Data Processing Agreement (DPA)
This agreement, under Art. 28 GDPR, governs the processing of your athletes' personal data that Refreesh carries out on your behalf through Athleex. You, the Personal Trainer, are the <strong>controller</strong>; Refreesh is the <strong>processor</strong>. The DPA forms part of the Terms of Service.
Version 2.1 of 28 September 2026 — effective upon publication for new customers and for customers who accept it in the app; for other existing customers from 29 October 2026 (until then the accepted version applies: 2.0 of 14 September 2026 or, until 14 October 2026, 1.0 of 4 May 2026)
Parties
<strong>Controller (Customer)</strong>: the individual or legal entity registered as a Personal Trainer and identified in the Athleex account.
<strong>Processor</strong>: Refreesh S.r.l. Società Benefit, Via Lazzaro Spallanzani 10, 20129 Milan (MI), Italy — VAT no. IT13516410969, REA MI-2727959, which operates the Athleex service — info@athleex.com.
1. Definitions
The terms "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in Articles 4 and 28 of Regulation (EU) 2016/679 (GDPR). "Service" means the Athleex platform (athleex.com and the iOS and Android apps).
2. Subject matter, duration and scope
The Processor processes the Controller's athletes' data only to deliver the Service, for the duration of the Terms of Service. The DPA covers the data the Controller uses to coach their athletes: programs, sessions, notes, meal plans, supplements, feedback, calendar, recorded invoices and fees, relationship chat, contacts received from the public page, content the Controller publishes on their public page (including any client photos), analytics provided to the Controller (Churn Radar, business dashboard) and, if the athlete consents, health data shared with the Controller.
Outside the scope of this DPA, because Refreesh is an independent controller, are the data the athlete processes in their own account and the processing Refreesh carries out for its own purposes (account, consents, subscriptions, security, abuse prevention, Athleex Score and Athlete Twin, leaderboard and challenges), described in the privacy notice. When the athlete activates Athleex Score and Athlete Twin, the results are also shown to the Controller with whom they have an active relationship: the Controller receives them within the limits of the athlete's consent and uses them only for their own professional service.
3. Nature, purpose, data subjects and categories of data
- Nature: collection through the Service, storage, organisation, consultation, statistical processing, communication to the Controller and the athlete, erasure.
- Purpose: management of the professional relationship between the Controller and their athletes.
- Data subjects: the Controller's athletes, prospective clients who contact them from the public page and people shown in the content the Controller publishes.
- Data: identifiers and contact details; training data; communications; fees and invoices; churn-risk scores; health data (measurements and weight, body composition and body measurement goals, progress photos, intolerances, food diary) only if the athlete has given Refreesh consent to processing and to sharing with the Controller.
4. Documented instructions
The Processor processes data only under the Controller's documented instructions, consisting of these Terms, the DPA and use of the Service's features. If an instruction infringes the GDPR, the Processor notifies the Controller. The Processor does not use athlete data for its own purposes other than those set out in section 2.
5. Processor's obligations
- ensure that persons authorised to process data are bound by confidentiality and trained;
- adopt the security measures in section 7;
- comply with the conditions in section 8 for sub-processors;
- assist the Controller in responding to data subject requests (section 9) and with the obligations under Arts. 32-36 GDPR (security, breaches, impact assessment, prior consultation);
- delete or return data at the end of the service (section 12);
- make available the information necessary to demonstrate compliance with Art. 28 GDPR and allow audits (section 13).
6. Controller's obligations
- inform athletes about its own processing (Arts. 13-14 GDPR); Refreesh also makes its own notice available in six languages;
- process health data only within the limits of the consent given by the athlete in the Service and for its own professional service;
- not enter special categories of data other than those provided for by the Service (for example diagnoses or treatments);
- not create or coach accounts of minors under 18, and confirm the athlete is an adult when creating their account;
- publish photos or results of clients on its public page only with their written consent, which it keeps and shows on the Processor's request, and without stating weight, measurements or other health information: Art. 2-septies(8) of the Italian Privacy Code prohibits disseminating health data;
- keep data confidential, not copy or disclose it outside the Service without a valid basis, protect its own credentials and complete two-step verification when required;
- immediately report suspicious access or breaches it becomes aware of to info@athleex.com;
- independently retain its tax documents: the Service is not a compliant document-retention system.
7. Security of processing
The Processor adopts measures appropriate to the risk (Art. 32 GDPR), updated over time:
- encrypted connections (TLS 1.2/1.3, HSTS); EU server (Hetzner, Germany) accessible only with an SSH key and protected by a firewall; database not exposed; the application runs without administrator privileges;
- application-level access control: the Controller sees only the data of athletes with an active relationship; health data only with athlete consent; photos, videos, attachments and invoices served only after authorisation is verified; a health-data access log;
- Argon2id passwords, following the guidelines of the Italian cybersecurity agency (ACN); two-step verification mandatory for administrators (phishing-resistant passkey) and for PTs with access to health data (authenticator app or email code; sessions of at most 7 days that expire after 24 hours of inactivity); passkeys; session list and revocation; an alert for every sign-in from a new device; password confirmation before a full data export;
- a limited authorised staff, bound by confidentiality, using a second factor, with logged administrative access;
- daily encrypted backups (AES-256 with integrity verification) of database and files, retained 14 days on the server and 60 days in an off-site EU copy; an automatic monthly restore test;
- continuous monitoring with alerts, rotated server logs, automatic operating-system security updates;
- push notifications without message content or health data;
- removal of metadata, including location, from uploaded images and videos; uploaded files encrypted on the server (AES-256-GCM); a security-event log with alerts.
The server's disks are not encrypted at the operating-system level: uploaded files are encrypted by the application and backups before leaving the server.
8. Sub-processors
The Controller grants general authorisation to use sub-processors. The current list, with purpose and place of processing, is published at athleex.com/legal/sub-processors. The Processor notifies the Controller by email of the addition or replacement of a sub-processor with at least 30 days' notice; the Controller may object for documented data-protection reasons and, if no solution is found, terminate the Service. The Processor imposes equivalent data-protection obligations on sub-processors (Art. 28(4) GDPR) and is liable for their conduct.
9. Assistance with data subject rights
The Service lets the athlete export their data in JSON and PDF, correct it, withdraw consents, opt out of Churn Radar and delete their account; the Controller can export the data processed on its behalf as provided in point 13. Requests the Processor receives regarding data processed on the Controller's behalf are forwarded to the Controller within 5 business days; the Processor provides the tools and information needed to respond.
10. Personal data breaches
The Processor notifies the Controller of any breach of data processed on its behalf, including at a sub-processor, without undue delay and in any event within 48 hours of becoming aware, at the account's email address, even with partial information: the information required by Art. 33(3) GDPR available at the time, supplemented as it becomes available, so that the Controller can notify the supervisory authority within 72 hours. The Processor documents every breach and takes measures to contain it.
11. Impact assessment and prior consultation
The Processor has carried out an impact assessment of the Service and makes a summary of the risks and measures available to the Controller on request, to support the Controller's own assessments (Arts. 35-36 GDPR).
12. International transfers
Servers, database and backups remain in the EU. Sub-processors that may process data in the United States operate on the basis of the EU-US Data Privacy Framework for the companies that are certified and in any case of Standard Contractual Clauses (Decision (EU) 2021/914) with supplementary measures assessed by the Processor. Push notifications, which pass through Apple and Google, do not contain message content or health data.
13. End of service: return and deletion
At any time the Controller can export from Settings » Export my data, in structured JSON with files in their original format, the data it entered in the Service (profile, public page, athletes and relationships, programs, meal plans, advice, supplements, notes, calendar, feedback, fees and invoices, contacts received, messages, challenges). On request the Processor provides within 30 days the full copy of the data processed on the Controller's behalf, including workouts logged by athletes and, within the limits of their consent, shared health data. When the Controller's account is closed, data processed on its behalf is deleted, at the end of the retrieval period set out in the Terms (section 10) if the Controller asked to switch to another provider. Data of athletes who have their own account remains in the athlete's account, of which Refreesh is the controller. Copies in encrypted backups are deleted when they expire (at most 60 days).
14. Audits and verification
On reasoned written request, the Processor provides the information needed to demonstrate compliance with the DPA, including a description of its security measures and the impact-assessment summary. If further verification is needed, the Controller may request, with reasonable notice and at its own expense, an audit by an independent auditor bound by confidentiality, carried out in a manner that does not compromise security or the data of other customers.
15. Liability
The parties' liability follows the Terms of Service, except where the law does not permit limitations, in particular Art. 82 GDPR.
16. Governing law and venue
The DPA is governed by Italian law and the GDPR. The courts of Milan, the Processor's registered office, have jurisdiction over disputes between the parties, without prejudice to data subjects' mandatory rights to bring proceedings before their own court or the supervisory authority.
17. Contact
For communications about the DPA write to Refreesh's privacy contact: info@athleex.com. Refreesh has not appointed a Data Protection Officer (DPO) because it is not mandatory. Expected response time: 5 business days.