Legal
Data processing agreement
Last updated: 27 August 2026
1. Parties and scope
This data processing agreement ("DPA") forms part of the terms of service between RungGym (the "processor") and you, the trainer, coach or business holding the subscription (the "controller"). It applies automatically from the moment you use the service — no signature is needed. It implements Article 28(3) of the GDPR for all personal data you enter into RungGym about your clients.
Company number: BE 1036.988.990
Registered name and address available via the Belgian company register (KBO/BCE) at kbopub.economie.fgov.be using this company number.
Email: info.runggym@gmail.com
2. Subject matter, duration, nature and purpose
We process your clients' personal data for one purpose only: operating the RungGym software for your account — storing client profiles, generating training blocks and producing PDF exports. The processing lasts as long as your subscription plus the 30-day export window described in the terms. We never use this data for our own purposes, do not sell it, and do not use it for advertising or profiling.
3. Categories of data and data subjects
Data subjects are your clients. The data you may enter about them includes: name, training goal, experience level, available equipment, training notes and injury information. Injury information is health data within the meaning of Article 9 GDPR. As controller, you are responsible for having a lawful basis to record it — in practice your client's explicit consent or your own professional-care relationship. Enter only what you need to build a safe plan.
4. Our obligations
As processor, we:
- process the data only on your documented instructions — in practice: the actions you perform in the software — unless EU or member-state law requires otherwise, in which case we inform you first where allowed;
- ensure that everyone authorised to process the data is bound by confidentiality;
- take the technical and organisational measures of Article 32 GDPR, including encryption in transit, row-level access control so that one trainer can never read another trainer's client data, and EU-based storage (see section 5);
- assist you, taking into account the nature of the processing, in answering data subject requests (access, rectification, erasure, portability) — your clients' data is visible and editable in your dashboard, and exportable as PDF at any time;
- assist you with your obligations under Articles 32–36 GDPR, including notifying you without undue delay after becoming aware of a personal data breach affecting your clients' data;
- delete all client personal data at the end of the service as described in the terms (30 days after cancellation, or earlier on request), unless EU or member-state law requires storage;
- make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In first instance we do this by providing documentation; an on-site audit requires 30 days' notice, happens at most once a year and at your cost.
5. Sub-processors
You give general written authorisation for the following sub-processors, which we need to run the service:
- Supabase (database and authentication) — data stored in the EU (AWS region eu-west-1, Ireland);
- Vercel (application hosting);
- Stripe (payments) — Stripe processes your own billing data as an independent controller; it never receives your clients' data.
We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain fully liable to you for their performance. We announce any intended change of sub-processor at least 30 days in advance by email; if you object, you can cancel before the change takes effect.
6. International transfers
Client data is stored in the European Union. Where a sub-processor's support or infrastructure entails access from outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision (for US providers: the EU–US Data Privacy Framework).
7. Precedence and contact
If this DPA conflicts with the terms of service on a data-protection point, this DPA prevails. Questions: info.runggym@gmail.com.