GDPR Compliance

This GDPR Compliance Statement describes how DojoMojo ("we," "us," or "our") handles the personal data of users located in the European Economic Area (EEA) and the United Kingdom (UK) in accordance with the General Data Protection Regulation (GDPR).

1. Lawful Basis for Processing

We process personal data only where we have a lawful basis under Article 6 of the GDPR, including:

  • Contract performance — to provide the Service you have requested.
  • Legal obligation — to comply with applicable laws and regulations.
  • Legitimate interests — to operate and secure our business, where those interests do not override your rights.
  • Consent — where you have explicitly agreed to specific processing activities.

2. Your GDPR Rights

If you are located in the EEA or UK, you have the following rights:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of your personal data, subject to legal retention obligations.
  • Right to restrict processing — request that we limit how we use your data in certain circumstances.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent — withdraw consent at any time without affecting prior lawful processing.

3. International Data Transfers

Your data is stored on infrastructure hosted in the United States. We rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards as required under Article 46 of the GDPR when transferring personal data outside the EEA or UK.

4. Data Protection Officer / Contact

If you wish to exercise any of your rights or have questions about our GDPR practices, please contact us:

You also have the right to lodge a complaint with your local supervisory authority.

5. Subprocessors

We use a small number of subprocessors (Supabase, Stripe, AWS SES, Vercel) to deliver the Service. Each is bound by data processing agreements and industry-standard security certifications. A current list of subprocessors is available on request.

6. Updates to This Statement

We may update this GDPR Compliance Statement from time to time. Material changes will be communicated via email or a prominent notice on the Service at least 30 days before they take effect.