Data Processing Addendum (DPA)
This DPA forms part of the EazyFit Terms where an individual PT or PT business is a controller and EazyFit processes personal data on that controller's behalf. It is intended to supply the core processor terms required by UK GDPR Article 28.
EazyFit operator
1. Parties and scope
The individual PT or PT business using EazyFit is the Controller and the EazyFit legal operator is the Processor for Customer Personal Data processed to provide EazyFit. This DPA lasts for the period EazyFit processes that data on the Controller's behalf.
Subject matter and purpose: hosting and operating coaching/client-management functionality, including programmes, optional nutrition/progress records, private PT-client messages, appointments, files, payments metadata, support and related service operations as instructed through use of the platform. The Controller—not EazyFit—decides which coaching information it asks its clients to provide.
2. Data subjects and data types
Data subjects may include the PT's clients, prospective clients and the PT account holder. Data can include identity/contact data, account identifiers, coaching records, messages, progress/media, nutrition/fitness information, appointment data, payment references and health-related/special-category information entered into the service.
3. Controller instructions and obligations
Processor will process Customer Personal Data only on documented instructions from Controller, including instructions inherent in configured use of EazyFit, unless UK law requires otherwise. Controller is responsible for the lawfulness of its instructions, transparency to data subjects, lawful bases, special-category conditions, data minimisation and accuracy.
Controller must not use EazyFit as a clinical record repository or instruct clients to upload medical records, diagnostic reports, medication lists, laboratory/test results or treatment histories. If a client voluntarily sends sensitive information in a coaching message, Controller is responsible for deciding whether it is necessary and lawful to retain/use, for responding within professional scope, and for taking appropriate deletion/restriction action where required.
4. Confidentiality and security
Processor will ensure persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and will implement technical and organisational measures appropriate to the risk, including access controls and service security measures.
5. Subprocessors
Controller gives general written authorisation for subprocessors needed to provide EazyFit. Processor remains responsible for imposing materially equivalent data-protection obligations on subprocessors as required by UK GDPR. The current subprocessor/service list is maintained on the Subprocessors & transfers page.
Where required, material additions or replacements will be communicated through an appropriate service/account notice and the updated list, giving the Controller an opportunity to raise reasonable data-protection objections before the relevant change where the contract or law requires that opportunity.
6. Data-subject rights and compliance assistance
Taking account of the nature of processing, Processor will provide reasonable assistance for Controller to respond to data-subject rights requests and, where required, with security obligations, breach assessments/notifications, DPIAs and regulatory consultations.
7. Personal-data breaches
Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide information reasonably available to support Controller's assessment and notification obligations.
8. International transfers
Processor will not make a restricted transfer of Customer Personal Data without a lawful transfer mechanism where UK transfer rules require one. Applicable subprocessors may use adequacy arrangements, the UK IDTA/Addendum or another lawful safeguard, with required risk assessment measures.
9. End of service
At Controller's choice and subject to product functionality, Processor will delete or return Customer Personal Data after the services end and delete existing copies, unless applicable law requires continued storage. Operational backups may be overwritten on the normal secure backup lifecycle.
10. Information and audits
Processor will make available information reasonably necessary to demonstrate compliance with Article 28 obligations and permit reasonable audits or inspections subject to appropriate confidentiality, security, scope, timing and cost controls. Processor will inform Controller if an instruction, in its reasonable view, infringes applicable data protection law.
11. Priority
If this DPA conflicts with the general Terms on processing Customer Personal Data, this DPA prevails for that processing. Mandatory data-protection law prevails over both.