Matfact
Español
FeaturesGuidesMigrationPricingWhatsAppContactMember loginAdmin

← Back to home

Data processing addendum

Privacy policyTerms of serviceData processing addendumSubprocessors

Last updated: 11 August 2026 Language: English

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Matfact (“Processor”) and the academy customer (“Controller”) that uses Matfact to process personal data of members and staff.


1. Roles

  • Controller: the gym / academy customer.
  • Processor: Matfact, processing personal data only on documented instructions of the Controller to provide the Services.
  • Matfact remains an independent controller for platform accounts, SaaS billing of the gym, and other processing described in the Privacy Policy.

2. Subject matter and duration

Processing of personal data uploaded or generated in the gym’s tenant (memberships, profiles linked to memberships, attendance, promotions, invitations, member dues identifiers, gym configuration) for the term of the Services and until deletion or anonymization per this DPA.


3. Nature and purpose

Hosting and processing such data so the Controller can operate academy workflows in Matfact (attendance, progression, scheduling, invitations, member dues via Stripe Connect where enabled).


4. Types of data and data subjects

  • Data subjects: members, coaches, admins, invitees; may include minors where the Controller uses child-type memberships.
  • Data: identity and contact fields, membership metadata, attendance/promotion records, billing identifiers/status, media URLs (e.g. avatars), invitations.

The Controller shall not instruct Matfact to process special-category data unless lawful and expressly agreed in writing.


5. Instructions

Matfact processes personal data only on the Controller’s documented instructions: use of the product features, configuration, and written support/DSAR instructions (including ops runbooks). Matfact informs the Controller if an instruction appears to infringe GDPR (Art. 28(3)).


6. Confidentiality

Personnel authorized to process personal data are bound by confidentiality obligations.


7. Security

Matfact implements appropriate technical and organizational measures (tenant isolation, access control, encryption in transit in production, password hashing, audit of privileged platform actions). Details may be summarized on request for legitimate audit needs.


8. Subprocessors

Controller authorizes Matfact to engage subprocessors listed at /subprocessors. Matfact remains responsible for subprocessor performance. Matfact will provide notice of material changes as described on that page. Objection rights: Controller may object on reasonable grounds related to data protection; if unresolved, Controller may terminate the affected Services.


9. International transfers

Where subprocessors transfer personal data outside the EEA, Matfact uses vendors that provide appropriate safeguards (e.g. SCCs) in their terms.


10. Assistance with data subject rights

Taking into account the nature of processing, Matfact assists the Controller with DSAR (access, erasure/anonymization, portability) via product features and ops procedures. The Controller remains responsible toward data subjects. Typical path: data subject → Controller → Matfact support with gym id and member/user identifiers.


11. Personal data breach

Matfact will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, with information reasonably available to assist the Controller with Art. 33/34 duties.


12. Deletion and return

Upon termination of Services or on written instruction, Matfact will delete or return personal data, or anonymize identifiers while retaining non-identifying operational history required for the integrity of attendance/progression records, unless Union or Member State law requires storage. Production erasure follows anonymization, not hard cascade delete (see Matfact ADR-019 / ops DSAR runbooks).


13. Audits

Upon reasonable written request (no more than once per 12 months, unless a breach or authority request), Matfact will make available information necessary to demonstrate compliance with this DPA, which may include security summaries and audit reports. On-site audits require reasonable notice and confidentiality, at Controller’s expense unless a material breach by Matfact is confirmed.


14. Children

Controller warrants it has a lawful basis (including parental authority where required) for any child-related personal data processed in the Services.


15. Order of precedence

If this DPA conflicts with the Terms regarding processing of Controller personal data, this DPA prevails.

PrivacyTermsDPASubprocessorsGuides[email protected]Member loginAdmin

© 2026 Matfact. All rights reserved.