Last updated: 26 June 2026
This Privacy Policy explains how MatPilot Limited collects, uses, shares and protects personal data when you use the MatPilot mobile app, websites and related services (together, the "Service"). We comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Irish Data Protection Act 2018 and the ePrivacy Regulations 2011 (S.I. 336/2011).
1. Controller & processor roles · 2. Data we collect · 3. How & why we use it (legal bases) · 4. Children · 5. Email & messaging · 6. Who we share with (sub-processors) · 7. International transfers · 8. Retention · 9. Your rights · 10. Automated decisions & AI · 11. Security · 12. Cookies · 13. Operator data-processing terms · 14. Complaints · 15. Changes
MatPilot is used by martial arts academies, gyms and coaches ("Operators") to run their business, and by their students and clients ("Members"). Who is responsible for which data depends on the data:
If you are a Member and want to exercise your rights over data held by your academy, contact your academy (the controller) and we will help them respond.
We do not intentionally collect special-category data (Article 9 GDPR). If an Operator chooses to record health or similar data about a Member, the Operator is the controller and is responsible for the lawful basis for doing so.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide and operate the Service (accounts, classes, billing, grading, messaging) and provide support | Performance of a contract (Art. 6(1)(b)); for Member data, the Operator's basis under its instructions |
| Process subscription payments and platform fees | Contract (Art. 6(1)(b)) |
| Send transactional, account-related notifications | Contract (Art. 6(1)(b)) / legitimate interests (Art. 6(1)(f)) |
| Secure the Service, prevent abuse and fraud, debug and improve it | Legitimate interests (Art. 6(1)(f)) |
| Keep financial, tax and audit records | Legal obligation (Art. 6(1)(c)) |
| Optional features that ask for your permission (e.g. geofenced check-in, any optional marketing) | Consent (Art. 6(1)(a)), which you can withdraw at any time |
Where we rely on legitimate interests, we have weighed them against your rights and only proceed where they are not overridden. You can object (see clause 9).
The digital age of consent in Ireland is 16 (section 31, Data Protection Act 2018). Individuals must be 16 to create their own MatPilot account. Academies frequently manage members who are minors; in that case the academy (as controller) must obtain and keep verifiable parent/guardian consent, including for the use of a minor's photograph. The Service provides per-member photo-consent controls and warns staff before posting a class photo that includes minors without consent on file. We do not knowingly let a child under 16 create an account for themselves.
MatPilot sends transactional, account-related email only (for example: a payment
received or failed, a trial converting, a new member joining, grading ready). These
are triggered by activity in the account and include a List-Unsubscribe header.
We do not send marketing email through this channel and we do not email purchased
or scraped lists. Owner notifications can be turned off per category in-app. Email is
delivered via Resend; we suppress addresses that hard-bounce or complain. Any
member-facing messages an Operator sends must comply with the ePrivacy Regulations
2011 and honour opt-outs.
If you receive a message through the in-app inbox that is harmful, offensive, or unlawful, you can report it directly within the app. We review reports promptly.
We do not sell personal data. We share it only with the service providers that help us run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, authentication (Cognito), file storage | EU (Stockholm, eu-north-1) |
| Amazon Bedrock / Anthropic | AI assistant & co-pilot (processes limited member context: names, plan and payment status) | USA (us-east-1) |
| Stripe | Payment processing & subscriptions (independent controller for payment data) | EU / USA |
| Resend | Transactional email delivery | EU (Ireland) / USA |
| Expo | Push notifications & crash/update services | USA |
| Twilio | SMS / WhatsApp, only if an academy enables it | USA |
| Apple & Google | App distribution and optional federated sign-in | USA / EU |
Each is bound by a data-processing agreement. We may also disclose data where required by law, to establish or defend legal claims, or to protect the rights and safety of users.
Our primary infrastructure is in the EU. Some providers process data in the United States, notably the AI features (Amazon Bedrock / Anthropic), push notifications (Expo), and parts of Stripe and Twilio. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, principally the European Commission's Standard Contractual Clauses (2021/914) together with the providers' supplementary measures, and on the EU–US Data Privacy Framework where a provider is certified. We minimise what is sent (for the AI features, only the limited context noted above). You can ask us for more information about these safeguards.
| Data | Retention |
|---|---|
| Account & academy/member data | While the account is active; deleted on verified request, subject to the exceptions below |
| Financial, invoice & tax records | Retained as required by Irish tax and company law (generally up to 6 years) |
| Audit logs of changes | Up to 1 year |
| Backups | Rolling, then overwritten |
When we erase data, we remove or irreversibly anonymise it except where we must keep limited records (e.g. transaction IDs for tax) by law.
Under the GDPR you have the right to:
Exercise any of these in-app (you can update your details, manage notifications, and file an export or deletion request from your account), on our Data & privacy rights page (sign in to request a copy of your data, or delete some or all of it), or by emailing admin@matpilot.io. We respond within one month (extendable by two months for complex requests, with notice), free of charge in normal cases. For data held by an academy about its Members, we route the request to that academy as controller and assist it.
We do not make decisions producing legal or similarly significant effects about an individual by solely automated means. The AI assistant and co-pilot summarise data and suggest or draft actions, but anything that affects a Member (such as sending a message) requires a human at the academy to confirm it. AI processing uses Amazon Bedrock / Anthropic in the US with the safeguards in clause 7, and is limited to the context needed to answer.
The AI may surface informational alerts about compliance matters, such as applicable VAT rates or Operator responsibilities, to help Operators run their business. These are for information only and do not constitute legal, tax or professional advice.
We use appropriate technical and organisational measures: encryption in transit (TLS), encryption at rest, scoped role-based access controls, EU-hosted managed infrastructure, audit logging, and least-privilege service permissions. No system is perfectly secure, but we work to protect your data and will notify you and the Data Protection Commission of a personal-data breach where the GDPR requires.
Our marketing website uses only what is strictly necessary to serve the pages and does not use advertising or cross-site tracking cookies. The mobile app uses secure device storage (not browser cookies) to keep you signed in. If we ever introduce non-essential cookies, we will ask for your consent first, as required by the ePrivacy Regulations 2011.
Where MatPilot processes Member personal data on an Operator's behalf, the following terms apply and form part of our agreement. MatPilot will:
Subject matter: provision of the Service. Duration: the term of the account. Nature/purpose: academy management. Data types/subjects: as in clause 2, concerning the Operator's Members and staff.
We would like the chance to resolve any concern first. Please contact admin@matpilot.io. You also have the right to lodge a complaint with the Irish supervisory authority:
Data Protection Commission (DPC)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
If you are in another EU/EEA country, you may also complain to your local supervisory authority.
We may update this policy from time to time. We will update the date above and, for material changes, give reasonable notice (by email or in-app) before they take effect.
MatPilot Limited (Company No. 819708, Republic of Ireland): admin@matpilot.io. See also our Terms & Conditions.