Start your 14-day free trial — no credit card required.

    Data Processing Agreement

    The Article 28 agreement between you as controller and FitFloww as processor. It applies to every account automatically — there is nothing to sign.

    Last updated: August 18, 2026

    1. It already applies to you

    This agreement takes effect for every FitFloww account from August 18, 2026. You do not need to request, negotiate, or countersign it. It forms part of the Terms of Service.

    If your organisation needs a signed copy for its records, email legal@fitflowwcrm.com and we will execute one.

    Who is who

    You are the controller of the personal data you store about your clients: you decide what is collected and why. FitFloww is the processor: we act on your instructions. For your own coach account and billing data, we are the controller — see the Privacy Policy.

    2. Subject matter and scope

    ItemDetail
    Subject matterProviding the FitFloww CRM platform under the Terms of Service
    DurationFor as long as your account is active, plus the deletion windows in §9
    Nature and purposeStoring, organising, displaying, transmitting, backing up, and deleting client records so you can run coaching services
    Categories of data subjectYour clients, and any team members you invite to your account
    Categories of personal dataContact details, profile information, scheduling data, payment records, messages, and health data
    Special category data (Art. 9)Health data: body measurements, progress photos, injury notes, nutrition records. You are responsible for holding the Art. 9(2) condition, normally the client’s explicit consent.

    3. Processing on your instructions

    • We process client personal data only on your documented instructions. Your use of the platform’s features is such an instruction.
    • We do not process it for our own purposes, do not sell it, and do not use it to train AI models.
    • If we are legally required to process it otherwise, we tell you first unless the law forbids us from doing so.
    • We will tell you if we consider an instruction to breach GDPR or UK GDPR.

    4. Confidentiality

    Everyone we authorise to access client personal data is bound by confidentiality obligations and gets access only where needed to operate or support the service. Access is limited to the smallest set of people that makes support possible.

    5. Security measures (Art. 32)

    Technical and organisational measures in place:

    • TLS 1.3 for all data in transit
    • AES-256 encryption at rest, applied by our database and storage provider
    • Session tokens mirrored into HttpOnly cookies so page scripts cannot read them
    • Row-level security policies so one coach cannot read another coach’s records
    • Passwords hashed by our authentication provider — we never see or store them
    • Card details handled by Stripe and never stored on FitFloww systems
    • Automated dependency and secret scanning on every build
    • Encrypted database backups with point-in-time recovery

    Stated plainly, because procurement will ask

    • FitFloww is not SOC 2 or ISO 27001 audited.
    • FitFloww is not HIPAA certified and does not sign Business Associate Agreements.
    • Messages are not end-to-end encrypted. They are encrypted in transit and at rest, and are readable by our database administrators.
    • Multi-factor authentication is not yet available.
    • Single sign-on (SAML/OIDC) is not yet available.

    Assess these against your own risk before storing sensitive records. We would rather lose a deal than pass an audit on a claim that is not true.

    6. Sub-processors

    • You give general authorisation for us to engage the sub-processors listed at the sub-processors page, each under a written contract imposing obligations no less protective than these.
    • We give at least 30 days’ notice before adding or replacing a sub-processor that handles client personal data.
    • You may object on reasonable data-protection grounds within those 30 days. If we cannot resolve the objection, you may terminate the affected service and receive a pro-rata refund of any prepaid unused period.
    • We remain liable to you for our sub-processors’ performance.

    Current list and change notifications: Sub-processors.

    7. Assisting with data subject requests

    • The platform lets you read, edit, export, and delete client records directly, which handles most requests without involving us.
    • Where a request cannot be satisfied through the platform, we assist you, taking into account the nature of the processing.
    • If a data subject contacts us directly about data you control, we refer them to you rather than acting ourselves — unless legally required to act.
    • We assist with data protection impact assessments and prior consultation under Arts. 35 and 36 on request.

    8. Personal data breaches

    • We notify you without undue delay, and in any event within 48 hours of becoming aware of a breach affecting client personal data you control.
    • The notice describes what happened, the categories and approximate number of records affected, the likely consequences, and the steps taken.
    • We give you the information you need to meet your own 72-hour notification duty to your supervisory authority.
    • We do not notify your supervisory authority or your data subjects on your behalf — that is your decision to make as controller.

    Report a suspected breach to security@fitflowwcrm.com.

    9. Return and deletion

    • You can export client data at any time — ask us and we provide a machine-readable copy within 30 days.
    • On termination, we delete client personal data from live systems within 30 days.
    • Encrypted backups roll over within a further 30 days, so deletion completes within 60 days of termination.
    • We retain only what law requires us to keep — billing and tax records, per the schedule below.
    CategoryRetentionNotes
    Coach account dataUntil deletion, then 30 daysDeleting your account starts a 30-day window during which it can be restored. After that it is removed from live systems.
    Client records, measurements, session notesUntil deleted by the coach, then 30 daysControlled by the coach who created them. Deleting a client removes their records on the same 30-day cycle.
    Progress photosUntil deleted by the coach, then 30 daysTreated as health data. Stored in access-controlled storage, not on a public URL.
    MessagesUntil deleted by a participant, then 30 daysEither participant deleting a conversation removes it for both.
    Encrypted database backupsUp to 30 daysPoint-in-time recovery. Deleted records can persist here until the window rolls over — this is why deletion is "within 30 days" and not instant.
    Server and access logs30 daysKept for security investigation and debugging, then discarded.
    Analytics events (PostHog)14 monthsOnly collected if you accept analytics cookies.
    Email delivery and engagement logs12 monthsBounce and unsubscribe records are kept longer so we do not email you again after you opt out.
    Support chat transcripts12 monthsHeld by Crisp. Only created if you accept optional cookies and open the chat.
    Billing and tax records7 yearsRetained because tax law requires it. This survives account deletion.

    10. Audits and information

    • We make available the information needed to demonstrate compliance with Art. 28.
    • You may request an audit once per year, or after a breach affecting your data. We ask for 30 days’ notice and reasonable scope, and you bear your own costs.
    • We are not SOC 2 or ISO 27001 audited, so we cannot substitute a certification report for an audit. We will answer a security questionnaire honestly instead.

    11. International transfers

    FitFloww and most of its sub-processors are in the United States. For personal data transferred from the EEA, the UK, or Switzerland, we rely on:

    • The European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), incorporated into this agreement by reference. Clause 7 docking, Clause 9(a) Option 2 general authorisation with 30 days’ notice, Clause 17 governed by Irish law, Clause 18(b) courts of Ireland.
    • The UK International Data Transfer Addendum (version B1.0) for UK transfers.
    • The Swiss addendum, with the Federal Data Protection and Information Commissioner as supervisory authority, for Swiss transfers.
    • The EU–US Data Privacy Framework where a sub-processor is certified under it.

    We have completed transfer impact assessments for our sub-processors and provide them on request.

    12. Liability and precedence

    Liability under this agreement is subject to the limitations in §14 of the Terms of Service, except where GDPR Art. 82 provides otherwise.

    Where this agreement conflicts with the Terms of Service on the processing of client personal data, this agreement prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.

    13. Contact

    FitFloww — data processing

    FitFloww (sole proprietorship)

    San Francisco, California, United States

    Email: legal@fitflowwcrm.com

    This agreement reflects our actual practices and is not legal advice. Have your own counsel review it against your obligations before relying on it.