Data Processing Agreement

This Data Processing Agreement forms part of the agreement between the Customer and the applicable DojoExpert contracting entity identified on the Customer's order, subscription confirmation or invoice. The DojoExpert software is owned by Link Lab j.d.o.o., Croatia. Where the Customer contracts with Link Lab Information Technologies Limited, that entity provides the Service under licence from Link Lab j.d.o.o. This Data Processing Agreement ("DPA") forms part of the agreement between the entity that provides service ("Processor", "Link Lab", "we", "us") and the Customer using DojoExpert ("Controller", "Customer").

This DPA applies whenever the Customer uploads, stores or otherwise processes Personal Data within the DojoExpert platform.

Contents

1. Definitions

Unless otherwise defined herein, capitalised terms shall have the meaning given to them in Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and applicable data protection legislation.

Term Meaning
Controller The Customer determining the purposes and means of processing Personal Data.
Processor Link Lab j.d.o.o., acting solely on documented instructions of the Customer.
Personal Data Any information relating to an identified or identifiable natural person.
Processing Any operation performed on Personal Data as defined by the GDPR.
Services The DojoExpert software platform and related services.
Subprocessor A third party engaged by the Processor to process Personal Data.

2. Purpose and Scope

This Agreement governs all Processing of Personal Data carried out by Link Lab on behalf of the Customer while providing the DojoExpert platform.

The Parties acknowledge that this Agreement satisfies the requirements of:

Where this DPA conflicts with any other agreement between the Parties regarding Personal Data Processing, this DPA shall prevail.

3. Roles of the Parties

Customer as Controller

The Customer determines:

Link Lab as Processor

Link Lab processes Personal Data exclusively on behalf of the Customer and strictly in accordance with documented instructions provided through the use of the Services or otherwise communicated by the Customer.

Link Lab does not determine the purposes of Processing Customer Data.

4. Processing Instructions

The Customer instructs Link Lab to Process Personal Data solely for the purpose of providing the Services.

Link Lab shall:

5. Subject Matter of Processing

Processing relates exclusively to operation of the DojoExpert platform, including administration of sports clubs and related organisational activities.

Processing activities may include:

6. Nature and Purpose of Processing

Personal Data is processed electronically using secure cloud infrastructure for the purpose of providing software services requested by the Customer.

Processing operations may include:

Link Lab shall not process Personal Data for its own independent purposes.

7. Categories of Personal Data and Data Subjects

Categories of Personal Data

Categories of Data Subjects

8. Confidentiality

Link Lab shall ensure that all persons authorised to Process Personal Data:

Administrative access to production systems is restricted to authorised Link Lab personnel who require such access for operational, maintenance or support purposes.

Access rights are granted according to the principle of least privilege and are reviewed whenever operational responsibilities change.

9. Security Measures

Link Lab implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of Processing and the risks to the rights and freedoms of natural persons.

Technical Measures

Organisational Measures

The Processor may improve or replace security measures over time provided that such changes do not materially reduce the overall level of protection.

10. Subprocessors

The Customer grants the Processor general authorisation to engage Subprocessors for the provision of the Services.

The Processor shall ensure that each Subprocessor is subject to written contractual obligations providing a level of protection for Personal Data that is substantially equivalent to those set out in this Agreement.

The Processor remains fully responsible for the performance of each authorised Subprocessor to the extent required by applicable data protection legislation.

Changes to Subprocessors

Where the Processor intends to appoint a new Subprocessor, the Processor shall provide the Customer with at least thirty (30) days' prior notice.

During this period the Customer may raise reasonable objections based on legitimate data protection concerns.

Where the Parties cannot reasonably resolve such concerns, either Party may terminate the affected Services in accordance with the applicable agreement.

11. International Data Transfers

The Customer acknowledges that the Services utilise infrastructure located within both the European Union and the United States.

Customer Personal Data may therefore be transferred to or accessed from jurisdictions outside the European Economic Area or the United Kingdom where required for the provision of the Services.

Whenever Personal Data is transferred internationally, Link Lab shall implement appropriate safeguards as required under applicable data protection legislation.

Such safeguards may include, where applicable:

Nothing in this Agreement shall be interpreted as preventing the Processor from using internationally recognised cloud infrastructure where appropriate safeguards are maintained.

12. Assistance with Data Subject Rights

Taking into account the nature of the Processing, Link Lab shall provide reasonable assistance enabling the Customer to fulfil its obligations regarding requests from Data Subjects.

Such assistance may include requests relating to:

Where Link Lab receives a request directly from a Data Subject relating to Customer Data, Link Lab shall, unless legally prohibited, promptly forward the request to the Customer and shall not respond except on documented instructions.

13. Personal Data Breaches

Link Lab maintains procedures for identifying, investigating and responding to suspected Personal Data Breaches.

Where Link Lab becomes aware of a Personal Data Breach affecting Customer Personal Data, Link Lab shall notify the Customer without undue delay after becoming aware of the breach.

To the extent reasonably available, such notification shall include:

The Processor shall cooperate with the Customer in investigating the incident and implementing reasonable remediation measures.

14. Audits

Upon reasonable written request, the Processor shall make available information reasonably necessary to demonstrate compliance with this Agreement.

Such information may include:

Where the above information is insufficient to satisfy a specific legal obligation of the Customer, the Parties may agree to a reasonable audit or inspection.

Any such audit shall:

Each Party shall bear its own costs associated with audits unless otherwise required by applicable law or agreed in writing.

15. Return and Deletion of Personal Data

Upon termination of the Services or upon the Customer's written request, Link Lab shall, at the Customer's choice and where technically feasible:

Deletion requests shall be carried out within a reasonable period unless retention is required by applicable law or necessary for the establishment, exercise or defence of legal claims.

Customer Data contained within backup media is not immediately overwritten. Such backup copies are retained solely for disaster recovery purposes and are automatically removed through the normal backup retention cycle.

Under Link Lab's current backup policy, production backups are retained for approximately three (3) months before automatic deletion.

Following completion of the applicable retention period, Customer Personal Data is permanently removed from backup systems in accordance with Link Lab's operational procedures.

Where the Customer does not provide deletion or return instructions within ninety (90) days after termination of the Services, Link Lab may securely delete the remaining Customer Data, unless retention is required by law.

16. Liability

Each Party shall remain responsible for complying with its respective obligations under applicable data protection legislation.

The Customer remains solely responsible for:

Link Lab shall be responsible only for its obligations as a Processor under applicable data protection legislation.

Nothing in this Agreement shall exclude or limit liability where such limitation is prohibited by applicable law.

17. Term and Termination

This Agreement becomes effective on the date Processing begins and remains in force for as long as Link Lab Processes Personal Data on behalf of the Customer.

Termination of the underlying Services Agreement automatically terminates this Data Processing Agreement, except for provisions that by their nature survive termination.

The following provisions shall survive termination:

18. Governing Law

This Agreement shall be governed by the law governing the principal agreement between the Parties unless mandatory data protection legislation requires otherwise.

Nothing in this Agreement limits the rights or powers of competent supervisory authorities under applicable privacy legislation.

19. Miscellaneous

Entire Agreement

This Agreement forms an integral part of the agreement governing the Customer's use of the Services.

Order of Precedence

In the event of any conflict between this Data Processing Agreement and any other agreement relating to the Processing of Personal Data, this Data Processing Agreement shall prevail.

Severability

If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

Amendments

Link Lab may update this Agreement where necessary to reflect changes in applicable law, regulatory guidance, security practices or the Services.

Where a change materially affects the rights or obligations of the Customer, reasonable prior notice shall be provided before the updated version becomes effective.

Contact

Questions regarding this Data Processing Agreement may be directed to:

Link Lab j.d.o.o.
Perini 14
52448 Sveti Lovreč
Croatia

E-mail: info@linklab.hr


Version 1.0
Last updated: July 2026

Annex I – Description of Processing

This Annex forms an integral part of the Data Processing Agreement and describes the Processing activities carried out by Link Lab on behalf of the Customer.

1. Subject Matter of Processing

The Processor provides the DojoExpert cloud platform, enabling sports clubs, associations and other organisations to manage their members, sporting activities, communications, billing and other operational processes.

The Processor Processes Personal Data solely to provide, maintain, support and secure the Services requested by the Customer.

2. Duration of Processing

Processing continues for the duration of the Customer's use of the Services.

Following termination of the Services, Personal Data is retained only for the period necessary to complete deletion procedures, comply with legal obligations or maintain disaster recovery backups in accordance with the Processor's backup retention policy.

3. Nature of Processing

The Processor may perform the following Processing operations where necessary for providing the Services:

4. Purpose of Processing

Processing is limited to providing software functionality requested by the Customer.

Typical purposes include:

5. Categories of Personal Data

Category Examples
Identity Data Name, surname, date of birth, gender where provided.
Contact Data E-mail address, telephone number, postal address.
Membership Data Membership status, club information, enrolment history.
Attendance Data Training attendance records.
Sport Data Belt grades, examinations, competition participation, rankings and results.
Financial Data Invoices, payment status, subscription information.
Communication Data Messages sent through the Services.
Documents Files uploaded by the Customer.
Images Photographs uploaded by the Customer.
Other Customer Data Any additional Personal Data entered by the Customer.

6. Categories of Data Subjects

7. Special Categories of Personal Data

The Services are not intended for the routine Processing of Special Categories of Personal Data as defined by Article 9 GDPR.

Where the Customer voluntarily stores such information within the Services, the Customer remains solely responsible for ensuring an appropriate legal basis for such Processing.

The Services are not specifically designed for the routine Processing of Special Categories of Personal Data. Where the Customer chooses to store such information, the Customer acts as Controller and is responsible for ensuring an appropriate legal basis and compliance with applicable data protection legislation.

8. Processing Frequency

Processing takes place continuously during the Customer's use of the Services, including user interactions, automated system operations, scheduled backups and support activities where requested by the Customer.

9. Data Location

The Services utilise infrastructure located within both the European Union and the United States.

Personal Data may therefore be stored or accessed within these regions where necessary for providing the Services.

10. Categories of Recipients

Personal Data may be disclosed only where necessary to:

11. International Transfers

Where Personal Data is transferred outside the European Economic Area or the United Kingdom, appropriate safeguards described in this Agreement shall apply.

12. End of Processing

Upon termination of the Services, Personal Data shall be returned or deleted in accordance with Section 15 of this Agreement unless retention is required by applicable law or necessary for disaster recovery backup retention.

Annex II – Technical and Organisational Measures (TOMs)

This Annex describes the technical and organisational measures implemented by Link Lab to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

1. Information Security Governance

Link Lab maintains internal procedures designed to protect the confidentiality, integrity and availability of Customer Personal Data.

Access to Personal Data is granted only where necessary for providing, maintaining or supporting the Services.


2. Authentication


3. Authorisation and Access Control


4. Encryption

Area Protection
Data in transit HTTPS / TLS encryption.
Data at rest Google Cloud default encryption for stored data.
Passwords ASP.NET Identity password hashing.

Link Lab relies on Google Cloud's managed encryption mechanisms for protection of stored production data.


5. Infrastructure Security


6. Backup and Disaster Recovery


7. Logging and Monitoring


8. Security Maintenance


9. Confidentiality


10. Incident Response

Link Lab maintains procedures for investigating suspected security incidents.

Where a Personal Data Breach affecting Customer Personal Data is confirmed, the Customer will be notified without undue delay.

Reasonable efforts will be made to investigate the incident, mitigate its effects and prevent recurrence where appropriate.


11. Data Deletion


12. International Transfers

Customer Personal Data may be processed using infrastructure located within the European Union and the United States.

Where international transfers occur, Link Lab implements appropriate safeguards described within this Agreement.


13. Business Continuity


14. Continuous Improvement

Security measures are periodically reviewed and may be updated to reflect changes in technology, applicable legal requirements, operational experience and emerging security risks.

Link Lab may implement additional safeguards provided that such changes do not materially reduce the overall level of protection provided to Customer Personal Data.

Annex III – Approved Subprocessors

This Annex identifies the Subprocessors authorised by Link Lab to process Personal Data on behalf of Customers in connection with the Services.

Each Subprocessor is engaged only where necessary for providing the Services. Link Lab remains responsible for ensuring that each Subprocessor is subject to appropriate contractual data protection obligations.

Subprocessor Purpose Location Data Processed
Google Cloud Platform Cloud infrastructure, hosting, database services and backups European Union / United States Customer Data, databases, backups
Amazon Web Services (Amazon S3) File storage United States Files uploaded by Customers
Amazon Simple Email Service (SES) Transactional e-mail delivery United States E-mail addresses and message delivery information
Stripe Online payment processing United States Subscription and payment information required to process payments
GoCardless Direct Debit payment processing United Kingdom Payment information required for Direct Debit transactions
Firebase Cloud Messaging Push notifications for the mobile application United States Push notification tokens
Google Analytics Website analytics United States Website usage data where applicable

Appointment of New Subprocessors

Link Lab may appoint additional Subprocessors where reasonably necessary for providing or improving the Services.

Customers will receive at least thirty (30) days' prior notice before a new Subprocessor is authorised to Process Customer Personal Data.

Customers may object to a new Subprocessor where they have reasonable and documented data protection concerns.

Where no reasonable alternative exists, either Party may terminate the affected Services in accordance with the applicable agreement.


Subprocessor Obligations


Contact

Questions regarding Subprocessors may be sent to:

Link Lab j.d.o.o.
Perini 14
52448 Sveti Lovreč
Croatia

info@linklab.hr