Data Processing Agreement
Last updated: 11 August 2026
Document version: 2026-08-11
Document type: Contractual — forms part of the Trainer Terms of Service
This Data Processing Agreement ("DPA") forms part of the Trainer Terms of Service ("Agreement") between LSTT Solutions Oy and each Trainer (or, where the Trainer belongs to an organisation, the organisation itself). It governs the processing of personal data that LostFit carries out on behalf of the Trainer or organisation in its capacity as data processor. In the event of any conflict between this DPA and the Agreement on a data protection matter, this DPA prevails.
Preamble
Data Controller: Each Trainer or organisation who has accepted the Trainer Terms of Service ("Controller"). Where a Trainer belongs to an organisation, the organisation is the Controller and accepts this DPA once through its owner or administrator, on behalf of all Trainers within it. The Controller determines the purposes and means of processing client personal data through the LostFit platform.
Data Processor: LSTT Solutions Oy, Business ID 3585888-3, registered address Takkulantie 320, 21270 Nousiainen, Finland ("Processor" or "LostFit"). The Processor processes personal data on documented instructions from the Controller in its capacity as Processor under this DPA. LostFit acts as an independent controller for the account, billing, security and product-analytics data described in its Privacy Policy; this DPA does not govern that processing.
This DPA is entered into automatically upon the Controller's acceptance of the Trainer Terms of Service. No separate signature is required.
This DPA implements the requirements of GDPR Article 28(3).
Article 1 — Definitions
- "GDPR": EU General Data Protection Regulation 2016/679.
- "Personal Data": any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
- "Processing": any operation or set of operations performed on Personal Data, as defined in GDPR Article 4(2).
- "Data Subject": an identified or identifiable natural person whose Personal Data is processed.
- "Sub-processor": any third party engaged by the Processor to carry out processing activities on behalf of the Controller.
- "Personal Data Breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
Article 2 — Scope and Duration
2.1 This DPA governs all processing of Personal Data carried out by LostFit as Processor on behalf of the Trainer as Controller in connection with the provision of the LostFit platform and related services.
2.2 This DPA commences on the date the Controller accepts the Trainer Terms of Service and remains in force for the duration of the Agreement.
2.3 Upon termination or expiry of the Agreement, the Processor shall delete or return all Personal Data in accordance with Article 8 of this DPA and section A.7 of Appendix A.
Article 3 — Processor Obligations
The Processor shall, in respect of all Personal Data processed under this DPA:
3.1 Instructions: Process Personal Data only on documented instructions from the Controller. The execution of the Agreement and this DPA constitutes the Controller's documented instructions. If the Processor is required by EU or Member State law to process Personal Data for other reasons, it shall inform the Controller of that legal requirement before processing, unless such law prohibits disclosure on grounds of public interest. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. The Processor may suspend execution of the affected instruction until the Controller confirms or withdraws it.
3.2 Confidentiality: Ensure that persons authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 Security: Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Appendix C. The Processor shall regularly test, assess, and evaluate the effectiveness of these measures.
3.4 Sub-processors: Only engage sub-processors in accordance with Article 5 of this DPA.
3.5 Data Subject Rights: Taking into account the nature of the processing, assist the Controller — by appropriate technical and organisational measures — in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under GDPR Chapter III (rights of access, rectification, erasure, restriction, portability, and objection). Where the Processor receives a request directly from a Data Subject relating to processing carried out on the Controller's behalf, it shall not respond to the request itself, other than to direct the Data Subject to the Controller, and shall forward the request to the Controller without undue delay and in any event within five (5) working days of identifying it as such.
Assistance that goes beyond the self-service functionality provided in the platform, and that requires significant engineering or manual effort, may be charged at the Processor's then-current professional services rates, notified to the Controller in advance.
3.6 Controller Assistance: Assist the Controller in ensuring compliance with its obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessment, and prior consultation), taking into account the nature of processing and the information available to the Processor.
3.7 Audit: Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
The parties agree the following mechanics for exercising that right:
(a) The Processor shall in the first instance satisfy audit requests by providing its then-current security documentation, this DPA's Appendix C, responses to a reasonable security questionnaire, and any third-party audit report or certification it holds. In most cases this will be sufficient to demonstrate compliance.
(b) Where the documentation in (a) does not reasonably enable the Controller to verify compliance, the Controller may conduct an on-site or remote inspection, no more than once in any twelve-month period, on at least thirty (30) days' prior written notice. This frequency limit does not apply where the inspection follows a Personal Data Breach affecting the Controller's data, or where a supervisory authority requires it.
(c) Any auditor mandated by the Controller must not be a competitor of the Processor and must be bound by confidentiality obligations no less protective than those in the Agreement.
(d) Inspections shall be conducted during normal business hours, without unreasonable disruption to the Processor's operations, and shall not extend to any data, systems, or premises relating to other customers of the Processor.
(e) Each party bears its own costs for the first inspection in any twelve-month period. The Controller shall reimburse the Processor's reasonable costs for any further inspection in the same period, unless the inspection reveals a material breach by the Processor.
3.8 Data Deletion: Upon termination of the Agreement, at the Controller's choice, delete or return all Personal Data and delete existing copies, unless EU or Member State law requires storage of the Personal Data. The Processor shall confirm deletion in writing within 30 days of the effective date of termination.
Article 4 — Controller Obligations
The Controller shall:
4.1 Ensure that there is a valid and documented lawful basis under GDPR Article 6 for each processing purpose for which it instructs the Processor.
4.2 Where Personal Data constitutes special categories of data under GDPR Article 9 (in particular health data), ensure that an appropriate condition under Article 9(2) applies — in particular, that explicit consent has been obtained from each Data Subject.
4.3 Provide Data Subjects with the required information under GDPR Articles 13 and 14, including information about the Processor's role.
4.4 Comply with all applicable data protection laws in relation to the processing of client Personal Data.
4.5 Ensure that its instructions to the Processor comply with applicable law.
Article 5 — Sub-processors
5.1 The Controller grants the Processor general authorisation to engage the sub-processors listed in Appendix B.
5.2 The Processor shall inform the Controller of any intended changes to the sub-processors listed in Appendix B — including additions or replacements — by giving at least 15 days' advance written notice to the email address associated with the Controller's account. The Controller may object to such changes on reasonable grounds by notifying the Processor in writing within the 15-day notice period.
5.2a Where a change to the sub-processors listed in Appendix B is required urgently to maintain the security, availability or continuity of the Service, the Processor may make the change before the notice period in Article 5.2 has elapsed, and shall inform the Controller without undue delay. The Controller's right to object under Article 5.2 and to terminate under Article 5.3 applies to such a change from the date the Controller is informed.
5.3 If the Controller objects to a new sub-processor and the Processor cannot accommodate the objection, the Controller may terminate the affected part of the Agreement on written notice without penalty.
5.4 The Processor shall ensure that any sub-processor is bound by data protection obligations equivalent to those in this DPA and shall remain fully liable to the Controller for the performance of the sub-processor's obligations.
Article 6 — Personal Data Breach Notification
6.1 The Processor shall notify the Controller of a Personal Data Breach without undue delay, and in any event within seventy-two (72) hours after becoming aware of it. The Processor becomes "aware" when it has a reasonable degree of certainty that a security incident has occurred that led to Personal Data being compromised; a period of investigation to establish that is not itself a delay.
Notification under this Article is not, and shall not be construed as, an acknowledgement of fault or liability by the Processor.
6.2 The notification shall include, to the extent available at the time of notification: (a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (b) the likely consequences of the Personal Data Breach; (c) the measures taken or proposed to be taken by the Processor to address the Personal Data Breach.
6.3 Where it is not possible to provide all information at the time of the initial notification, the Processor shall provide the remaining information in phases without undue further delay.
6.4 The Controller is responsible for assessing whether the breach must be notified to the competent supervisory authority and/or to affected Data Subjects, and for making such notifications in accordance with GDPR Articles 33 and 34. The Processor shall cooperate with the Controller in this process.
Article 7 — International Data Transfers
7.1 The Processor shall not transfer Personal Data to a country outside the EU/EEA without prior documented instruction from the Controller, unless required to do so by EU or Member State law. In such cases, the Processor shall inform the Controller of that legal requirement before transfer.
7.2 All international transfers of Personal Data shall be made using one of the mechanisms specified in GDPR Chapter V, as set out in Appendix B for each sub-processor involved in international transfers.
Article 8 — Return and Deletion of Data
8.1 Upon termination of the Agreement for any reason, the Processor shall: (a) during the 30-day period following account closure, provide the Controller, on request, with an export of the Personal Data in a structured, commonly used, machine-readable format, delivered within 30 days of the request; (b) thereafter permanently delete all Personal Data in accordance with the Retention Policy, unless legal retention obligations require continued storage.
8.2 Backup copies containing Personal Data will be deleted within 90 days of primary deletion, as part of the regular backup rotation cycle.
8.3 The Processor shall confirm deletion in writing within 30 days of the end of the export window.
Article 9 — Liability
9.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in Section 16 of the Trainer Terms of Service. Liability under this DPA and liability under the Agreement are not cumulative: the cap in Section 16 is an aggregate cap across both.
9.2 Nothing in this Article limits either party's liability to a Data Subject under GDPR Article 82, or any liability that cannot lawfully be limited between the parties.
9.3 Where one party has paid compensation to a Data Subject under GDPR Article 82 for damage caused wholly or partly by the other party's breach of this DPA or of the GDPR, it may claim back from the other party that part of the compensation corresponding to the other party's share of responsibility, in accordance with GDPR Article 82(5) and subject to Article 9.1.
9.4 The Controller shall indemnify the Processor against any claim, fine, or loss arising from the Controller's failure to establish or maintain a valid lawful basis under GDPR Article 6, or a valid condition under GDPR Article 9(2) for health data, in respect of processing it has instructed the Processor to carry out.
Article 10 — Governing Law
This DPA is governed by Finnish law. Any disputes arising from or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions of the Trainer Terms of Service.
Appendix A — Processing Details
A.1 Subject Matter
Provision of the LostFit fitness coaching platform, enabling the Controller (Trainer) to manage and deliver coaching services to their clients.
A.2 Nature of Processing
Hosting, storage, display, transmission, organisation, structuring, security monitoring, backup, and maintenance of Personal Data, as required to deliver the platform features used by the Controller.
A.3 Purpose of Processing
Enabling the Controller to deliver personal fitness coaching services to their clients, including:
- Creating and managing client accounts
- Assigning and delivering workout programmes and nutrition plans
- Recording and displaying client progress data (measurements, workout logs, goals)
- Enabling communication between trainer and client through the platform
- Storing health and fitness data entered by the trainer or client
- Where the Controller has enabled the AI Add-On (not currently available): generating AI-assisted workout suggestions and client progress summaries for the Controller's review, by transmitting pseudonymised measurement, goal, and workout-progression data to the AI inference sub-processor named in Appendix B at that time
A.4 Categories of Personal Data
- Client profile data (name, email address, date of birth, gender, language, time zone)
- Training and activity data (workout programmes, exercise logs, sets, repetitions, completion records)
- Body composition and measurement data (weight, body fat percentage, body measurements)
- Progress photos and body images
- Nutrition and lifestyle data (meal logs, calorie targets, dietary preferences, allergies)
- Goal and progress data (goals set by trainer or client, milestones, achievement records)
- Chat and messaging data (messages between trainer and client within the platform)
- Technical security and access data (login timestamps, device identifiers, IP addresses)
A.5 Categories of Data Subjects
Clients — natural persons who are end users of the Controller's coaching services and whose data the Controller has instructed the Processor to process.
A.6 Special Categories of Personal Data
Health data within the meaning of GDPR Article 9 (in particular body measurements, workout logs, progress photos, and dietary/allergy information). The Controller is responsible for establishing a valid Article 9(2) legal basis for all health data processing — in practice, explicit consent from each client.
A.7 Retention
Personal Data is processed for the duration of the coaching relationship and for the periods set out in the LostFit Retention Policy. Key periods:
- Client health/measurement data, workout logs, photos: deleted 30 days after the active coaching relationship ends or the Controller's account closes, whichever is earlier
- Client profile data: 3 years from the last active date or account closure, then deleted
- Financial/billing records: 6 years from the end of the fiscal year (Finnish Accounting Act); statutory financial statements and ledgers are retained for 10 years
- Login and security logs: personal identifiers (actor ID, local and public IP address) are anonymised 90 days after creation; the remaining anonymised device record is retained for security-monitoring and analytics purposes
The Processor shall delete Personal Data in accordance with these periods unless the Controller instructs otherwise (subject to applicable law).
Appendix B — Authorised Sub-Processors
The following sub-processors are authorised as of the date of this DPA. The Processor will give 15 days' advance notice before adding or changing any sub-processor.
| Sub-processor | Registered name | Role | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Supabase Inc. | Database, authentication, file storage | EU (eu-north-1) | EU — no international transfer |
| Cloudflare | Cloudflare, Inc. | Bot protection (Cloudflare Turnstile) on sign-up, login, password-reset and account-deletion forms | EU + US (global edge network) | EU-US Data Privacy Framework (DPF certified); EU Standard Contractual Clauses under the Cloudflare Data Processing Addendum |
| Vercel | Vercel Inc. | Application hosting and content delivery for the Trainer App and Website | EU (arn1, Stockholm) + US | EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) |
| Stripe | Stripe Payments Europe, Limited | Payment processing and subscription management | EU + US | EU-US Data Privacy Framework (DPF certified) |
| Resend | Resend Inc. | Transactional email delivery | EU (Ireland, eu-west-1) | EU — no international transfer |
| Sentry | Functional Software Inc. | Error monitoring and crash reporting | EU (Sentry EU region) | EU — no international transfer |
| PostHog | PostHog Inc. | Usage analytics for the marketing website and, subject to consent, the Trainer/Client Apps | EU (PostHog EU Cloud, Frankfurt) | EU — no international transfer |
| OneSignal | OneSignal Inc. | Push notification delivery | EU (Netherlands) + US | EU-US Data Privacy Framework (DPF certified) |
No AI inference sub-processor is engaged at present. The AI Add-On is not enabled for any Controller, and no Personal Data is transmitted to any AI provider. Before that feature is switched on, the Processor will add the provider to this Appendix with its role, processing location, and transfer mechanism, and will give the 15 days' advance notice required by Article 5.2 — during which the Controller may object under Article 5.3.
When engaged, any AI inference provider will receive only pseudonymised data: direct identifiers (name, email address, phone number, postal address, photographs, and free-text notes) removed before transmission, though the data remains Personal Data because the Processor retains the ability to re-link it. Any such provider will be engaged under terms requiring zero or minimal data retention and prohibiting use of the data to train its own models, and a transfer impact assessment will be available to the Controller on request.
Stripe acts as a Processor in respect of payment processing carried out on the Processor's instructions, and as an independent Controller in respect of fraud prevention, anti-money laundering, know-your-customer and regulatory compliance activities that it is required to perform in its own right as a licensed payment institution. Personal Data may be transferred onward to Stripe, LLC in the United States under the Data Transfers Addendum forming part of Stripe's Data Processing Agreement.
Appendix C — Technical and Organisational Security Measures
The Processor implements the following technical and organisational measures as appropriate to the risk, pursuant to GDPR Article 32:
C.1 Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256 or equivalent
- Database backups are encrypted
C.2 Access Controls
- Role-based access controls (RBAC) limit access to Personal Data to authorised personnel on a need-to-know basis
- Principle of least privilege applied to all system roles
- Row Level Security (RLS) is enforced at the database level; client data is accessible only to the relevant trainer
- Multi-factor authentication (MFA) is available on all LostFit accounts, and is required for LSTT Solutions personnel accessing the production infrastructure consoles (database, hosting, payment and source-control providers). In-application enforcement for administrative roles within LostFit is being rolled out
C.3 Audit and Logging
- Privileged access to Personal Data (staff dashboard and service role access) is logged
- Login events and security-relevant actions are logged; personal identifiers are anonymised 90 days after creation per the Retention Policy, and the anonymised record is retained for security-monitoring purposes
- Logs are accessible only to authorised personnel
C.4 Physical and Organisational Security
- Infrastructure is hosted in EU-based data centres with appropriate physical access controls (managed by Supabase / underlying providers)
- All personnel with access to Personal Data are bound by confidentiality obligations
- Data protection and security training is provided to relevant staff
C.5 Availability and Resilience
- Automated backups with geographic redundancy within the EU
- Incident response plan with defined escalation procedures
- Recovery time and recovery point objectives are defined and tested
C.6 Testing and Review
- Regular review of security practices in response to technological developments
- Vulnerability and dependency scanning integrated into the development pipeline
- Security patches applied in accordance with severity and impact
Contact
Questions about this DPA should be directed to:
LSTT Solutions Oy Business ID (Y-tunnus): 3585888-3 Registered address: Takkulantie 320, 21270 Nousiainen, Finland Email: gdpr@lsttsolutions.fi
© LSTT Solutions Oy. All rights reserved.