DATA PROCESSING ADDENDUM (DPA)

Last Updated: June 24, 2026

This Data Processing Addendum («DPA») forms part of the Terms of Service («Agreement») between iSME LLC, operating the TezFit platform («Processor»), and the customer organization using the Services («Controller»).

This DPA applies whenever the Processor processes Personal Data on behalf of the Controller in connection with the Services.

1. Definitions

«Personal Data» means any information relating to an identified or identifiable natural person.

«Controller» means the entity that determines the purposes and means of processing Personal Data.

«Processor» means the entity that processes Personal Data on behalf of the Controller.

«Applicable Data Protection Laws» means all applicable privacy and data protection laws, including where applicable the General Data Protection Regulation (GDPR).

2. Scope and Roles

The Controller determines the purposes and means of processing Personal Data.

The Processor processes Personal Data solely on behalf of the Controller and in accordance with the Controller’s documented instructions as reflected in the Agreement, this DPA, and the Controller’s use of the Services.

The parties acknowledge that:

  • Customer is the Data Controller.
  • TezFit is the Data Processor.

3. Subject Matter of Processing

The Processor provides software and related services for the management of fitness clubs, studios, sports facilities, wellness businesses, and related organizations.

Processing activities may include collection, storage, organization, retrieval, transmission, backup, reporting, and deletion of Personal Data as necessary to provide the Services.

4. Categories of Data

Depending on the Controller’s use of the Services, Personal Data may include:

  • Name
  • Email address
  • Phone number
  • Date of birth
  • Membership information
  • Attendance records
  • Booking information
  • Payment status and transaction references
  • Trainer assignments
  • Communication history
  • Any other data uploaded by the Controller


The Controller is solely responsible for determining which Personal Data is entered into the Services.

5. Categories of Data Subjects

Data subjects may include:

  • Members
  • Prospective members
  • Visitors
  • Trainers and instructors
  • Employees and contractors of the Controller
  • Other individuals whose information is entered into the Services by the Controller

6. Purpose of Processing

The Processor processes Personal Data solely for the purpose of:

  • Providing the Services;
  • Maintaining and securing the Services;
  • Providing technical support;
  • Creating backups and disaster recovery copies;
  • Complying with legal obligations;
  • Performing other activities requested by the Controller through the Services.

The Processor shall not sell, rent, or use Personal Data for its own marketing purposes.

7. Confidentiality

The Processor shall ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

Access to Personal Data shall be limited to personnel who require such access to perform their duties.

8. Security Measures

The Processor shall implement reasonable technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Such measures may include:

  • Access controls;
  • Authentication mechanisms;
  • Encrypted transmission using TLS/SSL;
  • System monitoring and logging;
  • Backup procedures;
  • Role-based permissions.

9. Subprocessors

The Controller authorizes the Processor to engage subprocessors as reasonably necessary to provide the Services.

Subprocessors may include providers of:

  • Cloud hosting;
  • Data storage;
  • Content delivery networks;
  • Email delivery services;
  • Monitoring and security services;
  • Backup and disaster recovery services.

The Processor remains responsible for the performance of its subprocessors under this DPA.

10. International Transfers

Where Personal Data is transferred across national borders, the Processor shall take reasonable steps to ensure an appropriate level of protection consistent with applicable law.

11. Assistance to Controller

Taking into account the nature of processing and information available to the Processor, the Processor shall provide reasonable assistance to the Controller in responding to requests from data subjects and in meeting applicable legal obligations.

12. Personal Data Breach

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.

Such notification shall include available information reasonably necessary for the Controller to understand the nature and impact of the incident.

13. Return and Deletion of Data

Upon written request by the Controller, the Processor shall:

  • Delete Personal Data,

unless retention is required by applicable law or necessary for legitimate backup and recovery purposes for a limited period.

14. Audit Rights

Upon reasonable written request, the Processor shall provide information reasonably necessary to demonstrate compliance with this DPA.

The parties may agree on reasonable audit procedures that do not unreasonably interfere with the Processor’s business operations or compromise the security of other customers.

15. Liability

The liability of each party under this DPA shall be subject to the limitations of liability set forth in the Agreement.

16. Order of Precedence

In the event of any conflict between this DPA and the Agreement regarding Personal Data processing, this DPA shall prevail to the extent of such conflict.

17. Governing Law

This DPA shall be governed by the same governing law specified in the Agreement.