DojoExpert Privacy Notice
Summary. DojoExpert is a business-to-business software service for martial arts clubs and schools. Depending on the applicable contracting entity, personal data relating to customer accounts, subscriptions, invoicing and payments may be processed by either Link Lab j.d.o.o. or Link Lab Information Technologies Limited in connection with providing the DojoExpert Service. Link Lab processes account, billing, support, website and service-usage information for its own business purposes. When a customer enters information about its members, prospective members, parents, guardians, coaches or other contacts into DojoExpert, the customer generally determines why and how that information is processed and Link Lab processes it on the customer's behalf.
We do not sell Customer Data. The DojoExpert service, its primary database and backups are hosted in the United States. This Notice explains what information we process, why we process it, where it is stored, who receives it and what rights may be available to individuals.
1. Scope
This Privacy Notice applies to personal information processed through the DojoExpert websites, web application, mobile applications, customer support channels and related services that link to this Notice (together, the Services).
It applies to website visitors, trial users, customer administrators, coaches and other authorised users of customer accounts. It also explains how we handle information that customers upload or otherwise submit about their members, prospective members, parents, guardians, staff and other contacts.
This Notice does not govern the independent privacy practices of our customers or third-party websites and services. A martial arts club or school using DojoExpert must provide its own privacy information to individuals where required by applicable law.
2. Who we are
DojoExpert is proprietary software developed and owned by Link Lab j.d.o.o., Perini 14, 52448 Sveti Lovreč, Croatia ("Link Lab Croatia").
Depending on the Customer's subscription and the contracting entity identified on the applicable order, subscription confirmation or invoice, the DojoExpert Service is provided either by:
Link Lab j.d.o.o., Croatia, Perini 14, 52448 Sv.Lovrec ("Link Lab Croatia") or
Link Lab Information Technologies Limited, Landscape House, Baldonnell Business Park, Dublin D22 P3K7, Ireland ("Link Lab Ireland"),
under licence from Link Lab Croatia.
Throughout this Privacy Notice, references to "we", "us" or "our" mean the applicable contracting entity providing the DojoExpert Service to you, unless the context indicates otherwise.
3. Our privacy roles
3.1 Link Lab as controller or business
Link Lab determines the purposes and means of processing personal information relating to its own business operations. This normally includes information about customer account administrators and authorised users, billing contacts, prospective customers, website visitors, support correspondents and business contacts. In this context, Link Lab acts as a controller under the EU GDPR and UK GDPR, and as a business or equivalent responsible organisation where comparable privacy laws apply.
3.2 Link Lab as processor or service provider
Customers use DojoExpert to manage their organisations and decide what information to enter, why it is used, how long it is kept and who may access it. For personal information contained in those customer-controlled records (Customer Data), the customer generally acts as the controller or business and Link Lab acts as its processor, service provider or contractor.
We process Customer Data to provide the Services, on the customer's documented instructions and as otherwise permitted or required by our agreement and applicable law. Customer Data remains under the customer's control and is not sold by Link Lab.
3.3 Requests concerning Customer Data
If your information was entered into DojoExpert by a martial arts club or school, please normally direct your privacy request to that organisation. We will assist the customer with the request as required by applicable law and our agreement. We may need to refer your request to the relevant customer because we may not be authorised to act independently on its records.
4. Information we process
4.1 Account and contact information
This may include name, organisation or club name, role, postal address, country, email address, telephone number, username, account identifiers, communication preferences and information supplied when registering for a trial or paid account.
4.2 Billing and transaction information
This may include billing contact details, billing address, subscription plan, payment status, invoice and transaction identifiers, tax information and limited payment-related metadata. Payment card and bank-payment details are handled primarily by payment providers such as Stripe and GoCardless. We generally do not receive or store complete card numbers or online banking credentials.
4.3 Customer Data
Depending on the features selected and the information a customer chooses to enter, Customer Data may include names, contact details, dates of birth, gender, membership details, belt or grade information, attendance, groups, fees and payments, competition information, results, communications, files, photographs and other records used by the customer to manage its organisation.
Customers must not use the Services to process information that is prohibited by our agreement or applicable law. Customers are responsible for determining whether a particular category of information requires consent, additional notice, enhanced protection or another lawful basis.
4.4 Communications and support information
We process messages, support requests, feedback and other communications sent to us. When a customer uses DojoExpert communication features, we process message content, recipient details, delivery information and, where enabled, information such as delivery, bounce, opening or link-interaction events.
4.5 Device, log and usage information
We may automatically process IP address, browser type, operating system, device type, application version, language, approximate location derived from IP address, login time, requested pages, referring URL, error information, security events and actions taken within the Services.
4.6 Mobile application information
Our mobile applications may process device and application identifiers, operating-system information, push-notification tokens, crash data and application-performance information. We do not intentionally collect precise geolocation through the DojoExpert mobile applications unless a feature expressly requests it and the user grants permission.
4.7 Website analytics
Subject to applicable consent requirements, we use Google Analytics to understand website and service usage, improve performance and evaluate the effectiveness of our communications. Analytics information may include online identifiers, device information and interactions with our websites.
4.8 Information we do not intentionally request
DojoExpert is not designed as a medical-record system, financial-account system or repository for government identification documents. Customers should not enter highly sensitive information unless it is necessary, lawful, supported by an appropriate DojoExpert feature and permitted by their agreement with us.
5. How we obtain information
We obtain personal information:
- directly from you when you contact us, create or use an account, request a trial, subscribe, pay an invoice or request support;
- from our customers when they create user accounts or enter Customer Data;
- automatically from browsers, devices, servers, cookies, logs, analytics tools and security systems;
- from payment providers and other service providers involved in delivering the Services;
- from publicly available business sources, referrals or business partners where permitted by law; and
- when you interact with us through social media, app stores or third-party platforms.
6. Purposes and legal bases
| Purpose | Typical information | EU/UK legal basis |
|---|---|---|
| Provide, operate and administer the Services | Account, contact, Customer Data, device and usage information | Performance of a contract; legitimate interests; processing on a customer's instructions |
| Authenticate users and secure accounts | Username, password-related credentials, IP address, logs and security events | Performance of a contract; legitimate interests in security and fraud prevention; legal obligations where applicable |
| Process subscriptions, payments and accounting | Billing details, transaction identifiers, tax and invoice information | Performance of a contract; legal obligations; legitimate interests in collecting amounts due |
| Provide support and communicate about the Services | Contact details, account details and correspondence | Performance of a contract; legitimate interests in customer service |
| Send operational notices | Email address, account and service information | Performance of a contract; legitimate interests in operating and securing the Services |
| Improve, diagnose and develop the Services | Usage, log, analytics, feedback and error information | Legitimate interests; consent for non-essential cookies where required |
| Market DojoExpert to business contacts | Business contact details and communication preferences | Consent where required; otherwise legitimate interests, subject to the right to object and applicable direct-marketing rules |
| Comply with law and protect rights | Information reasonably necessary for the relevant request, dispute, audit or investigation | Legal obligations; legitimate interests; establishment, exercise or defence of legal claims |
Where we rely on legitimate interests, we consider the relevant interests, necessity and impact on individuals. Where we rely on consent, consent may be withdrawn at any time without affecting processing already carried out lawfully.
Where Link Lab acts as a processor, the customer is responsible for identifying the lawful basis for processing Customer Data.
7. Customer Data and customer responsibilities
Customers are responsible for:
- providing appropriate privacy information to their members, prospective members, parents, guardians, coaches, employees and other individuals;
- having a valid legal basis for entering and using personal information in DojoExpert;
- configuring permissions and limiting access to authorised users;
- keeping account and Customer Data accurate and proportionate;
- responding to privacy requests concerning their records; and
- complying with laws applicable to communications sent through the Services.
Customers may export member and contact records using available DojoExpert functionality. The available export format and included fields may depend on the relevant feature.
9. Service providers and subprocessors
We use third parties to provide parts of the Services. The providers used for a particular customer or transaction may vary by location, payment method, enabled feature and technical configuration.
| Provider | Purpose | Typical processing locations |
|---|---|---|
| Google Cloud | Cloud database, infrastructure and backups | United States |
| Amazon Web Services, including Amazon S3 and Amazon SES | File storage and email delivery | May include the United States and other locations selected for the relevant service |
| Stripe | Card payments, subscription billing and payment-related fraud prevention | United States, European Union and other locations used by Stripe |
| GoCardless | Bank debit and payment processing | United Kingdom, European Union and other locations used by GoCardless |
| Google Analytics | Website and service analytics | May include the United States and other locations used by Google |
| Google Firebase | Mobile application services, including push notifications, diagnostics or performance functions | May include the United States and other locations used by Google |
We require providers that process personal information on our behalf to be subject to contractual or other appropriate data-protection obligations. A separate subprocessor list may provide more detailed and updated information.
10. Data location and international transfers
The DojoExpert primary database and its backups are hosted in the United States using Google Cloud SQL. Personal information may also be accessed or processed in Croatia and in other countries where our service providers operate.
These countries may have privacy laws that differ from those in your country. Where EU, EEA or UK personal data is transferred to a country that is not recognised as providing an adequate level of protection, we use an applicable transfer mechanism where required, such as:
- the European Commission's Standard Contractual Clauses;
- the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
- an applicable adequacy decision, including an applicable recipient's participation in the EU–U.S. Data Privacy Framework or UK Extension, where valid and relevant; or
- another lawful transfer mechanism or permitted derogation.
We also assess and apply supplementary technical, contractual or organisational measures where appropriate. Customers that transfer personal information to DojoExpert are responsible for ensuring that their own disclosures and use of the Services comply with applicable cross-border transfer requirements.
Australian customers should note that personal information submitted to DojoExpert may be disclosed to recipients in the United States, Croatia, the United Kingdom, countries in the European Union and countries in which the providers listed above operate.
11. Retention and deletion
We retain account and Customer Data while the relevant customer account is active and as needed to provide the Services.
Following account termination or a valid deletion request, production data is deleted or anonymised according to our deletion process. Residual copies may remain in backups for up to three months before being overwritten or deleted through the normal backup lifecycle. Backup data is isolated from ordinary use and is retained for continuity and recovery purposes.
Some information may be retained longer where reasonably necessary to:
- comply with tax, accounting, payment, corporate or other legal obligations;
- establish, exercise or defend legal claims;
- resolve disputes and enforce agreements;
- maintain security, prevent fraud or document consent and opt-out choices; or
- retain aggregated or de-identified information that no longer identifies an individual.
The precise period depends on the nature of the information, the purpose of processing, contractual commitments and applicable law.
13. Security
We use reasonable technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. Measures include encrypted network transmission using HTTPS, account authentication, access restrictions, backups, service monitoring and procedures for responding to security incidents.
No online service can guarantee absolute security. Customers and authorised users are responsible for maintaining the confidentiality of their credentials, using appropriately strong passwords, restricting account access and promptly notifying us of suspected compromise.
Additional information is available in our Security Policy.
14. Privacy rights
Depending on your location and applicable law, you may have the right to:
- request access to personal information about you;
- request correction of inaccurate or incomplete information;
- request deletion of personal information;
- request restriction of or object to certain processing;
- receive certain information in a portable format;
- withdraw consent where processing is based on consent;
- opt out of marketing communications;
- complain to a privacy or data-protection authority; and
- not be discriminated against for exercising rights provided by applicable law.
These rights are not absolute and may be subject to verification, legal exceptions and the privacy role in which we process the information. We may request information reasonably necessary to confirm identity and authority. An authorised agent may submit a request where permitted by law and where the agent's authority can be verified.
To exercise a right concerning information controlled by Link Lab, email info@linklab.hr. For Customer Data, contact the relevant club or school first.
15. Additional information for the EU, EEA and United Kingdom
For information for which Link Lab is the controller, you may have rights under the EU GDPR or UK GDPR to access, rectify, erase, restrict processing, object to processing and receive portable data, subject to applicable conditions and exceptions.
You have an absolute right to object to direct marketing. You may unsubscribe through the link in a marketing email or contact us.
Where processing is based on our legitimate interests, you may object based on your particular situation. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing is needed for legal claims.
Link Lab is established in Croatia. The competent EU supervisory authority for Link Lab is generally the Croatian Personal Data Protection Agency (AZOP). You may also contact the supervisory authority in the EU or EEA country where you live or work, or where you believe an infringement occurred. Individuals in the United Kingdom may complain to the UK Information Commissioner's Office (ICO).
We do not use personal information to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals, unless expressly disclosed for a specific feature and permitted by law.
16. Additional information for United States residents
United States privacy rights vary by state. This section applies to the extent a state privacy law covers Link Lab and the relevant processing. Nothing in this section represents that a particular law necessarily applies when its statutory thresholds or scope requirements are not met.
16.1 Categories of personal information
In the preceding 12 months, we may have processed the following broad categories: identifiers and contact information; customer records; commercial and transaction information; internet, application and electronic-network activity; approximate geolocation derived from IP address; professional or employment-related information; user-generated content; and inferences relating to use of the Services. Customer Data may include additional categories selected by the customer.
16.2 Sources, purposes and recipients
We obtain this information from the sources described in Section 5, use it for the purposes described in Section 6 and disclose it to the recipients described in Sections 8 and 9.
16.3 Sale, sharing and targeted advertising
We do not sell Customer Data for money. We do not knowingly sell personal information about individuals under 16 years of age. We do not disclose Customer Data for third parties' independent cross-context behavioural advertising.
Some state laws may define certain uses of analytics or advertising technologies as a “sale,” “sharing” or use for targeted advertising even when no money is exchanged. Where such a law applies and our use of a non-essential technology falls within that definition, we will provide the legally required notice and opt-out method.
16.4 Requests
Subject to applicable law, residents may be entitled to request confirmation, access, correction, deletion or portability, and to opt out of covered sale, sharing, targeted advertising or certain profiling. They may also have a right to appeal a refusal of a request. Submit requests to info@linklab.hr. We will not unlawfully discriminate against you for exercising an applicable privacy right.
16.5 California
Where the California Consumer Privacy Act, as amended, applies, the disclosures in this Notice are intended to describe our practices for the preceding 12 months and our current practices. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law, except to the extent Customer Data is processed on behalf of a customer as a service provider or contractor.
California's “Shine the Light” law may permit residents with an established business relationship to request information concerning certain disclosures for third parties' own direct-marketing purposes. We do not disclose Customer Data to third parties for those purposes.
17. Additional information for Australian residents
To the extent the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) apply to Link Lab or the relevant processing, we handle personal information in accordance with those requirements.
Individuals may request access to or correction of personal information held by Link Lab. We will respond within a reasonable period and, where permitted by law, may refuse a request on specified grounds. If we refuse, we will provide the legally required notice and information about available complaint mechanisms.
We use personal information for direct marketing only where permitted by law. Marketing messages include a means to opt out, and an opt-out request may be made by contacting us. Operational, account, security and legal notices are not marketing messages.
As explained in Section 10, personal information may be disclosed to overseas recipients, particularly in the United States, Croatia, the United Kingdom, countries in the European Union and other countries in which our providers operate. We take reasonable steps required by applicable law in connection with overseas disclosures.
If you make a privacy complaint, please describe the issue and provide sufficient contact details. We will investigate and respond within a reasonable period. If you are not satisfied, you may be entitled to complain to the Office of the Australian Information Commissioner (OAIC).
18. Children and minors
DojoExpert is offered to martial arts clubs, schools, coaches and other organisations. It is not offered directly to children for independent registration or purchase.
Customers may use DojoExpert to maintain records about child members. In that context, the customer determines the purpose and lawful basis of processing and is responsible for required notices, permissions and parental or guardian consent. Link Lab processes those records on the customer's behalf.
If you believe a child has provided personal information directly to Link Lab without appropriate authorisation, contact us so that we can investigate.
19. Security incidents and data breaches
We maintain procedures for assessing and responding to suspected personal-data breaches. Where Link Lab acts as a processor, we will notify the affected customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, in accordance with applicable law and contractual obligations.
Where Link Lab acts as controller, we will notify the competent authority and affected individuals when required by applicable law.
20. Changes to this Notice
We may update this Notice to reflect changes in the Services, our practices, providers or applicable law. The “Last updated” date identifies the current version. If a change materially affects how we use personal information, we will provide additional notice where required, such as through the Services, by email or on our website.
Changes do not retroactively reduce privacy rights or change a legal basis where applicable law requires additional notice or consent.
21. Contact and complaints
Questions, privacy requests and complaints may be submitted to:
Link Lab j.d.o.o.Privacy Contact
Perini 14
52448 Sveti Lovreč
Croatia
Email: info@linklab.hr
Please include enough information for us to understand the request and identify the relevant account or customer. Do not send passwords, complete payment-card numbers or unnecessary sensitive information by email.