Legal
Privacy Policy
What we collect, what we only hold on someone else’s behalf, and who to ask about which.
The short version
- This website sets no cookies, runs no analytics and carries no advertising trackers.
- If you fill in our form, we use your details to reply to you.
- We never sell personal data, and we do not use it to train anything.
- Records about members of a business belong to that business. We hold them on its instructions. If you are a member or a parent, ask that business — not us.
Two different situations
Nearly every question about this policy has two answers depending on which situation applies, so it is worth separating them up front.
We decide (we are the “controller”). When you browse this website, contact us, or subscribe as a customer, we decide what is collected and why. This policy governs it, and you come to us.
A business decides (we are the “processor”). When a gym, studio or club uses Black Belt CRM, the records they keep about their members are theirs. They decide what to collect and why; we store and handle it on their instructions. Their own privacy notice governs it, and a member or parent should approach them.
When you visit this website
Our host records ordinary technical information needed to serve pages and keep the site secure — IP address, browser type, page requested, and the time. This is standard server logging, kept only as long as it is useful for security and for keeping the site running, and not used to build a profile of you.
If you fill in our contact form, we collect your name, business name, email address, phone number, anything you write, and whether you ticked the boxes agreeing to be contacted by email or text. We use it to answer you and, if you agreed, to send information about the product. Consent boxes are never pre-ticked, and the time you gave consent is recorded so permission can be shown rather than assumed. You can withdraw it at any time by replying to any message or emailing us.
Our lawful basis is your consent for marketing messages, and our legitimate interest in responding to an enquiry you chose to send.
How we know which campaign brought you
If you arrive from an advertisement or a tagged link, the tags in the address — and the click identifier that Google, Meta or Microsoft adds — are stored in your browser for the rest of the visit, and attached if you later submit the form. It tells us which campaign produced an enquiry.
It is kept in session storage, not a cookie. It contains no information about you, is never shared, is not readable by another site, and is erased when you close the tab. If you never submit the form, it never reaches us at all.
Cookies and tracking
This website sets no cookies. There is no analytics package, no advertising pixel, no social plugin and no session cookie. Our fonts are served from our own domain rather than a font network, so no third party sees your visit.
The one exception is the contact page, which loads the form itself from our application at app.blackbeltcrm.com. That request is to us, not to a third party, and the form sets no cookie either.
Do Not Track and Global Privacy Control. Some browsers send a signal asking not to be tracked or not to have personal information sold or shared. We do not track you across sites and do not sell or share personal information in the first place, so there is nothing for the signal to switch off — but if we ever did any of that, we would honour it.
Links to other sites. Where we link somewhere else, that site has its own privacy practices and we are not responsible for them.
Because we set nothing that is not strictly necessary, there is no consent banner to click. If that changes, we will ask properly before setting anything, rather than treating your visit as agreement.
When you are a customer
If you subscribe, we hold your business details, the contact details of the people who use the service, your subscription and billing history, and records of support you have asked for.
Payments. Card details are entered into and held by our payment provider, not by us. We keep the last four digits and the card type so you can tell which card is on file, and the record of what was charged and when. Anexan bills your subscription and appears on your statement.
We use this to provide the service, take payment, give support, and send service messages such as billing notices and security notices. Service messages are not marketing and cannot be opted out of while you hold an account.
Member data we hold for a business
A business using Black Belt CRM records information about its members — names, contact details, dates of birth, family relationships, attendance, progress and grading, and payment history. Some of it concerns children.
We hold it on that business’s behalf and act on its instructions. We do not decide what is collected, we do not use it for our own purposes, we do not sell it, we do not share it with other customers, and we do not use it to train anything. We produce aggregated statistics about how the service is used, in a form that identifies nobody.
If you are a member or a parent and want to see, correct or delete a record, contact the business directly — they hold the relationship and control the record. If you contact us, we will refer you to them and let them know, because acting on their data without their instruction is exactly what we promise them we will not do.
Children
Many members of a membership business are children, so we set out plainly who is responsible for what.
Black Belt CRM is sold to businesses, and children are not users of it. They have no accounts, they do not sign in, and they never give us anything directly. A child’s record exists because the business they attend entered it while running that business.
That business decides what is recorded and why, and holds the relationship with the family. It is responsible for obtaining whatever permission the law where it operates requires, and for telling its own members how it handles their information. We hold the records on its instructions and for no other purpose.
We do not contact members, do not market to them, and do not use their records for anything except providing the service to the business.
If you are a parent with a question about your child’s record — what is held, correcting it, deleting it — speak to the business your child attends. It is their record and their decision to act on. If you contact us, we will refer you to them and let them know you asked.
Who else sees data
We never sell personal data. We share it only with:
- A text message provider, which delivers SMS sent through the service.
- A mail provider, which delivers email sent through the service.
- A hosting provider, which operates the servers the service runs on.
- A payment provider, which processes the subscription payments you make to us.
- Authorities, where the law requires it. Where we are permitted to tell the affected customer first, we will.
- A buyer, if the business is sold or merged — on notice, and subject to this policy.
Each works under a contract limiting them to providing that service to us. If you are a customer and need them named — for your own compliance records, or before you sign — ask and we will send you the current list.
About email from a business to its members. All of it is sent by us on that business’s behalf, through our mail relay. The business’s name appears as the sender, so it reads as mail from them, but the sending address is ours. That is deliberate: a mail server can only vouch for a domain it is authorised to sign for, and sending from a free personal address would fail authentication checks and land the message in spam.
Replies do not come to us. Every message carries the business’s own address as its reply address, so when a member replies it goes straight to that business’s own inbox and never passes through our systems. The only exception is a business that has given us no address of its own, in which case replies reach our support team.
Payments a business takes from its own members run through that business’s own merchant account and payment provider, not ours. Our payment provider handles only what you pay us.
Where a business is part of a franchise, its franchisor may be given access to relevant records under an agreement between them. That is the business’s arrangement, not ours.
Where data is held
The service runs in the United States, and our providers are named in the section above. A current list is available on request.
If you are in the United Kingdom or the European Economic Area, your data is transferred outside your region. We use the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK applies, as the legal mechanism. We rely on those clauses rather than on an adequacy decision alone, because arrangements between the EU and the US have twice been struck down and the current one is under appeal.
How we protect it
Traffic between your browser and this website, and between your browser and the application, is encrypted in transit using TLS. Access is limited to people who need it, each with their own credentials.
Email is different, and we would rather say so than imply otherwise. Once a message leaves us it travels between mail servers, and how it is protected on the rest of that journey depends on the receiving provider rather than on us. That is true of all email, not only ours. Treat email as you would a postcard: fine for a class reminder or a receipt, and not the place for anything sensitive.
We take backups so that data can be restored, and we review who has access. We deliberately do not list specific security measures here: a public page is the wrong place to publish the details of how a system is defended, and a claim on a website is worth nothing to you anyway. If you are evaluating us and need specifics, ask and we will answer directly.
If a breach affects personal data we hold for a customer, we tell that customer without undue delay so they can meet their own obligations, which in the UK and EU means notifying their regulator within 72 hours where the breach is reportable.
How long we keep it
- Enquiries: kept while we are following up and afterwards as a record of the enquiry and of any consent you gave. Ask us and we will delete yours.
- Member and account data: kept while the subscription runs, then for up to 90 days after it ends so an account can be restored if the business returns, and deleted after that. It is deleted sooner whenever the business asks. Backups are overwritten on their ordinary cycle, so data may persist in a backup briefly after deletion.
- Financial records — invoices, payments, what was charged and collected: kept for as long as tax, accounting and limitation law requires, which is longer than 90 days. These are our own books. They do not include the member roster, which is deleted on the schedule above.
- Consent records: kept while consent is relied on, and afterwards as evidence that it was given.
You can export your own data as CSV or Excel files at any time while your subscription is active. Do it before access ends — export is self-service.
Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, correct it, delete it, get a portable copy, object to or restrict how we use it, and withdraw consent. You will never be treated differently for exercising these rights.
In the UK and EU these come from the GDPR, and you may also complain to your data protection authority — the ICO in the UK.
In California the CCPA as amended gives you rights to know, delete, correct and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not process it for targeted advertising. Other US states give similar rights and we apply the same process to all of them.
To exercise any of these, email info@anexan.com. We respond within the time the applicable law allows, and may need to verify your identity first.
If your request concerns a record held by a business that uses Black Belt CRM, we will pass you to them, because it is their record to act on.
Changes to this policy
We update this policy as the service and the law change. The date at the top always reflects the current version. Where a change materially affects you, we will tell customers by email or in the application before it takes effect.
Contact
Anexan Solutions, Inc.
Florida, USA
info@anexan.com
The terms governing use of the service are in ourTerms of Service. This policy covershttps://blackbeltcrm.com and the Black Belt CRM application.