The controller is the business identified in the FitFormiq Order, hereinafter the „Controller” or the „Trainer”.
The processor is Quanmedia Sp. z o.o., ul. Żwirki 17, 90-539 Łódź, Poland, KRS 0000539599, NIP 7272794495, hereinafter the „Processor” or the „Operator”.
The Agreement is concluded electronically upon acceptance with the Order or activation of the service and forms part of the agreement for the Platform. It takes precedence over the Terms in matters of data processing.
The system records evidence of conclusion: at least the identifier of the Controller and of the accepting user, the version and hash of the document content, the wording of the statement, a timestamp, and the channel and source of acceptance. A copy of, or a durable link to, the accepted version is made available to the Controller. Acceptance constitutes a documented processing instruction and does not replace the legal basis under Article 6 or Article 9 GDPR, which the Controller determines.
§ 2. Subject matter of processing
The Controller entrusts personal data to the Processor solely for the purpose of hosting and providing the FitFormiq Platform, support, security, backups, export, deletion and operation of features instructed by the Controller.
The duration of processing corresponds to the term of the agreement for the Platform, the switching and data retrieval periods and the ordinary deletion cycle for secured backups, unless the law requires longer retention.
Categories of data subjects include Clients and their representatives, customers and purchasers of the Controller’s Products, team members, trainers, instructors and other persons whose data the Controller lawfully enters into the Platform.
Categories of data include identification, contact and account data, image, training and dietary plans, tasks, activities, measurements, progress, schedules, communications, orders, technical data and health data and other special categories of data if the Controller decides to enter them lawfully.
Operations include collection, recording, organisation, storage, adaptation, making data available to authorised users, transmission, restriction, export, copying and deletion.
§ 3. Instructions and Controller’s obligations
The Processor acts solely on the documented instructions of the Controller, which consist of the Agreement, the Terms, Account configuration and directions compliant with the agreement given by authorised persons.
If an instruction infringes the GDPR or other data protection law, the Processor informs the Controller and may suspend its performance until the matter has been clarified.
The Controller is responsible for the lawfulness, fairness and minimisation of data, the legal bases under Articles 6 and 9 GDPR, privacy notices, data subject rights, retention periods, user permissions and the assessment of whether the Platform is appropriate for the intended processing.
The Controller does not instruct the processing of data whose use is prohibited or data exceeding the agreed purpose. The Controller also ensures the required consent of the legal representative for minors’ data.
§ 4. Processor’s obligations
The Processor ensures that persons authorised to process the data are authorised and bound by confidentiality.
The Processor applies technical and organisational measures appropriate to the risk.
The Processor maintains records required by law and makes available the information necessary to demonstrate compliance with Article 28 GDPR.
Taking into account the nature of the service and the information available, the Processor assists the Controller with the exercise of data subject rights, security obligations, data protection impact assessments, consultations and personal data breach notifications.
The Processor promptly forwards to the Controller a data subject request concerning entrusted data and does not respond on the merits without instructions unless required by law.
After the service ends, the Processor returns or deletes the data in accordance with the Controller’s choice, the Terms and the law.
The Processor may process data without instructions if required by Union or Member State law. It informs the Controller of that legal requirement before processing unless the law prohibits such information.
Assistance exceeding the Processor’s standard features and obligations may be charged according to an accepted quotation if the need does not result from a breach on the Processor’s part.
§ 5. Security and personal data breaches
Depending on the risk, the Processor applies in particular encryption in transit, secure password hashing, access controls and roles, the principle of least privilege, backups, updates, event logging, network protection and response and availability restoration procedures.
The Controller configures roles, protects login credentials, keeps the user list up to date and reports incidents without undue delay.
After becoming aware of a personal data breach concerning entrusted data, the Processor notifies the Controller without undue delay, where possible within 48 hours, and provides the available information required by Article 33(3) GDPR. Information may be provided in phases.
The Processor takes reasonable measures to mitigate the effects. Notification does not constitute an admission of fault or liability. The Controller decides whether to notify a supervisory authority or data subjects unless the obligation applies directly to the Processor.
§ 6. Subprocessors and transfers
The Controller grants general authorisation for the use of subprocessors needed for hosting, transactional email, backups, monitoring, support and IT infrastructure.
A current named list of subprocessors, their functions and countries of processing is made available to the Controller in the Panel or upon request. As at the effective date it includes in particular: Quanmedia Sp. z o.o. (hosting and infrastructure, Poland/EEA), PayPro S.A. — Przelewy24 (payment handling, Poland) and Resend, Inc. (transactional email, United States — based on Standard Contractual Clauses). The Processor informs the Controller of an intended addition or replacement at least 14 days in advance.
The Controller may raise a reasoned objection relating to data protection within that period. The parties seek a reasonable solution. If no solution is possible, the Processor may refrain from using the relevant entity or feature, or either Party may terminate the part of the service affected by the objection.
The Processor imposes on the subprocessor obligations providing no less protection than this Agreement and remains responsible for the subprocessor’s performance in accordance with Article 28(4) GDPR.
Data is, as a rule, processed within the EEA. A transfer outside the EEA requires a mechanism compliant with Chapter V GDPR, in particular an adequacy decision or Standard Contractual Clauses and, where necessary, supplementary safeguards.
§ 7. Audit and cooperation
Upon written request, the Processor provides information reasonably necessary to demonstrate compliance. Current certifications, reports and a remote audit are used in the first instance.
The Controller may conduct an audit no more than once a year, on at least 30 days’ notice, during business hours, without access to other customers’ data, code, security measures or secrets unrelated to the audit. The frequency and notice restrictions do not apply following a material breach or at the request of an authority.
The Controller bears the cost of the audit unless it demonstrates a material, culpable breach by the Processor. The auditor must be independent, competent and bound by confidentiality.
§ 8. Liability and termination
The parties are responsible for their respective obligations under the GDPR. Contractual liability between the parties is subject to the limitations in the Terms to the extent that this does not infringe mandatorily applicable law or third-party rights.
Upon termination, the Processor enables the export and deletion of data in accordance with the Terms. After the retrieval period expires, it deletes active data and deletes backups in the ordinary secure cycle unless the law requires their retention.
Provisions concerning confidentiality, liability, an audit relating to an earlier period and deletion of data survive termination of the Agreement.
Annex A. Processing details
Subject matter: provision of the FitFormiq SaaS.
Nature and purpose: operations described in § 2 on the Controller’s instructions.
Duration: the agreement, switching period, retrieval period and the secure backup deletion cycle (up to 30 days).
Data subjects, data and operations: § 2(3)-(5).
Hosting location: European Economic Area unless a lawful transfer is identified in the subprocessor list.
Contact for data protection and incidents: kontakt@fitformiq.com.
Annex B. Minimum list of measures
HTTPS/TLS for transmission and secure password hashing;
role-based access control and organisation isolation;
backups and a restoration procedure;
updates and vulnerability management;
security logs, monitoring and incident response;
staff confidentiality and provider controls;
secure deletion and data export;
periodic review of the adequacy of measures to the risk.