This document provides an overview of the security architecture, technical safeguards and organisational measures implemented by Link Lab j.d.o.o. to protect Customer Data processed through the DojoExpert platform.
DojoExpert is a cloud-based software platform designed for sports clubs, associations and organisations. The platform is developed and operated by Link Lab j.d.o.o..
Protection of Customer Data is an integral part of the platform design. Security controls are implemented across the application, cloud infrastructure and operational processes to reduce the risk of unauthorised access, accidental loss or disclosure of information.
Security measures are reviewed periodically and updated where appropriate to address operational requirements and evolving security risks.
DojoExpert follows several fundamental security principles.
| Principle | Description |
|---|---|
| Least Privilege | Access to systems and Customer Data is granted only where operationally required. |
| Confidentiality | Customer information is accessible only to authorised personnel. |
| Integrity | Measures are implemented to reduce the risk of unauthorised modification of Customer Data. |
| Availability | Infrastructure monitoring, cloud services and daily backups help maintain service availability. |
| Continuous Improvement | Security controls are periodically reviewed and improved where practical. |
DojoExpert is hosted using cloud infrastructure provided by Google Cloud Platform.
| Component | Technology |
|---|---|
| Operating System | Microsoft Windows Server |
| Web Server | Microsoft IIS |
| Database | Microsoft SQL Server managed through Google Cloud SQL |
| Hosting | Google Cloud Platform |
| Server Administration | Plesk |
| Remote Administration | Remote Desktop Protocol (RDP) |
Development and production environments are maintained separately to reduce operational risk.
DojoExpert utilises infrastructure located within the European Union and the United States.
Depending on the specific service involved, Customer Data may be processed using infrastructure located in either region.
| Service | Primary Purpose |
|---|---|
| Google Cloud SQL | Production database |
| Google Cloud Storage | Backups |
| Amazon S3 | Customer file storage |
| Amazon SES | Transactional email delivery |
| Stripe | Online payment processing |
| GoCardless | Direct Debit payment processing |
| Firebase | Mobile push notifications |
International transfers are protected using appropriate safeguards as described in the Data Processing Agreement.
All communication between users and the DojoExpert platform is protected using industry-standard encryption protocols.
| Security Control | Implementation |
|---|---|
| HTTPS | All production traffic is encrypted using HTTPS. |
| TLS Certificates | Certificates are issued and renewed using Let's Encrypt. |
| Firewall | Windows Firewall is used to restrict and protect server network access. |
| Remote Administration | Administrative access to production systems is restricted to authorised personnel using secure administrative channels. |
Only services required for operation of the platform are exposed to the public network.
User authentication is implemented using Microsoft ASP.NET Identity.
Administrative access to critical cloud infrastructure is protected using Multi-Factor Authentication (MFA).
| Platform | MFA |
|---|---|
| Google Cloud Platform | Enabled |
| Stripe | Enabled |
| GoCardless | Enabled |
| DojoExpert Customer Administrator Accounts | Currently authenticated using password-based authentication. Multi-Factor Authentication is planned for a future platform release. |
Future security enhancements may include optional or mandatory Multi-Factor Authentication for Customer administrator accounts.
Access to information is controlled through role-based permissions implemented within the DojoExpert platform.
Production systems may be accessed only by authorised Link Lab personnel where necessary to provide technical support, maintenance or operational services.
Administrative access is limited to individuals who have been explicitly authorised to perform such activities.
Encryption is used to protect Customer Data both during transmission and while stored within cloud infrastructure.
| Area | Protection |
|---|---|
| Data in Transit | HTTPS / TLS encryption. |
| Passwords | ASP.NET Identity password hashing. |
| Stored Data | Google Cloud default encryption at rest. |
| Backup Data | Protected through Google Cloud managed infrastructure. |
Link Lab relies on Google Cloud managed encryption services for storage encryption and infrastructure protection.
Backup procedures are designed to support recovery following unexpected data loss or operational disruption.
| Backup Control | Description |
|---|---|
| Backup Frequency | Daily. |
| Storage Platform | Google Cloud. |
| Retention Period | Approximately three (3) months. |
| Purpose | Disaster recovery only. |
Backups are not intended as a long-term archive of Customer information.
Expired backups are automatically removed through the configured backup retention process.
The DojoExpert platform is monitored to help maintain service availability, identify operational issues and support incident investigation.
| Area | Implementation |
|---|---|
| Availability Monitoring | Production services are monitored using Site24x7. |
| Infrastructure Monitoring | Infrastructure health is monitored through cloud platform tools and operational monitoring. |
| Operational Logs | System and application logs are retained according to operational requirements. |
Monitoring information is used to assist with platform reliability, performance analysis and troubleshooting.
Security considerations are incorporated throughout the development and maintenance of the DojoExpert platform.
Security is considered throughout the software development lifecycle, taking into account the size, complexity and operational requirements of the platform.
Link Lab periodically reviews the platform and supporting infrastructure to identify and address known security risks.
Where appropriate, security patches are installed following assessment and testing.
Link Lab maintains procedures for responding to security incidents affecting the DojoExpert platform.
Incident response activities may include:
Where required by applicable law or contractual obligations, Customers will be notified without undue delay following confirmation of a Personal Data Breach affecting their information.
Administrative systems used to manage the DojoExpert platform are protected using commercially supported endpoint protection software.
| Protection | Implementation |
|---|---|
| Endpoint Protection | Microsoft Defender. |
| Operating System Updates | Applied periodically as part of routine maintenance. |
| Administrative Access | Restricted to authorised personnel. |
DojoExpert uses carefully selected third-party service providers to support operation of the platform.
| Provider | Purpose |
|---|---|
| Google Cloud Platform | Cloud infrastructure and managed database services. |
| Amazon S3 | Customer file storage. |
| Amazon SES | Transactional email delivery. |
| Stripe | Payment processing. |
| GoCardless | Direct Debit payment processing. |
| Firebase Cloud Messaging | Push notifications for the mobile application. |
Additional subprocessors may be introduced where operationally necessary. Customers will be informed in accordance with the Data Processing Agreement.
Privacy and data protection considerations are incorporated into the design and operation of the DojoExpert platform.
These measures support compliance with the General Data Protection Regulation (GDPR) and other applicable privacy requirements.
Questions regarding information security or data protection may be directed to:
Link Lab j.d.o.o.
Perini 14
52448 Sveti Lovreč
Croatia
E-mail:
info@linklab.hr
| Document | DojoExpert Security Overview |
| Version | 1.5 |
| Owner | Link Lab j.d.o.o. |
| Last Updated | July 2026 |