Last updated: 31 August 2026
This Privacy Policy explains how MatPilot Limited collects, uses, shares and protects personal data when you use the MatPilot mobile app, websites and related services (together, the "Service"). It applies wherever you are.
MatPilot is used by academies across Europe, the United Kingdom, Switzerland, North America and Brazil. Rather than give people in some countries fewer rights than people in others, we apply one standard to everyone: the one set by the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). As an Irish company we are directly bound by the GDPR, the Irish Data Protection Act 2018 and the ePrivacy Regulations 2011 (S.I. 336/2011). Your own country's law may give you further rights on top, and clause 10 sets out what they are and who you can complain to.
1. Controller & processor roles · 2. Data we collect · 3. How & why we use it (legal bases) · 4. Children · 5. Email & messaging · 6. Who we share with (sub-processors) · 7. International transfers · 8. Retention · 9. Your rights · 10. Your rights where you live · 11. Automated decisions & AI · 12. Security · 13. Cookies · 14. Operator data-processing terms · 15. Complaints · 16. Changes
MatPilot is used by martial arts academies, gyms and coaches ("Operators") to run their business, and by their students and clients ("Members"). Who is responsible for which data depends on the data:
If you are a Member and want to exercise your rights over data held by your academy, contact your academy (the controller) and we will help them respond.
We do not intentionally collect special-category data (Article 9 GDPR). If an Operator chooses to record health or similar data about a Member, the Operator is the controller and is responsible for the lawful basis for doing so.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide and operate the Service (accounts, classes, billing, grading, messaging) and provide support | Performance of a contract (Art. 6(1)(b)); for Member data, the Operator's basis under its instructions |
| Process subscription payments and platform fees | Contract (Art. 6(1)(b)) |
| Send transactional, account-related notifications | Contract (Art. 6(1)(b)) / legitimate interests (Art. 6(1)(f)) |
| Secure the Service, prevent abuse and fraud, debug and improve it | Legitimate interests (Art. 6(1)(f)) |
| Keep financial, tax and audit records | Legal obligation (Art. 6(1)(c)) |
| Optional features that ask for your permission (e.g. geofenced check-in, any optional marketing) | Consent (Art. 6(1)(a)), which you can withdraw at any time |
Where we rely on legitimate interests, we have weighed them against your rights and only proceed where they are not overridden. You can object (see clause 9).
You must be at least 16 to create your own MatPilot account, anywhere in the world. We apply one minimum rather than a different one per country, and 16 is at or above the threshold in every market we operate in: the EU sets the digital age of consent between 13 and 16 (Ireland's is 16, under section 31 of the Data Protection Act 2018), the UK's is 13, and US federal law protects children under 13. Where the law where you live sets a higher minimum than 16, that one applies. Academies frequently manage members who are minors; in that case the academy (as controller) must obtain and keep verifiable parent/guardian consent, including for the use of a minor's photograph. The Service provides per-member photo-consent controls and warns staff before posting a class photo that includes minors without consent on file. We do not knowingly let a child under 16 create an account for themselves.
MatPilot sends transactional, account-related email only (for example: a payment
received or failed, a trial converting, a new member joining, grading ready). These
are triggered by activity in the account and include a List-Unsubscribe header.
We do not send marketing email through this channel and we do not email purchased
or scraped lists. Owner notifications can be turned off per category in-app. Email is
delivered via Resend; we suppress addresses that hard-bounce or complain. Any
member-facing messages an Operator sends must comply with the electronic-marketing
law of the country its Members are in (the ePrivacy rules in the EEA and the UK,
CAN-SPAM and state law in the US, CASL in Canada, the Marco Civil and the LGPD in
Brazil) and must honour opt-outs.
If you receive a message through the in-app inbox that is harmful, offensive, or unlawful, you can report it directly within the app. We review reports promptly.
We do not sell personal data. We share it only with the service providers that help us run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, authentication (Cognito), file storage | EU (Stockholm, eu-north-1) |
| Amazon Bedrock / Anthropic | AI assistant & co-pilot (processes limited member context: names, plan and payment status) | USA (us-east-1) |
| Stripe | Payment processing & subscriptions (independent controller for payment data) | EU / USA |
| Resend | Transactional email delivery | EU (Ireland) / USA |
| Expo | Push notifications & crash/update services | USA |
| Twilio | SMS / WhatsApp, only if an academy enables it | USA |
| Apple & Google | App distribution and optional federated sign-in | USA / EU |
Each is bound by a data-processing agreement. We may also disclose data where required by law, to establish or defend legal claims, or to protect the rights and safety of users.
Our primary infrastructure is in the EU. Some providers process data in the United States, notably the AI features (Amazon Bedrock / Anthropic), push notifications (Expo), and parts of Stripe and Twilio. Where personal data is transferred out of the region it was collected in, we rely on appropriate safeguards: under Chapter V GDPR for the EEA, principally the European Commission's Standard Contractual Clauses (2021/914) together with the providers' supplementary measures and the EU–US Data Privacy Framework where a provider is certified; the UK Addendum and IDTA for the United Kingdom; the Swiss addendum to the Clauses for Switzerland; and the international-transfer conditions of the LGPD (Articles 33 to 36) for Brazil. Wherever you are, the safeguard is the same set of contracts and the same infrastructure. We minimise what is sent (for the AI features, only the limited context noted above). You can ask us for more information about these safeguards.
| Data | Retention |
|---|---|
| Account & academy/member data | While the account is active; deleted on verified request, subject to the exceptions below |
| Financial, invoice & tax records | Retained as long as the tax and company law we are subject to requires (Irish law, generally up to 6 years). Operators have their own retention obligations in their own country, which may be longer |
| Audit logs of changes | Up to 1 year |
| Backups | Rolling, then overwritten |
When we erase data, we remove or irreversibly anonymise it except where we must keep limited records (e.g. transaction IDs for tax) by law.
Wherever you live, and whichever law covers you, we give you the right to:
Exercise any of these in-app (you can update your details, manage notifications, and file an export or deletion request from your account), on our Data & privacy rights page (sign in to request a copy of your data, or delete some or all of it), or by emailing admin@matpilot.io. We respond within one month (extendable by two months for complex requests, with notice), free of charge in normal cases. For data held by an academy about its Members, we route the request to that academy as controller and assist it.
Clause 9 is what we give everyone. Your own country's law may add to it, or name a regulator you can go to. This is where MatPilot operates and what applies:
| Where you are | The law that also applies | Who you can complain to |
|---|---|---|
| EEA (EU, Iceland, Liechtenstein, Norway) | The GDPR and your country's national data-protection act | Your national supervisory authority, or our lead authority (clause 15) |
| United Kingdom | The UK GDPR and the Data Protection Act 2018 (UK) | Information Commissioner's Office, ico.org.uk |
| Switzerland | The Federal Act on Data Protection (revFADP) | Federal Data Protection and Information Commissioner, edoeb.admin.ch |
| Brazil | The LGPD (Lei nº 13.709/2018). Your rights include confirmation of processing, access, correction, anonymisation or deletion, portability, and information about who we share with | ANPD, gov.br/anpd |
| Canada | PIPEDA and the provincial privacy acts | Office of the Privacy Commissioner of Canada, priv.gc.ca |
| Mexico | The Federal Law on Protection of Personal Data Held by Private Parties, including your ARCO rights (access, rectification, cancellation, opposition) | Mexico's federal data-protection authority |
| United States | Your state's privacy law where you have one (for example the CCPA as amended by the CPRA in California): the right to know, delete, correct, and to opt out of sale or sharing | Your state attorney general |
Two things we will say plainly for the US, because state law asks us to. We do not sell personal data and we do not share it for cross-context behavioural advertising, so there is nothing for you to opt out of. And we will never give you a worse price, or a worse service, for exercising any right on this page.
You exercise all of them the same way, whichever row you are in: in-app, on the Data & privacy rights page, or by emailing admin@matpilot.io. If your country's law gives you a right this policy does not mention, you still have it, and asking us is enough.
We do not make decisions producing legal or similarly significant effects about an individual by solely automated means. The AI assistant and co-pilot summarise data and suggest or draft actions, but anything that affects a Member (such as sending a message) requires a human at the academy to confirm it. AI processing uses Amazon Bedrock / Anthropic in the US with the safeguards in clause 7, and is limited to the context needed to answer.
The AI may surface informational alerts about compliance matters, such as applicable VAT rates or Operator responsibilities, to help Operators run their business. These are for information only and do not constitute legal, tax or professional advice.
We use appropriate technical and organisational measures: encryption in transit (TLS), encryption at rest, scoped role-based access controls, EU-hosted managed infrastructure, audit logging, and least-privilege service permissions. No system is perfectly secure, but we work to protect your data and will notify you, our lead supervisory authority and any other regulator entitled to be told of a personal-data breach, within the deadline the law that covers you sets.
Our marketing website uses only what is strictly necessary to serve the pages and does not use advertising or cross-site tracking cookies. The mobile app uses secure device storage (not browser cookies) to keep you signed in. If we ever introduce non-essential cookies, we will ask for your consent first, everywhere, as the ePrivacy rules require in the EEA and the UK.
Where MatPilot processes Member personal data on an Operator's behalf, the following terms apply and form part of our agreement. MatPilot will:
Subject matter: provision of the Service. Duration: the term of the account. Nature/purpose: academy management. Data types/subjects: as in clause 2, concerning the Operator's Members and staff.
We would like the chance to resolve any concern first. Please contact admin@matpilot.io. You also have the right to complain to a regulator, and you can always choose the one where you live rather than the one where we are.
Because MatPilot is established in Ireland, our lead supervisory authority under the GDPR's one-stop-shop is:
Data Protection Commission (DPC)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
If you are in another EEA country you may complain to your own national supervisory authority instead, and it will deal with us through the DPC. If you are outside the EEA, clause 10 names the regulator for your country.
We may update this policy from time to time. We will update the date above and, for material changes, give reasonable notice (by email or in-app) before they take effect.
MatPilot Limited (Company No. 819708, Republic of Ireland): admin@matpilot.io. See also our Terms & Conditions.