Data processing agreement
Part of the terms and accepted with them. It governs what we do with your members' data, which is yours and not ours.
Version 2026-09-02b
1. Who is who
You, the gym, are the controller: you decide what data is collected from your members and what for. We are the processor: we handle it solely on your behalf and on your instructions.
Your instructions are, concretely, normal use of the product plus anything you ask us in writing. If an instruction of yours appeared to us to breach applicable law, we tell you before carrying it out.
2. What data and whose
From your members: identification and contact, plan and payments, attendance, routines and progress, and — if you use it — the health record, which contains health data and may concern minors together with their responsible adult.
From your team: identification, contact and role within the panel.
We do not process any of it for purposes of our own. We do not sell it, do not share it, and do not train models on it.
3. Confidentiality
Anyone on our side who can reach the data is bound by confidentiality and reaches it only when needed to operate the service or when you ask.
4. Security
Each gym is isolated in the database by row-level rules, so a query made from one gym cannot return another gym's data even if the application has a bug. The health record is further restricted to the person themselves, to the owner and reception of their gym, and to the teacher that person is assigned to.
All traffic is encrypted. Credentials with broad access live only on the server and never in the browser.
We take backups and verify them by restoring them, not merely by taking them.
5. Sub-processors
You authorise these four, each for its own purpose: Supabase (database and accounts, Brazil), Cloudflare (servers, network and domains), Polar (subscription billing outside Argentina) and Mercado Pago (billing in Argentina).
If we add another, we give you 30 days' notice. If you disagree, you may cancel at no cost before the change takes effect.
We are answerable for what our sub-processors do as if we had done it ourselves.
6. International transfers
The database is in Brazil. If you are in the European Union, the transfer relies on the standard contractual clauses, which are deemed incorporated into this agreement; if you are in another country with its own rules, we apply the mechanism that law provides.
Your site's public content is distributed over a global network. Your members' data is not: the panel is never cached anywhere.
7. Your members' rights
If a member asks you for access, rectification, erasure, portability or objection, you are the one who answers. We give you the tools and, where needed, assist you at no charge.
Part of it they can already exercise alone: any member deletes their own health record from their panel, without asking anyone's permission.
If a member writes to us directly, we do not answer them about their data: we refer them to you and tell you.
8. Data breaches
If we detect a breach affecting your data or your members', we tell you without undue delay and at the latest within 72 hours of detecting it, with what we know: what happened, who is affected, what we are doing and what we recommend you do.
Notifying the authority and the affected people is yours to do, because you are the controller; we give you everything you need in order to do it.
9. When you leave
On request we hand over your members' contact details — first name, surname, email and phone — and the history of the payments you charged them, in machine-readable files. We do not hand over database dumps, the rest of the system's data, or anything intended to rebuild the product elsewhere.
If a member exercises a right over data outside that list — their health record, their payment history — we give you what you need to answer that person, case by case.
When the service ends, your data and your members' data stay for 60 days and are then deleted. Backups rotate, so deleted data may persist for up to 30 further days in a backup and goes with it.
10. Audit
We give you in writing the information you need to check that we comply with this: what measures we apply, which sub-processors there are, and what we store.
We do not run on-site audits of our providers' infrastructure, because it is not ours. If your regulator requires more, tell us and we will work it out.
11. Duration
This agreement applies for as long as we process data on your behalf, and the confidentiality obligations survive it.