LEGAL
Last updated: 12 August 2026
Effective date: 12 August 2026
This Privacy Policy explains how MyTaek [LEGAL ENTITY TYPE] ("MyTaek," "we," "us," "our") collects, uses, discloses, and protects personal data when you use the MyTaek website, application, and related services (the "Service").
This Policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the U.S. Children's Online Privacy Protection Act (COPPA), and applicable U.S. state privacy laws (including the California Consumer Privacy Act/CPRA and comparable state laws). Where these laws impose differing requirements, the more protective standard applies to users in that jurisdiction.
MyTaek [LEGAL ENTITY TYPE]
[REGISTERED ADDRESS]
Contact: [PRIVACY CONTACT EMAIL]
Data Protection Officer (if appointed): [DPO NAME/EMAIL]
EU Representative (if MyTaek is not established in the EU, per GDPR Art. 27): [EU REP NAME/ADDRESS]
UK Representative (if applicable, per UK GDPR Art. 27): [UK REP NAME/ADDRESS]
For personal data uploaded to the Service by a Dojang/school about its students and parents, the Dojang/school is the data controller and MyTaek acts as data processor under a separate Data Processing Addendum. This Policy describes MyTaek's own processing as controller (e.g., account, billing, and platform-usage data) and, where relevant, our role as processor.
We do not intentionally collect special category data (e.g., health data, racial or ethnic origin, religious beliefs) except where a school voluntarily records limited, training-relevant health/injury notes (e.g., "student has an existing knee injury, avoid high-impact drills") for the safety of the student. Such notes are entered at the discretion of the school/coach as controller, are treated as confidential, and are used only for training safety purposes. Do not enter sensitive medical detail beyond what is necessary for safety.
MyTaek is a B2B/B2B2C platform used by martial arts schools; children do not register for accounts directly. Instead:
We rely on the following legal bases under GDPR Article 6:
| Purpose | Legal basis |
|---|---|
| Providing the Service, account management, billing | Performance of a contract (Art. 6(1)(b)) |
| Processing children's data | Consent of parent/guardian (Art. 6(1)(a), Art. 8) |
| Security, fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Product analytics, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)), withdrawable at any time |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
We use personal data to: (a) provide, operate, and maintain the Service; (b) process payments and manage subscriptions; (c) communicate with you about your account, updates, and support requests; (d) personalize gamification and progress features; (e) improve and develop the Service, including through aggregated/de-identified analytics; (f) detect, prevent, and address fraud, abuse, and security incidents; (g) comply with legal obligations; and (h), with consent where required, send marketing communications, which you may opt out of at any time.
We do not sell personal data, and we do not use children's personal data for targeted advertising.
We share personal data only as described below, and only with parties bound by appropriate contractual data protection obligations:
We do not share personal data with third parties for their own independent marketing purposes without your explicit consent.
Where we transfer personal data originating in the EU/EEA or UK to a country not deemed to provide an adequate level of protection (including the United States), we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures where required. A copy of the relevant safeguards is available upon request to [PRIVACY CONTACT EMAIL].
We use cookies and similar technologies for: (a) strictly necessary functions (authentication, security, load balancing); (b) preferences (language, display settings); (c) analytics (understanding usage patterns); and (d), where applicable and with consent, marketing/retargeting.
Where required by law (e.g., the EU ePrivacy Directive), we obtain your consent before placing non-essential cookies, via a cookie consent banner, and you may withdraw consent at any time through our cookie settings tool or your browser settings.
We retain personal data only as long as necessary for the purposes described in this Policy. Specifically:
You have the right to: access your personal data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict processing; object to processing based on legitimate interests or for direct marketing; data portability; and to withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with your national supervisory authority (in the Netherlands: the Autoriteit Persoonsgegevens).
Where applicable, you have the right to: know what personal data is collected, used, and disclosed; delete personal data; correct inaccurate data; opt out of the sale or sharing of personal data (we do not sell or share personal data as defined under these laws); limit use of sensitive personal data; and not be discriminated against for exercising these rights.
To exercise any of these rights, contact [PRIVACY CONTACT EMAIL]. We will respond within the time required by applicable law (generally one month under GDPR, 45 days under CPRA). We may need to verify your identity before fulfilling a request. Parents/guardians may exercise these rights on behalf of a minor as described in Section 3.
We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including: encryption of data in transit (TLS) and at rest where applicable; access controls and role-based permissions; regular security review of our infrastructure and dependencies; and contractual security obligations imposed on our processors. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required under GDPR Art. 33, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
We do not use fully automated decision-making that produces legal or similarly significant effects concerning you without human involvement. Gamification scoring, progress tracking, and chatbot responses are informational/engagement features and do not affect legal rights or access to core educational/training services.
The Service may contain links to third-party websites or services not operated by us. We are not responsible for the privacy practices of such third parties. We encourage you to review their privacy policies.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or in-app notice at least 14 days before the changes take effect, and, where required by law, we will obtain any necessary fresh consent before the changes apply to previously collected data.
Questions, requests, or complaints regarding this Privacy Policy or our data practices can be directed to:
Email: [PRIVACY CONTACT EMAIL]
Postal address: [REGISTERED ADDRESS]
EU Representative (if applicable): [EU REP CONTACT]
We log the inputs to our pricing wizard so we can improve MyTaek. These logs are anonymous: they contain business facts (student count, tuition) and a session identifier that lasts only for the browser tab. We do not log your IP address, your email, or any personal identifier.
This document is a draft template and has not been reviewed by a licensed attorney. It must be reviewed and adapted by qualified legal counsel in each relevant jurisdiction before publication or use. Brackets like 12 August 2026 and [PRIVACY CONTACT EMAIL] must be filled in before going live.