1. Parties and roles
The school is the controller: it determines the purposes and means of processing. sabondojo is the processor: it processes personal data on the school's behalf and only on its documented instructions, including as regards international transfers.
If sabondojo believes an instruction infringes applicable law, it will tell the school without delay and may suspend that instruction until the point is resolved.
2. Subject matter, duration and scope
| Item | Detail |
|---|---|
| Subject matter | Provision of the sabondojo martial-arts school management software |
| Duration | For as long as the subscription is in force, plus the published retention periods |
| Nature and purpose | Hosting, storage, retrieval, modification and deletion of data in order to manage students, classes, attendance, tuition and communications |
| Categories of data subjects | Students (including minors), guardians, instructors, administrative staff |
| Categories of data | Identity and contact details, date of birth, attendance, technical progression, financial and payment data, messages and posts, and — only with explicit consent — health data and images |
3. Division of obligations
| Obligation | Owner |
|---|---|
| Lawful basis for enrolling and processing a student's data | The school |
| Collecting guardian consent | The school, through the interface we provide |
| Verifying the guardian relationship | The school |
| Answering access, rectification and erasure requests | The school, with the tooling we give it |
| Notifying the supervisory authority of a breach | The school; sabondojo notifies the school without undue delay |
| Database security, backups and access control | sabondojo |
| Enforcing retention periods in code | sabondojo; the school configures them within the published limits |
| Registering the database with the authority where required | Each party, for its own database |
4. Confidentiality
Every member of sabondojo staff with access to personal data is bound by a confidentiality duty that survives the end of their employment or engagement, in line with arts. 9 and 10 of Ley 25.326 and art. 28(3)(b) GDPR. Access is granted on a need-to-serve basis and revoked when the task ends.
5. Security measures
Technical and organisational measures in place today:
- Encryption in transit (TLS) across the application and to the database.
- Passwords stored as bcrypt hashes; never in clear text.
- Attachments (receipts, profile pictures, scanned consent forms) in private storage, reachable only through short-lived signed links issued after a permission check.
- A single visibility gate per student, crossed by every read of the health record and the sensitive data hanging off it.
- Role- and location-scoped access: staff see their school, an instructor their own group, a student only themselves, and a guardian their child — the health record only on a verified link.
- Isolation between schools at the query level, with scope filters applied on the server and never in the browser.
- Backups managed by the database provider, with point-in-time recovery.
Committed improvements not yet implemented, stated here because a school deserves to know before signing: an audit log of health-record access, immediate session revocation when a person is unlinked, and column-level encryption of the health record.
6. Subprocessors
The school gives general authorisation for the subprocessors published on the Subprocessors page. sabondojo imposes on them by contract obligations no less strict than those in this agreement, and remains liable to the school for their performance.
Any addition or change is announced at least 30 days in advance, with a right to object on reasoned grounds and, where no reasonable alternative exists, a right to terminate without penalty.
7. Assistance to the controller
sabondojo assists the school, as far as reasonable and taking into account the nature of the processing, to: handle data subject requests; meet its security, breach-notification and impact-assessment duties; and provide the information needed to demonstrate compliance.
If a data subject contacts sabondojo directly, we do not answer on our own account: we route the request to the school and tell the person we did.
8. Security incidents
sabondojo will notify the school without undue delay — targeting 24 hours — from becoming aware of an incident affecting personal data processed on its behalf.
The notification will contain what is known at the time: the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken and a contact for follow-up. Information is completed as the investigation progresses.
The deadlines the school owes its authority are its own: 3 business days to the ANPD in Brazil, 72 hours in the European Union. Our commitment is calibrated so it can meet them.
9. International transfers
Where processing involves a transfer outside the school's country, it relies on an adequacy decision where one exists — Argentina has one for the European Union — or otherwise on standard contractual clauses with the relevant provider. The effective hosting region is stated on the Subprocessors page and can be pinned to the European Union at an EU school's request.
10. Audit
sabondojo will make available to the school the information needed to demonstrate compliance with this agreement and will allow audits, including inspections, by the school or an auditor it appoints, on reasonable notice, during business hours, once a year unless an incident justifies another, and subject to confidentiality.
11. Return and deletion
On termination the school chooses between the return of its data in a structured, commonly used format, or its deletion. Absent instruction, the periods published in the Privacy notice apply: 30 days to export, deletion from active systems at 90 days.
What the law requires us to keep — accounting records and consent records — is excepted, kept for the statutory period and for that purpose only. Backups expire by rotation within 35 days and are not restored selectively.
12. Term and precedence
This agreement applies from a school's onboarding and for as long as data is processed on its behalf. Where it conflicts with the Terms of service on a data-protection matter, this agreement prevails.
A school that needs a signed copy, or a negotiated version of this text, can ask us at the address in the footer.