Data Processing Agreement
Version 1.0 · 28 July 2026 · between you (the trainer) and Spotter
This agreement applies whenever you use Spotter to hold personal data about your clients. It exists because UK GDPR Article 28 requires a written contract between a controller and a processor. It sits alongside our Terms and Privacy policy.
1. Roles
You are the controllerof your clients' personal data: you decide what to collect and why. Spotter is the processor: we act only on your instructions. Using the app is your instruction to store, display, back up and transmit that data as the features require.
2. Subject matter and duration
We process client data for as long as your account is active, plus the short period a backup takes to roll over after deletion.
3. Nature and purpose
Storing and displaying client records, sessions and bookings, workout logs, payment tracking, measurements and progress photos; sending transactional email on your behalf; and syncing sessions to your calendar if you connect one.
4. Types of data and data subjects
Data subjects: your clients, and people who enquire or book through your public page. Data: names, email addresses, phone numbers, session and payment history, workout data, and — where you choose to record it — body measurements, health notes and progress photos, which are special category (health) data.
5. Your obligations
You confirm that you have a lawful basis for everything you enter, and explicit consent for any health data — measurements, health notes and progress photos. You confirm this per client in the app. You are responsible for telling your clients that you use Spotter and for handling their requests. You must not enter data you have no right to hold.
6. Our obligations
- Process client data only on your instructions.
- Keep it confidential and limit staff access to what support and operations require.
- Apply appropriate security: encryption in transit, private file storage with short-lived signed links, and database-level row-level security so no trainer can reach another's data.
- Help you meet requests from your clients — access, correction, deletion, portability — and provide export and delete tools so you can action most of them yourself.
- Tell you about a personal data breach without undue delay and within 72 hours of becoming aware.
- Delete client data on your instruction, and everything under your account when you delete it.
- Make available the information you need to demonstrate compliance.
7. Sub-processors
You give general authorisation for the sub-processors listed in our Privacy policy — currently Supabase, Vercel, Resend and Google. We will tell you before adding or replacing one, and you may object. Each is bound by data protection terms no weaker than these.
8. International transfers
Client data is stored in the United Kingdom(London region), so for UK controllers it never leaves the jurisdiction. Where a sub-processor transfers data outside the UK/EEA, it does so under Standard Contractual Clauses or an adequacy decision.
9. Return and deletion
You can export all your data as JSON from Settings at any time. On account deletion we delete client records and photos permanently rather than hiding them.
10. Beta
Spotter is in beta. We are a small team, and the service is provided without warranty as described in the Terms. That does not reduce the data protection obligations above — those apply in full.
Contact
privacy@heyspotter.co