BJJ Intensive Camp
Camps FAQ My Camps
ENDEIT

Data Privacy

Privacy Policy

Last updated: August 27, 2026

Protecting personal data matters to us. This Privacy Policy explains which personal data we process when you visit our website, contact us, or book a BJJ Intensive Camp.

This Privacy Policy applies to bjjintensivecamp.com and the camp information, booking forms, FAQ features, email communication, and participant administration offered through it.

1. Controller

The controller responsible for processing personal data is:

BJJ Intensive Camp
Renato Migliaccio
919 E Rte 66
Glendora, CA 91740
USA

Email: email@bjjintensivecamp.com. Website: bjjintensivecamp.com.

For organizing individual camps, BJJ Intensive Camp may involve local partners, coaches, assistants, or service providers. They receive personal data only where necessary for organization, delivery, participant administration, payment allocation, or support.

2. Privacy Contact

For privacy questions or to exercise your rights, contact us at email@bjjintensivecamp.com.

3. GDPR Scope

Although the controller is based in the United States, our offer is also directed to participants in the European Union. We therefore observe the GDPR requirements for processing personal data of people in the EU where applicable.

4. General Processing Principles

We process personal data only where necessary to operate the website, handle requests, manage camp bookings, communicate with participants, allocate bank-transfer payments, run the camps, or comply with legal duties.

We pay particular attention to data minimization, purpose limitation, transparency, and appropriate technical and organizational security measures.

5. Legal Bases

We process personal data under Art. 6(1)(b) GDPR where processing is necessary for pre-contractual steps or contract performance, especially booking requests, camp bookings, participant administration, payment information, and camp communication.

We process data under Art. 6(1)(c) GDPR where this is required to comply with legal duties, especially tax, accounting, and retention duties.

We process data under Art. 6(1)(f) GDPR where this is necessary for legitimate interests, especially secure and stable website operation, IT security, abuse prevention, internal organization, and documentation of bookings and communication.

Where we ask for consent, for example optional marketing communication or separate photo/video approval, processing is based on Art. 6(1)(a) GDPR.

6. Website Visits and Server Logs

When you access our website, technical data transmitted by your browser or device is processed to deliver the site, maintain stability and security, analyze errors, and detect misuse or attacks.

The legal basis is Art. 6(1)(f) GDPR. Server logs are stored only as long as necessary for security, error analysis, and traceability, unless longer storage is required to investigate misuse, technical incidents, or security events.

  • IP address
  • date and time of access
  • requested page or file
  • browser type and version
  • operating system
  • referrer page
  • transferred data volume
  • status messages and technical error logs

7. Contact

If you contact us by email, phone, contact form, or social media, we process the data you provide to answer your request, manage communication, and, where applicable, take pre-contractual or contractual steps.

The legal basis is Art. 6(1)(b) GDPR if your request relates to a camp booking or possible contract. For general communication, the legal basis is Art. 6(1)(f) GDPR.

  • name
  • email address
  • phone number
  • message content
  • date and communication history
  • social media profile if you contact us through a platform

8. Camp Bookings

When you book a camp or send a booking request through our website, we process the data necessary to handle and deliver your booking.

We use this data to process the booking, communicate with you, manage participant lists, allocate payments, prepare and run the camp, provide support, document booking/cancellation/payment/communication, and comply with legal duties.

The legal basis is Art. 6(1)(b) GDPR. Where statutory retention or documentation duties apply, the legal basis is Art. 6(1)(c) GDPR. For internal organization and security, Art. 6(1)(f) GDPR may also apply.

Please do not submit sensitive health data, diagnoses, or medical details in the normal booking form. If physical limitations are relevant for participation, contact us separately so we can clarify which information is actually needed.

  • first and last name
  • email address and phone number
  • country and language
  • selected camp and package
  • booking date and booking number
  • payment status and payment reference
  • voluntary messages or notes
  • booking status, for example open, paid, cancelled, or completed
  • technical proof data, for example submission time and accepted legal notices

9. Bank Transfer and Payment Allocation

In the current minimal setup, payment is made by bank transfer to the stated IBAN. We do not store credit card data and do not use an external online payment provider such as PayPal, Stripe, Mollie, or Apple Pay for this payment process.

Payment itself is processed by the banks involved. Banks process payment data under their own responsibility and applicable legal requirements.

Where a local organizational partner or payee in Austria or another country is involved, they receive only the information required for payment allocation, booking administration, and camp organization.

The legal basis is Art. 6(1)(b) GDPR for booking performance and Art. 6(1)(c) GDPR for accounting and tax duties.

  • booking number
  • payment reference or purpose
  • payment status
  • amount and payment receipt date
  • account holder name where visible from the payment receipt
  • internal payment notes

10. Booking Confirmations and Email Communication

We send emails related to your booking. These emails are required to process your booking and run the camp; they are not marketing emails.

Technical email service providers or SMTP providers may be used. Recipient address, subject, email content, and technical delivery data may be processed.

The legal basis is Art. 6(1)(b) GDPR. Art. 6(1)(f) GDPR also applies to technical delivery security and traceability.

  • receipt confirmation and booking confirmation
  • payment information, reminders, and confirmations
  • organizational camp information and changes
  • cancellation or rebooking information
  • support communication

11. My Camps Area and Private Access Links

After a booking, a private access link or token may be created so you can access information about your booking and camp.

The private access link is personal and should not be shared with other people.

The legal basis is Art. 6(1)(b) GDPR because the function serves booking delivery and administration. Art. 6(1)(f) GDPR also applies to security and abuse prevention.

  • booking number
  • access token
  • camp and participant data
  • booking and payment status
  • technical access data for security

12. Admin Area and Internal Administration

Bookings are managed internally through a protected admin area. Authorized people can view bookings, update payment status, resend booking confirmations, manage cancellations, edit camp data, and create CSV exports for organization or accounting.

Only people who need this information for organization, delivery, support, or billing are involved.

The legal bases are Art. 6(1)(b), Art. 6(1)(c), and Art. 6(1)(f) GDPR.

13. FAQ, Search, and Chat

Our website may offer FAQ search or a chat feature. Your entered questions are processed to provide relevant information about camps, booking, travel, payment, schedule, or organization.

For security, abuse prevention, troubleshooting, and conversation continuity, we log the questions and assistant answers together with a random chat-session identifier, timestamps, the selected website language, relevant camp context, the IP address, and the browser user agent. These logs are visible only in the protected admin area and are automatically deleted after 90 days.

When the AI chat is enabled, your current question and a limited recent chat history are sent to OpenAI for the sole purpose of generating a grounded answer from our camp knowledge. We do not intentionally send booking records, contact details, or payment data to OpenAI through the chat.

Please do not enter sensitive data, health data, payment data, or confidential information into the chat.

The integration asks the OpenAI Responses API not to store response application state. According to OpenAI's API data controls, API data is not used to train its models unless the customer explicitly opts in; standard abuse-monitoring logs may nevertheless retain prompts and responses for up to 30 days unless stricter account-level retention controls apply.

The legal basis is Art. 6(1)(f) GDPR. If your request directly relates to a booking, Art. 6(1)(b) GDPR may also apply. Processing by service providers in the United States is also addressed in section 20.

14. Photos, Videos, Testimonials, and Media

Photos, videos, or testimonials may be created in connection with camps. Publication of recognizable photos, videos, or testimonials occurs only where an appropriate legal basis exists, especially consent or separate approval.

If you voluntarily provide a testimonial, photo, video, or other content, we process it for the stated purpose.

You can withdraw consent at any time with effect for the future. Processing that was lawful before withdrawal remains unaffected.

The legal basis is Art. 6(1)(a) GDPR where consent is obtained. In individual cases, Art. 6(1)(f) GDPR may apply where processing is based on legitimate interests and no overriding interests of the data subject exist.

15. Cookies and Similar Technologies

In the current minimal setup, our website uses only technically necessary cookies or comparable storage technologies. They are required for secure and reliable website operation and are not used for marketing, retargeting, or tracking.

The legal basis is Art. 6(1)(f) GDPR.

In the current minimal setup, we do not use cookies for Google Analytics, Meta Pixel, retargeting, or comparable tracking or marketing purposes.

If analytics, marketing, or third-party cookies are used later, we will obtain the required consent beforehand and update this Privacy Policy.

  • language setting
  • admin session
  • security functions
  • technical form functions
  • access protection for protected areas

16. No Google Analytics, Meta Pixel, or External Tracking in the Minimal Setup

In the current minimal setup, we do not use external tracking tools such as Google Analytics, Meta Pixel, TikTok Pixel, or comparable advertising and analytics tools. If such services are used later, they will not be activated without corresponding information and, where required, prior consent.

17. No WordPress, WooCommerce, or reCAPTCHA in the New System

This website is not operated with WordPress or WooCommerce in the current system. Booking forms are processed directly through our own website.

In the current minimal setup, we do not use Google reCAPTCHA. If external spam or bot protection services are used later, this Privacy Policy will be updated accordingly.

18. Hosting, Database, and Technical Infrastructure

Our website is operated on servers of technical hosting and IT service providers. Technical access data, website data, database contents, booking data, uploads, and backups may be processed where necessary for operation, security, maintenance, and availability.

The website uses a local database to store camp, booking, FAQ, settings, and administration data. Uploads, for example camp images or website media, may be stored in the file system.

Technical service providers process personal data only where required for their service.

The legal bases are Art. 6(1)(b) GDPR for booking performance, Art. 6(1)(c) GDPR for legal duties, and Art. 6(1)(f) GDPR for secure and stable website operation.

19. Recipients of Personal Data

Personal data may be transmitted to the following categories of recipients where necessary. Personal data is not sold or passed on for advertising purposes.

  • hosting and IT service providers
  • email and SMTP service providers
  • banks and payment institutions for bank transfers
  • local organizational partners, coaches, or camp assistants
  • accounting, tax advisory, or commercial service providers
  • technical maintenance and security providers
  • authorities, courts, or public bodies where legally required
  • authorized internal people involved in organizing and running camps

20. Processing in the United States and Other Third Countries

The controller is based in the United States. Personal data may therefore also be processed in or accessed from the United States.

From a GDPR perspective, the United States is a third country outside the European Union and the European Economic Area. Where personal data is transferred to service providers, partners, or recipients in the United States or other third countries, this occurs only where an appropriate legal basis or data protection mechanism exists.

This may include an adequacy decision, certification under a recognized data privacy framework, standard contractual clauses, or another basis permitted under the GDPR. We limit such transfers to what is necessary.

21. Social Media Profiles and External Links

We maintain profiles on social media platforms, especially Facebook, Instagram, and YouTube. If you visit our profiles there or communicate with us through those platforms, personal data may be processed by the platform operators.

The privacy information of the respective providers also applies. We do not have full influence over processing by these platforms.

Our website may also contain links to external websites. The respective operators are responsible for content and data processing on external websites.

22. Newsletter and Marketing Communication

In the current minimal setup, we do not send newsletters or automated marketing communication without separate consent.

If you voluntarily subscribe to camp news, offers, or marketing emails in the future, we process your email address and, where applicable, your name based on consent under Art. 6(1)(a) GDPR. You can withdraw consent at any time with effect for the future.

Booking-related emails, for example payment information or organizational camp notices, are not marketing emails and are sent based on the booking.

23. Special Categories of Personal Data

Please do not submit special categories of personal data in the normal booking form. This includes health data, diagnoses, injury details, religious or political information, and comparable sensitive information.

If processing special data is required in an individual case, this occurs only on an appropriate legal basis and only to the necessary extent.

24. Minors

Our camps and services are generally directed to adults. If minors may participate in a camp, this occurs only under the applicable participation terms and, where required, with consent of a legal guardian.

We do not knowingly collect personal data from children or young people unless this is required for a specific participation and legally permitted.

25. Retention Period

We store personal data only as long as necessary for the respective purposes.

Requests are stored as long as necessary for handling and traceability. Booking data is stored for the duration of the booking and beyond where required for evidence, support, cancellation, payment allocation, accounting, or legal duties.

Payment and accounting-relevant data is stored under statutory retention periods, which may amount to several years for accounting documents, receipts, and invoices.

Technical logs are generally stored only short-term unless longer storage is required for security, error analysis, or investigation of misuse.

Data processed based on consent is stored until withdrawal or until the purpose ceases. After expiry of the respective periods, personal data is deleted or anonymized unless legal duties or legitimate reasons require further storage.

26. Security

We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration, or disclosure. No digital processing can be completely risk-free.

  • protected admin access
  • access restrictions
  • secure server configuration
  • encrypted transmission where technically provided
  • regular backups of relevant data
  • limiting access to necessary people
  • rate limits and abuse protection
  • technical separation of public and administrative areas

27. Your Rights

Under the GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability, objection to processing based on Art. 6(1)(f) GDPR, withdrawal of consent with effect for the future, and the right not to be subject to solely automated decisions with legal or similarly significant effects.

To exercise your rights, contact us at email@bjjintensivecamp.com.

28. Right to Lodge a Complaint

If you believe that the processing of your personal data violates data protection law, you may lodge a complaint with a data protection supervisory authority.

For people in Austria, the relevant authority is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria, email: dsb@dsb.gv.at.

You may also contact another competent data protection supervisory authority in the EU.

29. No Automated Decision-Making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

30. Changes to this Privacy Policy

We may update this Privacy Policy if our website, data processing, technical service providers, or legal requirements change. The current version published on the website applies.

BJJ Intensive Camp

Train with experienced coaches, share the mats with an international community, and enjoy unforgettable BJJ camps on and off the mats.

Contact

email@bjjintensivecamp.com

Privacy Policy Cookie Policy
Camp Assistant Ask about camps, booking, pricing, levels...

Hi! Ask me anything about BJJ Intensive Camp, from dates and availability to accommodation, training levels, and booking.