1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller, specifically the Controller's Clients and end-users.
"Special Category Data" means Personal Data revealing health, biometric, or genetic data, or data concerning physical exercise, nutrition, sleep, mood, body measurements, and progress photos, as defined in Article 9 of the GDPR.
"Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller, including infrastructure, storage, communications, and media-processing providers listed in Section 5.
"Data Subject" means the natural person whose Personal Data is processed, including Clients and Coaches.
"Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
2. Roles and Scope of Processing
The nature, purpose, and scope of processing are determined by the Service's feature set and the Controller's use of that feature set.
Nature and Purpose
The Processor provides a software infrastructure (GraphQL API, backend services, web/mobile applications) that enables the Controller to manage a fitness coaching practice. This includes role onboarding (TRAINER/CLIENT), invite-code generation, join-request management, trainer-client relationship lifecycle, versioned exercise and meal libraries, training plan and meal plan templates with assignments, workout session tracking, nutrition logging and aggregation, progress tracking, check-ins, scaling suggestions, one-off and recurring payment requests, chat messaging, notifications, user-initiated data export, and associated media processing.
Categories of Data
Identity and account data: name, email, username, bcrypt password hashes, Google OAuth identifiers, avatars, role, online/offline presence, bank account details, device tokens, and JWT/password-reset token metadata.
Communication and relationship data: invite codes, join requests (PENDING, ACCEPTED, REJECTED, CANCELLED), trainer-client relationship status, chat messages (one-to-one and group) with text, images, documents, workout/meal/payment references, read receipts, typing indicators, and presence status.
Health, biometric, and visual data: body weight, body fat percentage, muscle mass, up to fourteen body-part circumferences, progress photos (front, side, back, other), meal images, and exercise videos.
Training and workout data: training plan templates and versions, weekly workout grids, day exercises, planned sets (set number, reps range, target weight, toFailure, myoRepMatch, dropset, target RPE/RIR-style fields), client tweaks, assigned plans, workout session lifecycle, logged sets (weight, reps, toFailure, note), session feedback, and weekly activity.
Nutrition data: nutrition goals (calories, protein, carbohydrates, fat, target weight, instructions), meal library entries and versions, meal plan templates and versions, assigned meal plans, weekly slots and options, custom nutrition records, meal plan records, and daily nutrition aggregation.
Check-in and progress data: mood, energy, sleep, soreness, reminders, alerts, weight logs, bodyfat logs, musclemass logs, circumference logs, progress summary ranges and deltas.
Payment and billing data: one-off and recurring payment requests, templates, statuses (PENDING, PAID, CANCELLED, OVERDUE), manual marking events, Paddle subscription records, and scheduled overdue marking results.
System and technical data: IP addresses, FCM device tokens, Redis cache and rate-limit counters, Pino logs, Prometheus metrics, BullMQ queue metadata, ClamAV scan results, image/video/PDF processing metadata, and data export request records.
Categories of Data Subjects
The Controller's end-Clients and any other natural persons whose Personal Data the Controller uploads or causes to be processed through the Service (including, but not limited to, individuals whose progress photos or contact details the Controller adds).
Roles
The Coach is the Data Controller for all Client data. GainSync is the Data Processor, providing the software infrastructure to store and process such data exclusively on the Controller's documented instructions as embodied in the normal use of the Service.
3. Obligations of the Controller (The Coach)
The Controller guarantees and warrants that:
They have a valid legal basis under Article 6 of the GDPR to process their Clients' Personal Data, including the use of chat, notifications, and media sharing.
They have obtained explicit, affirmative, and legally valid consent from their Clients under Article 9 of the GDPR to process Special Category Data (health, biometric, body measurements, sleep, mood, soreness, and progress photos) before such data is uploaded by the Coach or the Client.
They will not use the Service to process Personal Data of individuals under 16 without verifiable parental or guardian consent.
They will ensure that Personal Data is accurate and up to date, and will notify GainSync of any errors affecting the Controller's Clients.
They are solely responsible for the content of training plans, meal plans, scaling suggestions, payment requests, chat messages, and any advice or instructions given to Clients.
Indemnification
The Controller shall fully indemnify and hold the Processor harmless from any claims, fines, damages, or regulatory actions resulting from the Controller's failure to obtain lawful consent, comply with Controller obligations under this DPA, or mishandle Client data.
4. Obligations of the Processor (GainSync)
The Processor agrees that it shall:
Process Personal Data solely on the documented instructions of the Controller, as established by the normal use of the Service, including plan assignments, session logging, nutrition logging, progress updates, check-ins, payments, chat, notifications, and data exports.
Ensure that all personnel authorized to process Personal Data have committed themselves to confidentiality.
Implement appropriate technical and organizational measures, including bcrypt password hashing, JWT access/refresh tokens, role-based guards (TRAINER/CLIENT), signed URLs for media, Redis-backed rate limiting, ClamAV scanning, image optimization, video remuxing, PDF validation, structured Pino logging, and PostgreSQL per-service databases, to protect data against unauthorized destruction, loss, alteration, or disclosure.
Not use the Controller's Personal Data for its own commercial purposes, except where data has been fully anonymized so that it can no longer be linked to an identifiable natural person.
Assist the Controller in responding to data subject requests, data protection impact assessments, and supervisory authority inquiries by providing the technical tools available in the Service.
5. Sub-processing
The Controller grants the Processor general written authorization to engage Sub-processors to fulfill its obligations. The current Sub-processors include:
PostgreSQL per service for structured data persistence; Redis for cache, pub-sub, sessions, invite codes, and rate-limiting; Supabase/S3-compatible object storage with signed URLs for media; BullMQ for job queues; Resend for transactional email; Firebase Cloud Messaging (FCM) for push notifications and device-token pruning; Paddle as Merchant of Record for Coach subscriptions; ClamAV for malware scanning; sharp and jpegtran for image optimization; ffmpeg for video remuxing; and pdf-lib for PDF validation.
The Processor shall ensure that any Sub-processor is bound by data protection obligations materially similar to those in this DPA. The Processor remains fully liable to the Controller for the performance of the Sub-processor's obligations.
6. Data Subject Requests (Client Rights)
The Controller is solely responsible for responding to requests from their Clients exercising their GDPR rights (e.g., right to access, right to erasure/deletion, right to data portability).
If the Processor receives a direct request from a Client, the Processor will, without undue delay, direct the Client to the Controller.
The Processor shall provide the Controller with the technical tools necessary to fulfill these requests, including the ability to deactivate an account (soft delete), permanently erase a Client's data, and initiate a user-initiated full data export delivered by email.
7. Personal Data Breaches
The Processor shall notify the Controller without undue delay (and no later than 48 hours) after becoming aware of a confirmed Personal Data breach affecting the Controller's data, including unauthorized access to media, databases, chat messages, or Client profiles.
The notification will include sufficient information to allow the Controller to meet any obligations to report the breach to supervisory authorities or the affected Clients.
The Processor will take commercially reasonable steps to mitigate the effects of the breach and to restore the integrity of the affected systems.
8. Return and Deletion of Data
Upon termination or expiration of the Coach's account or the ending of a trainer-client relationship, the Processor shall, at the choice of the Controller where technically feasible, delete or return all Personal Data to the Controller. Deactivation of an account triggers a soft-delete state followed by permanent eradication of Personal Data within 30 days.
The Processor will permanently erase Personal Data from production databases and object storage within 30 days of account termination, unless EU or Member State law requires continued storage of specific data (e.g., billing records). Backups are retained only for the limited period necessary for disaster recovery and are deleted in accordance with the Processor's backup retention schedule.
9. International Transfers
If the Processor or its Sub-processors transfer Personal Data outside the European Economic Area (EEA), such transfers will comply with Chapter V of the GDPR by relying on an Adequacy Decision or by using the EU Commission's Standard Contractual Clauses (SCCs) with appropriate supplementary measures.
← Back to home