How it works Features Pricing Help Get MatPilot Pro

Privacy Policy

Last updated: 26 June 2026

This Privacy Policy explains how MatPilot Limited collects, uses, shares and protects personal data when you use the MatPilot mobile app, websites and related services (together, the "Service"). We comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Irish Data Protection Act 2018 and the ePrivacy Regulations 2011 (S.I. 336/2011).

Controller. MatPilot Limited, a company incorporated in the Republic of Ireland (company number 819708), registered office 2 Hermitage Lane, Ballyowen Lane, Co. Dublin, K78 K7P0, Republic of Ireland. For privacy questions or to exercise your rights, contact admin@matpilot.io.

1. Controller & processor roles · 2. Data we collect · 3. How & why we use it (legal bases) · 4. Children · 5. Email & messaging · 6. Who we share with (sub-processors) · 7. International transfers · 8. Retention · 9. Your rights · 10. Automated decisions & AI · 11. Security · 12. Cookies · 13. Operator data-processing terms · 14. Complaints · 15. Changes

1. Controller & processor roles

MatPilot is used by martial arts academies, gyms and coaches ("Operators") to run their business, and by their students and clients ("Members"). Who is responsible for which data depends on the data:

  • MatPilot is the controller for: Operator account and staff data, billing and subscription data, website and app analytics we collect, security logs, and our own communications with you.
  • The Operator is the controller, and MatPilot is the processor, for the Member data an Operator enters or uploads (member profiles, attendance, grading, documents, photos, guardian details, etc.). We process it only on the Operator's documented instructions, as set out in clause 13.

If you are a Member and want to exercise your rights over data held by your academy, contact your academy (the controller) and we will help them respond.

2. Data we collect

  • Identity & contact: name, email address, phone, and (for Members where the academy records it) date of birth and address. Authentication is handled via Amazon Cognito.
  • Academy & membership data: academy profiles, plans, classes, bookings, attendance/check-ins, belt & grading records, notes, documents and waivers an Operator creates or uploads.
  • Photos: profile photos and end-of-class team photos uploaded by Operators or Members. Photos of identifiable people are personal data; for minors, photo consent is recorded per member.
  • Guardian details for members who are minors, where the academy records them.
  • Staff safeguarding data (instructors/managers): Garda-vetting and first-aid status, recorded by the Operator as informational flags.
  • Payment data: billing is processed by Stripe. We do not store full card numbers; we store references (e.g. customer/subscription IDs, amounts, status) needed to manage memberships and our own subscription.
  • Communications: in-app messages/inbox, notification preferences, and support emails.
  • Device, usage & log data: technical data (device/app version, IP address, timestamps, crash diagnostics) needed to operate, secure and debug the Service. Crash reporting uses Sentry.
  • Location: we do not track your location. If an academy enables optional geofenced check-in, your device's coarse location is used only at the moment you check in, to confirm you are at the venue.

We do not intentionally collect special-category data (Article 9 GDPR). If an Operator chooses to record health or similar data about a Member, the Operator is the controller and is responsible for the lawful basis for doing so.

3. How & why we use it, and our legal bases

PurposeLegal basis (GDPR Art. 6)
Provide and operate the Service (accounts, classes, billing, grading, messaging) and provide supportPerformance of a contract (Art. 6(1)(b)); for Member data, the Operator's basis under its instructions
Process subscription payments and platform feesContract (Art. 6(1)(b))
Send transactional, account-related notificationsContract (Art. 6(1)(b)) / legitimate interests (Art. 6(1)(f))
Secure the Service, prevent abuse and fraud, debug and improve itLegitimate interests (Art. 6(1)(f))
Keep financial, tax and audit recordsLegal obligation (Art. 6(1)(c))
Optional features that ask for your permission (e.g. geofenced check-in, any optional marketing)Consent (Art. 6(1)(a)), which you can withdraw at any time

Where we rely on legitimate interests, we have weighed them against your rights and only proceed where they are not overridden. You can object (see clause 9).

4. Children

The digital age of consent in Ireland is 16 (section 31, Data Protection Act 2018). Individuals must be 16 to create their own MatPilot account. Academies frequently manage members who are minors; in that case the academy (as controller) must obtain and keep verifiable parent/guardian consent, including for the use of a minor's photograph. The Service provides per-member photo-consent controls and warns staff before posting a class photo that includes minors without consent on file. We do not knowingly let a child under 16 create an account for themselves.

5. Email & messaging

MatPilot sends transactional, account-related email only (for example: a payment received or failed, a trial converting, a new member joining, grading ready). These are triggered by activity in the account and include a List-Unsubscribe header. We do not send marketing email through this channel and we do not email purchased or scraped lists. Owner notifications can be turned off per category in-app. Email is delivered via Resend; we suppress addresses that hard-bounce or complain. Any member-facing messages an Operator sends must comply with the ePrivacy Regulations 2011 and honour opt-outs.

If you receive a message through the in-app inbox that is harmful, offensive, or unlawful, you can report it directly within the app. We review reports promptly.

6. Who we share data with (sub-processors)

We do not sell personal data. We share it only with the service providers that help us run the Service:

ProviderPurposeLocation
Amazon Web Services (AWS)Hosting, database, authentication (Cognito), file storageEU (Stockholm, eu-north-1)
Amazon Bedrock / AnthropicAI assistant & co-pilot (processes limited member context: names, plan and payment status)USA (us-east-1)
StripePayment processing & subscriptions (independent controller for payment data)EU / USA
ResendTransactional email deliveryEU (Ireland) / USA
ExpoPush notifications & crash/update servicesUSA
TwilioSMS / WhatsApp, only if an academy enables itUSA
Apple & GoogleApp distribution and optional federated sign-inUSA / EU

Each is bound by a data-processing agreement. We may also disclose data where required by law, to establish or defend legal claims, or to protect the rights and safety of users.

7. International transfers

Our primary infrastructure is in the EU. Some providers process data in the United States, notably the AI features (Amazon Bedrock / Anthropic), push notifications (Expo), and parts of Stripe and Twilio. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, principally the European Commission's Standard Contractual Clauses (2021/914) together with the providers' supplementary measures, and on the EU–US Data Privacy Framework where a provider is certified. We minimise what is sent (for the AI features, only the limited context noted above). You can ask us for more information about these safeguards.

8. How long we keep data

DataRetention
Account & academy/member dataWhile the account is active; deleted on verified request, subject to the exceptions below
Financial, invoice & tax recordsRetained as required by Irish tax and company law (generally up to 6 years)
Audit logs of changesUp to 1 year
BackupsRolling, then overwritten

When we erase data, we remove or irreversibly anonymise it except where we must keep limited records (e.g. transaction IDs for tax) by law.

9. Your rights

Under the GDPR you have the right to:

  • access your personal data and get a copy;
  • rectify inaccurate data and complete incomplete data;
  • erase your data ("right to be forgotten");
  • restrict or object to processing, including processing based on legitimate interests;
  • data portability: receive your data in a structured, machine-readable format;
  • withdraw consent at any time where we rely on consent;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see clause 10).

Exercise any of these in-app (you can update your details, manage notifications, and file an export or deletion request from your account), on our Data & privacy rights page (sign in to request a copy of your data, or delete some or all of it), or by emailing admin@matpilot.io. We respond within one month (extendable by two months for complex requests, with notice), free of charge in normal cases. For data held by an academy about its Members, we route the request to that academy as controller and assist it.

Manage your data online. Visit matpilot.io/data-rights to sign in with your app login and download a copy of your data, delete specific categories of data without closing your account, or delete your account entirely.

10. Automated decision-making & AI

We do not make decisions producing legal or similarly significant effects about an individual by solely automated means. The AI assistant and co-pilot summarise data and suggest or draft actions, but anything that affects a Member (such as sending a message) requires a human at the academy to confirm it. AI processing uses Amazon Bedrock / Anthropic in the US with the safeguards in clause 7, and is limited to the context needed to answer.

The AI may surface informational alerts about compliance matters, such as applicable VAT rates or Operator responsibilities, to help Operators run their business. These are for information only and do not constitute legal, tax or professional advice.

11. Security

We use appropriate technical and organisational measures: encryption in transit (TLS), encryption at rest, scoped role-based access controls, EU-hosted managed infrastructure, audit logging, and least-privilege service permissions. No system is perfectly secure, but we work to protect your data and will notify you and the Data Protection Commission of a personal-data breach where the GDPR requires.

12. Cookies

Our marketing website uses only what is strictly necessary to serve the pages and does not use advertising or cross-site tracking cookies. The mobile app uses secure device storage (not browser cookies) to keep you signed in. If we ever introduce non-essential cookies, we will ask for your consent first, as required by the ePrivacy Regulations 2011.

13. Data-processing terms for Operators (Article 28)

Where MatPilot processes Member personal data on an Operator's behalf, the following terms apply and form part of our agreement. MatPilot will:

  • process Member data only on the Operator's documented instructions (including these Terms and use of the Service), unless required by law;
  • ensure persons authorised to process the data are bound by confidentiality;
  • apply appropriate security measures (clause 11);
  • engage only sub-processors listed in clause 6 (or notified to the Operator) under written terms with equivalent obligations, and remain responsible for them;
  • assist the Operator, taking account of the nature of processing, with data-subject requests and with security, breach-notification and impact-assessment obligations;
  • notify the Operator without undue delay on becoming aware of a personal-data breach;
  • at the Operator's choice, delete or return Member data at the end of the service, save for records we must retain by law;
  • make available information needed to demonstrate compliance and allow reasonable audits.

Subject matter: provision of the Service. Duration: the term of the account. Nature/purpose: academy management. Data types/subjects: as in clause 2, concerning the Operator's Members and staff.

14. Complaints

We would like the chance to resolve any concern first. Please contact admin@matpilot.io. You also have the right to lodge a complaint with the Irish supervisory authority:

Data Protection Commission (DPC)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie

If you are in another EU/EEA country, you may also complain to your local supervisory authority.

15. Changes to this policy

We may update this policy from time to time. We will update the date above and, for material changes, give reasonable notice (by email or in-app) before they take effect.

Contact

MatPilot Limited (Company No. 819708, Republic of Ireland): admin@matpilot.io. See also our Terms & Conditions.

Terms & Conditions →

Operational software for martial arts academies.

Product

How it works Features Help

Company

Privacy Terms Your data & rights Age suitability Accessibility
© 2026 MatPilot Limited. All rights reserved. MatPilot Limited · Company No. 819708 · 🇮🇪 Republic of Ireland