Skip to main content
sabondojo

Data processing agreement

This is the agreement governing the processing of personal data between the school and sabondojo. It is drafted to meet GDPR art. 28, LGPD art. 39 and the security and confidentiality duties of Ley 25.326. It is incorporated by reference into the Terms of service and applies from the moment a school is onboarded.

Version 2026-08-16 · effective 2026-08-16

Draft

Draft — pending legal review

We wrote this ourselves at sabondojo, from our own reading of Ley 25.326 (Argentina), the LGPD (Brazil), the GDPR (EU), Ley 21.719 (Chile), the LFPDPPP (Mexico), Ley 1581 (Colombia) and COPPA (United States). No lawyer has reviewed it yet. We are publishing it as a draft anyway, because a school needs something concrete to read before trusting us with its students' data — and a text you can argue with beats a text that does not exist. Nothing here is legal advice.

1. Parties and roles

The school is the controller: it determines the purposes and means of processing. sabondojo is the processor: it processes personal data on the school's behalf and only on its documented instructions, including as regards international transfers.

If sabondojo believes an instruction infringes applicable law, it will tell the school without delay and may suspend that instruction until the point is resolved.

2. Subject matter, duration and scope

ItemDetail
Subject matterProvision of the sabondojo martial-arts school management software
DurationFor as long as the subscription is in force, plus the published retention periods
Nature and purposeHosting, storage, retrieval, modification and deletion of data in order to manage students, classes, attendance, tuition and communications
Categories of data subjectsStudents (including minors), guardians, instructors, administrative staff
Categories of dataIdentity and contact details, date of birth, attendance, technical progression, financial and payment data, messages and posts, and — only with explicit consent — health data and images

3. Division of obligations

ObligationOwner
Lawful basis for enrolling and processing a student's dataThe school
Collecting guardian consentThe school, through the interface we provide
Verifying the guardian relationshipThe school
Answering access, rectification and erasure requestsThe school, with the tooling we give it
Notifying the supervisory authority of a breachThe school; sabondojo notifies the school without undue delay
Database security, backups and access controlsabondojo
Enforcing retention periods in codesabondojo; the school configures them within the published limits
Registering the database with the authority where requiredEach party, for its own database

4. Confidentiality

Every member of sabondojo staff with access to personal data is bound by a confidentiality duty that survives the end of their employment or engagement, in line with arts. 9 and 10 of Ley 25.326 and art. 28(3)(b) GDPR. Access is granted on a need-to-serve basis and revoked when the task ends.

5. Security measures

Technical and organisational measures in place today:

  • Encryption in transit (TLS) across the application and to the database.
  • Passwords stored as bcrypt hashes; never in clear text.
  • Attachments (receipts, profile pictures, scanned consent forms) in private storage, reachable only through short-lived signed links issued after a permission check.
  • A single visibility gate per student, crossed by every read of the health record and the sensitive data hanging off it.
  • Role- and location-scoped access: staff see their school, an instructor their own group, a student only themselves, and a guardian their child — the health record only on a verified link.
  • Isolation between schools at the query level, with scope filters applied on the server and never in the browser.
  • Backups managed by the database provider, with point-in-time recovery.

Committed improvements not yet implemented, stated here because a school deserves to know before signing: an audit log of health-record access, immediate session revocation when a person is unlinked, and column-level encryption of the health record.

6. Subprocessors

The school gives general authorisation for the subprocessors published on the Subprocessors page. sabondojo imposes on them by contract obligations no less strict than those in this agreement, and remains liable to the school for their performance.

Any addition or change is announced at least 30 days in advance, with a right to object on reasoned grounds and, where no reasonable alternative exists, a right to terminate without penalty.

7. Assistance to the controller

sabondojo assists the school, as far as reasonable and taking into account the nature of the processing, to: handle data subject requests; meet its security, breach-notification and impact-assessment duties; and provide the information needed to demonstrate compliance.

If a data subject contacts sabondojo directly, we do not answer on our own account: we route the request to the school and tell the person we did.

8. Security incidents

sabondojo will notify the school without undue delay — targeting 24 hours — from becoming aware of an incident affecting personal data processed on its behalf.

The notification will contain what is known at the time: the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken and a contact for follow-up. Information is completed as the investigation progresses.

The deadlines the school owes its authority are its own: 3 business days to the ANPD in Brazil, 72 hours in the European Union. Our commitment is calibrated so it can meet them.

9. International transfers

Where processing involves a transfer outside the school's country, it relies on an adequacy decision where one exists — Argentina has one for the European Union — or otherwise on standard contractual clauses with the relevant provider. The effective hosting region is stated on the Subprocessors page and can be pinned to the European Union at an EU school's request.

10. Audit

sabondojo will make available to the school the information needed to demonstrate compliance with this agreement and will allow audits, including inspections, by the school or an auditor it appoints, on reasonable notice, during business hours, once a year unless an incident justifies another, and subject to confidentiality.

11. Return and deletion

On termination the school chooses between the return of its data in a structured, commonly used format, or its deletion. Absent instruction, the periods published in the Privacy notice apply: 30 days to export, deletion from active systems at 90 days.

What the law requires us to keep — accounting records and consent records — is excepted, kept for the statutory period and for that purpose only. Backups expire by rotation within 35 days and are not restored selectively.

12. Term and precedence

This agreement applies from a school's onboarding and for as long as data is processed on its behalf. Where it conflicts with the Terms of service on a data-protection matter, this agreement prevails.

A school that needs a signed copy, or a negotiated version of this text, can ask us at the address in the footer.

Data processing agreement — sabondojo