FitSplit Gym Data Processing Addendum
Last updated: July 6, 2026
This Gym Data Processing Addendum ("DPA") forms part of the agreement between FitSplit and the gym, studio, fitness business, or organization using FitSplit ("Gym", "Customer", "you").
FitSplit is owned and operated by Blume Labs, with its registered address at [REGISTERED ADDRESS].
1. Purpose
This DPA governs FitSplit's processing of personal data on behalf of the Gym in connection with the FitSplit Service.
If there is a conflict between this DPA and the Terms of Service, this DPA controls for processing of Gym-controlled personal data.
2. Roles
For Gym member and staff data processed in a Gym workspace:
- the Gym is generally the controller/data fiduciary/business;
- FitSplit is generally the processor/service provider/vendor processing data on the Gym's behalf.
For FitSplit's own platform operations, such as security, abuse prevention, service improvement, support, legal compliance, billing with the Gym, and platform administration, FitSplit may act as an independent controller/data fiduciary/business.
3. Processing instructions
FitSplit will process Gym personal data only:
- to provide, secure, support, and improve the Service;
- according to the agreement, Terms, this DPA, and documented Gym instructions;
- as necessary to comply with law;
- as otherwise permitted by applicable data protection law.
The Gym instructs FitSplit to process personal data as needed to provide the Service features selected or used by the Gym and its users.
4. Categories of data subjects
Data subjects may include:
- Gym members;
- Gym owners;
- trainers;
- staff;
- platform administrators;
- prospective members or people who contact the Gym through FitSplit;
- emergency or support contacts if the Gym enters such data.
5. Categories of personal data
Data may include:
- identity and contact data;
- account credentials and authentication metadata;
- role, staff type, gym association, and account status;
- workout programs, exercise logs, PT sessions, and progress data;
- body metrics, macro/nutrition data, goals, coach notes, and injury notes;
- attendance records and location/geofence verification data;
- membership packages, membership dates, and payment request records;
- notifications, activity records, support messages, and gym notices;
- profile photos, logos, exercise media, and uploaded files;
- device, usage, session, security, and diagnostic data.
6. Sensitive data
The Service may process health-related, fitness, body metric, injury, location, and authentication data that may be sensitive under applicable law.
The Gym is responsible for:
- providing required notices to members and staff;
- obtaining valid consent or another lawful basis where required;
- ensuring trainers and staff enter only necessary and appropriate information;
- avoiding medical diagnosis or treatment records unless legally permitted and appropriate;
- honoring member rights and withdrawal requests where applicable.
FitSplit will use reasonable safeguards for sensitive data and will process it only as needed for the Service and permitted purposes.
7. Gym obligations
The Gym will:
- comply with applicable privacy, employment, consumer, health, safety, and gym-operation laws;
- have a lawful basis for collecting and using personal data in FitSplit;
- provide privacy notices to members, trainers, and staff;
- obtain consent where required, including for minors, health/fitness data, location/geofence attendance, and push notifications;
- keep role permissions accurate;
- promptly disable access for staff or members who should no longer have access;
- avoid uploading unlawful, excessive, or irrelevant personal data;
- respond to data subject requests where the Gym is responsible;
- notify FitSplit promptly of suspected unauthorized access involving FitSplit.
8. FitSplit obligations
FitSplit will:
- process Gym personal data according to documented instructions;
- maintain appropriate technical and organizational security measures;
- restrict personnel access to those with a need to know;
- require confidentiality from personnel who access personal data;
- assist the Gym with data subject requests where reasonably possible;
- assist with security incident investigation where required;
- provide information reasonably needed to demonstrate compliance with this DPA;
- delete or return Gym personal data at the end of services, subject to legal retention, backups, archives, and legitimate operational needs.
9. Security measures
FitSplit's current safeguards include:
- encrypted transport;
- Firebase Authentication;
- role-based access controls;
- Firestore and Storage security rules;
- gym-scoped tenant isolation;
- privileged server-side actions and Cloud Functions;
- login lockout controls;
- protected credentials;
- data archive/deletion workflows;
- operational monitoring and diagnostics.
Security measures may evolve over time, provided the overall level of protection is not materially reduced.
10. Subprocessors
The Gym authorizes FitSplit to use subprocessors listed in the Subprocessor List.
FitSplit will impose appropriate data-protection obligations on subprocessors and remains responsible for subprocessors' performance of their data-processing obligations to the extent required by applicable law.
FitSplit may update subprocessors by providing reasonable notice. If the Gym objects on reasonable data-protection grounds, the parties will work in good faith to resolve the objection.
11. International transfers
FitSplit is operated from India and uses cloud providers that may process data in India and other countries. Where required, FitSplit will use appropriate transfer safeguards, such as provider data-processing terms, standard contractual clauses, contractual protections, and technical controls.
The Gym is responsible for confirming that its use of FitSplit and transfer of data to FitSplit is lawful for its users and locations.
12. Data subject requests
If FitSplit receives a request from a member, staff member, or other data subject relating to Gym-controlled data, FitSplit may:
- respond directly where legally required or where FitSplit is the controller;
- route the request to the Gym;
- ask the requester to contact the Gym;
- assist the Gym in fulfilling the request.
The Gym is responsible for responding to requests where it is the controller/data fiduciary/business.
13. Security incidents
FitSplit will notify the Gym without undue delay after becoming aware of a confirmed personal data breach affecting Gym personal data, where notification is required by applicable law or contract.
The notice may include, where known:
- nature of the incident;
- categories of affected data;
- likely consequences;
- measures taken or proposed;
- recommended Gym actions.
The Gym is responsible for any notifications to its members, staff, regulators, or other parties unless applicable law requires FitSplit to notify directly.
14. Audits and information
Upon reasonable written request, FitSplit will provide information reasonably necessary to demonstrate compliance with this DPA. Any audit must be scoped, confidential, non-disruptive, and subject to reasonable frequency and security restrictions.
15. Return and deletion
At termination of the Gym's use of FitSplit, FitSplit will delete or return Gym personal data according to the agreement and feasible export/deletion capabilities, unless retention is required or permitted by law, security, backups, archives, dispute prevention, or legitimate business operations.
Current app behavior includes a 60-day archive retention period for supported deleted records.
16. Liability
Liability under this DPA is subject to the limitation of liability in the applicable agreement between FitSplit and the Gym, unless applicable law requires otherwise.
17. Contact
FitSplit privacy contact: fitsplit.in@gmail.com
Grievance Officer: [GRIEVANCE OFFICER NAME]