Privacy Policy

Last updated: 29 July 2026

Effective date: 29 July 2026

Welcome to Arisecore Taiji Academy (“we”, “us”, “our”, “the Site”). We take your privacy and the security of personal information seriously. This Privacy Policy applies when you use our websites (including arisecore.org, arisecoretaiji.com, datongtaiji.com and related subdomains), use our training-analysis tools, purchase courses/services, or otherwise interact with us.

For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we process personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and applicable local laws.

1. Data Controller & Contact

Under the GDPR, the data controller for your personal data is:

  • Brand name

    Arisecore Taiji Academy

  • Legal entity

    Datong Tai Chi Academy Ltd.

  • Registered address

    Saskatchewan, Canada

  • Privacy contact email

    [email protected]

Contact for privacy matters

If you have questions, comments, or rights requests about this Privacy Policy or our processing of personal data, please contact us at the email above.

2. Data We Collect & Purposes

We follow data minimisation and collect/process personal data only as needed for the purposes below:

  • Account & identity

    Content: email address, login credentials provided via our authentication stack, account nickname. Purposes: create and manage your account, verify identity, provide service access and customer support.

  • Transactions & subscriptions

    Content: purchase records, course-pack / live viewing access status, order identifiers (e.g. Stripe transaction IDs). Purposes: perform contracts, grant access, financial reconciliation, and legal accounting/audit requirements.

  • Pose & telemetry (training analysis)

    Self-practice (IMU / MediaPipe): sensor data and motion imagery are processed on your device (on-device) for real-time analysis. Raw video and real-time sensor streams are not uploaded to our servers. We only receive and store conclusive metrics produced on-device (e.g. completion indicators, training metrics and scores) to record your personal training history. Workshop / coach-led analysis (YOLO pose): training video and process data may be temporarily transferred to cloud storage for batch evaluation. After evaluation, original video and intermediate process data are automatically and permanently deleted within 7 days; only final posture-evaluation conclusions and training reports are retained in the backend.

  • Workshop & event registration

    Content: contact details and basic information submitted in registration forms. Purposes: organise, schedule and notify online/offline workshops and events.

  • Interviews & media

    Content: video, photos or interview records that may include your likeness or voice. Purposes: brand communication and teaching display — published only after we obtain your clear authorisation.

  • Technical & operations logs

    Content: IP address, browser type, OS, access time, pages visited, crash logs. Purposes: network security, fraud prevention, diagnosing failures and improving experience.

3. Legal Bases (GDPR Art. 6)

  • Contract (Art. 6(1)(b))

    Account data, payment records, course access and training reports needed to deliver purchased courses or teaching services.

  • Legitimate interests (Art. 6(1)(f))

    System logs and essential cookies for operations, security, fraud prevention and service quality.

  • Consent (Art. 6(1)(a))

    Publishing interview/media containing your likeness, or sending non-essential marketing. You may withdraw consent at any time.

  • Legal obligation (Art. 6(1)(c))

    Retaining transaction and financial records as required by tax and accounting laws.

4. Payments & Processors

Card and online payments are processed by Stripe. We do not store, transmit or process full card numbers or CVV on our own servers. Stripe processes payment data under its privacy policy. We receive only status, identifiers and confirmations needed to grant access. Trusted processors (data processors) may include Cloudflare (Cloudflare R2) for temporary encrypted storage of workshop YOLO-pose evaluation video (≤ 7 days, then deleted with process data), and infrastructure/identity providers for account security and stable storage. Processors are bound by DPAs and may process data only on our instructions.

5. International Transfers

Our operations and servers may be outside the EEA (e.g. Canada). When personal data is transferred outside the EEA, we use appropriate GDPR safeguards: Canada’s EU adequacy decision where applicable; otherwise Standard Contractual Clauses (SCCs) or other lawful mechanisms.

6. Cookies & Local Storage

We use essential cookies and local storage (e.g. session cookie arise_sid) for core features: login sessions, language preference and theme. These are strictly necessary. If we later introduce non-essential analytics or tracking cookies, we will seek clear consent (e.g. via a cookie banner).

7. Retention

  • Workshop raw video & pose process data

    Up to 7 days. After batch analysis completes or the 7-day limit is reached, original video and intermediate data are permanently deleted; only final reports without raw sensitive imagery are kept.

  • Training conclusions & reports

    While your account remains active, so you can review history.

  • Account data

    While your account remains active; upon deletion we delete or anonymise unless law requires otherwise.

  • Transaction & tax records

    As required by law (often 6–7 years).

  • Logs

    Typically no more than 90–180 days.

8. Your GDPR Rights (EEA users)

If you are in the EU/EEA you may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights related to automated decision-making. Our AI pose analysis is assistive teaching feedback only and is not automated decision-making with legal or similarly significant effects. To exercise rights, email [email protected]. We may verify identity and aim to respond within one month as required by GDPR.

9. Complaints to a Supervisory Authority

If you believe our processing violates the GDPR, you may lodge a complaint with a Data Protection Authority in your place of residence, work, or alleged infringement.

10. Minors

Our site and courses are primarily for adults. We do not knowingly collect personal data from children under 16 (or the lower age required by local law). If we learn we collected such data without guardian consent, we will take steps to delete it.

11. Changes

We may update this Policy to reflect services (e.g. new AI training features) or law. Updates will be posted here with a new “Last updated” date. For material changes we may notify via site notice or email.

12. Contact Us

  • Brand

    Arisecore Taiji Academy

  • Email

    [email protected]

  • Websites

    arisecore.org / arisecoretaiji.com / datongtaiji.com