Matfact
Español
FeaturesGuidesMigrationPricingWhatsAppContactMember loginAdmin

← Back to home

Privacy policy

Privacy policyTerms of serviceData processing addendumSubprocessors

Last updated: 17 August 2026 Language: English Jurisdiction: Spain / European Union

This Privacy Policy describes how Matfact (“we”, “us”) processes personal data when you use our websites, admin console, member web app, and mobile applications (the “Services”).


1. Who is responsible?

1.1 When Matfact is the controller

Matfact is the controller for:

  • Platform accounts (registration, login, profile fields we store for your user account)
  • Matfact SaaS billing for academies
  • Landing-page contact messages sent to us
  • Security, fraud prevention, and platform administration

Contact: general inquiries via the contact form or [email protected]; privacy matters: [email protected].

1.2 When your academy (gym) is the controller

Your martial arts academy is the controller of personal data it enters or manages in Matfact for academy operations (memberships, attendance, promotions, member dues collection, invitations, join requests, and related gym settings). In that case Matfact acts as a processor under a Data Processing Addendum.

If you are a student or coach and want to exercise GDPR rights about academy data, contact your academy first. We assist academies under our DPA and ops procedures.


2. Personal data we process

Depending on how you use the Services, we may process:

  • Identity and contact: email, name, phone, address; optional date of birth when an academy records it for a child account
  • Account: password hash, email verification status, preferred language, avatar image URL; account kind (standard or managed child without login)
  • Social login: provider subject identifiers and email from Google or Apple Sign-In
  • Academy context: membership role, member type (including child-type memberships), attendance and promotion history linked to your membership
  • Family linking: guardian–ward links at an academy (who may act for a child membership), including role and link status (active, revoked, or emancipated)
  • Billing: Stripe customer/subscription identifiers and related status; who is the dues billing contact (member or guardian). Card data is handled by Stripe, not stored by Matfact
  • Technical: session cookies or mobile session keys; security logs
  • Join requests: when you ask to join a discoverable academy, your identity and optional message; staff notes on reject
  • Communications: content of emails we send or contact-form messages

We do not sell personal data.


3. Purposes and legal bases

PurposeLegal basis (GDPR)
Provide and secure your account and the ServicesContract (Art. 6(1)(b)); legitimate interests for security (Art. 6(1)(f))
Process academy data on the gym’s instructionsProcessing as processor (Art. 28); gym’s own bases apply toward members
SaaS subscription billingContract
Send transactional email (verify, reset, invites)Contract / legitimate interests
Respond to contact-form enquiriesLegitimate interests / pre-contract
Comply with law and enforce termsLegal obligation / legitimate interests

4. Cookies

We use essential cookies only:

  • Session cookie for signed-in web sessions
  • CSRF cookie for security

We do not use analytics or advertising cookies today. If that changes, we will update this policy and add consent where required.

Mobile apps may store a session key and preferences (e.g. locale, selected gym) in on-device storage instead of cookies.


5. Recipients and subprocessors

We use infrastructure and service providers listed on our Subprocessors page (hosting, database, media storage, email, payments, social login). They process data only to provide their services to us.


6. International transfers

Some subprocessors are in the United States or other countries outside the EEA. Where required, transfers rely on appropriate safeguards such as the vendor’s Standard Contractual Clauses or other lawful transfer mechanisms in their data processing terms.


7. Retention

We keep personal data only as long as needed for the purposes above, including legal, accounting, and security needs. See our internal retention schedule summarized as:

  • Account data: while the account is active, then anonymized or deleted per erasure requests
  • Operational academy history (attendance, promotions): retained for the academy; personal identifiers are anonymized on valid erasure
  • Billing records: as required for tax and Stripe retention
  • Contact emails: retained in our ops inbox per support needs (typically up to 12 months)

8. Your rights

Where Matfact is controller, you may request access, rectification, erasure, restriction, portability, and objection, and you may lodge a complaint with your supervisory authority (in Spain, the AEPD).

How to exercise rights

  • Platform account / Matfact-controller data: contact [email protected] (or the website contact form / [email protected]).
  • Academy (member) data: contact your gym; they may instruct us to export or anonymize data.

We may need to verify your identity before fulfilling a request.

Account deletion

You may request deletion of your Matfact platform account by emailing `[email protected]` from the address on your account (or explain why you cannot). We will verify your identity, then anonymize your platform identity within a reasonable time. Attendance, promotion, and membership history at your academy may be retained in anonymized form for the gym’s operational records. To delete academy-held member data, contact your gym first.

In the mobile app and member web profile, Legal → Request account deletion opens the same email channel.


9. Children and family accounts

Academies may create child-type memberships and, where they use family accounts, link a guardian’s platform account to a child’s membership at that academy.

  • Managed child accounts may have no email and no login. The guardian signs in and may switch to act for the child (progress, waiver, dues) while the session remains the guardian’s.
  • Waiver: child acceptances still require a typed guardian name and relationship (evidence of parental authority). Where a linked guardian accepts in-app, we also record which user signed.
  • Independence: staff may invite a child to their own login, or graduate them to an independent account. Graduation ends active guardian access (links are retained as emancipated audit history). Dues billing contact may move to the member at that time.
  • Optional date of birth is gym-entered for roster purposes only. Matfact does not use it to auto-enforce age gates or change member type.
  • Academies remain the controller for child and guardian operational data and must have a lawful basis (including parental authority where required). Matfact provides linking and delegation tooling as processor under the DPA.

Erasure of a guardian does not erase the child’s membership data; active links are revoked. See our DSAR and erasure procedures for academies.


10. Security

We apply technical and organizational measures appropriate to the risk, including tenant isolation, encrypted transport in production, hashed passwords, and access controls. No method of transmission or storage is perfectly secure.


11. Changes

We may update this policy. The “Last updated” date will change, and material changes may be highlighted on the website or by email where appropriate.


12. Related documents

  • Terms of Service
  • Data Processing Addendum
  • Subprocessors
PrivacyTermsDPASubprocessorsGuides[email protected]Member loginAdmin

© 2026 Matfact. All rights reserved.