Data Processing Addendum

How we process your clients' data on your behalf, as your processor.

Effective 1 August 2026.

Draft, pending legal review. This document has not yet been reviewed by a solicitor. Anything shown in [square brackets] still needs completing. It is published so the terms are visible while the wording is finalised, and it is not yet a substitute for professional legal advice.

1. What this is

This addendum forms part of the Terms of Service and governs how we process personal data about your clients. Where it conflicts with the rest of the terms on data protection, this addendum wins. Terms defined in UK data protection law - the UK GDPR and the Data Protection Act 2018 - carry that meaning here.

2. The parties and their roles

For the personal data you record about your clients, you are the controller and PTToolBox, operated by James Swift trading as PTToolBox, is the processor. You decide why and how that data is processed; we process it only to provide the service to you, and only on your documented instructions, which these terms and your use of the app together set out.

3. What we process, and for whom

  • Subject matter and duration. Processing client data to provide PTToolBox, for as long as your account is open, then as clause 9 describes.
  • Nature and purpose. Storing, organising, analysing and generating documents and suggestions from the data you enter, so you can coach your clients.
  • Categories of data subject. The clients you coach.
  • Categories of personal data. Contact and identity details; training, check-in and nutrition records; and special-category health data such as injuries, medical-screening answers and body measurements.

4. Your responsibilities as controller

You warrant that you have a lawful basis to process each client’s data, and that for health data you hold the client’s explicit consent or another valid Article 9 condition. You warrant that your instructions to us, and our processing on them, will not put us or you in breach of data protection law. This warranty is the substance of the client-consent clause in the Acceptable Use Policy.

5. Our obligations as processor

  • Instructions only. We process client data only on your instructions, unless the law requires otherwise, in which case we will tell you first unless the law forbids it.
  • Confidentiality. Anyone we let process the data is bound to keep it confidential.
  • Security. We keep the technical and organisational measures described on our Security page, appropriate to the risk of processing health data.
  • Assisting you. Taking account of what we can see, we help you respond to data-subject requests, and with your data-protection impact assessments and consultations with the regulator.
  • Breaches. We notify you without undue delay after becoming aware of a personal data breach affecting your client data, with the detail you need to meet your own reporting duties.
  • Audit. We make available the information needed to show we meet these obligations, and allow for audits on reasonable notice, subject to confidentiality and the security of other coaches’ data.

6. Sub-processors

You give general authorisation for us to engage the sub-processors listed below to process client data. Each is bound by terms protecting the data to a standard no lower than this addendum, and we remain responsible to you for what they do.

  • Google (Firebase) - Hosting and database. Stores your account, your clients, and everything you record about them — check-ins, workouts, nutrition, notes. Processed in Google Cloud regions. Transfers outside the UK rely on the UK International Data Transfer Addendum. Terms.
  • Anthropic (Claude API) - AI features. Receives the client context needed when you use an AI feature, and returns the result. Anthropic does not train its models on data sent through the API. Processed in the United States. Transfers rely on Standard Contractual Clauses with the UK Addendum. Terms.
  • Stripe - Payments. Handles subscription payments. Card details go straight to Stripe and never reach PTToolBox. Stripe holds your billing identity, not your clients' data. Processed in the United States and the EU. Transfers rely on Standard Contractual Clauses. Terms.
  • Vercel - Application hosting. Serves the application and processes request logs. Client data passes through Vercel in transit; it is stored in Firebase, not on Vercel. Processed in the United States and other regions. Transfers rely on Standard Contractual Clauses. Terms.

If we intend to add or replace a sub-processor we will give you advance notice in the app or by email, so you have a chance to object on reasonable data-protection grounds before it starts.

7. International transfers

Where a sub-processor processes client data outside the United Kingdom, we ensure an approved transfer mechanism is in place - the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent safeguard. The location and basis for each is noted against it in the list above.

8. Data-subject requests

The service lets you access, correct, export and delete your clients’ data directly. If a client exercises their rights, they should contact you as their controller; if such a request reaches us, we will refer it to you rather than answer it ourselves, and help you respond.

9. Return and deletion

You can delete client data at any time from within the service. When your account closes, we delete or, at your choice, return your client data within a reasonable period, except for the minimum we are required by law to retain, and except for backups, which age out on our ordinary backup cycle.

10. Liability

Liability under this addendum is subject to the limitations in the Terms of Service. Because you determine what client data enters the service and on what lawful basis, you are responsible for claims arising from your not having the right or the consent to process it.

11. Contact

Data-protection questions and requests under this addendum go to jswiftfitness@gmail.com.