This Data Processing Agreement applies when a trainer uses Forma to process client personal data for the trainer’s independent coaching activity.
1. Parties and roles
The Trainer is the controller for client coaching purposes. Kamil Dike Software, Robotnicza 3, 97-310 Wola Moszczenicka, Poland, NIP 7712920344 (“KDS”), is the processor for personal data handled on the Trainer’s documented instructions through Forma.
KDS remains a separate controller for Forma accounts, security, billing, legal compliance, and other purposes described in the Privacy Policy. This Agreement does not change those separate roles.
2. Scope and duration
Processing covers hosting and presenting trainer–client relationships, invitations, assigned routines, schedules, activity status, completion history, and feedback so the Trainer can provide coaching through Forma.
This Agreement applies while the Trainer uses the trainer service and for any later period in which KDS must retain or remove entrusted data under this Agreement, the Privacy Policy, or applicable law.
3. Processing details
- Data subjects: the Trainer’s clients, prospective clients who receive invitations, and people identified in coaching content.
- Personal data: identifiers, contact details, profile information, invitations, trainer relationships, routines, exercise instructions, schedules, activity and adherence information, completion records, ratings, feedback, and related technical identifiers.
- Operations: collection, recording, organization, storage, retrieval, display, transmission between the connected Trainer and client, restriction, support, security review, and deletion.
- Purpose: providing the trainer workspace and connected client coaching features selected by the Trainer.
4. Trainer obligations and instructions
- The Trainer determines a lawful purpose and legal basis, gives clients required privacy information, and handles any consent or other authorization needed for coaching.
- The Trainer uses Forma only for lawful instructions consistent with the Terms, this Agreement, and the product’s intended functionality.
- The Trainer minimizes submitted data, keeps it accurate, and does not use Forma as medical records or enter special-category data unless doing so is necessary, lawful, and appropriately protected.
- The Trainer’s configuration and ordinary use of Forma are documented processing instructions. Additional instructions must be sent to the data protection contact and may require agreement on feasibility and cost.
5. KDS processor obligations
- Process entrusted data only on documented instructions, unless Union or Member State law requires otherwise.
- Ensure people authorized to process entrusted data are bound by confidentiality.
- Maintain appropriate technical and organizational security measures.
- Inform the Trainer if an instruction appears to infringe data-protection law.
- Assist the Trainer, taking account of the nature of processing and information available to KDS, with data-subject rights, security obligations, breach notifications, impact assessments, and regulator consultations.
- Make information reasonably necessary to demonstrate Article 28 compliance available to the Trainer.
6. Security measures
- Firebase Authentication and server-side authorization for restricted operations.
- Firestore access rules and relationship-based access boundaries.
- Encryption in transit and provider-managed encryption at rest.
- Restricted production access, managed secrets, signed Stripe webhooks, and hashed Watch access tokens.
- Operational logging, error monitoring, backups or service resilience provided by the infrastructure, and procedures for investigating security events.
- Regular review of safeguards in light of risk, available technology, and the nature of the service.
7. Subprocessors
The Trainer gives KDS general authorization to use subprocessors needed to operate Forma. Current relevant providers include Google Cloud/Firebase for hosting, authentication, database, functions, performance monitoring, and logging; Sentry (Functional Software, Inc.) for application error monitoring; Google Workspace/Gmail for support; and the push service selected by the client’s browser or device, such as services operated by Apple, Google, Microsoft, or Mozilla, when notifications are enabled.
When the Trainer chooses AI routine import, Google Cloud Vertex AI processes the submitted routine text in the EU multi-region to return a structured draft. KDS does not store the prompt and schedules an unconfirmed normalized draft for deletion after 24 hours.
KDS will impose data-protection obligations appropriate to the service and remains responsible for its subprocessors as required by Article 28. KDS may update subprocessors and will provide reasonable notice of a material change. The Trainer may object on reasonable data-protection grounds; if the concern cannot be resolved, the Trainer may stop the affected feature or terminate the trainer service.
8. Requests and personal-data breaches
If KDS receives a request relating primarily to entrusted coaching data, KDS may direct the requester to the Trainer unless law requires another response. KDS will provide reasonable technical assistance available through Forma or support.
KDS will notify the Trainer without undue delay after becoming aware of a personal-data breach affecting entrusted data and will provide available information reasonably needed for the Trainer’s assessment and notification duties.
9. International transfers
KDS and its providers may process data outside the European Economic Area. Where a restricted transfer occurs, KDS will use an applicable transfer mechanism, such as an adequacy decision or standard contractual clauses, together with supplementary measures where required.
10. Return and deletion
On a verified instruction or termination of the relevant processing, KDS will delete or make available entrusted data within a reasonable period, unless law requires retention. The Trainer’s archive action limits access but does not itself request deletion.
AI routine prompts are not retained by Forma. Unconfirmed normalized AI drafts are scheduled for deletion after 24 hours; account deletion removes UID-linked drafts, quota records, and operational credit records.
Deletion obligations do not apply to data KDS must retain as a separate controller, data belonging to an independently maintained client account, or data required for security, legal claims, tax, or another legal obligation. Such data remains subject to the Privacy Policy and applicable law.
11. Reviews and audits
KDS will first satisfy reasonable review requests with current documentation and written responses. If that is insufficient, the Trainer may request a proportionate audit no more than once per year, unless a breach or regulator requires otherwise. Audits must protect other users, security, and confidential information and avoid unreasonable disruption. The requesting Trainer bears exceptional external audit costs unless material non-compliance is found.
12. Priority, liability, and law
If this Agreement conflicts with the general Terms on processor obligations, this Agreement controls. The remaining Terms, including applicable liability provisions, continue to apply.
This Agreement is governed by Polish law, without limiting mandatory rights or powers of competent data-protection authorities and courts.