Immutable archived copy of version 1. The current version is always at dojocore.io/privacy.

Version
1
Effective date
12 August 2026
Last updated
12 August 2026
Current version
/privacy/

DojoCore Privacy Policy

Effective date: 12 August 2026 Last updated: 12 August 2026

1. About this policy

This Privacy Policy explains how WhiteBelt Limited, a company incorporated in Hong Kong (“WhiteBelt”, “DojoCore”, “we”, “us” or “our”), collects, uses, discloses, stores and otherwise processes personal data in connection with DojoCore.

It applies to the dojocore.io website, the app.dojocore.io application, academy and member-facing pages operated through DojoCore, DojoCore Telegram bots and related onboarding flows, and our emails, support channels, demonstrations and other communications relating to DojoCore (together, the “Service”).

WhiteBelt Limited is registered in Hong Kong with company number 76938845 and has its registered office at Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong

Privacy enquiries may be sent to [email protected].

2. DojoCore and your Academy

DojoCore is a software platform used by martial arts academies, sports clubs, gyms and similar organisations (“Academies”) to manage their operations.

Depending on the processing activity, WhiteBelt may act as a controller of personal data or as a processor acting on behalf of an Academy.

2.1 Where WhiteBelt acts as a controller

WhiteBelt determines the purposes and means of processing — and therefore acts as a controller — in relation to:

2.2 Where WhiteBelt acts as a processor

When an Academy uploads, creates or otherwise processes information about its members, students, guardians, coaches or other customers through DojoCore (“Academy Member Data”), the Academy normally acts as the controller and WhiteBelt acts as its processor.

In that situation:

If you are a member or student of an Academy, that Academy’s own privacy notice also applies to the processing of your personal data. This Privacy Policy does not replace it.

2.3 Where WhiteBelt acts as an independent controller of platform data

WhiteBelt may act as an independent controller for limited processing necessary for the security, integrity, legal compliance and administration of the DojoCore platform — including authentication and security logging, fraud and abuse prevention, infrastructure security, enforcement of platform restrictions and responding to lawful requests — even where the underlying record is Academy Member Data otherwise processed on an Academy’s behalf.

2.4 Academy responsibilities

Each Academy using DojoCore is responsible for providing its members with an accurate privacy notice; establishing a lawful basis for its processing; obtaining parental or guardian authorisation and valid recurring-payment authorisation where required; keeping personal data accurate; restricting staff access appropriately; responding to member privacy requests; avoiding the collection of unnecessary or prohibited sensitive information; ensuring imported data was collected lawfully; configuring appropriate retention; and complying with applicable consumer, marketing, payment and privacy laws.

3. Information we process

3.1 Website visitors and prospective customers

When you visit our website, request information, apply to join a beta programme or book a demonstration, we may collect your contact and identity information, your role and Academy details, the content of your enquiry or booking, our correspondence with you, and technical information such as IP address, device and browser information, approximate location derived from IP address, referring pages and pages viewed.

3.2 Academy accounts and authorised users

For Academies and their authorised users we may collect contact and identity information; account role and permissions; Academy name, address, contact and business details; account settings and preferences; authentication, login and audit records; records of acceptance of our Terms and Data Processing Agreement; connected payment-account identifiers and connection status; support requests and feedback; and information provided during onboarding or data migration.

3.3 Academy Member Data

Depending on the Academy’s configuration and the information the Academy chooses to collect, Academy Member Data may include:

Academies must not use DojoCore to store unnecessary sensitive information — including medical records, detailed health information, biometric templates, criminal records, passport copies or government identity documents — unless WhiteBelt has expressly agreed in writing and the Academy has established an appropriate lawful basis.

3.4 Information collected through Telegram

Academies may use a DojoCore Telegram bot to onboard or communicate with members. When a person interacts with a DojoCore Telegram bot, we may receive information made available by Telegram, including Telegram user and chat identifiers, username and display name, language setting, the messages, commands and selections sent to the bot, and technical interaction data. The bot may also request onboarding details such as name, email address, telephone number and date of birth.

The information requested through the bot is determined by the relevant Academy and is processed by DojoCore on that Academy’s behalf.

Telegram independently processes personal data under its own terms and privacy policy, and we do not control Telegram’s independent processing, infrastructure or retention practices. Users should not submit medical, financial, government identification or other highly sensitive information through Telegram messages.

3.5 Payment information

DojoCore allows eligible Academies to create or connect a Stripe Standard account. Stripe, rather than DojoCore, collects and processes the financial, identity-verification and payment information required to create and operate a Stripe account.

We receive limited payment-related information from Stripe, such as Stripe account and customer identifiers, payment-method identifiers, transaction amounts and currencies, payment status, subscription and invoice information, refund or dispute status, and limited card details such as card brand and the final four digits.

DojoCore does not collect or store complete payment-card numbers, card security codes or online-banking credentials.

Payments made by Academy members are processed by Stripe for the relevant Academy. The Academy is the seller of the membership or other service and receives the funds through its own Stripe account. Stripe independently processes personal data for payment, identity-verification, fraud-prevention and regulatory purposes described in its own privacy documentation.

3.6 Email delivery

We use an email delivery provider to send authentication, security, account, billing and other transactional messages. The provider processes email addresses and technical delivery information on our behalf. We do not include complete payment-card information or unnecessary sensitive Academy Member Data in email messages.

3.7 Technical, security and usage information

When the Service is accessed, we may automatically collect IP address; browser, device and operating-system information; application version; date and time of access; authentication and security events; requested pages and API endpoints; session identifiers; error and diagnostic information; approximate location derived from IP address; referring URL; feature usage; audit-log information; and performance information.

We seek to prevent passwords, access tokens, complete form submissions and unnecessary personal data from being included in application logs.

3.8 Support and communications

If you communicate with us, we may collect your contact details, the content and attachments of your message, call notes, support history and diagnostic information.

3.9 How we obtain information

We may obtain personal data directly from you; from an Academy or another authorised user of the same Academy; from a parent or guardian; through a DojoCore Telegram bot; through Stripe, our email provider, our scheduling provider or another connected service; automatically from your browser, device or use of the Service; from public business sources, referrals or business partners; and during data migration or import performed at an Academy’s request.

Where an Academy supplies personal data about another person, the Academy is responsible for ensuring it has the right to provide that information to DojoCore.

4. Information you are required to provide

Some personal data is required in order to create or administer an account, authenticate a user, process a requested transaction or provide a requested feature. Other information is optional.

Where information is required, failure to provide it may prevent us, or the relevant Academy, from creating an account, completing onboarding, processing a transaction or providing the relevant part of the Service. Where a field is optional, declining to provide it will not prevent you from using the parts of the Service that do not depend on it.

For Academy Member Data, the Academy decides which fields it collects and whether they are required. The Academy should indicate this at the point of collection.

We use personal data to provide and administer the Service (creating and administering accounts, authenticating users, configuring Academy workspaces, managing members, schedules, classes and attendance, administering packages and entitlements, supporting recurring billing workflows, connecting Academy payment accounts, sending service notifications, providing support and importing or exporting Academy data); to keep the Service secure and prevent misuse (protecting accounts, maintaining separation between Academies, detecting unauthorised access, investigating errors and security incidents, preventing fraud and abuse, enforcing permissions and maintaining audit records); to communicate with users; to improve the Service using usage information, feedback and aggregated or de-identified information; and to meet our legal, tax, accounting and regulatory obligations and to establish, exercise or defend legal claims.

We do not use identifiable Academy Member Data to advertise third-party products, and we do not use it to train general-purpose artificial-intelligence models without the Academy’s express written authorisation and an appropriate legal basis.

Where the EU GDPR, UK GDPR or another law requiring a legal basis applies, our main bases are as follows.

Processing Main legal basis
Academy owner account and signup Contract, or steps taken before entering into a contract
Academy employees and other authorised users Legitimate interests in providing the Service to the Academy
Authentication, security and abuse prevention Legitimate interests in operating a secure and reliable service
Customer support Contract; legitimate interests
Billing for the DojoCore subscription Contract; legal obligation
Product analytics necessary to improve the Service Legitimate interests
Optional marketing Consent, or legitimate interests where legally permitted
Legal, tax and accounting records Legal obligation
Academy Member Data The Academy determines the basis; WhiteBelt acts as processor

Where we rely on legitimate interests, we balance those interests against the rights and freedoms of the individuals concerned. Where processing is necessary to establish, exercise or defend legal claims, or to protect a person’s vital interests, we rely on the corresponding basis available under applicable law.

We do not make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects.

6. Service providers and disclosures

6.1 The relevant Academy

Information submitted by an Academy member may be made available to authorised users of that Academy, subject to their roles and permissions, and may be used by the Academy in accordance with its own privacy notice and applicable law.

6.2 Service providers

We use third-party providers to operate DojoCore, including providers of hosting and cloud infrastructure, database and object storage, content delivery and network security, transactional email, payment processing, communication platforms, call scheduling, error monitoring, backups, security and professional services.

The current list of providers that process Academy Member Data on our behalf is available at dojocore.io/subprocessors. These providers may process information only for the purposes for which they were engaged and are bound by contractual and legal obligations.

6.3 Independent third parties

Some third parties integrated with DojoCore determine their own purposes for certain processing and act as independent controllers rather than as our processors. These include Stripe, for payments, identity verification, fraud prevention and regulatory compliance, and Telegram, as the communication platform through which users interact with Academy bots. Their own terms and privacy policies govern that processing, and this Privacy Policy does not cover it. We encourage users to review the privacy information published by each relevant third party.

6.4 Other disclosures

We may disclose personal data to lawyers, accountants, auditors, insurers and other professional advisers where reasonably necessary; where we reasonably believe disclosure is necessary to comply with law or legal process, respond to a valid request from a court, regulator or public authority, investigate fraud or unlawful conduct, protect the safety and rights of users or others, or establish, exercise or defend legal claims; and as part of a merger, financing, acquisition, reorganisation, sale of assets or similar transaction, subject to appropriate confidentiality and data-protection safeguards.

7. International transfers

WhiteBelt Limited is incorporated in Hong Kong. The Service may use infrastructure and service providers in other countries. Current processing locations and relevant providers are described in our subprocessor information at dojocore.io/subprocessors. WhiteBelt personnel may access and process information from outside the country where the data is hosted, including from Hong Kong.

Some service providers and integrations may process personal data in other countries, including the United States and elsewhere, as described in this Policy and in our subprocessor information.

Where EU or UK data-transfer rules apply, the relevant transfer mechanism — such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum — is documented in our Data Processing Agreement and in the applicable service-provider agreement. You may contact us at [email protected] for information about the safeguards that apply to a particular transfer, and to request a copy where you are entitled to one.

Where WhiteBelt is required by applicable law to appoint a representative in the European Union or the United Kingdom, details of that representative will be made available in this Privacy Policy.

8. Children and guardians

DojoCore is a business service intended for use by Academies and their authorised adult administrators. Children must not create an Academy administrative account.

Because martial arts academies frequently serve children, DojoCore may process information relating to minors on an Academy’s instructions. Where an Academy member is a minor, onboarding, communications, contractual acceptance and payments should be handled by the member’s parent or legal guardian where required by applicable law or by the terms of the relevant third-party service.

DojoCore does not authorise or encourage minors to create or use third-party accounts, including Telegram accounts, contrary to that third party’s applicable terms. Academies should not direct minors to complete Telegram-based onboarding themselves; a parent or guardian should do so on the minor’s behalf.

Academies are responsible for identifying when parental or guardian authorisation is required and for obtaining it. An Academy should structure a child’s record separately from the parent or guardian who manages communications, contracts and payments, and must not upload unnecessary sensitive information about children. We do not use children’s personal data for behavioural advertising.

If you believe a child has submitted personal data without appropriate authorisation, contact the relevant Academy or email us at [email protected].

9. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, to comply with legal obligations and to establish, exercise or defend legal claims.

WhiteBelt may retain limited information after deletion where required by law or necessary for WhiteBelt’s own security, accounting or legal obligations.

When data is no longer required, we delete it, anonymise it, or isolate it until it is deleted from backups.

10. Security

We use appropriate technical and organisational safeguards designed to protect personal data, taking into account the nature of the information, the Service and the relevant risks. These include encrypted network communications (HTTPS/TLS) and access controls.

No method of storage or transmission is completely secure, and we cannot guarantee that a security incident will never occur.

If we identify a personal-data breach affecting Academy Member Data, we will notify the affected Academy without undue delay and provide reasonable assistance so that the Academy can meet its own legal obligations.

11. Your privacy rights

Depending on your location and the applicable law, you may have the right to obtain confirmation that your personal data is being processed and to request access to it; to request correction of inaccurate or incomplete data; to request deletion; to request restriction of processing; to object to certain processing, including processing based on legitimate interests; to receive certain data in a portable format; to withdraw consent where processing is based on consent; to opt out of marketing; to receive information about recipients or categories of recipients and about international transfers; and to lodge a complaint with a privacy or data-protection authority.

These rights are not absolute and may be subject to legal exceptions.

11.1 Requests about Academy Member Data

If your personal data was collected by an Academy, submit your request directly to that Academy. The Academy is responsible for deciding how to respond. DojoCore will provide reasonable assistance to the Academy as required by our Data Processing Agreement and applicable law.

11.2 Requests about data controlled by WhiteBelt

For information controlled directly by WhiteBelt, contact [email protected]. We may request information necessary to verify your identity and protect personal data against unauthorised disclosure, and we will respond within the period required by applicable law.

11.3 Hong Kong

Under Hong Kong privacy law, individuals may request access to and correction of personal data held by WhiteBelt. Requests should be addressed to the Privacy Contact, WhiteBelt Limited, at [email protected]. Where permitted by law, we may charge a reasonable fee directly related to the cost of processing a data-access request.

12. Communications and marketing

Transactional messages — including authentication, security, billing, account and service messages — are part of the Service and may not include an unsubscribe option.

We may separately send marketing communications about DojoCore to Academy owners, prospective customers and business contacts. Where applicable law requires consent or another affirmative indication before we use personal data for direct marketing, we will obtain it before doing so.

You can opt out of marketing at any time using the unsubscribe link in the message or by contacting [email protected]. Opting out of marketing does not stop transactional messages.

We do not use Academy Member Data for WhiteBelt’s own direct marketing unless the person has independently requested communications from WhiteBelt or another lawful basis applies. Academies are independently responsible for ensuring that marketing messages sent to their own members through DojoCore comply with applicable consent, identification and unsubscribe requirements.

13. Cookies and similar technologies

DojoCore uses cookies, local storage and similar technologies that are necessary to authenticate users, maintain sessions, protect accounts, prevent abuse, remember preferences, operate forms and maintain the security and functionality of the Service. Strictly necessary technologies cannot always be disabled without preventing the Service from functioning.

We do not currently use cookies for advertising, cross-site tracking or the creation of third-party advertising profiles. If we introduce non-essential analytics, advertising or tracking technologies, we will provide additional information and request consent where required by applicable law.

Browser settings may allow you to delete or block cookies, but doing so may affect the operation of the Service.

We may also create statistical, aggregated or de-identified information that does not reasonably identify an individual, and use it to understand product usage, measure performance, improve DojoCore and plan our business. We will not attempt to re-identify properly de-identified information except where necessary to verify that the de-identification is effective, or where otherwise permitted by law.

14. Changes to this policy

We may update this Privacy Policy to reflect changes to the Service, our data practices, our providers, applicable law or our organisational structure. We will publish the updated version on this page and change the “Last updated” date. If a change materially affects how we use personal data, we will provide additional notice where reasonably practicable or legally required.

15. Contact us

Questions, requests and complaints concerning this Privacy Policy may be sent to:

WhiteBelt Limited Company number: 76938845 Registered office: Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong Privacy email: [email protected] Support email: [email protected]

Individuals may also have the right to complain to a privacy regulator in their country. For matters governed by Hong Kong privacy law, complaints may be submitted to the Office of the Privacy Commissioner for Personal Data, Hong Kong.

For questions about Academy Member Data, contacting the relevant Academy first will usually be the fastest way to resolve the request.