LEGAL

Privacy policy

Last updated: 12 August 2026
Effective date: 12 August 2026

This Privacy Policy explains how MyTaek [LEGAL ENTITY TYPE] ("MyTaek," "we," "us," "our") collects, uses, discloses, and protects personal data when you use the MyTaek website, application, and related services (the "Service").

This Policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the U.S. Children's Online Privacy Protection Act (COPPA), and applicable U.S. state privacy laws (including the California Consumer Privacy Act/CPRA and comparable state laws). Where these laws impose differing requirements, the more protective standard applies to users in that jurisdiction.

1. Who we are / data controller

MyTaek [LEGAL ENTITY TYPE]
[REGISTERED ADDRESS]
Contact: [PRIVACY CONTACT EMAIL]
Data Protection Officer (if appointed): [DPO NAME/EMAIL]
EU Representative (if MyTaek is not established in the EU, per GDPR Art. 27): [EU REP NAME/ADDRESS]
UK Representative (if applicable, per UK GDPR Art. 27): [UK REP NAME/ADDRESS]

For personal data uploaded to the Service by a Dojang/school about its students and parents, the Dojang/school is the data controller and MyTaek acts as data processor under a separate Data Processing Addendum. This Policy describes MyTaek's own processing as controller (e.g., account, billing, and platform-usage data) and, where relevant, our role as processor.

2. Personal data we collect

2.1 Data you provide directly

  • Account data: name, email address, phone number, password (hashed), role (School Owner, Coach, Parent, Student).
  • School/business data: school name, address, business registration details (for School Owner accounts).
  • Billing data: billing name, billing address, and payment details. Payment card numbers are collected and stored by our payment processor, [PAYMENT PROCESSOR], not by MyTaek directly.
  • Student/child profile data (entered by a parent/guardian or by school staff): name, date of birth, belt rank/progress, attendance, emergency contact information, and any notes entered by coaches.
  • Communications: messages sent through the Service, support requests, and survey responses.
  • Chatbot interactions: text you submit to the MyTaek Chatbot and the responses generated.

2.2 Data collected automatically

  • Usage data: pages/features accessed, session duration, clickstream, gamification activity (e.g., "Dojang Rivals" progress, XP, in-app rewards).
  • Device/technical data: IP address, browser type, device identifiers, operating system, referring URLs.
  • Cookies and similar technologies: see Section 8 (Cookies).

2.3 Data from third parties

  • Payment confirmation data from our payment processor.
  • Where applicable, data from single sign-on providers (e.g., Google) if you choose to authenticate that way.

2.4 Special categories of data

We do not intentionally collect special category data (e.g., health data, racial or ethnic origin, religious beliefs) except where a school voluntarily records limited, training-relevant health/injury notes (e.g., "student has an existing knee injury, avoid high-impact drills") for the safety of the student. Such notes are entered at the discretion of the school/coach as controller, are treated as confidential, and are used only for training safety purposes. Do not enter sensitive medical detail beyond what is necessary for safety.

3. Children's data (COPPA / GDPR Article 8)

MyTaek is a B2B/B2B2C platform used by martial arts schools; children do not register for accounts directly. Instead:

  • Student accounts for children under 13 (US) or under the applicable digital consent age in the EU/EEA (13-16, depending on member state) are created and controlled by a parent/legal guardian, or by the school with the parent/guardian's consent.
  • Before a child's personal data is entered into the Service, the parent/guardian (or the school, acting on the parent's documented consent) must provide verifiable parental consent. Acceptable methods include: consent captured at school enrollment paired with a parent email confirmation, a signed consent form retained by the school, or in-app parental consent confirmation sent to the parent's verified email.
  • We collect only the minimum data about a child necessary to provide the Service. We do not use children's data for behavioral advertising, do not sell children's data, and do not enable children to publicly post content or communicate directly with strangers through the Service.
  • A parent/guardian may at any time: review the personal data collected about their child, request correction, request deletion, and refuse further collection, by contacting [PRIVACY CONTACT EMAIL] or the school directly.
  • If we learn that a child's data was collected without appropriate parental consent, we will delete that data promptly.

4. Legal basis for processing (EU/EEA/UK)

We rely on the following legal bases under GDPR Article 6:

PurposeLegal basis
Providing the Service, account management, billingPerformance of a contract (Art. 6(1)(b))
Processing children's dataConsent of parent/guardian (Art. 6(1)(a), Art. 8)
Security, fraud preventionLegitimate interests (Art. 6(1)(f))
Product analytics, service improvementLegitimate interests (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a)), withdrawable at any time
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

5. How we use personal data

We use personal data to: (a) provide, operate, and maintain the Service; (b) process payments and manage subscriptions; (c) communicate with you about your account, updates, and support requests; (d) personalize gamification and progress features; (e) improve and develop the Service, including through aggregated/de-identified analytics; (f) detect, prevent, and address fraud, abuse, and security incidents; (g) comply with legal obligations; and (h), with consent where required, send marketing communications, which you may opt out of at any time.

We do not sell personal data, and we do not use children's personal data for targeted advertising.

6. How we share personal data

We share personal data only as described below, and only with parties bound by appropriate contractual data protection obligations:

  • Service providers/processors: hosting (e.g., Vercel), content management (e.g., Sanity), payment processing (e.g., [PAYMENT PROCESSOR]), analytics, and customer support tooling, each bound by a data processing agreement.
  • The relevant Dojang/school: coaches and school administrators can access student/parent data necessary to run the school.
  • Legal and safety disclosures: where required to comply with law, legal process, or governmental request; to protect rights, property, or safety; or to enforce our Terms of Service.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy's protections continuing to apply.

We do not share personal data with third parties for their own independent marketing purposes without your explicit consent.

7. International data transfers

Where we transfer personal data originating in the EU/EEA or UK to a country not deemed to provide an adequate level of protection (including the United States), we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures where required. A copy of the relevant safeguards is available upon request to [PRIVACY CONTACT EMAIL].

8. Cookies and similar technologies

We use cookies and similar technologies for: (a) strictly necessary functions (authentication, security, load balancing); (b) preferences (language, display settings); (c) analytics (understanding usage patterns); and (d), where applicable and with consent, marketing/retargeting.

Where required by law (e.g., the EU ePrivacy Directive), we obtain your consent before placing non-essential cookies, via a cookie consent banner, and you may withdraw consent at any time through our cookie settings tool or your browser settings.

9. Data retention

We retain personal data only as long as necessary for the purposes described in this Policy. Specifically:

  • Account data: retained for the duration of the account, plus [X months/years] after closure for legal/dispute purposes.
  • Billing/transaction records: retained per statutory bookkeeping requirements (typically 7 years in the Netherlands; comparable periods elsewhere).
  • Children's data: retained only while the child is an active student, plus a limited period thereafter for school record continuity, unless a parent/guardian requests earlier deletion.
  • Chatbot conversation logs: retained for [X days/months] for quality and safety review, then deleted or anonymized.
  • Post-termination school data: upon account termination, school roster and student history data is preserved for a 30-day grace period, during which the school owner may request a CSV export via Support. After this period, all data is permanently and irreversibly deleted, subject to statutory preservation requirements.

10. Your rights

10.1 EU/EEA/UK users (GDPR)

You have the right to: access your personal data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict processing; object to processing based on legitimate interests or for direct marketing; data portability; and to withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with your national supervisory authority (in the Netherlands: the Autoriteit Persoonsgegevens).

10.2 US state privacy rights

Where applicable, you have the right to: know what personal data is collected, used, and disclosed; delete personal data; correct inaccurate data; opt out of the sale or sharing of personal data (we do not sell or share personal data as defined under these laws); limit use of sensitive personal data; and not be discriminated against for exercising these rights.

10.3 Exercising your rights

To exercise any of these rights, contact [PRIVACY CONTACT EMAIL]. We will respond within the time required by applicable law (generally one month under GDPR, 45 days under CPRA). We may need to verify your identity before fulfilling a request. Parents/guardians may exercise these rights on behalf of a minor as described in Section 3.

11. Data security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including: encryption of data in transit (TLS) and at rest where applicable; access controls and role-based permissions; regular security review of our infrastructure and dependencies; and contractual security obligations imposed on our processors. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11.1 Data breach notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required under GDPR Art. 33, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

12. Automated decision-making

We do not use fully automated decision-making that produces legal or similarly significant effects concerning you without human involvement. Gamification scoring, progress tracking, and chatbot responses are informational/engagement features and do not affect legal rights or access to core educational/training services.

13. Third-party links

The Service may contain links to third-party websites or services not operated by us. We are not responsible for the privacy practices of such third parties. We encourage you to review their privacy policies.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or in-app notice at least 14 days before the changes take effect, and, where required by law, we will obtain any necessary fresh consent before the changes apply to previously collected data.

15. Contact us

Questions, requests, or complaints regarding this Privacy Policy or our data practices can be directed to:

Email: [PRIVACY CONTACT EMAIL]
Postal address: [REGISTERED ADDRESS]
EU Representative (if applicable): [EU REP CONTACT]

Pricing wizard analytics

We log the inputs to our pricing wizard so we can improve MyTaek. These logs are anonymous: they contain business facts (student count, tuition) and a session identifier that lasts only for the browser tab. We do not log your IP address, your email, or any personal identifier.

This document is a draft template and has not been reviewed by a licensed attorney. It must be reviewed and adapted by qualified legal counsel in each relevant jurisdiction before publication or use. Brackets like 12 August 2026 and [PRIVACY CONTACT EMAIL] must be filled in before going live.