Privacy Policy
Last updated: 29 July 2026
Effective date: 29 July 2026
Welcome to Arisecore Taiji Academy (“we”, “us”, “our”, “the Site”). We take your privacy and the security of personal information seriously. This Privacy Policy applies when you use our websites (including arisecore.org, arisecoretaiji.com, datongtaiji.com and related subdomains), use our training-analysis tools, purchase courses/services, or otherwise interact with us.
For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we process personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and applicable local laws.
1. Data Controller & Contact
Under the GDPR, the data controller for your personal data is:
Brand name
Arisecore Taiji Academy
Legal entity
Datong Tai Chi Academy Ltd.
Registered address
Saskatchewan, Canada
Privacy contact email
Contact for privacy matters
If you have questions, comments, or rights requests about this Privacy Policy or our processing of personal data, please contact us at the email above.
2. Data We Collect & Purposes
We follow data minimisation and collect/process personal data only as needed for the purposes below:
Account & identity
Content: email address, login credentials provided via our authentication stack, account nickname. Purposes: create and manage your account, verify identity, provide service access and customer support.
Transactions & subscriptions
Content: purchase records, course-pack / live viewing access status, order identifiers (e.g. Stripe transaction IDs). Purposes: perform contracts, grant access, financial reconciliation, and legal accounting/audit requirements.
Pose & telemetry (training analysis)
Self-practice (IMU / MediaPipe): sensor data and motion imagery are processed on your device (on-device) for real-time analysis. Raw video and real-time sensor streams are not uploaded to our servers. We only receive and store conclusive metrics produced on-device (e.g. completion indicators, training metrics and scores) to record your personal training history. Workshop / coach-led analysis (YOLO pose): training video and process data may be temporarily transferred to cloud storage for batch evaluation. After evaluation, original video and intermediate process data are automatically and permanently deleted within 7 days; only final posture-evaluation conclusions and training reports are retained in the backend.
Workshop & event registration
Content: contact details and basic information submitted in registration forms. Purposes: organise, schedule and notify online/offline workshops and events.
Interviews & media
Content: video, photos or interview records that may include your likeness or voice. Purposes: brand communication and teaching display — published only after we obtain your clear authorisation.
Technical & operations logs
Content: IP address, browser type, OS, access time, pages visited, crash logs. Purposes: network security, fraud prevention, diagnosing failures and improving experience.
3. Legal Bases (GDPR Art. 6)
Contract (Art. 6(1)(b))
Account data, payment records, course access and training reports needed to deliver purchased courses or teaching services.
Legitimate interests (Art. 6(1)(f))
System logs and essential cookies for operations, security, fraud prevention and service quality.
Consent (Art. 6(1)(a))
Publishing interview/media containing your likeness, or sending non-essential marketing. You may withdraw consent at any time.
Legal obligation (Art. 6(1)(c))
Retaining transaction and financial records as required by tax and accounting laws.
4. Payments & Processors
Card and online payments are processed by Stripe. We do not store, transmit or process full card numbers or CVV on our own servers. Stripe processes payment data under its privacy policy. We receive only status, identifiers and confirmations needed to grant access. Trusted processors (data processors) may include Cloudflare (Cloudflare R2) for temporary encrypted storage of workshop YOLO-pose evaluation video (≤ 7 days, then deleted with process data), and infrastructure/identity providers for account security and stable storage. Processors are bound by DPAs and may process data only on our instructions.
5. International Transfers
Our operations and servers may be outside the EEA (e.g. Canada). When personal data is transferred outside the EEA, we use appropriate GDPR safeguards: Canada’s EU adequacy decision where applicable; otherwise Standard Contractual Clauses (SCCs) or other lawful mechanisms.
6. Cookies & Local Storage
We use essential cookies and local storage (e.g. session cookie arise_sid) for core features: login sessions, language preference and theme. These are strictly necessary. If we later introduce non-essential analytics or tracking cookies, we will seek clear consent (e.g. via a cookie banner).
7. Retention
Workshop raw video & pose process data
Up to 7 days. After batch analysis completes or the 7-day limit is reached, original video and intermediate data are permanently deleted; only final reports without raw sensitive imagery are kept.
Training conclusions & reports
While your account remains active, so you can review history.
Account data
While your account remains active; upon deletion we delete or anonymise unless law requires otherwise.
Transaction & tax records
As required by law (often 6–7 years).
Logs
Typically no more than 90–180 days.
8. Your GDPR Rights (EEA users)
If you are in the EU/EEA you may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights related to automated decision-making. Our AI pose analysis is assistive teaching feedback only and is not automated decision-making with legal or similarly significant effects. To exercise rights, email [email protected]. We may verify identity and aim to respond within one month as required by GDPR.
9. Complaints to a Supervisory Authority
If you believe our processing violates the GDPR, you may lodge a complaint with a Data Protection Authority in your place of residence, work, or alleged infringement.
10. Minors
Our site and courses are primarily for adults. We do not knowingly collect personal data from children under 16 (or the lower age required by local law). If we learn we collected such data without guardian consent, we will take steps to delete it.
11. Changes
We may update this Policy to reflect services (e.g. new AI training features) or law. Updates will be posted here with a new “Last updated” date. For material changes we may notify via site notice or email.
12. Contact Us
Brand
Arisecore Taiji Academy
Email
Websites
arisecore.org / arisecoretaiji.com / datongtaiji.com