This Data Processing Agreement forms part of the agreement between the Customer and the applicable DojoExpert contracting entity identified on the Customer's order, subscription confirmation or invoice. The DojoExpert software is owned by Link Lab j.d.o.o., Croatia. Where the Customer contracts with Link Lab Information Technologies Limited, that entity provides the Service under licence from Link Lab j.d.o.o. This Data Processing Agreement ("DPA") forms part of the agreement between the entity that provides service ("Processor", "Link Lab", "we", "us") and the Customer using DojoExpert ("Controller", "Customer").
Unless otherwise defined herein, capitalised terms shall have the meaning given to them in Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and applicable data protection legislation.
| Term | Meaning |
|---|---|
| Controller | The Customer determining the purposes and means of processing Personal Data. |
| Processor | Link Lab j.d.o.o., acting solely on documented instructions of the Customer. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Processing | Any operation performed on Personal Data as defined by the GDPR. |
| Services | The DojoExpert software platform and related services. |
| Subprocessor | A third party engaged by the Processor to process Personal Data. |
This Agreement governs all Processing of Personal Data carried out by Link Lab on behalf of the Customer while providing the DojoExpert platform.
The Parties acknowledge that this Agreement satisfies the requirements of:
Where this DPA conflicts with any other agreement between the Parties regarding Personal Data Processing, this DPA shall prevail.
The Customer determines:
Link Lab processes Personal Data exclusively on behalf of the Customer and strictly in accordance with documented instructions provided through the use of the Services or otherwise communicated by the Customer.
Link Lab does not determine the purposes of Processing Customer Data.
The Customer instructs Link Lab to Process Personal Data solely for the purpose of providing the Services.
Link Lab shall:
Processing relates exclusively to operation of the DojoExpert platform, including administration of sports clubs and related organisational activities.
Processing activities may include:
Personal Data is processed electronically using secure cloud infrastructure for the purpose of providing software services requested by the Customer.
Processing operations may include:
Link Lab shall not process Personal Data for its own independent purposes.
Link Lab shall ensure that all persons authorised to Process Personal Data:
Administrative access to production systems is restricted to authorised Link Lab personnel who require such access for operational, maintenance or support purposes.
Access rights are granted according to the principle of least privilege and are reviewed whenever operational responsibilities change.
Link Lab implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of Processing and the risks to the rights and freedoms of natural persons.
The Processor may improve or replace security measures over time provided that such changes do not materially reduce the overall level of protection.
The Customer grants the Processor general authorisation to engage Subprocessors for the provision of the Services.
The Processor shall ensure that each Subprocessor is subject to written contractual obligations providing a level of protection for Personal Data that is substantially equivalent to those set out in this Agreement.
The Processor remains fully responsible for the performance of each authorised Subprocessor to the extent required by applicable data protection legislation.
Where the Processor intends to appoint a new Subprocessor, the Processor shall provide the Customer with at least thirty (30) days' prior notice.
During this period the Customer may raise reasonable objections based on legitimate data protection concerns.
Where the Parties cannot reasonably resolve such concerns, either Party may terminate the affected Services in accordance with the applicable agreement.
The Customer acknowledges that the Services utilise infrastructure located within both the European Union and the United States.
Customer Personal Data may therefore be transferred to or accessed from jurisdictions outside the European Economic Area or the United Kingdom where required for the provision of the Services.
Whenever Personal Data is transferred internationally, Link Lab shall implement appropriate safeguards as required under applicable data protection legislation.
Such safeguards may include, where applicable:
Nothing in this Agreement shall be interpreted as preventing the Processor from using internationally recognised cloud infrastructure where appropriate safeguards are maintained.
Taking into account the nature of the Processing, Link Lab shall provide reasonable assistance enabling the Customer to fulfil its obligations regarding requests from Data Subjects.
Such assistance may include requests relating to:
Where Link Lab receives a request directly from a Data Subject relating to Customer Data, Link Lab shall, unless legally prohibited, promptly forward the request to the Customer and shall not respond except on documented instructions.
Link Lab maintains procedures for identifying, investigating and responding to suspected Personal Data Breaches.
Where Link Lab becomes aware of a Personal Data Breach affecting Customer Personal Data, Link Lab shall notify the Customer without undue delay after becoming aware of the breach.
To the extent reasonably available, such notification shall include:
The Processor shall cooperate with the Customer in investigating the incident and implementing reasonable remediation measures.
Upon reasonable written request, the Processor shall make available information reasonably necessary to demonstrate compliance with this Agreement.
Such information may include:
Where the above information is insufficient to satisfy a specific legal obligation of the Customer, the Parties may agree to a reasonable audit or inspection.
Any such audit shall:
Each Party shall bear its own costs associated with audits unless otherwise required by applicable law or agreed in writing.
Upon termination of the Services or upon the Customer's written request, Link Lab shall, at the Customer's choice and where technically feasible:
Deletion requests shall be carried out within a reasonable period unless retention is required by applicable law or necessary for the establishment, exercise or defence of legal claims.
Customer Data contained within backup media is not immediately overwritten. Such backup copies are retained solely for disaster recovery purposes and are automatically removed through the normal backup retention cycle.
Under Link Lab's current backup policy, production backups are retained for approximately three (3) months before automatic deletion.
Following completion of the applicable retention period, Customer Personal Data is permanently removed from backup systems in accordance with Link Lab's operational procedures.
Where the Customer does not provide deletion or return instructions within ninety (90) days after termination of the Services, Link Lab may securely delete the remaining Customer Data, unless retention is required by law.
Each Party shall remain responsible for complying with its respective obligations under applicable data protection legislation.
The Customer remains solely responsible for:
Link Lab shall be responsible only for its obligations as a Processor under applicable data protection legislation.
Nothing in this Agreement shall exclude or limit liability where such limitation is prohibited by applicable law.
This Agreement becomes effective on the date Processing begins and remains in force for as long as Link Lab Processes Personal Data on behalf of the Customer.
Termination of the underlying Services Agreement automatically terminates this Data Processing Agreement, except for provisions that by their nature survive termination.
The following provisions shall survive termination:
This Agreement shall be governed by the law governing the principal agreement between the Parties unless mandatory data protection legislation requires otherwise.
Nothing in this Agreement limits the rights or powers of competent supervisory authorities under applicable privacy legislation.
This Agreement forms an integral part of the agreement governing the Customer's use of the Services.
In the event of any conflict between this Data Processing Agreement and any other agreement relating to the Processing of Personal Data, this Data Processing Agreement shall prevail.
If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
Link Lab may update this Agreement where necessary to reflect changes in applicable law, regulatory guidance, security practices or the Services.
Where a change materially affects the rights or obligations of the Customer, reasonable prior notice shall be provided before the updated version becomes effective.
Questions regarding this Data Processing Agreement may be directed to:
Link Lab j.d.o.o.
Perini 14
52448 Sveti Lovreč
Croatia
E-mail:
info@linklab.hr
Version 1.0
Last updated: July 2026
This Annex forms an integral part of the Data Processing Agreement and describes the Processing activities carried out by Link Lab on behalf of the Customer.
The Processor provides the DojoExpert cloud platform, enabling sports clubs, associations and other organisations to manage their members, sporting activities, communications, billing and other operational processes.
The Processor Processes Personal Data solely to provide, maintain, support and secure the Services requested by the Customer.
Processing continues for the duration of the Customer's use of the Services.
Following termination of the Services, Personal Data is retained only for the period necessary to complete deletion procedures, comply with legal obligations or maintain disaster recovery backups in accordance with the Processor's backup retention policy.
The Processor may perform the following Processing operations where necessary for providing the Services:
Processing is limited to providing software functionality requested by the Customer.
Typical purposes include:
| Category | Examples |
|---|---|
| Identity Data | Name, surname, date of birth, gender where provided. |
| Contact Data | E-mail address, telephone number, postal address. |
| Membership Data | Membership status, club information, enrolment history. |
| Attendance Data | Training attendance records. |
| Sport Data | Belt grades, examinations, competition participation, rankings and results. |
| Financial Data | Invoices, payment status, subscription information. |
| Communication Data | Messages sent through the Services. |
| Documents | Files uploaded by the Customer. |
| Images | Photographs uploaded by the Customer. |
| Other Customer Data | Any additional Personal Data entered by the Customer. |
The Services are not intended for the routine Processing of Special Categories of Personal Data as defined by Article 9 GDPR.
Where the Customer voluntarily stores such information within the Services, the Customer remains solely responsible for ensuring an appropriate legal basis for such Processing.
The Services are not specifically designed for the routine Processing of Special Categories of Personal Data. Where the Customer chooses to store such information, the Customer acts as Controller and is responsible for ensuring an appropriate legal basis and compliance with applicable data protection legislation.
Processing takes place continuously during the Customer's use of the Services, including user interactions, automated system operations, scheduled backups and support activities where requested by the Customer.
The Services utilise infrastructure located within both the European Union and the United States.
Personal Data may therefore be stored or accessed within these regions where necessary for providing the Services.
Personal Data may be disclosed only where necessary to:
Where Personal Data is transferred outside the European Economic Area or the United Kingdom, appropriate safeguards described in this Agreement shall apply.
Upon termination of the Services, Personal Data shall be returned or deleted in accordance with Section 15 of this Agreement unless retention is required by applicable law or necessary for disaster recovery backup retention.
This Annex describes the technical and organisational measures implemented by Link Lab to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Link Lab maintains internal procedures designed to protect the confidentiality, integrity and availability of Customer Personal Data.
Access to Personal Data is granted only where necessary for providing, maintaining or supporting the Services.
| Area | Protection |
|---|---|
| Data in transit | HTTPS / TLS encryption. |
| Data at rest | Google Cloud default encryption for stored data. |
| Passwords | ASP.NET Identity password hashing. |
Link Lab relies on Google Cloud's managed encryption mechanisms for protection of stored production data.
Link Lab maintains procedures for investigating suspected security incidents.
Where a Personal Data Breach affecting Customer Personal Data is confirmed, the Customer will be notified without undue delay.
Reasonable efforts will be made to investigate the incident, mitigate its effects and prevent recurrence where appropriate.
Customer Personal Data may be processed using infrastructure located within the European Union and the United States.
Where international transfers occur, Link Lab implements appropriate safeguards described within this Agreement.
Security measures are periodically reviewed and may be updated to reflect changes in technology, applicable legal requirements, operational experience and emerging security risks.
Link Lab may implement additional safeguards provided that such changes do not materially reduce the overall level of protection provided to Customer Personal Data.
This Annex identifies the Subprocessors authorised by Link Lab to process Personal Data on behalf of Customers in connection with the Services.
Each Subprocessor is engaged only where necessary for providing the Services. Link Lab remains responsible for ensuring that each Subprocessor is subject to appropriate contractual data protection obligations.
| Subprocessor | Purpose | Location | Data Processed |
|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure, hosting, database services and backups | European Union / United States | Customer Data, databases, backups |
| Amazon Web Services (Amazon S3) | File storage | United States | Files uploaded by Customers |
| Amazon Simple Email Service (SES) | Transactional e-mail delivery | United States | E-mail addresses and message delivery information |
| Stripe | Online payment processing | United States | Subscription and payment information required to process payments |
| GoCardless | Direct Debit payment processing | United Kingdom | Payment information required for Direct Debit transactions |
| Firebase Cloud Messaging | Push notifications for the mobile application | United States | Push notification tokens |
| Google Analytics | Website analytics | United States | Website usage data where applicable |
Link Lab may appoint additional Subprocessors where reasonably necessary for providing or improving the Services.
Customers will receive at least thirty (30) days' prior notice before a new Subprocessor is authorised to Process Customer Personal Data.
Customers may object to a new Subprocessor where they have reasonable and documented data protection concerns.
Where no reasonable alternative exists, either Party may terminate the affected Services in accordance with the applicable agreement.
Questions regarding Subprocessors may be sent to:
Link Lab j.d.o.o.
Perini 14
52448 Sveti Lovreč
Croatia
info@linklab.hr