Data processing agreement
Last updated: September 8, 2026
This agreement supplements the terms of sale between NetFit (the "Processor") and the Client (the "Controller") whenever NetFit processes personal data on the Client's behalf as part of the platform. It applies to data about members, prospects, or other individuals whose processing purposes and means the Client determines.
1. Instructions
NetFit processes data only on the Client's documented instructions, notably to provide the subscribed features and to ensure hosting, security, support, and the operations necessary to perform the contract. If NetFit believes an instruction constitutes a manifest breach of applicable regulations, it notifies the Client and may suspend execution pending compliant instructions.
2. Nature, purpose, and duration of processing
Processing includes collection through the Client's interface, hosting, access by authorized users, modification, export, backup, deletion, and logging. The purposes are managing members and subscriptions, access control, tracking payments and check-ins, billing, and notifications.
Processing lasts for the duration of the contract, plus a 30-day transition and deletion period after the contract effectively ends (see Privacy Policy, section 8), subject to legal retention obligations, notably accounting.
3. Categories of data and data subjects
Data processed: identity, contact details, optional photo, subscription information, payment and check-in history, technical identifiers, and logs necessary for security.
Data subjects: the Client's members and prospects, the Client's team members, and, where the Client decides, minors enrolled under its responsibility.
The Client agrees not to enter health data or other particularly sensitive data into fields not designed for it; NetFit does not request this type of data within the service's current scope.
4. Confidentiality
NetFit ensures that people authorized to process data are bound by an appropriate confidentiality obligation and only access the data necessary for their duties.
5. Security
- Encryption of communications.
- Hashed passwords.
- Role-based access control.
- Logical separation of data between client gyms.
- Logging of access and relevant security events.
- Backup and restoration measures suited to the service.
- Internal incident management procedures.
6. Sub-processors
The Client authorizes NetFit to use the technical sub-processors necessary for the service, notably OVH for hosting, Resend for transactional emails, and the mobile money payment provider used for billing. NetFit remains responsible to the Client for these sub-processors' compliance with applicable data protection obligations, and notifies the Client of any change of sub-processor when regulations require it.
7. Assistance and data subject rights
Given the nature of the processing, NetFit provides reasonable assistance to the Client in responding to its members' requests for access, rectification, deletion, or objection, when such requests concern data hosted in NetFit. The Client remains the main point of contact for its members regarding the exercise of these rights.
8. Data breach
NetFit notifies the Client without undue delay after becoming aware of a personal data breach affecting data processed on its behalf, specifying, to the extent available, the nature of the incident, the categories of data concerned, and the measures taken or planned.
9. International transfers
Data hosting (OVH) may involve processing outside Senegal, notably in France or Europe. NetFit selects its providers taking into account recognized security guarantees for this type of transfer.
10. Audits
NetFit makes available the information reasonably necessary to demonstrate compliance with its obligations as a processor. Any audit must be reasonable, proportionate, carried out with prior notice, and must not compromise the security or confidentiality of other Clients.
11. End of processing
At the end of the contract, NetFit makes the Client's data available through the export means offered, then deletes or anonymizes it within 30 days after the contract effectively ends, unless a longer legal retention obligation applies (notably accounting).
12. Precedence
In the event of a contradiction between this agreement and the terms of sale on a matter relating exclusively to personal data protection, this agreement prevails.
13. Client responsibilities
- Determine the purposes and legal bases of its own processing.
- Inform its members in accordance with applicable rules.
- Ensure the accuracy of data entered into NetFit.
- Define and control its staff's access rights.
- Not use NetFit for an unlawful purpose or one not intended by the service.
14. Contact
For any question about this agreement: contact@netfitsn.com.