Data Processing Agreement

Effective 8 August 2026.

This Data Processing Agreement (“DPA”) forms part of the agreement between the gym or studio operator (“Controller”, “Customer”) and Gareth Holton, trading as BoxOp, of Halifax, West Yorkshire, HX3 7SA, United Kingdom (“Processor”, “BOXOP”), and applies whenever the Processor processes personal data on the Controller's behalf via the BOXOP Service, per UK GDPR Article 28.

1. Subject matter and duration

The Processor processes personal data on the Controller's instructions for as long as the Controller has an active BOXOP subscription, and thereafter only to the extent needed to comply with §7 (return/deletion).

2. Nature and purpose of processing

Hosting, storage, and processing of member and staff data to provide gym scheduling, membership management, class programming, in-app messaging, payment facilitation, and related notifications.

3. Categories of data subjects

  • Gym members
  • Gym staff (owners, coaches, admin users) acting on the Controller's behalf

4. Types of personal data

  • Contact details (name, email, phone)
  • Date of birth and gender, used for the Controller's demographic reporting (reported as age bands and counts, with groups of fewer than five suppressed)
  • Membership and booking history, attendance, class programming results and benchmarks
  • Payment references and subscription status (card data itself is held by Stripe, not BOXOP)
  • In-app messages between members and gym staff
  • Device/push tokens for notifications
  • Records of which version of the Controller's or Processor's terms a data subject accepted, and when

The Service provides no field for health data and does not request or infer it, so no special category (Article 9) data is intentionally collected. Free-text fields — coach comments, member notes and messages — will however accept whatever is typed into them. If the Controller uses them to record health information, the Controller is responsible for identifying its Article 9 condition for doing so; the Processor recommends against it. See also Privacy Policy §3.

5. Processor obligations

The Processor shall:

  • Process personal data only on the Controller's documented instructions, including regarding international transfers, unless required otherwise by law.
  • Ensure persons authorised to process the data are subject to confidentiality obligations.
  • Implement appropriate technical and organisational security measures, including tenant-level row-level security so one gym cannot access another gym's data, TLS encryption in transit, rate limiting, and boot-time enforcement of strong authentication secrets.
  • Not engage a sub-processor without the Controller's general authorisation (see §6) and impose equivalent data protection obligations on any sub-processor.
  • Assist the Controller, insofar as reasonably possible, in responding to data subject rights requests and in meeting its obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs).
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
  • At the Controller's choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless retention is required by law.
  • Make available to the Controller information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on reasonable notice.

6. Sub-processors

The Controller provides general authorisation for the Processor to engage the following sub-processors, each bound by data protection terms consistent with this DPA:

  • Supabase — database hosting and authentication (EU-West, Ireland).
  • Stripe — payment processing, Stripe Connect payouts.
  • Resend — transactional email delivery.
  • Twilio — SMS/WhatsApp notification delivery (where enabled).
  • Expo / Apple / Google — mobile push notification delivery.
  • Anthropic — processes staff-submitted prompts to generate AI-assisted marketing draft content (US-based; transferred under the UK International Data Transfer Addendum or equivalent SCCs).

We'll give the Controller reasonable notice before adding or replacing a sub-processor so they can object on reasonable data-protection grounds.

7. International transfers

Personal data is primarily hosted in the EU/UK. Where a sub-processor is located outside the UK/EEA, transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent adequacy mechanism.

8. Return or deletion of data

On termination of the Customer's subscription, the Controller may export member data for a reasonable period. After that period, or on request, the Processor will delete Controller personal data from production systems, subject to standard backup retention cycles, within a reasonable time.

9. Liability & governing law

Liability under this DPA is subject to the limitations set out in the underlying Terms of Service. This DPA is governed by the laws of England and Wales.

10. Contact

Data protection queries: Gareth Holton, trading as BoxOp, Halifax, West Yorkshire, HX3 7SA, United Kingdom. Email: hello@boxop.co.uk.