GDPR Policy
Last updated: July 22, 2026
1. Introduction
This policy explains how Dojos.ro complies with Regulation (EU) 2016/679 ("GDPR") when processing the personal data of platform users - admins, coaches, front desk staff, parents, and students. It supplements our Privacy Policy.
For any request related to data protection, you can contact us at hello@dojos.ro or +40 741 887 832.
2. Roles: controller and processor
Each dojo is, in its relationship with its own students and parents, a data controller (it determines the purpose and means of processing - e.g. what information it keeps about students). Dojos.ro acts as a data processor, providing the technical infrastructure through which the dojo manages its data.
3. Legal bases for processing
- Performance of the relationship between student/parent and dojo (e.g. attendance, belt, and fee records).
- Consent, for optional data (e.g. medical information, photos).
- The dojo's legitimate interest in communicating effectively with parents and organizing its activity.
- Legal obligations, where applicable (e.g. financial records).
4. Data about minors
A significant part of the data in the Platform concerns children (minor students): name, date of birth, belt, attendance, photos, sometimes medical information relevant to their safety during training. This data is entered by the dojo's admin/coach and/or the parent, under their own responsibility, and is visible only to the dojo's relevant staff, the parent, and the student themself.
We recommend that dojo admins obtain the consent of parents/legal guardians before uploading photos of students or medical information, in line with the dojo's own policy.
5. Categories of data processed
- Identification and contact data (name, email, phone).
- Data about sporting activity (belts, attendance, competitions, technical assessments).
- Limited financial data (tuition fee records, no card data).
- Special data, entered optionally: medical/emergency information, photos.
- User-generated content (posts, comments, messages).
6. Rights of data subjects
Anyone whose data is processed through the Platform has the right to:
- be informed of and access their own data;
- have inaccurate or incomplete data corrected;
- have their data deleted ("the right to be forgotten"), within legal limits;
- restrict or object to certain processing;
- receive their data in a structured, portable format;
- file a complaint with their country's national data protection supervisory authority, if they believe their rights have been violated.
For minor students, these rights are exercised by the parent/legal guardian, on the child's behalf.
7. Data security
Access to data is restricted by role (each user sees only what they're allowed to, within their own dojo), connections are encrypted (HTTPS), and the infrastructure is hosted via Google Cloud / Firebase, with its own security measures.
8. International transfers
Data is stored and processed via the Google Cloud / Firebase infrastructure, which may involve processing in data centers located in the European Union or in other jurisdictions with adequate data protection safeguards, in accordance with Google's own policies.
9. Retention period
Data is kept for as long as the dojo and the associated account remain active. At the request of the dojo's admin or the data subject, data can be deleted or anonymized, except where the law requires it to be kept for a specific period.
10. Contact for data protection
For any request regarding your personal data (access, correction, deletion, complaint), you can contact us directly:
Email: hello@dojos.ro
Phone: +40 741 887 832