and syllabus progress, the timetable, attendance registers, memberships, dues and payments recorded, finance entries and their descriptions, and any notes typed into free-text fields.
  • Payment data — on a paid plan, Stripe collects the card details on its own pages. What we store is the Stripe customer, subscription and price identifiers, the subscription's status and plan, the amount and currency, the dates of the current period, whether it is set to cancel, and the reason a payment failed. No card number, expiry date or security code reaches us.
  • Support and feedback — the content of messages you send us, the page they were sent from, and our replies.
  • Technical data — IP address, browser and device type, pages requested, timestamps, referrer, and error and security logs. This is how a request is served and how abuse is spotted.
  • Analytics data — where you consent to it, pseudonymous measurement data from Google Analytics as described in our Cookie Policy.
  • Advertising data — where you consent to it, and only while you are signed out and reading the public syllabus and federation pages, the data an advert request carries to Google AdSense: the page, your IP address, your browser and Google's own advertising identifier for it, as described in our Cookie Policy. No account or dojo data is ever part of it. Once you are signed in, on any plan, no advert is shown to you and no advert script is loaded — so for anyone with an account this category is empty.

We do not ask for special-category data (article 9 GDPR: health, injuries, beliefs, and so on), and we ask dojos not to record it unless they have a lawful basis for it under both article 6 and article 9. Free-text notes are covered by that too.

4. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR art. 6)
Creating and running your account, and providing the ServiceAccount data, dojo dataPerformance of the contract — art. 6(1)(b)
Keeping the Service secure — authentication, abuse and fraud prevention, loggingTechnical data, account dataLegitimate interests — art. 6(1)(f): running a service that is not broken into
Taking payment and preventing payment fraudPayment data, account dataContract — art. 6(1)(b); and legal obligation for the accounting record — art. 6(1)(c)
Service emails — confirmation, password reset, notices about changesAccount dataContract — art. 6(1)(b)
Answering support messages and acting on feedbackSupport data, account dataLegitimate interests — art. 6(1)(f): supporting our own users
Audience measurement with Google AnalyticsAnalytics dataConsent — art. 6(1)(a), withdrawable at any time
Showing adverts on the free public pages, so they can stay freeAdvertising dataConsent — art. 6(1)(a), withdrawable at any time and asked for separately from analytics
Keeping the invoices and records our own tax law requiresPayment data, account dataLegal obligation — art. 6(1)(c)
Improving the Service from aggregated, anonymous statisticsNo personal data once aggregatedLegitimate interests — art. 6(1)(f)

Where we rely on legitimate interests, we have weighed them against your rights and you may object at any time under article 21 GDPR — see section 9. We do not sell your data, and we do not use it to train machine-learning models. Your account data and your dojo's data are never used for advertising and are never passed to an advertising network: the adverts that fund the free public pages are served to a browser reading a syllabus page, not to a person we have identified, and they do not run inside the app at all.

5. The same processing, under Japanese law

As a business operator handling personal information in Japan, we state our purposes of use as set out in the table above. We do not provide personal data to third parties other than as described in section 6 — entrustment of processing and business succession, which the Act on the Protection of Personal Information treats as not requiring separate consent — or where the law requires it. Requests for disclosure, correction, suspension of use or deletion under the Act are handled at the address in section 12, and a complaint may be brought to the Personal Information Protection Commission (個人情報保護委員会).

6. Who else processes it

We use the following sub-processors. Each is bound by a contract that limits them to processing on our instructions, and we tell customers before adding a new one.

ProviderWhat it doesWhereTransfer mechanism
Vercel Inc.Hosting and delivery of the applicationUnited States / EU regionsEU Standard Contractual Clauses
SupabaseThe managed PostgreSQL database holding dojo dataConfigurable regions, including the EU and the United StatesEU Standard Contractual Clauses where hosted outside the EEA
Mailtrap (operated by Railsware)Delivery of service emailsNot tied to a single countryEU Standard Contractual Clauses where applicable
Stripe Payments Europe, Ltd. and affiliatesPayment processing and card handlingIreland / United StatesSCCs; Stripe is also an independent controller for fraud prevention and its own legal duties
Google Ireland Ltd. / Google LLCGoogle Analytics audience measurement — only with your consentIreland / United StatesEU–US Data Privacy Framework and SCCs
Google Ireland Ltd. / Google LLCGoogle AdSense advertising on the public pages — only with your consent. Google is an independent controller for how it selects and measures advertsIreland / United StatesEU–US Data Privacy Framework and SCCs

Beyond these, we disclose personal data only where the law obliges us to (a valid order from a court or authority), where it is necessary to establish or defend a legal claim, or to a successor of the business in a merger or transfer — in which case we tell you first and this policy continues to apply until it is replaced.

There is one more case, and it is not a disclosure anybody asks us for. Where content stored in or sent through the Service appears to be unlawful — material depicting the abuse of a child, a credible threat to someone's life or safety, or anything else the law requires or allows us to act on — we may preserve it and refer it to the police or to the competent authority, together with the account details and technical records needed to identify where it came from. We may also suspend the account concerned. We will tell the account holder where the law permits it, and we will not where telling them would defeat the purpose of the referral or is otherwise prohibited.

7. International transfers

We are established in Japan, so personal data from the European Economic Area and the United Kingdom is transferred to Japan. For the EEA this is covered by the European Commission's adequacy decision for Japan of 23 January 2019, together with the Supplementary Rules adopted by Japan's Personal Information Protection Commission, which apply additional protections to data received from the EEA — including limits on onward transfer and on the use of sensitive data. The UK recognises Japan on an equivalent basis.

Where a sub-processor is in the United States or another country without an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), or on the EU–US Data Privacy Framework where the provider is certified under it. We will send you the relevant clauses on request.

8. How long we keep it

DataKept for
Account dataWhile the account exists, then deleted or anonymised within 30 days of closure
Dojo data, including members, attendance and the booksWhile the dojo exists. After a dojo is deleted or a subscription ends, 30 days to export, then deletion
BackupsRolling backups are overwritten within 90 days; a deletion works through them on that cycle
Invoices and payment recordsAs long as our own tax and accounting law requires — currently up to 7 years
Security and access logs12 months, unless a log is needed for an open incident
Support messages3 years from the last exchange
Analytics data14 months, and only where consent was given

A dojo may have to keep its accounting records far longer than we keep them — often 7 or 10 years. That obligation is the dojo's, not ours: export the books and keep your own copies. See section 6 of the Terms of Use.

9. How we protect it

  • Traffic is encrypted in transit with TLS, and the database is encrypted at rest by our provider.
  • Passwords are stored only as bcrypt hashes; we cannot read them, and a reset replaces rather than reveals.
  • Sessions use signed, short-lived tokens in a SameSite cookie, and every dojo-scoped query is re-checked server-side against the requester's membership — a dojo id that is not yours resolves to nothing, whatever the URL says.
  • Access to production data is limited to those who need it, and administrative access is logged.
  • No system is perfectly secure. If a breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours as required by article 33 GDPR, and we tell you directly where article 34 requires it. As a Japanese operator we also report to the Personal Information Protection Commission where the Act requires.

10. Your rights

If the GDPR applies to you, you have the right to: obtain confirmation and a copy of your data (art. 15); have inaccurate data corrected (art. 16); have data erased (art. 17); restrict processing (art. 18); receive your data in a portable, machine-readable form and have it transmitted to another controller (art. 20); object to processing based on our legitimate interests, including at any time (art. 21); and withdraw a consent you gave, without affecting what was done before you withdrew it (art. 7(3)).

You are also not subject to any decision with legal or similarly significant effect taken solely by automated means: we do not profile you and we do not make automated decisions of that kind (art. 22).

Write to privacy@smartdojo.net to exercise any of these. We reply within one month, and tell you if we need longer for a complex request. We may ask for enough information to be sure it is you asking — that check exists for your protection.

If your data was recorded by a dojo rather than by you, the dojo is the controller: we will pass your request on to it and help it answer. If you are unhappy with how we handle it, you may complain to the supervisory authority of the EU/EEA country where you live or work, to the UK Information Commissioner's Office, or to Japan's Personal Information Protection Commission. We would rather you told us first.

11. Cookies, analytics and advertising

We use the cookies and local storage strictly necessary to sign you in and remember your preferences, and — only where you have consented — Google Analytics to measure how the site is used and Google AdSense to show adverts on the free public pages. Both are off until you accept them, they are asked for separately so you can accept one and refuse the other, and you may change your mind at any time. Everything we set is listed, with its purpose and lifetime, in our Cookie Policy.

12. Children

The free SmartDojo service is open to users aged 12 and over. Any paid plan or payment feature requires you to be at least 16, or the age of digital consent in your country where that is higher. Dojos do record minors — that is what a children's class is — and the responsibility for the parent's or guardian's consent, and for what is recorded about a child, sits with the dojo as controller. Keep it to what running the class actually requires.

13. Changes to this policy

We update this policy when what we do changes. The date at the top is the date the current text took effect. For a change that materially affects how we use your data, we give notice by email or in the app at least 30 days beforehand, and where the change relies on consent we ask again rather than assume.

14. Contact

SmartDojo, based in Japan. Email: privacy@smartdojo.net. EU representative (art. 27 GDPR): to be appointed.