Dojo managementSmartDojo
Privacy Policy
How SmartDojo handles personal data in SmartDojo — what we collect, why, who else sees it, and the rights you can exercise.
Last updated — 10 August 2026
1. Who is responsible
The controller for the data described here is SmartDojo, based in Japan. For any question about this policy, or to exercise a right, write to privacy@smartdojo.net.
Our representative in the European Union under article 27 GDPR is to be appointed. We have not appointed a Data Protection Officer, as we are not required to; privacy@smartdojo.net reaches the person who is accountable for this policy.
This policy applies to the SmartDojo application, the public site and the reference syllabus. It forms part of our Terms of Use.
2. Which hat we wear — controller or processor
SmartDojo holds two different kinds of personal data, and the law treats them differently:
- Your account and your use of the Service — we decide why and how it is processed, so we are the controller. This policy is our notice to you under articles 13 and 14 GDPR.
- The people a dojo records — its members, their ranks, their attendance, their dues — the dojo decides why and how, so the dojo is the controller and we are its processor. We touch that data only on the dojo's instructions.
For that second category, sections 3 to 9 of this policy are the data processing agreement required by article 28(3) GDPR between the dojo and us: they set out the subject matter, duration, nature and purpose of the processing, the categories of data and of data subject, and our obligations. We process only on documented instructions (the dojo's use of the Service, plus anything it asks us in writing), we bind everyone with access to confidentiality, we apply the measures in section 8, we engage the sub-processors listed in section 6 and tell dojos before adding one, we help with data-subject requests and with breach notification, we delete or return the data at the end as described in section 7, and we make available the information needed to demonstrate all of it.
A dojo is responsible for having a lawful basis for what it records about its members and for telling them about it. We cannot do that for a dojo, and a dojo should not assume this policy does it.
3. What we collect
- Account data — first and last name, email address, a hashed password (never the password itself), your language and display settings, the dojos you belong to and your role in each, and your account status.
- Dojo data — everything a dojo records: members and their contact details, ranks, gradings and syllabus progress, the timetable, attendance registers, memberships, dues and payments recorded, finance entries and their descriptions, and any notes typed into free-text fields.
- Payment data — on a paid plan, Stripe collects the card details on its own pages. What we store is the Stripe customer, subscription and price identifiers, the subscription's status and plan, the amount and currency, the dates of the current period, whether it is set to cancel, and the reason a payment failed. No card number, expiry date or security code reaches us.
- Support and feedback — the content of messages you send us, the page they were sent from, and our replies.
- Technical data — IP address, browser and device type, pages requested, timestamps, referrer, and error and security logs. This is how a request is served and how abuse is spotted.
- Analytics data — where you consent to it, pseudonymous measurement data from Google Analytics as described in our Cookie Policy.
- Advertising data — where you consent to it, and only while you are signed out and reading the public syllabus and federation pages, the data an advert request carries to Google AdSense: the page, your IP address, your browser and Google's own advertising identifier for it, as described in our Cookie Policy. No account or dojo data is ever part of it. Once you are signed in, on any plan, no advert is shown to you and no advert script is loaded — so for anyone with an account this category is empty.
We do not ask for special-category data (article 9 GDPR: health, injuries, beliefs, and so on), and we ask dojos not to record it unless they have a lawful basis for it under both article 6 and article 9. Free-text notes are covered by that too.
4. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Creating and running your account, and providing the Service | Account data, dojo data | Performance of the contract — art. 6(1)(b) |
| Keeping the Service secure — authentication, abuse and fraud prevention, logging | Technical data, account data | Legitimate interests — art. 6(1)(f): running a service that is not broken into |
| Taking payment and preventing payment fraud | Payment data, account data | Contract — art. 6(1)(b); and legal obligation for the accounting record — art. 6(1)(c) |
| Service emails — confirmation, password reset, notices about changes | Account data | Contract — art. 6(1)(b) |
| Answering support messages and acting on feedback | Support data, account data | Legitimate interests — art. 6(1)(f): supporting our own users |
| Audience measurement with Google Analytics | Analytics data | Consent — art. 6(1)(a), withdrawable at any time |
| Showing adverts on the free public pages, so they can stay free | Advertising data | Consent — art. 6(1)(a), withdrawable at any time and asked for separately from analytics |
| Keeping the invoices and records our own tax law requires | Payment data, account data | Legal obligation — art. 6(1)(c) |
| Improving the Service from aggregated, anonymous statistics | No personal data once aggregated | Legitimate interests — art. 6(1)(f) |
Where we rely on legitimate interests, we have weighed them against your rights and you may object at any time under article 21 GDPR — see section 9. We do not sell your data, and we do not use it to train machine-learning models. Your account data and your dojo's data are never used for advertising and are never passed to an advertising network: the adverts that fund the free public pages are served to a browser reading a syllabus page, not to a person we have identified, and they do not run inside the app at all.
5. The same processing, under Japanese law
As a business operator handling personal information in Japan, we state our purposes of use as set out in the table above. We do not provide personal data to third parties other than as described in section 6 — entrustment of processing and business succession, which the Act on the Protection of Personal Information treats as not requiring separate consent — or where the law requires it. Requests for disclosure, correction, suspension of use or deletion under the Act are handled at the address in section 12, and a complaint may be brought to the Personal Information Protection Commission (個人情報保護委員会).
7. International transfers
We are established in Japan, so personal data from the European Economic Area and the United Kingdom is transferred to Japan. For the EEA this is covered by the European Commission's adequacy decision for Japan of 23 January 2019, together with the Supplementary Rules adopted by Japan's Personal Information Protection Commission, which apply additional protections to data received from the EEA — including limits on onward transfer and on the use of sensitive data. The UK recognises Japan on an equivalent basis.
Where a sub-processor is in the United States or another country without an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), or on the EU–US Data Privacy Framework where the provider is certified under it. We will send you the relevant clauses on request.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account data | While the account exists, then deleted or anonymised within 30 days of closure |
| Dojo data, including members, attendance and the books | While the dojo exists. After a dojo is deleted or a subscription ends, 30 days to export, then deletion |
| Backups | Rolling backups are overwritten within 90 days; a deletion works through them on that cycle |
| Invoices and payment records | As long as our own tax and accounting law requires — currently up to 7 years |
| Security and access logs | 12 months, unless a log is needed for an open incident |
| Support messages | 3 years from the last exchange |
| Analytics data | 14 months, and only where consent was given |
A dojo may have to keep its accounting records far longer than we keep them — often 7 or 10 years. That obligation is the dojo's, not ours: export the books and keep your own copies. See section 6 of the Terms of Use.
9. How we protect it
- Traffic is encrypted in transit with TLS, and the database is encrypted at rest by our provider.
- Passwords are stored only as bcrypt hashes; we cannot read them, and a reset replaces rather than reveals.
- Sessions use signed, short-lived tokens in a SameSite cookie, and every dojo-scoped query is re-checked server-side against the requester's membership — a dojo id that is not yours resolves to nothing, whatever the URL says.
- Access to production data is limited to those who need it, and administrative access is logged.
- No system is perfectly secure. If a breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours as required by article 33 GDPR, and we tell you directly where article 34 requires it. As a Japanese operator we also report to the Personal Information Protection Commission where the Act requires.
10. Your rights
If the GDPR applies to you, you have the right to: obtain confirmation and a copy of your data (art. 15); have inaccurate data corrected (art. 16); have data erased (art. 17); restrict processing (art. 18); receive your data in a portable, machine-readable form and have it transmitted to another controller (art. 20); object to processing based on our legitimate interests, including at any time (art. 21); and withdraw a consent you gave, without affecting what was done before you withdrew it (art. 7(3)).
You are also not subject to any decision with legal or similarly significant effect taken solely by automated means: we do not profile you and we do not make automated decisions of that kind (art. 22).
Write to privacy@smartdojo.net to exercise any of these. We reply within one month, and tell you if we need longer for a complex request. We may ask for enough information to be sure it is you asking — that check exists for your protection.
If your data was recorded by a dojo rather than by you, the dojo is the controller: we will pass your request on to it and help it answer. If you are unhappy with how we handle it, you may complain to the supervisory authority of the EU/EEA country where you live or work, to the UK Information Commissioner's Office, or to Japan's Personal Information Protection Commission. We would rather you told us first.
12. Children
The free SmartDojo service is open to users aged 12 and over. Any paid plan or payment feature requires you to be at least 16, or the age of digital consent in your country where that is higher. Dojos do record minors — that is what a children's class is — and the responsibility for the parent's or guardian's consent, and for what is recorded about a child, sits with the dojo as controller. Keep it to what running the class actually requires.
13. Changes to this policy
We update this policy when what we do changes. The date at the top is the date the current text took effect. For a change that materially affects how we use your data, we give notice by email or in the app at least 30 days beforehand, and where the change relies on consent we ask again rather than assume.
14. Contact
SmartDojo, based in Japan. Email: privacy@smartdojo.net. EU representative (art. 27 GDPR): to be appointed.