Features ROI Pricing FAQ Blog About Free trial Log in
Theme
Registration pending. As Athletis is being incorporated, some statutory details (full company name, registered address, trade and companies register number, VAT) will be completed as soon as the registration certificate is issued.

1. Subject-matter and framework

This Data Processing Agreement (the DPA) governs the processing of personal data carried out by Athletis on behalf of the Client in the course of providing the Athletis service (the Service), an all-in-one software solution for sports coaches covering client tracking, payments, invoicing, automatic reminders and a website builder, accessible at athletis.app and my.athletis.app.

The Service is published by Athletis, a company being incorporated ([to be completed at registration]), whose legal representative and publication director is Aymen Ezzayer, contactable at hello@athletis.app. Further identification details appear in the legal notice.

This DPA is concluded pursuant to Article 28 of Regulation (EU) 2016/679 (the GDPR) and the French Data Protection Act n°78-17 of 6 January 1978 (loi Informatique et Libertés). It forms an integral part of the contractual relationship between the Client and Athletis. It complements the general terms of use (the Terms) and, on any matter relating to the protection of personal data, it prevails over the Terms in the event of conflict.

2. Definitions

The terms below carry the meaning assigned to them by Article 4 of the GDPR:

  • Controller: the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processor: the natural or legal person which processes personal data on behalf of the controller.
  • Subprocessor: a further processor engaged by the processor to carry out specific processing activities on behalf of the controller.
  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data, whether or not by automated means, such as collection, recording, storage, consultation, use, transmission, erasure or destruction.
  • Data subject: the identified or identifiable natural person to whom the personal data relates.
  • Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Terms not defined in this DPA carry the meaning given to them by the GDPR or, failing that, by the Terms.

3. Roles of the parties

For the personal data of the Client's own clients and prospects processed through the Service, the parties acknowledge that:

  • the Client (a professional sports coach acting as a self-employed person, a micro-entrepreneur, or a company) is the controller. The Client determines the purposes and means of the processing and remains responsible for compliance with the applicable data-protection law with respect to that data;
  • Athletis is the processor. Athletis processes personal data solely on the Client's documented instructions and for the sole purpose of providing the Service.

The Client warrants that it has a lawful basis under Article 6 of the GDPR for each processing operation it instructs, and that it has provided its own clients with the required information and, where applicable, obtained their consent. Athletis processes the personal data of the Client's clients exclusively in its capacity as processor and does not use it for its own purposes.

Where Athletis processes personal data relating to the Client itself (account, billing and administration of the Service), Athletis acts as controller for those limited purposes, as described in its privacy policy; such processing falls outside the scope of this DPA.

4. Duration

This DPA takes effect on the date the Client first accesses the Service and remains in force for the entire duration of the Client's subscription. It continues to apply, for the relevant obligations, until all personal data processed on the Client's behalf has been returned or deleted in accordance with clause 13. The provisions relating to confidentiality, liability and the return or deletion of data survive the termination of this DPA for as long as required by their nature.

5. Description of the processing

The subject-matter, nature and purpose of the processing, the duration, the categories of data subjects and the categories of personal data processed on the Client's behalf are described in Annex 1, which forms an integral part of this DPA. The processing is carried out for the sole purpose of enabling Athletis to provide the Service to the Client in accordance with the Terms and the Client's instructions.

6. Documented instructions

Athletis processes the personal data only on the basis of the Client's documented instructions, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by European Union or Member State law to which Athletis is subject. In such a case, Athletis informs the Client of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Client's instructions are constituted by this DPA, the Terms, the configuration options offered within the Service, and any additional written instruction the Client provides through the account or at hello@athletis.app. Athletis immediately informs the Client if, in its opinion, an instruction infringes the GDPR, the French Data Protection Act or any other applicable data-protection provision.

7. Confidentiality

Athletis ensures that the persons authorised to process the personal data on its behalf, whether employees, agents or contractors, have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation persists after those persons cease their duties and after the termination of this DPA. Access to the personal data is granted strictly to the persons who need it to perform their tasks in connection with the Service.

8. Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons, Athletis implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures are set out in Annex 3.

Athletis regularly reviews and, where necessary, updates these measures to maintain their appropriateness. Any update maintains a level of protection equivalent to or higher than that described in Annex 3.

9. Subprocessors

The Client grants Athletis a general written authorisation to engage subprocessors for the performance of the Service. The subprocessors engaged at the date of this DPA are listed in Annex 2, together with their role and location.

Athletis informs the Client of any intended addition or replacement of a subprocessor, thereby giving the Client the opportunity to object to such changes on reasonable, data-protection related grounds within a reasonable period following the notice. If the Client raises a legitimate objection that cannot be resolved, the Client may terminate the affected part of the Service under the conditions of the Terms.

Where Athletis engages a subprocessor, it imposes on that subprocessor, by way of a contract, the same data-protection obligations as those set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures, in accordance with Article 28(4) of the GDPR. Athletis remains fully liable to the Client for the performance of that subprocessor's obligations.

10. Transfers outside the EU

The personal data processed on the Client's behalf is hosted primarily within the European Union. Athletis does not transfer this data to a country outside the European Union or the European Economic Area except as necessary to provide the Service and only where an appropriate safeguard under Chapter V of the GDPR is in place.

As identified in Annex 2, only Cloudflare, a United States company used for hosting, content delivery and anti-bot protection, may entail a transfer outside the European Union. Such transfers are covered by the European Commission's Standard Contractual Clauses and/or by the EU-US Data Privacy Framework, together with any supplementary measures required to ensure an essentially equivalent level of protection. Athletis makes the relevant safeguards available to the Client on request.

11. Assisting with data-subject rights

Taking into account the nature of the processing, Athletis assists the Client, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Client's obligation to respond to requests from data subjects exercising their rights under Articles 12 to 23 of the GDPR, in particular the rights of access, rectification, erasure, restriction, portability and objection.

Where a data subject addresses such a request directly to Athletis, Athletis forwards it to the Client without undue delay and does not respond to it itself, unless the Client instructs otherwise. The Service provides features allowing the Client to consult, rectify, export and delete the personal data of its own clients directly.

12. Assisting with security, breaches and DPIA

Athletis assists the Client in ensuring compliance with the obligations set out in Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to Athletis. This assistance covers the security of processing, the notification of personal data breaches to the supervisory authority and to data subjects, the carrying out of data protection impact assessments and, where applicable, prior consultation with the supervisory authority.

Athletis notifies the Client of any personal data breach affecting the Client's data without undue delay after becoming aware of it. The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Athletis provides any further information reasonably necessary to enable the Client to meet its own notification obligations, the Client remaining responsible, as controller, for notifying the competent supervisory authority (the CNIL) and, where required, the affected data subjects.

13. Return or deletion at end of processing

At the end of the provision of the Service, and at the Client's choice, Athletis either deletes or returns to the Client all the personal data processed on its behalf, and deletes existing copies, unless European Union or Member State law requires storage of the personal data.

Throughout the subscription and during any applicable reversibility period, the Client may export its own clients' data in a structured, commonly used and machine-readable format through the features of the Service. Following termination, and subject to the legal retention obligations mentioned above (in particular the retention of accounting and invoicing records), Athletis proceeds with the deletion of the data within a reasonable period and certifies such deletion to the Client on request.

14. Records and audits

Athletis maintains a record of the categories of processing activities carried out on the Client's behalf, in accordance with Article 30(2) of the GDPR, and makes available to the Client all the information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.

Athletis allows for and contributes to audits, including inspections, conducted by the Client or another auditor mandated by the Client, in accordance with Article 28(3)(h) of the GDPR. Audits are carried out at the Client's expense, subject to reasonable prior notice, during business hours, no more than once per year unless a personal data breach or a request from a supervisory authority justifies otherwise, and in a manner that does not disproportionately disrupt Athletis's operations or compromise the confidentiality of other clients' data. Athletis may satisfy an audit request by providing relevant certifications, security reports or the answers to a written questionnaire where these adequately demonstrate compliance.

15. Liability

Each party is liable for the damage caused by processing that infringes the GDPR in accordance with Article 82 of the GDPR. As processor, Athletis is liable only where it has not complied with the obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to the Client's lawful instructions.

The Client, as controller, is responsible for the lawfulness of the processing it instructs, for the existence of a lawful basis and for the information and consent of its own clients; the Client indemnifies Athletis against any claim arising from a breach of these obligations. The financial limitations and exclusions of liability set out in the Terms apply to this DPA to the fullest extent permitted by the applicable mandatory law, it being specified that no clause of this DPA limits a party's liability where such limitation is prohibited by law.

16. Controller obligations

The Client undertakes to:

  • provide only lawful and documented instructions in respect of the processing;
  • ensure that it has, and maintains, a lawful basis under Article 6 of the GDPR for each processing operation carried out through the Service;
  • provide its own clients and prospects with the information required by Articles 13 and 14 of the GDPR and, where applicable, obtain and keep evidence of their consent;
  • ensure the accuracy, relevance and lawfulness of the personal data it enters into or uploads to the Service, and keep that data up to date;
  • refrain from entering into the Service any special categories of data referred to in Article 9 of the GDPR beyond what the Service is intended to process, and inform Athletis where such data is nonetheless necessary;
  • cooperate with Athletis to the extent required to enable each party to comply with its data-protection obligations.

17. General provisions

On any matter relating to the protection of personal data, this DPA prevails over the Terms and over any other document exchanged between the parties in the event of conflict. On all other matters, the Terms continue to apply.

This DPA is governed by French law. It is interpreted and applied in accordance with the GDPR (Regulation (EU) 2016/679) and the French Data Protection Act n°78-17 of 6 January 1978. The competent supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.

Athletis may amend this DPA to reflect changes in the applicable law, in the Service or in its subprocessors; the Client is informed of any material change under the conditions of the Terms. If any provision of this DPA is held invalid, the remaining provisions remain in full force. Any question relating to this DPA may be addressed to hello@athletis.app or through the contact page.

Annex 1: Description of the processing

Categories of data subjects. The processing concerns the personal data of the natural persons whose data the Client records in the Service, namely the Client's own clients (the coach's athletes and members) and prospects.

Categories of personal data. The following categories are processed on the Client's behalf:

  • identity and contact details (such as name, first name, email address, telephone number, postal address);
  • coaching sessions and scheduling data (bookings, attendance, session history and calendar entries);
  • payment and transaction status (amounts due and paid, invoice and payment status), it being specified that payment card data is handled by the payment provider and is not stored by Athletis;
  • any notes recorded by the coach in relation to a client (such as objectives, progress and follow-up remarks).

Nature and purpose of the processing. Collection, recording, organisation, structuring, storage, consultation, use, transmission and erasure of the personal data, carried out for the sole purpose of providing the Service to the Client: client tracking, session scheduling, automatic reminders, payment collection and invoicing, and operation of the coach's website.

Duration of the processing. The processing lasts for the duration of the Client's subscription and until the personal data is returned or deleted in accordance with clause 13, subject to any legal retention obligation.

Annex 2: Subprocessors

Athletis engages the following subprocessors to provide the Service. Data is hosted primarily within the European Union; only Cloudflare, a United States company, may entail a transfer outside the European Union, subject to the safeguards described in clause 10.

  • Scaleway (France, EU): application and database hosting.
  • OVHcloud (France, EU): mailbox hosting.
  • Mailjet / Sinch (European Union): sending of transactional emails (notifications and reminders).
  • Mollie (Netherlands, EU): payment processing and collection.
  • Cloudflare (United States): hosting, content delivery network (CDN) and Turnstile anti-bot protection. This is the only non-EU subprocessor; transfers are covered by the European Commission's Standard Contractual Clauses and/or by the EU-US Data Privacy Framework.

Annex 3: Technical and organisational measures

Athletis implements and maintains the following technical and organisational measures, in accordance with Article 32 of the GDPR, and adapts them as necessary to preserve an appropriate level of security:

  • Encryption in transit and at rest: personal data is encrypted in transit (TLS) and at rest.
  • Access control: access to personal data is restricted on a need-to-know basis, with individual authentication and role-based permissions.
  • EU hosting: application and database hosting is located within the European Union.
  • Data minimisation: only the personal data necessary for the purposes of the Service is collected and processed.
  • Logging and monitoring: access and processing activities are logged and monitored to detect and respond to anomalies and security incidents.
  • Regular backups: personal data is backed up regularly to ensure availability and the ability to restore access in a timely manner following an incident.
  • Segregation of client data: each Client's data is logically segregated so that a Client cannot access the data of another Client.
  • Vetted subprocessors: subprocessors are selected on the basis of the guarantees they provide and are bound by contractual data-protection obligations equivalent to those of this DPA.

A legal question?

Our team replies within one business day.

View pricing Free trial