Personal Data Protection (GDPR)

Last updated: March 2026. Compliant with Regulation (EU) 2016/679 and the Belgian Law of July 30, 2018

1. Data Controller

The controller for the processing of personal data is:

As a small-scale sports club, Dynamis Taekwon-Do is not required to appoint a mandatory Data Protection Officer (DPO). The data controller directly assumes these responsibilities.

2. Collected Data and Purposes

We collect and process the following personal data, for two distinct purposes:

Purpose Collected Data Legal Basis (GDPR)
Contact Form Last name, first name, email address, message Legitimate interest (Art. 6.1.f)
Member Area Member number (assigned by the club manager), last name, first name, rank, subscription type, registration date Performance of a contract (Art. 6.1.b)
Internal Messaging (Member Area) Content of messages exchanged with the instructor Performance of a contract (Art. 6.1.b)
Connection Status Online/offline status, date of last activity Legitimate interest (Art. 6.1.f)
Site Audience Measurement Anonymized navigation data (Google Analytics) Consent (Art. 6.1.a)

Member Area: The member number is manually assigned by the club manager upon registration — you cannot choose it yourself. Authentication is based on this number, your first name, and your last name. These details are verified server-side via a secure session (HTTP-only session cookie). No password is stored. Member area data is strictly used to provide you access to your personal documents and grading videos.

Privacy by Design: This site was built applying the principle of data minimization (Art. 5.1.c GDPR). Only the data strictly necessary for each purpose is collected. No automated profiling, no automated decision-making (Art. 22 GDPR), and no processing for marketing purposes are carried out.

3. Consent and Legal Basis

Each processing activity is based on a distinct legal basis, in accordance with Art. 6 of the GDPR:

4. Retention Period

5. Data Security & Breach Notification

We implement the appropriate technical measures to protect your data:

Notification in the event of a data breach (Art. 33 GDPR): Should a personal data breach occur that is likely to result in a risk to your rights and freedoms, Dynamis Taekwon-Do commits to notifying the Belgian Data Protection Authority (DPA) within 72 hours of becoming aware of the incident. If the breach is likely to result in a high risk, the data subjects will also be informed without delay (Art. 34 GDPR).

6. Your Rights (Belgian Law of July 30, 2018)

In accordance with the GDPR and the Belgian Law of July 30, 2018, you have the following rights:

Right GDPR Article What this means
Access Art. 15 Obtain a copy of your data
Rectification Art. 16 Have inaccurate data corrected
Erasure Art. 17 Request the deletion of your data
Restriction Art. 18 Temporarily restrict processing
Objection Art. 21 Object to processing based on legitimate interest
Portability Art. 20 Receive your data in a structured, commonly used and machine-readable format (e.g. CSV)
Refusal of automated profiling Art. 22 No automated decision-making or profiling is performed on this site

To exercise these rights, contact us at: dynamis.taekwondo@gmail.com. We will respond within one month (GDPR legal timeframe). For complex requests, this period may be extended by two further months, with prior notification.

7. Cookies

8. Processing via Third-Party Services

OVHcloud (website host)

The website and Member Area data are hosted by OVH SAS, a French company whose servers are located in the European Union (France). OVH is subject to European data protection law.
Headquarters: 2 rue Kellermann, 59100 Roubaix, France.
OVH Privacy Policy: ovhcloud.com/en/personal-data-protection

Google LLC (Google Maps)

The map embedded on the Info page is provided by Google Maps (Google LLC, United States). Google may collect browsing data via third-party cookies. Privacy Policy: policies.google.com/privacy

Google LLC (Google Analytics)

Used to measure site traffic. Privacy Policy: policies.google.com/privacy

9. Data Transfers Outside the EU

Member Area data is hosted by OVHcloud in France and does not leave the European Union.

The following services involve data transfers outside the EU, framed by appropriate safeguards:

10. Complaints to the Supervisory Authority

If you believe your rights are not being respected, you may lodge a complaint with the Data Protection Authority (DPA), the Belgian supervisory authority:

We do, however, encourage you to contact us first at dynamis.taekwondo@gmail.com so we can resolve any issues amicably.

← Back to website