Privacy policy
Last updated: 6 August 2026
1. Who we are
JudoHQ is a free, open-source club management platform for voluntary judo clubs in the United Kingdom, operated from the UK.
For the purposes of UK GDPR, each club (through the individual who registers and administers it) is the data controller for member data entered into the platform, and JudoHQ acts as a data processor on the club's behalf. For platform-level account data — your login credentials and the service emails we send to operate the platform — JudoHQ is the data controller. The platform operator can be contacted for all data protection matters at privacy@judohq.co.uk (see section 13).
2. Data we collect
We collect and process the following categories of personal data:
- Club administrator data: name, email address, and password provided during club registration.
- Member data: name, email, date of birth, grade/belt level, BJA membership number, address, emergency contact information, and attendance records — added by club administrators or provided by members during sign-up.
- Medical data (special category): optional medical notes (e.g. allergies, conditions, medication) that you, a parent/guardian, or a club administrator may record so coaches can keep members safe during training. This is special-category data under UK GDPR and is only collected with explicit consent (see section 4).
- Guest event entrant data: if you enter a club's competition or grading as a guest (without an account), the club collects your name, email address, date of birth, and — depending on the event — your BJA membership number (optional), your own club's name (optional), age group, weight or weight category, current and target grade, and, for competitions, your photo and film consents. The club running the event is the controller of this data; it is used only to run the event, take the entry fee, and contact you about your entry. Competition draws and results are published; unless you give both media consents, you appear on public pages as initials and club only. See section 7 for how long guest entries are kept and section 8 for how to exercise your rights without an account.
- Why a guest entrant is asked for a date of birth: competition entries are grouped into age categories, and the platform will not place — or allow an official to move — an entrant whose age it cannot verify into any category open to under-18s. That safeguarding rule is the reason the date of birth is necessary rather than merely useful, and it is the same reason members give theirs. On gradings it is used to check whether a grade on the junior-only pathway can be entered for. We store the date of birth and display only the age: it is not shown on entry lists, draws, results or exports, and the “view your entry” page shows the entrant's age on the day, never the date. It is removed with the rest of your entry details on request (section 8).
- Account data: login credentials, session tokens, and activity logs.
- Payment and billing data: transaction amounts, payment status, Stripe payment identifiers (we never store card numbers), refund request reasons, and membership billing history. Processed to fulfil your club membership and event fees.
- Safeguarding data: incident (injury) reports and behaviour/welfare reports recorded by club staff, which may include the names of those involved, descriptions of what happened, and any treatment or follow-up.
- Club email data: when someone emails a club's address (e.g. yourclub@judohq.co.uk) we record message metadata — sender, recipient, subject, and delivery outcome — so the club can audit its mail routing. Message bodies are forwarded to the club's configured mailbox and are not stored by JudoHQ (see sections 5 and 7).
- Feedback you submit: messages sent through the in-app feedback button or the Judo Helper (AI) thumbs-up/thumbs-down controls — the topic you pick, an optional rating, your message, the page you were on, and your browser type. This goes to the JudoHQ platform developer (not your club) to improve the service.
- Technical and security data: IP addresses and request information used for rate limiting and security monitoring. Rate-limiting counters are short-lived and expire automatically. We do not collect analytics or tracking data.
3. How we use your data
We use personal data to:
- Provide and operate the JudoHQ club management platform
- Manage club memberships, gradings, competitions, and attendance
- Keep members safe — recording injuries, welfare concerns and (with explicit consent) medical information so clubs can meet their safeguarding and duty-of-care obligations
- Process payments and refunds for memberships, gradings, competitions, and shop purchases
- Send notifications that club administrators or members have opted into
- Maintain platform security and prevent fraud
- Comply with legal obligations
4. Legal basis for processing
We process your personal data under the following legal bases as defined by UK GDPR:
- Contractual necessity: to provide the services you signed up for (club management, membership tracking) — including, for guest event entrants, taking and administering the event entry you asked for. A guest entrant's date of birth is processed on this basis: an entry cannot lawfully or safely be placed in an age and weight category without an age, and the platform refuses to place an entrant whose age is unknown alongside children.
- Consent (guest media consents): a guest competition entrant's photo and film consents are processed on the basis of consent, given per entry on the entry form. Either consent can be withdrawn at any time via the link in the confirmation email, with immediate effect on public pages.
- Legitimate interests: to improve the platform, communicate important updates, and maintain security. Where we rely on legitimate interests we balance them against your rights and freedoms, giving particular weight to the interests of children.
- Consent: for optional features such as the Judo Helper (AI) and any optional communications. You can withdraw consent at any time.
- Legal obligation: to comply with applicable laws and regulations (for example, tax record-keeping).
- Vital interests: in a medical emergency we may use emergency contact and medical information to protect someone's life or health.
Some of the data we process is special-category data under Article 9 UK GDPR, and we rely on the following additional conditions:
- Medical information: processed only with your explicit consent (Article 9(2)(a)), given by you — or by a parent/guardian for a junior — when the information is added. You can withdraw this consent and have the information removed at any time. In an emergency we may also rely on the vital-interests condition (Article 9(2)(c)).
- Safeguarding and welfare reports: processed because it is in the substantial public interest to safeguard children and individuals at risk (Article 9(2)(g) UK GDPR with paragraph 18 of Schedule 1 to the Data Protection Act 2018). We do not rely on consent for safeguarding records, which is why they cannot be deleted on request (see section 7).
5. Data sharing
We do not sell or rent personal data to third parties. We may share data with:
- Hosting: JudoHQ hosts and operates the platform and its database itself, on servers located in the United Kingdom or the European Economic Area. Your data is not stored on third-party cloud application platforms, other than the network, payment and email providers described below.
- Cloudflare (network and protection): traffic between your device and JudoHQ passes through Cloudflare, which provides the secure network tunnel to our servers and shields the service from attacks and abuse. Cloudflare terminates the encrypted (HTTPS) connection, so requests pass through it before they reach us, and it sees connection details including your IP address, the address you asked for, and your browser type. We do not give Cloudflare access to our database or our accounts. Cloudflare operates a global network, so this traffic may be handled outside the UK — see the international transfers note in section 7.
- Stripe (payment processing) for membership, grading, competition, and shop payments. We do not store card numbers — payments are completed on Stripe-hosted checkout pages. See section 6 for Stripe Connect and international transfers.
- Resend (email delivery) to send transactional emails (account verification, membership and payment confirmations, renewal reminders sent 14 and 3 days before a membership expires, and notifications). We share only the recipient email address and the message content. Resend also receives email sent to club addresses (e.g. yourclub@judohq.co.uk), which we forward to the club's configured mailbox — JudoHQ keeps message metadata only, never the message body. Resend is a US-based provider, so email data passes outside the UK — see the international transfers note in section 7.
- Browser push services (only if you turn on push alerts): push alerts are off by default. If you switch them on for a device, the alert has to travel through the push service built into that browser — Google (Chrome and Android), Mozilla (Firefox), Apple (Safari, iPhone and iPad) or Microsoft (Edge). That service receives a unique address for your device and the alert itself, which is encrypted so the push service cannot read its contents. These providers are based outside the UK — see the international transfers note in section 7. You can turn push alerts off again, per device, at any time on the Notifications page; in-app and email notifications are unaffected.
- No AI provider: we do not share any data with third-party AI companies. The optional Judo Helper (AI) runs entirely on hardware that JudoHQ operates in the United Kingdom — see section 11.
- Club administrators: member data is visible to the administrators of the club the member belongs to, including refund requests and reasons you submit.
- National governing body (British Judo Association): your club may share member details — name, date of birth, BJA licence number and expiry, grade, and (for juniors) a guardian's contact details — with the British Judo Association or its affiliated bodies for licensing, insurance, and grading purposes. This is part of running an affiliated judo club, so the club relies on its legitimate interests and the necessity of performing your membership. It is an ordinary administrative disclosure only — no health or medical data is shared this way — and each export is logged by the club.
- Legal authorities: if required by law, regulation, or legal process.
6. Payments and Stripe Connect
JudoHQ uses Stripe to process payments. Your club may receive payouts in two ways:
- Stripe Connect (recommended): your club connects a bank account via Stripe Express onboarding in Dashboard → Settings → Payments. Members pay your club directly; Stripe handles identity verification, card processing, and payouts to your club's bank account. JudoHQ stores only a Stripe account identifier and payment status flags — not bank details.
- Legacy platform billing: until Connect is complete, some clubs may process payments via the JudoHQ platform Stripe account. Payout arrangements for legacy clubs are managed by the platform operator.
Payment-related data we process includes transaction amounts, payment status, Stripe payment identifiers, refund request reasons, and membership billing history. We retain payment audit records for as long as needed to operate the service, resolve disputes, and meet legal obligations.
Stripe is an independent data controller for payment processing. Payment data may be transferred outside the UK/EEA (including to the United States) under Stripe's safeguards. See Stripe's Privacy Policy for details. Club administrators who enable Connect also accept Stripe's Connected Account Agreement during onboarding.
7. Data storage, security and retention
Data is stored on servers that JudoHQ hosts and operates itself, located in the United Kingdom and European Economic Area. We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, row-level access controls that isolate each club's data, and regular security reviews.
International transfers. Your data is stored in the UK/EEA. It is not transferred outside the UK except in the following cases: Stripe (payments — see section 6) and Resend (email delivery), both US-based and both of which may process data in the United States; Cloudflare, whose global network carries traffic to and from the site and may handle it outside the UK; and, only where you have switched on push alerts, the push service built into your browser (Google, Mozilla, Apple or Microsoft), which receives your device's push address and the encrypted alert. These restricted transfers are safeguarded by appropriate measures under Articles 44–46 UK GDPR — the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as set out in each provider's data processing terms.
Retention. We keep personal data only for as long as necessary for the purposes described in this policy:
- Account, profile and membership data: retained while your account is active. When an account is deleted or an erasure request is completed, we delete or irreversibly anonymise your personal data. Where an account simply lapses, we retain it for up to 24 months after your last membership ends (so returning members can rejoin easily), then delete or anonymise it.
- Members deleted by a club administrator: when a club administrator deletes a member, that member's access to the club ends immediately and their personal data is permanently deleted 7 days later. During those 7 days the club can reverse the deletion — this short window exists so that a deletion made in error (for example, the wrong person picked from a list of similar names) does not destroy a member's records. Nothing is disclosed to anyone new during the window, and the data is still covered by every right described in section 8: a subject access request made in that period still returns the data, because we still hold it. This window does not apply where you ask us to erase your data — a request you make yourself (through your account settings or as an erasure request) is actioned without this delay, and a club administrator actioning your request on your behalf can also erase your data immediately.
- Club records deleted by a club administrator: when a club administrator deletes something the club manages — a training session, an announcement, a shop item, a syllabus technique, a draft event — that record is removed from the app straight away and held, unreadable to everyone, for 7 days so the club can undo a mistake. Where such a record has your personal data attached (most often the attendance register of a deleted session, or a technique sign-off), that data is held for the same 7 days and then permanently deleted. The purpose is protective: before this, deleting a session in error destroyed its whole register with no way back. During the window nothing is disclosed to anyone new, a subject access request still returns the data because we still hold it, and an erasure — yours or one made on your behalf — removes you from these held records immediately and is verified to have done so.
- Guest event entries: a guest entry is kept as part of the event's record (entry lists, draws and results) by the club that ran the event. You can ask for your entry details — including the date of birth given at entry, and the copy of it held on the draw — to be removed at any time (section 8); where the entry was paid, the underlying payment record is retained as an accounting record (next bullet) with your identifying details removed on request. The “view your entry” link in a guest confirmation email stops working 90 days after the event.
- Payment and accounting records: retained for 6 years to meet UK tax and accounting obligations (HMRC). This retention is processing under a legal obligation — Article 6(1)(c) UK GDPR — so the right to erasure does not extend to deleting these records (Article 17(3)(b)). Where you exercise erasure, they are instead retained in anonymised form: your name and email address are removed from retained invoices and credit notes, and other personal identifiers are stripped from payment records, while the financial details (amounts, dates and document numbers) are kept for the remainder of that period.
- Incident and safeguarding reports: retained in line with UK safeguarding guidance and are not deleted when an account is erased. Reports involving a child are kept at least until that person's 25th birthday; reports involving adults are kept for at least 7 years from the date of the report, then reviewed for deletion.
- Signed club agreements (risk acknowledgment): when you (or a parent/guardian on a child's behalf) e-sign a club's risk-acknowledgment and club-agreement document, we keep the signed record — the document version and its content fingerprint, the typed name, who signed and in what capacity, the date and time, and technical signing details (IP address and browser) — as evidence for the establishment, exercise or defence of legal claims (Article 6(1)(f) UK GDPR). Because claims can lawfully be brought years later (Limitation Act 1980), these records are kept for at least 7 years after your membership ends, and where the record concerns someone who signed (or was signed for) as a child, at least until that person's 21st birthday, then reviewed for deletion. The right to erasure does not extend to deleting these records (Article 17(3)(e)); on erasure the record is unlinked from your account but the signed record itself is kept for the remainder of the period.
- Judo Helper (AI) audit metadata: retained for up to 90 days for safeguarding review, then automatically deleted. Chat message bodies are never stored (see section 11).
- Club email metadata: the routing record for each message sent to a club address (sender, recipient, subject, delivery outcome — never the message body) is retained for up to 12 months, then deleted.
- Data-request records: the log of your export and erasure requests (who asked, when, and the outcome) is retained for 6 years as evidence of our UK GDPR compliance.
- Verification and password-reset tokens: stored only as a cryptographic hash and short-lived — email verification tokens expire after 24 hours and password-reset tokens after 1 hour; they are deleted once used or expired.
- Backups: the database server that holds your personal data is backed up automatically by our hosting provider (UK/EEA) on a short rolling daily cycle — each backup covers the previous 24 hours and is replaced as the cycle rotates. The application server, which holds very little personal data (short-lived security counters and operational logs), is backed up daily to a backup server on our own private infrastructure and those backups are rotated on a fixed schedule. Backups exist only for disaster recovery and are never used for any other purpose. When you exercise your right to erasure we delete your data from live systems straight away; copies in backups expire as the backup cycles above rotate, and if a backup ever had to be restored we would re-apply completed erasure requests.
- Security counters: rate-limiting and session counters are held in memory only and expire automatically within hours.
8. Your rights
Under UK GDPR, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your personal data (“right to be forgotten”). Records we are legally required to keep — invoices, credit notes and other accounting records (Article 6(1)(c) UK GDPR / HMRC rules) and safeguarding reports — are not deleted but are anonymised or retained under those legal bases, as described in section 7
- Restriction: limit how we process your data
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Withdraw consent: withdraw consent at any time where processing is based on consent
You can exercise the most common rights directly from your account: Dashboard → Profile lets you download a machine-readable copy of your data (portability) and request account deletion (erasure). Requests are logged and actioned by your club administrator through a data-request queue, subject to the retention obligations in section 7 (for example, anonymised accounting records).
If you entered an event as a guest (no account): your confirmation email contains a link to view your entry and, for competitions, to withdraw a photo or film consent — no account needed. For anything else — a copy of your details, correction, or erasure — email privacy@judohq.co.uk quoting the reference from your confirmation email (or the name, email address and event you entered, if you no longer have it).
To exercise any other right, or if you cannot access your account, contact your club administrator or email us at the address below. Exercising your rights is free of charge, and we (or your club, as controller) will respond within one calendar month of receiving your request.
If you are unhappy with how your data has been handled, you have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; helpline 0303 123 1113; ico.org.uk/make-a-complaint. We would appreciate the chance to resolve your concern first, but you can go to the ICO at any time.
10. Children's data
JudoHQ is used by clubs with junior members. Anyone under 18 cannot create their own account — the sign-up flow blocks this and directs them to a parent or guardian. A junior's record is created and managed by a parent/guardian (from Dashboard → My children) or by a club administrator, and the junior does not have their own login.
Parental or guardian consent is required before a junior's data is processed, and separately before a junior may use the Judo Helper (AI). We design the platform in line with the ICO's Age Appropriate Design Code: we collect only the minimum data needed to run the club, settings default to the highest level of privacy, and we never show advertising, profile children, use their data for marketing, track their location, or use nudge techniques to encourage them to share more data. Children's data is processed in accordance with the UK GDPR and the Data Protection Act 2018.
If you are under 18 — the short version
Your parent or guardian (or your club) looks after your judo record — things like your name, belt and which sessions you came to. We only use it to run your club. We never sell it, never show you adverts, and never share it with anyone who doesn't need it. If something worries you about your information, tell your parent, guardian, or your club's welfare officer, and they can ask us to help.
11. Judo Helper (AI)
The optional Judo Helper is an AI assistant that answers questions about official British Judo rules and club services. It is off by default until your club administrator enables it. Members (and parents/guardians for juniors) must give separate consent before use.
- What we send: your question, your grade band (not your name or contact details), and excerpts from official public documents. If you ask the helper about your own account — your kit sizes, your membership, your grading or competition fees, or your shop orders — the summary it looks up for you is also sent to the model for that answer. Before processing, we automatically remove common personal identifiers from your question — email addresses, phone numbers, dates (including dates of birth), BJA licence numbers and postcodes. This automatic filter cannot reliably detect free-text details such as names or street addresses, so please avoid typing them into the helper; anything you do type is still processed only on our own server and is not sent to any third party (see What we keep, below, for how long it stays there).
- Processing: answers are generated by a language model running on hardware that JudoHQ owns and operates in the United Kingdom — see section 1 for who we are. Your question does not leave that hardware: it is not sent to any third-party AI provider, and it is not shared with the British Judo Association. British Judo publishes the rules and syllabi the helper quotes from; it does not run this service and does not receive what you type into it.
- What we keep: chat message bodies are never written to the database. The conversation you are currently having is held in short-lived server memory for up to two hours (the last 50 turns) so the helper can follow the thread, and expires automatically after that. We keep minimal audit metadata (intent, tools used, retrieved document IDs — never the text you typed) for up to 90 days for safeguarding review, after which it is deleted automatically.
- Safeguarding: messages indicating abuse or self-harm are not sent to the AI — you receive a static response with welfare contacts.
- Your rights: you can withdraw AI consent at any time in your profile settings, or ask your club to disable the feature.
12. Changes to this policy
We may update this policy from time to time to reflect changes to the platform or the law. We will notify registered club administrators by email of any material changes before they take effect, and the “last updated” date at the top of this page will always show the current version.
13. Contact us
If you have questions about this privacy policy or wish to exercise your data rights, please contact your club administrator or email us at privacy@judohq.co.uk.