Privacy Policy

Last Updated: 10 February 2026

This Privacy Policy explains how Bitbox OÜ ("Bitbox," "we," "us," or "our") collects, uses, discloses, and protects personal data when you access or use DojoAccess (the "Service").

This Policy is intended to comply with the EU General Data Protection Regulation (GDPR) and is designed for global use.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

1. Controller Information

  • Data Controller: Bitbox OÜ
  • Registered Address: Kirsi tn 4-21, 76606, Keila, Estonia
  • Contact Email: solutions.bitbox@gmail.com
  • Country of Establishment: Estonia

For purposes of GDPR, Bitbox OÜ acts primarily as a data processor when processing personal data on behalf of dojos or martial arts schools using the Service, and as a data controller for limited data related to its own business operations.

2. Scope of This Policy

This Privacy Policy applies to:

  • Visitors to the DojoAccess website
  • Account holders and authorized users
  • Dojos, schools, and organizations using the Service

It does not apply to personal data processed by dojos or schools outside of the Service.

3. Categories of Personal Data We Process

Depending on how the Service is used, we may process the following categories of personal data:

3.1 Account and Contact Information

  • Name
  • Email address
  • Phone number
  • Organization name
  • Login credentials (hashed)

3.2 Student and Member Data (Submitted by Customers)

  • Names of students or members
  • Date of birth or age category
  • Attendance records
  • Membership status
  • Billing identifiers (non-card data)
  • Guardian or parent contact information (where applicable)

3.3 Technical and Usage Data

  • IP address
  • Device and browser type
  • Log files and timestamps
  • Usage metrics and feature interaction

3.4 Payment Data

Payment card information is not stored by Bitbox OÜ. Payments are processed by third-party payment providers.

4. Lawful Bases for Processing (GDPR Article 6)

We process personal data only when at least one lawful basis applies:

  • Contractual necessity – to provide the Service
  • Legitimate interests – to operate, secure, and improve the Service
  • Legal obligation – to comply with applicable laws
  • Consent – where explicitly required (e.g., marketing communications)

Where Bitbox OÜ acts as a data processor, processing is based on the instructions of the customer (data controller).

5. How We Use Personal Data

We use personal data to:

  • Provide, operate, and maintain the Service
  • Authenticate users and manage accounts
  • Process payments and subscriptions
  • Communicate service-related information
  • Provide customer support
  • Improve performance, security, and usability
  • Comply with legal obligations

6. Children’s Data

DojoAccess may process personal data relating to children, as many martial arts students are minors.

Bitbox OÜ does not collect children’s data directly. All such data is submitted and controlled by the dojo or school, which is responsible for:

  • Obtaining valid parental or guardian consent
  • Ensuring compliance with applicable child data protection laws

7. Data Hosting and International Transfers

  • The Service is hosted on servers located within the European Union.
  • Personal data is processed primarily within the EU.

If personal data is transferred outside the EU/EEA, appropriate safeguards are used, such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs).

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy.

Customer-submitted data is retained for the duration of the customer’s account and is typically deleted or anonymized within 30 days of account termination, unless a longer retention period is required by law for tax or legal compliance.

9. Data Sharing and Disclosure

We may share personal data with:

  • Service providers and subprocessors (e.g., hosting, payment, email delivery)
  • Payment processors (for billing purposes)
  • Legal authorities where required by law

All subprocessors are bound by contractual obligations consistent with GDPR requirements.

10. Data Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, and regular security monitoring. However, no system can be guaranteed to be 100% secure.

11. Your Rights Under GDPR

Where applicable, individuals have the right to:

  • Access their personal data
  • Rectify inaccurate data
  • Request erasure ("right to be forgotten")
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

Requests should be directed to the relevant dojo or school (data controller). Bitbox OÜ will assist controllers as required.

12. Cookies and Tracking Technologies

DojoAccess uses only strictly necessary cookies for authentication, session management, security, and fraud prevention.

Because we do not use tracking or advertising cookies, we do not show a cookie consent banner. You can control cookie settings through your browser, but the Service may not function correctly without these essential cookies.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or email. Continued use of the Service constitutes acceptance of the updated Policy.

14. Contact Us

For questions about this Privacy Policy or data protection matters, contact:

Bitbox OÜ
solutions.bitbox@gmail.com
Kirsi tn 4-21, 76606, Keila, Estonia

This Privacy Policy is provided as a general template and does not constitute legal advice. You should have this document reviewed by qualified legal counsel before use.