1. Who decides about your data
The school where you train is the data controller: it decides what data it asks for, what it uses it for, and for how long, within what the law allows. sabondojo is the data processor: we provide the software and process the data on the school's instructions.
In practice this means that if you want to access, correct or delete your data, the school handles the request — and we are contractually bound to give it the tools to do so within the statutory deadlines. If you write to us directly, we route the request to the school and tell you we did.
The relationship between the school and sabondojo is set out in our Data processing agreement, which is public and part of this same set of documents.
2. What data we process
We ask for what a school needs to run, and nothing beyond it. The ordinary data is:
- Student identity and contact details: name, email address, phone number.
- Date of birth. It is the fact that makes every rule about minors enforceable: without it, the system cannot tell a seven-year-old from a forty-year-old.
- Identity and contact details of at least one guardian when the student is a minor, plus the declared relationship (mother, father, legal guardian, other).
- Class attendance, and belt and level progression.
- Tuition, payments, dates and payment receipts.
- Training objectives, chosen from a fixed list (self-defence, fitness, competition, discipline, stress relief, community, weight loss, fun). There is no free-text field.
- Emergency contact and the people authorised to collect the student.
- Messages with the school's staff and posts in the location's forum.
Account data: if you have portal access, we also hold your username, the hash of your password (never the password itself) and your profile picture.
3. What we only process with your explicit consent
Two categories are not collected merely because someone enrolled. Each is asked for separately, starts as NO, and can be withdrawn at any time without losing your place in class.
- Health data: allergies, medical conditions, medication, injuries, physician and authorisation for emergency care. This is special-category data (art. 7 Ley 25.326, art. 9 GDPR). The step is skippable: leave it blank and the registration still completes, with no health data stored at all.
- Internal image use: a profile photo visible to the school's staff inside the system.
- External image use: publication on the school's social media, non-commercial.
The two image checkboxes are separate on purpose. Schools tend to treat them as one thing and families do not: agreeing that the school may keep a photo on file is not the same as agreeing that it may post it on Instagram.
4. What we never ask for
Neither in a form field nor in free text: racial or ethnic origin, religion, political or philosophical opinions, trade-union membership, sexual orientation or sex life, criminal records.
Nor biometric data of any kind. There is no face-recognition, fingerprint or voice check-in, and there will not be. If we ever automate attendance, it will be with a rotating QR code or a PIN, which solve the same problem without creating an irreversible fact about a child.
The system's free-text fields (instructor notes, progress observations, reason for an absence) are labelled so staff do not record health, family or legal information there. If it appears anyway, we treat it with the same care as special-category data.
5. What each piece of data is used for, and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Enrolling the student and running the relationship with the school | Identity, contact, date of birth, location | Performance of the contract (with the guardian, where the student is a minor) |
| Recording attendance, belts and progress | Attendance, belt, level, assessments | Performance of the contract |
| Charging and crediting tuition | Amounts, dates, receipts | Performance of the contract and accounting duties |
| Announcing class changes, cancellations and school events | Contact details, class enrolment | Performance of the contract |
| Acting in a training emergency | Health data, emergency contact | Explicit consent, and vital interests where the person cannot consent |
| Showing a photo on the student's record | Image | Consent (internal use) |
| Publishing photos or video on the school's social media | Image | Consent (external use) |
| Sending promotions or commercial news | Contact details | Prior opt-in consent, and never to minors |
6. Minors
Anyone under 18 needs a guardian on file, verified by the school. That adult grants or withdraws the health and image consents, and exercises the rights listed below.
A minor does not create their own account at enrolment. From age 14, the guardian may grant them portal access to see their classes, attendance and progress. When that happens we tell the child on first sign-in, in plain words: the guardian still sees everything, including their messages. Watching someone without their knowledge is wrong, and it also fails the transparency duty.
A minor can never edit their health data, change who their guardian is, or touch payments.
At 18 the person decides for themselves: we ask them to re-affirm their consents in their own name and to choose which guardians keep access. With no answer within 90 days, guardian access is revoked. When in doubt, less access, not more.
Minors' data is never used for commercial or advertising purposes.
7. How we record consent
Every decision — granting, refusing or withdrawing — is stored as a new record, with the date, who took it, in what capacity (yourself, a guardian, or school staff entering a signed paper form) and the exact version of this notice that was on screen at the time.
We never modify or delete an earlier record. Withdrawing adds a new entry; the previous one stays, because it is the evidence that what was done until that day was lawful. Withdrawal is not retroactive, but it stops the use going forward.
When we change this notice materially, earlier consents keep pointing at the old version — which is exactly how we know who has to be asked again.
To withdraw a consent, ask the school, or write to the address in the footer. It has to be as easy as granting it, and it is.
8. How long we keep each thing
Periods run from the day the student leaves the school. Each school may shorten them within these limits; sabondojo enforces them in the software.
| Data | Retention | Why |
|---|---|---|
| Health record | Deleted on departure, with a 90-day grace period | There is no reason to keep a former student's allergies |
| Instructor notes and progress assessments | 24 months | Free text, highly sensitive, of little value once cold |
| Reasons given for an absence | 12 months | They age out fast and often contain health information |
| Attendance and belt history | 5 years | It is the one thing a returning student actually needs |
| Payments (amounts and dates) | 10 years | Commercial record-keeping duty (art. 328 CCyC, Argentina) |
| Attached payment receipts | 24 months | The image is not the record; the ledger entry is |
| Messages and forum posts | 24 months | — |
| Consent records | 10 years, never deleted | They are the evidence that everything else was lawful |
| Sessions and sign-in data | 90 days | — |
If you ask for erasure and there is billing involved, we anonymise your record (name, email and phone replaced by an identity-free marker) and keep the accounting entry. We always tell you what was kept and why.
9. Who we share it with
We do not sell personal data, and we do not hand it to third parties for advertising. Ever.
The infrastructure providers we need in order to run the service are listed — with their role, the category of data they touch and their region — on the Subprocessors page. That list is versioned: we give notice before adding one.
Beyond that, we only disclose data when a competent authority requires it through a valid legal route, and in that case we tell the school unless the law forbids it.
10. Your rights, and how fast we answer
You can request access to your data, its rectification, its update, its erasure, restriction of or objection to certain processing, and portability of what you provided. Where the student is a minor, the guardian exercises these rights.
We apply the shortest applicable deadline: 10 calendar days for access and 5 business days for rectification (Ley 25.326, arts. 14 and 16), 15 days for confirmation of processing under the LGPD, and one month under the GDPR. Argentina's is the tightest, and it is the one we hold ourselves to internally.
The request goes to the school, which is the controller. If you would rather write to us, we forward it and confirm that it arrived.
In Argentina you may also complain to the Agencia de Acceso a la Información Pública; in Brazil to the ANPD; in the EU to your national supervisory authority.
11. Security and incidents
Passwords are stored hashed (bcrypt), attachments live in private storage reachable only through short-lived signed links, and every read of a student's record passes through a single permission check: school staff see their students, an instructor sees their own, a student sees themselves, and a guardian sees their child — the health record only once the school has verified the relationship in person.
If a security incident affecting personal data occurs, we notify the school without undue delay, with what we know, so it can meet its own deadlines: 3 business days to the ANPD in Brazil, 72 hours to the authority in the EU. That is the tightest clock that applies to us, and it is the one we build to for everyone.
12. Cookies and analytics
We use no advertising cookies and no third-party tracking cookies. The only cookies we set are the ones the application needs: the session cookie that keeps you signed in, and the one that remembers which location you are looking at.
We measure aggregate site usage with Vercel Analytics, which works without cookies and builds no profiles of individuals. If we ever add a tool that does use cookies, it will appear here, on the subprocessor list, and with advance notice.
13. International transfers
Data is hosted with providers that may operate outside your country. Argentina holds an adequacy decision from the European Commission, so an EU→Argentina transfer needs no further instrument. For the rest we rely on each provider's data processing agreement and standard contractual clauses. The specific region of each is on the Subprocessors page.
14. Changes to this notice
Every version of this notice has an identifier and an effective date, both printed above. A material change — a new purpose, a new subprocessor, a longer retention period — is announced before it takes effect and, where it applies, means asking for consent again.
Wording or translation fixes that do not change meaning do not create a new version; they are mentioned in the next one that does.