Template prepared for review by a qualified lawyer before launch. This document has not yet been reviewed by counsel and must not be relied on until it has been.
Mr Z for Gyms: Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the Mr Z for Gyms Business Terms (the "Terms") between the Gym (the "Controller") and Zen Vitality Partners FZ-LLC, Ras Al Khaimah, United Arab Emirates ("Mr Z", the "Processor", "we"). It sets out the terms required by Article 28 of the EU General Data Protection Regulation 2016/679 ("GDPR") and of the UK GDPR, and applies whenever we process personal data on the Gym's behalf to provide the Service.
Capitalised terms not defined here have the meaning given in the Terms or in the GDPR.
1. Definitions
- "Data Protection Laws": the GDPR; the UK GDPR and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection; the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data; and any other data protection law that applies to the processing.
- "Member Data": personal data about Members, and about Gym staff where it appears in Member records, that we process on the Gym's behalf to provide the Service, as described in Annex 1.
- "Subprocessor": a third party we engage to process Member Data.
- "SCCs": the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
- "UK Addendum": the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
- "Personal Data Breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Member Data.
2. Roles of the parties
2.1 For Member Data, the Gym is the controller and Mr Z is the processor.
2.2 Mr Z is an independent controller, not a processor, for: the details of the Gym's owner and staff accounts; the Gym's billing and payment information; records we must keep for our own legal, tax and accounting obligations; security and abuse prevention; and aggregated statistics that do not identify the Gym or any individual. That processing is described in our Privacy Notice.
3. The Gym's obligations as controller
3.1 Lawful basis. The Gym is responsible for having a lawful basis for the processing it instructs, and for the accuracy of the Member Data it gives us (for example, the names and email addresses it adds or imports).
3.2 Health data. Member Data includes data concerning health, which is special category data under Article 9 GDPR. The Gym is responsible for having a valid condition for that processing, in most cases the Member's explicit consent, and for collecting and recording it. The Member App does not currently ask Members for that consent on the Gym's behalf. [Product owner: decide whether the Member App should collect explicit consent for health data on the Gym's behalf before the first scan or health questionnaire.]
3.3 Transparency. The Gym is responsible for giving its Members a privacy notice that covers the Service. To help, the Member App links to a short notice titled "Privacy at" followed by the Gym's name, which says the Gym is the controller and Mr Z processes data on its behalf. That short notice supports the Gym's own notice and does not replace it.
3.4 Adults only. The Gym must give access only to people aged 18 or over.
3.5 Instructions. The Gym's instructions must comply with Data Protection Laws.
4. Our obligations as processor
We will:
- (a) process Member Data only on the Gym's documented instructions, which are the Terms, this DPA and the Gym's use and configuration of the Service, unless the law requires otherwise, in which case we will tell the Gym first unless the law prohibits it;
- (b) tell the Gym promptly if, in our opinion, an instruction infringes Data Protection Laws;
- (c) ensure that everyone we authorise to process Member Data is bound by confidentiality;
- (d) implement the technical and organisational measures in Annex 3;
- (e) engage Subprocessors only as set out in section 5;
- (f) help the Gym respond to Members exercising their rights (section 6);
- (g) help the Gym meet its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us;
- (h) delete or return Member Data when the Terms end (section 9);
- (i) make available the information needed to demonstrate compliance with Article 28 and allow audits (section 10);
- (j) not sell Member Data, and not use it for our own advertising or to train AI models.
5. Subprocessors
5.1 The Gym gives us general written authorisation to engage Subprocessors. The Subprocessors in use at the date of this version are listed below.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Vercel Inc. | Hosting of the web application and its server functions, content delivery, application logs; registration of Custom Domains | All Member Data in transit; logs may contain email addresses and IP addresses | United States [confirm the function region; none is configured, so Vercel's default US region applies]; global edge network |
| Railway Corporation | Managed PostgreSQL database where all stored Member Data is kept | All stored Member Data | [confirm the region of the Railway database] |
| Anthropic, PBC | AI processing: coaching replies, training and nutrition plans, meal analysis, posture and body-composition analysis of photos, form review of still frames from live sessions, monthly reviews | Profile, health, training and nutrition data; photos and still frames, sent for analysis only | United States |
| OpenAI (OpenAI OpCo, LLC) | Speech-to-text for voice dictation, and text-to-speech for the coach's spoken cues | Members' voice recordings when they dictate; text of coaching cues | United States |
| Resend (Plus Five Five, Inc.) | Sending emails: sign-in codes and service emails to Members and to the Gym | Email addresses, names, email content | United States |
| Stripe (Stripe, Inc.; Stripe Payments Europe, Ltd. for European customers) | Payments, invoicing and tax calculation for the Gym's purchases | The Gym's billing data only. Stripe receives no Member Data | United States and Ireland |
5.2 The following services are also contacted, but receive no Member Data from us, or receive it only as stated:
- USDA FoodData Central (United States government): our servers send food names to look up nutrition values, with no identifier of the Member.
- Google (storage.googleapis.com) and jsDelivr: the Member's browser downloads the on-device pose-estimation model and its runtime from them, which reveals the device's IP address to them; no camera images are sent.
- Gravatar (Automattic Inc., United States) is not used in the Member App: no hash of a Member's email address, and no request from a Member's device, is sent to Gravatar. The Member App shows the Member's initial, or the profile photo of the Google account the Member signed in with, if any.
5.3 We impose on each Subprocessor data protection obligations that offer at least the same level of protection as this DPA, and we remain responsible to the Gym for their performance. [Confirm that a signed DPA is in place with each provider listed in 5.1, and confirm each legal entity name.]
5.4 We will give at least 30 days' notice by email before adding or replacing a Subprocessor, and update this list. The Gym may object on reasonable data protection grounds within that period. If we cannot address the objection, the Gym may end the affected part of the Service and receive a pro rata refund of Fees it has prepaid for the period after the change.
6. Members' rights requests
6.1 Requests from Members to access, correct, export, erase or restrict their data, or to object to its processing, are the Gym's to answer.
6.2 If a Member contacts us directly, we will not answer the request ourselves, other than to tell the Member that we have passed it to the Gym. We will forward it to the Gym within 5 business days.
6.3 There is currently no self-service export or deletion of a Member's data in the Member App or the Owner Console. On the Gym's written request to contact@askmrz.io, we will export, correct or delete a Member's data within 14 days, so the Gym can meet its own deadline.
7. Personal Data Breaches
7.1 We will notify the Gym without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Member Data.
7.2 The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of Members and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot give all of this at once, we will give it in stages without further undue delay.
7.3 We will cooperate with the Gym and take reasonable steps to contain and remedy the breach. Notifying supervisory authorities and Members is the Gym's decision, and we will not do so on its behalf unless the law requires it.
8. International transfers
8.1 We are established in the United Arab Emirates, and our Subprocessors process data in the countries listed in section 5, including the United States. These countries may not have been found by the European Commission or the UK to provide an adequate level of protection.
8.2 To the extent the Gym transfers Member Data subject to the GDPR to us, the SCCs, Module Two (controller to processor), are incorporated into this DPA, with the Gym as data exporter and Mr Z as data importer, and: Clause 7 does not apply; under Clause 9(a), Option 2 applies with the notice period in section 5.4; the optional wording in Clause 11 does not apply; under Clause 13, the supervisory authority is that of the Gym's establishment; under Clauses 17 and 18, the law and courts are those of [EU member state, for example Ireland]. Annexes I and II of the SCCs are completed by Annexes 1 to 3 of this DPA.
8.3 For transfers subject to the UK GDPR, the UK Addendum is incorporated, completed with the information in this DPA. For transfers subject to Swiss law, the SCCs apply with the references adapted to the Swiss Federal Act on Data Protection.
8.4 For onward transfers to Subprocessors outside the EEA, the UK and Switzerland, we rely on the Subprocessor's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions where it holds one, and otherwise on the SCCs. [Confirm, per Subprocessor, which mechanism applies, and prepare a transfer impact assessment.]
8.5 If the SCCs conflict with this DPA, the SCCs prevail.
9. Retention and deletion
9.1 During the Terms, we keep Member Data for as long as the Gym's account is active. When the Gym removes a Member, the Member loses access at once; the Member's data is kept until the Gym asks us to delete it or the Terms end. [Product owner: decide whether a removed Member's data should be deleted automatically after a set period.]
9.2 Photos and recordings are not kept: see Annex 1, section F.
9.3 When the Terms end, the Gym may ask for an export for 30 days (Terms, section 19). After that period, or earlier if the Gym instructs us in writing, we delete the Member Data from our live systems within 30 days and confirm it in writing on request. Copies in backups are deleted as the backups expire [confirm backup retention period]. We may keep Member Data only where the law requires it, and then only for that purpose.
10. Information and audits
10.1 We will make available to the Gym, on request, the information reasonably needed to demonstrate compliance with this DPA, including this DPA's annexes and the relevant terms and certifications of our Subprocessors.
10.2 Where that information is not enough, the Gym, or an independent auditor bound by confidentiality, may audit our compliance once in any 12 months, on at least 30 days' written notice, during business hours and in a way that does not disrupt the Service or compromise other customers' data. The Gym bears its own costs. Audits required by a supervisory authority, or following a Personal Data Breach, are not limited to once a year.
11. Liability and precedence
11.1 Each party's liability under this DPA is subject to the limits in section 17 of the Terms, except where Data Protection Laws or the SCCs do not allow it.
11.2 On data protection, this DPA prevails over the Terms. This DPA lasts for as long as we process Member Data for the Gym.
Annex 1: Description of the processing
A. Subject matter, nature and purpose: providing the Service to the Gym and its Members, namely AI fitness coaching, live AI personal training sessions, training and nutrition plans and logs, check-ins, posture and body-composition scans, progress tracking, monthly reviews, sign-in and service emails, and the Owner Console's view of Members' activity.
B. Duration: for the term of the Terms and until deletion under section 9. The processing is continuous.
C. Data subjects: the Gym's Members; Gym staff named in notes they write about Members.
D. Categories of personal data:
- Identity and contact: email address, name, language, time zone.
- Account and usage: sign-in events, Seat status, Session balance and use, activity dates, technical logs including IP addresses. The IP address used when a Gym signs up is stored only as a salted one-way hash.
- Profile: age, sex, height, weight, goals, training experience, equipment, schedule, dietary preferences.
- Training: workouts, sets, repetitions and loads, live-session results such as repetition counts, joint angles and body keypoints computed on the device, and written form reviews.
- Nutrition: meals and snacks logged, recipes, nutrition targets.
- Notes written by Gym staff about a Member.
E. Special categories of data (health): injuries and physical limitations, answers to the optional pre-session health questionnaire, body-composition results (such as body fat percentage and lean mass), posture assessment results, daily check-ins about how the Member feels, and any health information the Member chooses to enter. Restrictions and safeguards: access limited as described in Annex 3; no use for advertising or AI training; no sale.
F. Photos, video and audio. Posture and body-composition photos, meal photos and uploaded workout documents are sent to the AI Subprocessor (Anthropic) for analysis at the moment they are submitted, and are not stored by Mr Z: the application has no file or image storage for them, and only the results (numbers and text) are saved in the database. During live sessions, the camera video is analysed on the Member's own device to estimate body position, and video is not uploaded; a small number of still frames per set are sent to the AI Subprocessor for form review and are not stored. Voice recordings for dictation are sent to OpenAI for transcription and are not stored; only the resulting text is used. The AI Subprocessors may keep inputs for a limited period under their own API terms [confirm each provider's current API data retention period and that inputs are not used for training].
Annex 2: Subprocessors
The list of Subprocessors is in section 5.1 of this DPA and forms Annex 2.
Annex 3: Technical and organisational security measures
These are the measures in place at the date of this version. Items marked for confirmation depend on provider settings that cannot be verified from our code alone.
- Encryption in transit: the Service is served only over HTTPS (TLS). Connections from our servers to the database: [confirm TLS is enforced on the Railway connection].
- Encryption at rest: [confirm Railway encrypts database storage at rest].
- Access separation: each Gym owner account can open only its own Gym's Owner Console and Members; each Member can see only their own data. Administrative access to all Gyms is limited to one named Mr Z administrator account.
- Authentication: Members sign in with a six-digit code sent by email, which is rate limited; passwords, where used, are stored only as salted scrypt hashes. Signed-in sessions are held in encrypted session cookies managed by Auth.js.
- Data minimisation: photos, video and voice recordings are not stored (Annex 1, F); card details are handled only by Stripe; the sign-up IP address is stored only as a salted hash.
- Secrets: API keys and credentials are kept in the hosting provider's environment settings, not in source code.
- Personnel: access to production systems is limited to personnel who need it and are bound by confidentiality. [Confirm the list of people with production access, and that two-factor authentication is enabled on the Vercel, Railway, Stripe, Anthropic, OpenAI, Resend and code-hosting accounts.]
- Backups and recovery: [confirm the Railway backup schedule, retention and a tested restore procedure].
- Logging: application errors are logged by the hosting provider for operations and security. [Confirm the log retention period.]
Contact
Questions about this DPA, Members' requests and breach reports: contact@askmrz.io. Zen Vitality Partners FZ-LLC, [registered address], Ras Al Khaimah, United Arab Emirates. [If required: EU and UK representative under Article 27 GDPR / UK GDPR, name and address.]

