Legal

Privacy Policy

Last updated: 2026-09-21

This explains how KABUSHIKI GAISYA LETS BJJ (corporate number 3011101104512, “we”, “us”) handles personal information in connection with DOJO CORE (the “Service”). We act in two different capacities, and which one applies changes how information is handled.

Terms used here

  • “Academy” — the business (company or sole trader) that signs up and manages its members
  • “Member” — a person who trains at the academy and uses the card and member page
  • “This website” — dojo-core.com, where the Service is described and sold

For the academy's own staff details, we are the controller. For member information, we are a processor acting on the academy's instructions: what is collected, and what it is used for, is the academy's decision.

1. What we collect

About the academy

When you enquire or sign up: the contact's name, email address, phone number, and details of the academy. Card details are held by the payment processor; we never receive them.

About members

Whatever the academy enters into the Service: name, member number, belt, plan, attendance history, and optionally date of birth, email address, phone number and an emergency contact.

This website

This website uses Google Analytics to understand how it is visited (see 4-1). It sets no advertising cookies. What you send through the contact form, and your email address, are used only to reply to you. The server keeps ordinary access logs (IP address, browser type, requested URL) for security, for up to 30 days.

2. What it is used for

  • answering your enquiry
  • providing, configuring and maintaining the Service, and dealing with faults
  • invoicing and confirming payment
  • sending important notices (changes to the terms, outages, changes to the Service)
  • detecting and preventing unauthorised access
  • meeting obligations under the law

We do not sell member information. We do not use it for advertising. We do not train models on it. We do not show it to other academies.

3. Who it goes to (processors and third parties abroad)

These are the main processors and third-party services involved.

  • Cloudflare, Inc. (USA) — servers, database, and email sent by the Service
  • Apple Inc. (USA) — delivering and updating the card in Apple Wallet
  • Google LLC (USA) — delivering and updating the card in Google Wallet; serving the typefaces on this website
  • Stripe, Inc. (USA) — monthly payment. Stripe handles card details; we never receive them

What reaches the wallet providers is limited to what is printed on the card (name, member number, belt, plan). Beyond that, we disclose information only on the academy's instructions or where the law requires it.

4. Cookies and the external-transmission rule

4-1. Cookies

This website uses Google Analytics cookies to see which pages are read and how often. It sets no advertising cookies and no ad tags. You can stop Google Analytics from collecting this information with Google’sGoogle Analytics Opt-out Browser Add-on. For visitors from the European Economic Area, the United Kingdom and Switzerland, Google Analytics cookies are not used. Within the Service itself (the academy's admin screens and the member page) we use the minimum cookies needed to keep you logged in and to prevent misuse.

4-2. Information transmitted externally (Telecommunications Business Act, art. 27-12)

The following information is sent from a visitor's device to these companies, as needed to run the Service.

Cloudflare, Inc. (USA)
Sent: IP address, user agent, requested URL, and on the contact page the browser signals used by Cloudflare Turnstile / Purpose: serving responses, detecting and blocking unauthorised access, limiting how often the contact form can be submitted, and telling people from bots on the contact form (Turnstile)
Google LLC (USA)
Sent: IP address, user agent / Purpose: serving the typefaces (Google Fonts) used on this website
Google LLC (USA) — Google Analytics
Sent: the URL and title of pages viewed, referrer, device and browser type, screen size, approximate region, and a cookie identifier / Purpose: analysing how this website is visited (not used to identify individuals)
Apple Inc. (USA) / Google LLC (USA)
Sent: the information printed on the card, and device registration details / Purpose: delivering and updating the card in Apple Wallet or Google Wallet (only where a member has added the card to their wallet)
Stripe, Inc. (USA)
Sent: session information when moving to the payment screen, and card details entered there / Purpose: processing card payments and preventing fraud

5. Where it is held

Data is held on Cloudflare's network and may be processed outside the academy's own country, including in the United States. Transfers rely on the standard contractual clauses and equivalent safeguards of each provider.

6. Safeguards

  • each academy has its own database and running environment; there is no shared member table across academies
  • passwords are stored hashed, never in plain text
  • the QR code on the card holds one unguessable string — no name, no member number
  • access to production is limited to the operators
  • all traffic is encrypted
  • significant actions in the admin screens are logged

7. If there is a breach

If personal data is leaked, lost, damaged, or accessed without authorisation — or we believe it may have been — this is what we do.

  • we contact the academy as soon as we know
  • we tell you what leaked and how far it reached
  • we stop the cause and reissue whatever needs reissuing — member QR codes, passwords
  • we prepare the material the academy needs to explain it to its members
  • for information where we are the controller (the academy's staff details, for example) we report to the Personal Information Protection Commission and notify the individuals within the statutory deadline, under Article 26 of Japan's Act on the Protection of Personal Information
  • for member information the academy is the controller, so the duty to report and notify is the academy's. We hand over everything we know and help you through it

We will not hide it.

8. How long it is kept

Member information is kept while the contract runs. On cancellation we export it in a machine-readable format (CSV) and hand it over, then remove it from production within 30 days of the final export and from backups within 90 days. The academy's own staff details are kept while the account is open and for seven years after, as tax law requires. Access logs on this website are kept for up to 30 days.

9. Your rights (access, correction, deletion, restriction)

Depending on where you live, you may ask to see, correct, delete or take a copy of your information, or ask us to stop processing it. Members should ask their own academy; academies can contact us at any time. We verify who is asking, act within 30 days of receiving the request as a rule, and confirm completion to the registered email address. You are free to complain to the Personal Information Protection Commission or your local authority.

10. Children's membership

The Service is provided to businesses. Where an academy enters a child's information into the Service, obtaining the consent of a parent or legal guardian is the academy's responsibility.

The Service allows a child's membership to be linked to a parent's account. The card and the attendance record are then visible from the parent's own page. Requests on a child's behalf should come through the parent or the academy.

11. Changes to this policy

We may revise this policy as the law or the Service changes. Where a change is significant we announce it at least 30 days before it takes effect, both in the Service and by email to the registered address.

12. Contact

Company
KABUSHIKI GAISYA LETS BJJ (corporate number 3011101104512)
Representative
Hiromichi Fujiwara, Representative Director
Address
Nishi-Shinjuku Mizuma Bldg 2F, 3-13 Nishi-Shinjuku 3-chome, Shinjuku-ku, Tokyo 160-0023, Japan
Email
hello@dojo-core.com
Phone
+81-80-5492-6225