DojoCore Data Processing Addendum
Version 1.0
This Data Processing Addendum (“DPA”) forms part of the agreement governing the use of DojoCore between WhiteBelt Limited, a company incorporated in Hong Kong (“WhiteBelt”, “DojoCore”, “Processor”, “we”, “us” or “our”), and the martial arts academy, gym, sports club or other organisation using DojoCore (“Customer”, “Academy” or “Controller”).
This DPA becomes effective when the Customer accepts the DojoCore Terms of Service, an order form or other agreement that incorporates this DPA (the “Agreement”).
No separate signature is required where applicable law permits electronic acceptance.
1. Definitions
For purposes of this DPA:
“Applicable Data Protection Law” means any law or regulation relating to privacy, data protection or the processing of Personal Data that applies to the relevant Processing under the Agreement, including, where applicable:
- Regulation (EU) 2016/679 (“GDPR”);
- the UK GDPR and Data Protection Act 2018;
- the Hong Kong Personal Data (Privacy) Ordinance;
- applicable United States state privacy laws, including the California Consumer Privacy Act (“CCPA”);
- applicable Canadian, Australian and New Zealand privacy laws; and
- any successor or replacement legislation.
“Customer Personal Data” means Personal Data Processed by WhiteBelt on behalf of Customer in connection with the Service.
Customer Personal Data does not include Personal Data that WhiteBelt Processes independently as a Controller, such as information relating to Customer’s DojoCore account, WhiteBelt’s own billing relationship with Customer, business enquiries, security administration and other processing described in the DojoCore Privacy Policy.
“Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates.
“Personal Data”, “Controller”, “Processor”, “Processing” and equivalent terms have the meanings given to them under Applicable Data Protection Law.
“Restricted Transfer” means a transfer of Personal Data that requires a transfer mechanism or other safeguard under Applicable Data Protection Law.
“Security Incident” means a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data Processed by WhiteBelt.
Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful login attempts, port scans or blocked attacks.
“Service” means the DojoCore software and related services provided under the Agreement.
“Subprocessor” means a third party engaged by WhiteBelt to Process Customer Personal Data on behalf of Customer.
2. Scope and roles
2.1 Customer as Controller
Customer acts as Controller of Customer Personal Data.
Customer determines, among other things:
- which individuals become members or students of the Academy;
- which Personal Data the Academy requires;
- why that data is collected;
- which Academy staff may access it;
- the Academy’s membership and attendance policies;
- the Academy’s membership terms;
- its payment and cancellation policies;
- its communications with members; and
- the period for which the Academy requires the data.
Customer represents that it acts as Controller in respect of the Customer Personal Data it Processes through the Service. If Customer requires WhiteBelt to act as a Subprocessor to another Controller, Customer shall contact WhiteBelt before submitting the relevant Personal Data so that the parties can agree appropriate terms.
2.2 WhiteBelt as Processor
WhiteBelt Processes Customer Personal Data on behalf of Customer solely to provide, maintain, secure and support the Service and in accordance with this DPA and Customer’s documented instructions.
2.3 WhiteBelt as independent Controller
Nothing in this DPA prevents WhiteBelt from Processing Personal Data as an independent Controller where WhiteBelt independently determines the purposes and essential means of Processing.
Such Processing is governed by the DojoCore Privacy Policy rather than this DPA.
3. Customer instructions
Customer instructs WhiteBelt to Process Customer Personal Data as necessary to:
- provide the Service;
- perform the Agreement;
- implement Customer’s configuration of DojoCore;
- perform actions initiated by Customer’s authorised users;
- provide member-facing functionality configured by Customer;
- process imports and migrations requested by Customer;
- provide technical and customer support;
- maintain security and availability;
- use authorised Subprocessors; and
- comply with other documented instructions provided by Customer.
The Agreement, this DPA, Customer’s use and configuration of the Service, and written support or administrative requests collectively constitute Customer’s documented instructions.
WhiteBelt shall not Process Customer Personal Data for unrelated purposes except where required by applicable law. WhiteBelt does not acquire ownership of Customer Personal Data, does not sell Customer Personal Data and does not Process Customer Personal Data for third-party advertising purposes. Customer retains all rights in Customer Personal Data as between Customer and WhiteBelt, subject to the limited rights necessary for WhiteBelt to provide the Service.
If WhiteBelt is legally required to Process Customer Personal Data contrary to Customer’s instructions, WhiteBelt will inform Customer before Processing unless applicable law prohibits such notification.
If WhiteBelt reasonably believes that an instruction violates Applicable Data Protection Law, WhiteBelt will inform Customer and may suspend the affected Processing until the parties resolve the issue.
4. Customer responsibilities
Customer is responsible for its compliance with Applicable Data Protection Law.
In particular, Customer shall:
-
have a lawful basis for collecting and Processing Customer Personal Data;
-
provide Data Subjects with any privacy information required by law;
-
obtain any consent, authorisation or parental or guardian permission required by law;
-
ensure that Customer Personal Data provided to DojoCore was collected lawfully;
-
ensure that Customer’s instructions to WhiteBelt are lawful;
-
maintain the accuracy of Customer Personal Data where required;
-
configure user permissions appropriately;
-
ensure that only authorised persons have access to Customer’s DojoCore account;
-
respond to Data Subject requests for access, correction, deletion, objection or similar rights;
-
comply with applicable laws relating to its memberships, subscriptions, recurring payments, marketing and communications;
-
ensure that its use of Telegram, Stripe and other integrations complies with applicable law and the relevant third-party terms; and
-
configure DojoCore to collect only Personal Data reasonably necessary for the Academy’s legitimate purposes.
5. Sensitive data
DojoCore’s standard Service is not designed as a medical records, healthcare records, biometric identification or criminal-records system.
Unless WhiteBelt expressly agrees otherwise in writing, Customer shall not intentionally use DojoCore to store:
- detailed medical records;
- diagnoses;
- medication information;
- genetic information;
- biometric identification templates;
- facial-recognition templates;
- criminal records;
- passport or national identity document copies;
- government authentication credentials; or
- other highly sensitive Personal Data not reasonably required for ordinary Academy management.
Customer acknowledges that free-form fields should not be used to store unnecessary sensitive information.
This restriction does not prevent ordinary Processing of information such as a member’s:
- name;
- contact details;
- date of birth;
- guardian relationship;
- membership;
- classes;
- attendance;
- payment status; or
- other information described in Schedule 1.
6. Children and minors
Customer acknowledges that martial arts academies may Process Personal Data relating to children.
Where Customer uses DojoCore in connection with minors, Customer is responsible for determining:
- whether parental or guardian involvement is required;
- whether parental consent or authorisation is required;
- what information may lawfully be collected;
- who may enter into membership terms;
- who may authorise recurring payments; and
- what communications may be sent to the minor.
Where required by applicable law, or by the terms of a relevant third-party service, Customer shall ensure that an appropriate parent or legal guardian participates in onboarding, membership, communications and payment processes.
Customer shall not direct or encourage a minor to create or use a third-party account, including a Telegram account, contrary to that third party’s applicable terms.
WhiteBelt will provide reasonable technical functionality to support guardian-managed member records where available in the Service.
7. Confidentiality
WhiteBelt shall ensure that persons authorised to Process Customer Personal Data:
- access such data only where necessary for their duties;
- are subject to contractual, statutory or other appropriate confidentiality obligations; and
- receive access only to the extent reasonably necessary.
WhiteBelt shall restrict production access to personnel and contractors who require access for legitimate operational, security or support purposes.
8. Security
8.1 Security programme
WhiteBelt shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against:
- unauthorised access;
- unlawful Processing;
- accidental disclosure;
- accidental or unlawful alteration;
- destruction; and
- loss.
The measures applicable to the Service are described in Schedule 2.
8.2 Risk-based approach
Security measures shall take into account:
- the nature and scope of the Processing;
- the type of Personal Data;
- the state of available technology;
- the risks to Data Subjects; and
- the size and nature of the Service.
8.3 Changes to security measures
WhiteBelt may modify its security measures as technology and the Service develop, provided that WhiteBelt does not materially reduce the overall level of protection for Customer Personal Data.
9. Security Incidents
WhiteBelt shall notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.
Where information is available, the notification will include:
- a description of the nature of the Security Incident;
- the categories of affected data;
- the categories of affected Data Subjects;
- the likely consequences of the Security Incident;
- measures taken or proposed to address the Security Incident; and
- information reasonably necessary for Customer to meet its legal notification obligations.
WhiteBelt may provide information in phases as an investigation progresses.
WhiteBelt shall take reasonable steps to:
- contain the incident;
- investigate the cause;
- mitigate reasonably foreseeable harm;
- prevent recurrence where reasonably practicable; and
- cooperate with Customer in relation to Customer’s legal obligations.
Notification of a Security Incident does not constitute an admission of fault or liability.
Customer remains responsible for determining whether notifications to regulators, Data Subjects or other parties are legally required, except where WhiteBelt itself has a direct statutory notification obligation.
10. Subprocessors
10.1 General authorisation
Customer gives WhiteBelt general written authorisation to engage Subprocessors for the Processing of Customer Personal Data.
The current list of Subprocessors is available at:
https://dojocore.io/subprocessors
The Subprocessor List, as updated from time to time in accordance with this Section 10, is incorporated into this DPA.
10.2 New Subprocessors
WhiteBelt will inform Customer in advance of intended additions or replacements of Subprocessors where required by Applicable Data Protection Law, giving Customer a reasonable opportunity to object on data-protection grounds. For Restricted Transfers governed by the EU SCCs or the UK Addendum, the notice period specified in Section 16.2 applies.
Notice may be provided:
- by email to Customer’s account owner;
- through the Service; or
- through another durable electronic communication mechanism.
10.3 Objections
Customer may object to a proposed Subprocessor promptly after receiving notice, on reasonable and documented data-protection grounds.
The parties will attempt in good faith to resolve the objection.
If the parties cannot reasonably resolve the objection, WhiteBelt may:
- provide the affected Service without that Subprocessor, where reasonably possible;
- offer an alternative configuration; or
- permit Customer to terminate the affected part of the Service.
10.4 Subprocessor obligations
WhiteBelt shall enter into written agreements with its Subprocessors that impose data-protection obligations appropriate to the relevant Processing and providing a level of protection materially equivalent to the relevant obligations imposed on WhiteBelt under this DPA.
WhiteBelt remains responsible to Customer for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.
10.5 Third-party services that are not Subprocessors
Not every third-party service used with DojoCore is necessarily a Subprocessor.
Software that WhiteBelt operates itself on infrastructure it controls is Processing by WhiteBelt rather than by a Subprocessor; the relevant infrastructure or hosting provider is the Subprocessor.
Where Customer creates or connects its own Stripe Standard account, Stripe may have a direct contractual relationship with Customer and may Process data independently under Stripe’s own terms. Similar considerations may apply to other integrations.
The Subprocessor List identifies third parties that WhiteBelt treats as Subprocessors for purposes of this DPA.
11. Data Subject requests
Taking into account the nature of the Processing, WhiteBelt shall provide reasonable assistance to Customer to enable Customer to respond to requests by Data Subjects exercising rights under Applicable Data Protection Law.
This may include requests relating to:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability; or
- withdrawal of consent.
If WhiteBelt receives a request directly from a Data Subject relating to Customer Personal Data, WhiteBelt will ordinarily:
- inform the Data Subject that the relevant Academy is responsible for the data; and/or
- forward the request to Customer.
WhiteBelt will not independently determine the substantive outcome of a Data Subject request unless required by law.
Customer is responsible for responding to the request.
12. Assistance with compliance and regulatory cooperation
Taking into account the nature of the Processing and information available to WhiteBelt, WhiteBelt shall provide reasonable assistance to Customer with obligations relating to:
- security of Processing;
- Personal Data breaches;
- Data Subject notifications;
- data protection impact assessments;
- privacy or risk assessments;
- consultations with supervisory authorities; and
- other processor-assistance requirements imposed by Applicable Data Protection Law.
WhiteBelt shall cooperate with competent supervisory authorities to the extent required by Applicable Data Protection Law, and shall, where legally permitted, inform Customer of regulatory enquiries specifically relating to Customer Personal Data.
WhiteBelt is not required to perform Customer’s legal analysis or act as Customer’s legal adviser.
13. Data return and deletion
13.1 During the Agreement
Customer may use functionality made available in the Service to:
- access Customer Personal Data;
- export Customer Personal Data;
- correct Customer Personal Data; and
- delete or anonymise Customer Personal Data.
13.2 Termination
Following termination of the Agreement, Customer has 30 days to export Customer Personal Data using functionality made available in the Service, or to request that WhiteBelt return it.
Unless Customer provides contrary lawful instructions during that period, Customer instructs WhiteBelt to delete Customer Personal Data from active production systems after the export period expires.
If Customer instead instructs WhiteBelt to delete Customer Personal Data before the export period expires, WhiteBelt shall delete it from active production systems without undue delay, and Section 13.3 applies from that deletion.
13.3 Backups
Deleted Customer Personal Data may remain in protected backups for up to 30 days and will not be used except where necessary for disaster recovery.
If a backup is restored, applicable deletions will be re-applied.
13.4 Legally required retention
WhiteBelt may retain Customer Personal Data where applicable law requires retention, or where retention is necessary for WhiteBelt’s own security, accounting or legal obligations.
Any retained Personal Data will remain protected under this DPA and will be Processed only for the purpose for which it is retained.
14. Audits and compliance information
WhiteBelt shall make available to Customer information reasonably necessary to demonstrate compliance with applicable processor obligations under this DPA.
Customer may conduct, or appoint an independent auditor to conduct, a reasonable audit or assessment, including an inspection, where required by Applicable Data Protection Law.
Unless a regulator, Security Incident or reasonable evidence of material non-compliance requires otherwise:
- Customer shall first use documentation provided by WhiteBelt;
- audits shall normally occur no more than once in any 12-month period;
- Customer shall provide reasonable advance notice;
- audits shall take place during normal business hours;
- audits shall not unreasonably interfere with WhiteBelt’s business;
- Customer shall not access information relating to other customers;
- auditors must be independent and subject to confidentiality obligations; and
- Customer shall bear its own audit costs.
If an audit identifies material non-compliance by WhiteBelt, WhiteBelt shall take reasonable corrective action.
Nothing in this Section limits a supervisory authority’s lawful powers.
15. International Processing and transfers
Customer acknowledges that WhiteBelt is incorporated in Hong Kong and that the Service may use infrastructure and providers located in countries other than Customer’s country.
The locations and relevant service providers used for Customer Personal Data are identified in the current Subprocessor List and related Service documentation.
Customer authorises WhiteBelt to Process and transfer Customer Personal Data to those locations subject to:
- this DPA;
- appropriate contractual safeguards;
- Applicable Data Protection Law; and
- any additional transfer mechanism required by law.
WhiteBelt shall not rely on this Section alone where Applicable Data Protection Law requires a specific Restricted Transfer mechanism.
16. European Economic Area Restricted Transfers
16.1 Application
Where:
- Customer Personal Data is protected by the GDPR;
- Customer transfers that data to WhiteBelt in a country outside the EEA;
- the transfer constitutes a Restricted Transfer; and
- the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are a valid and applicable transfer mechanism,
the EU SCCs are incorporated into this DPA.
16.2 SCC selections
For such transfers:
Module: Module 2 — Transfer Controller to Processor.
Clause 7 — Docking Clause: not used unless the parties separately agree otherwise.
Clause 9(a): Option 2 — General Written Authorisation.
Notice period for new Subprocessors: 14 days.
Clause 11 optional independent dispute-resolution mechanism: not used.
Clause 17 governing law: laws of Ireland.
Clause 18 courts: courts of Ireland.
16.3 Annex I.A — Parties
Data Exporter
The Customer.
The Customer’s:
- legal name;
- address;
- responsible contact;
- email; and
- role
are the details contained in Customer’s DojoCore organisation profile, order form or other Agreement information at the time this DPA is accepted.
Activities relevant to the transfer: use of the DojoCore Service as described in Schedule 1.
Role: Controller.
Data Importer
WhiteBelt Limited Company number: 76938845 Registered office: Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Hong Kong S.A.R. Contact person: Privacy Contact, WhiteBelt Limited Email: [email protected]
Activities relevant to the transfer: provision, maintenance, security and support of the DojoCore Service as described in Schedule 1.
Role: Processor.
Record of acceptance
Electronic acceptance of the Agreement and this DPA constitutes execution of the relevant SCC annex information to the extent permitted by applicable law.
WhiteBelt shall create and retain a record of each Customer’s acceptance, including the version of this DPA accepted, the date and time of acceptance, the accepting user and the Customer details described above. WhiteBelt shall retain the accepted version of this DPA, or a verifiable copy of it, for as long as this DPA remains in effect. WhiteBelt shall make that record available to Customer on reasonable request.
16.4 Annex I.B — Description of transfer
The information required by Annex I.B of the EU SCCs is set out in Schedule 1 of this DPA.
16.5 Annex I.C — Supervisory authority
The competent supervisory authority shall be determined in accordance with Clause 13 of the EU SCCs.
16.6 Annex II — Security measures
The technical and organisational measures required by Annex II are set out in Schedule 2.
16.7 Annex III — Subprocessors
The authorised Subprocessors are those identified in the Subprocessor List, as updated in accordance with Section 10 and Clause 9(a) of the EU SCCs.
16.8 Transfer assessment and supplementary measures
The parties shall reasonably cooperate where the GDPR requires an assessment of the laws and practices applicable to a Restricted Transfer or consideration of supplementary safeguards.
16.9 Where the EU SCCs are not applicable
The parties acknowledge that the EU SCCs adopted under Commission Implementing Decision (EU) 2021/914 do not apply to every possible transfer scenario.
Where a Restricted Transfer requires a safeguard but those EU SCCs are not legally available for the particular transfer, the parties shall cooperate in good faith to implement another valid transfer mechanism required by applicable law.
Customer shall not instruct WhiteBelt to commence a Restricted Transfer for which no lawful transfer mechanism is available.
17. United Kingdom Restricted Transfers
Where Customer Personal Data protected by UK Data Protection Law is subject to a Restricted Transfer from the United Kingdom to WhiteBelt, and the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses is an available transfer mechanism, the parties enter into the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force 21 March 2022 (“UK Addendum”), completed as set out in the Tables below.
Table 1 — Parties
| Exporter | Importer | |
|---|---|---|
| Parties’ details | The Customer, with the details described in Section 16.3 (Data Exporter). | WhiteBelt Limited, with the details described in Section 16.3 (Data Importer). |
| Key Contact | The responsible contact identified in Customer’s DojoCore organisation profile. | Privacy Contact, WhiteBelt Limited, [email protected] |
Table 2 — Selected SCCs, Modules and Selected Clauses
The Addendum EU SCCs are the EU SCCs described in Section 16, including the Appendix Information, and with Module 2 (Transfer Controller to Processor) applying.
The selections described in Section 16.2 apply.
Table 3 — Appendix Information
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs, and which for this Addendum is set out in:
- Annex 1A — List of Parties: Section 16.3;
- Annex 1B — Description of Transfer: Schedule 1;
- Annex II — Technical and organisational measures: Schedule 2; and
- Annex III — List of Sub processors: the Subprocessor List, as updated in accordance with Section 10 and Clause 9(a) of the Addendum EU SCCs.
Table 4 — Ending this Addendum when the Approved Addendum changes
Which Parties may end this Addendum as set out in Section 19: Importer and Exporter.
(References in this Section 17 to Sections 18 and 19 are to the Sections of the Mandatory Clauses of the Approved Addendum, not to Sections of this DPA.)
Alternative Part 2 Mandatory Clauses
| Mandatory Clauses | Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses. |
|---|
18. United States privacy laws
18.1 General processor status
Where an applicable United States state privacy law uses the terms “controller” and “processor”, Customer acts as Controller and WhiteBelt acts as Processor for Customer Personal Data covered by this DPA.
WhiteBelt shall:
- Process such data only under Customer’s instructions;
- maintain confidentiality;
- maintain reasonable security;
- assist with applicable consumer rights;
- delete or return data as required;
- impose appropriate obligations on Subprocessors; and
- provide reasonable information demonstrating compliance.
18.2 California
Where the CCPA applies to Customer Personal Data:
- Customer is the “business” to the extent Customer meets the relevant statutory definition; and
- WhiteBelt acts as a “service provider” or “contractor”, as applicable.
The specific business purposes for which WhiteBelt Processes the Personal Information are those described in Schedule 1.
WhiteBelt shall not:
-
sell Customer Personal Data;
-
share Customer Personal Data for cross-context behavioural advertising;
-
retain, use or disclose Customer Personal Data for purposes other than the specific business purposes described in this DPA, except as permitted by the CCPA;
-
retain, use or disclose Customer Personal Data outside the direct business relationship between WhiteBelt and Customer except as permitted by the CCPA; or
-
combine Customer Personal Data with Personal Information obtained from another source except where permitted by the CCPA.
WhiteBelt shall:
- provide the same level of privacy protection required of service providers or contractors under applicable CCPA provisions;
- notify Customer if WhiteBelt determines that it can no longer meet its applicable CCPA obligations;
- permit Customer to take reasonable and appropriate steps to help ensure compliant Processing;
- cooperate with reasonable Customer requests necessary to remediate unauthorised Processing; and
- impose applicable CCPA service-provider or contractor restrictions on relevant Subprocessors.
Nothing in this DPA constitutes a sale or sharing of Customer Personal Data by Customer to WhiteBelt.
19. Aggregated and anonymised data
Customer instructs WhiteBelt that it may anonymise or aggregate Customer Personal Data, and may use the resulting information for purposes such as:
- security;
- capacity planning;
- Service analytics;
- performance measurement;
- reliability;
- product improvement; and
- statistical reporting,
provided that the resulting information does not constitute Personal Data under Applicable Data Protection Law.
Information from which direct identifiers have been removed but which can still be attributed to an identifiable individual, whether by WhiteBelt or by another person using reasonably available means, remains Customer Personal Data and remains subject to this DPA. Nothing in this Section authorises WhiteBelt to use such information for its own independent purposes.
Pseudonymisation may be used as a security and data-minimisation measure in the course of Processing under this DPA.
WhiteBelt shall not attempt to re-identify information that has been anonymised, except where necessary to validate the effectiveness of the anonymisation or as otherwise permitted by law.
Where Applicable Data Protection Law imposes specific requirements on de-identified or aggregated data, WhiteBelt shall comply with those requirements.
20. Artificial intelligence and model training
WhiteBelt shall not use Customer Personal Data to train, fine-tune or otherwise develop general-purpose artificial-intelligence or machine-learning models for WhiteBelt’s independent purposes.
This Section does not prevent Customer from enabling Service features that use an artificial-intelligence provider to Process Customer Personal Data on Customer’s instructions, subject to this DPA and the Subprocessor requirements in Section 10.
This Section does not prevent WhiteBelt from using aggregated or anonymised information in accordance with Section 19.
21. Conflict and hierarchy
If there is a conflict concerning Processing of Customer Personal Data:
- mandatory EU SCC provisions apply first where applicable;
- mandatory UK Addendum provisions apply where applicable to UK Restricted Transfers;
- this DPA applies next; and
- the Agreement applies thereafter.
No limitation or exclusion of liability in the Agreement shall reduce rights or liabilities that cannot lawfully be limited under Applicable Data Protection Law, the EU SCCs or UK Addendum.
22. Liability
Except to the extent prohibited by Applicable Data Protection Law or overridden by the EU SCCs or UK Addendum, each party’s liability arising from this DPA is subject to the applicable liability provisions of the Agreement.
Nothing in this DPA limits liability that cannot legally be limited.
23. Term
This DPA remains in effect for as long as WhiteBelt Processes Customer Personal Data on behalf of Customer.
Sections that by their nature must survive termination, including confidentiality, security, deletion, Restricted Transfer provisions and applicable statutory obligations, survive for as long as WhiteBelt retains Customer Personal Data.
24. Changes to this DPA
WhiteBelt may update this DPA where reasonably necessary to:
- reflect changes in Applicable Data Protection Law;
- implement new regulatory requirements;
- update transfer mechanisms;
- reflect material changes to the Service; or
- improve data-protection terms.
WhiteBelt will not make changes that materially reduce the overall protection of Customer Personal Data without reasonable notice.
Where a change materially affects Customer’s rights or obligations, WhiteBelt will provide notice through the Service, email or another durable electronic means.
Mandatory amendments to incorporated transfer instruments take effect in accordance with those instruments.
25. Notices and privacy contact
Notices to Customer under this DPA may be sent to the owner or administrative contact associated with Customer’s DojoCore account.
Privacy and data-protection notices to WhiteBelt may be sent using the privacy contact identified in the current DojoCore Privacy Policy:
Schedule 1 — Details of Processing
1. Subject matter
WhiteBelt provides DojoCore, a software platform used by martial arts academies, gyms, sports clubs and similar organisations to manage their operations and relationships with members.
2. Duration
Processing continues for the duration of the Agreement.
Following termination, Processing continues for the export period described in Section 13.2 — up to 30 days, or less where Customer instructs earlier deletion — after which Customer Personal Data is deleted from active production systems. Residual copies in protected backups expire within the period described in Section 13.3, up to 30 days.
Processing may continue beyond those periods only to the extent necessary to comply with applicable law or to establish, exercise or defend legal claims, as described in Section 13.4.
3. Nature of Processing
Processing may include:
- collection;
- receipt;
- recording;
- organisation;
- structuring;
- storage;
- retrieval;
- consultation;
- display;
- use;
- transmission;
- import;
- export;
- matching;
- restriction;
- deletion;
- anonymisation;
- backup; and
- other operations necessary to provide the Service.
Personal Data may be collected:
- directly by Customer;
- through authorised Customer staff;
- through secure imports;
- through member-facing DojoCore interfaces;
- through DojoCore Telegram bot interactions;
- from parents or guardians;
- from payment or integration providers; or
- through ordinary use of the Service.
4. Purposes
Customer instructs WhiteBelt to Process Customer Personal Data for purposes including:
Member management
- creating and maintaining member records;
- identifying members;
- managing contact information;
- maintaining guardian relationships;
- recording membership status.
Scheduling and classes
- class scheduling;
- booking;
- class participation;
- coach or staff assignment.
Attendance
- check-ins;
- attendance history;
- QR or messaging-based attendance workflows.
Memberships and entitlements
- membership packages;
- class credits;
- membership periods;
- renewals;
- freezes;
- cancellations;
- entitlements.
Billing operations
- invoices;
- payment status;
- recurring-payment scheduling;
- payment-provider references;
- subscription state;
- refunds or payment failures where supported.
WhiteBelt does not need to receive full payment-card details for these purposes.
Communications
- onboarding;
- transactional messages;
- membership notices;
- payment notices;
- operational Academy communications.
Authentication and security
- access control;
- account authentication;
- abuse prevention;
- security logs;
- technical diagnostics.
Migration and support
- importing Customer records;
- assisting Customer with migration;
- troubleshooting;
- Customer-requested support.
Compliance
- maintaining records of terms acceptance;
- recurring-payment authorisations;
- consent or preference records;
- deletion and export operations.
5. Categories of Data Subjects
Customer Personal Data may relate to:
- current Academy members;
- former Academy members;
- prospective members;
- students;
- parents;
- guardians;
- family contacts;
- Academy coaches;
- instructors;
- Customer staff;
- other persons whose information Customer lawfully Processes through the Service.
Data Subjects may include minors.
6. Categories of Personal Data
Depending on Customer’s configuration of the Service and the information Customer chooses to collect:
Identity information
- first name;
- last name;
- date of birth;
- internal member identifier.
Contact information
- email address;
- telephone number.
Messaging identifiers
- Telegram user ID;
- Telegram username;
- chat identifier;
- related bot interaction metadata.
Family and guardian information
- guardian identity;
- guardian contact details;
- relationship between guardian and child member.
Academy relationship information
- membership;
- package;
- entitlement;
- membership start and expiry;
- membership status;
- classes;
- bookings;
- attendance;
- remaining credits.
Payment-related information
- payment status;
- amount;
- currency;
- billing date;
- subscription status;
- payment-provider account, customer and payment-method identifiers;
- transaction and invoice identifiers;
- card brand and last four digits where supplied by the payment provider.
Full card numbers and card security codes are not intended to be Processed by DojoCore.
Consent and contractual records
- membership terms version;
- acceptance timestamp;
- recurring-payment authorisation;
- cancellation request;
- consent or preference records;
- technical evidence associated with acceptance.
Technical information
- IP address;
- timestamps;
- session and authentication metadata;
- browser/device information;
- application logs;
- audit and security events.
Communications
- communications with the Academy through supported Service channels;
- operational support information.
7. Special Categories / Sensitive Data
The standard Service is not intended for systematic Processing of special-category or highly sensitive Personal Data.
Customer is instructed not to submit such data except where:
- the functionality expressly supports it;
- there is a legitimate need;
- Customer has established an appropriate lawful basis; and
- WhiteBelt has agreed to the Processing where required.
8. Frequency
Processing is continuous for active Customer accounts and occurs whenever Customer, its authorised users or its members use the relevant Service functionality.
Schedule 2 — Technical and Organisational Measures
WhiteBelt implements and maintains technical and organisational measures appropriate to the nature and risks of the Processing. The measures currently applicable to the Service include those described below.
1. Access control
Privileged access to production infrastructure shall be protected using appropriate authentication and access controls.
2. Encryption in transit
Public web and API access to the production Service uses encrypted network transport (HTTPS/TLS).
3. Customer and tenant isolation
The Service implements logical access controls designed to prevent one Customer from accessing another Customer’s data. Customer-facing access is scoped according to Academy identity, authenticated user, user role and permissions.
4. Payment information
DojoCore uses payment-provider hosted or tokenised payment mechanisms. Full payment-card numbers and CVV/CVC card security codes are not intended to be Processed or stored by DojoCore.