Data Processing Agreement
This agreement forms part of the Terms of Service between Mat Track Ltd and the gym using the service. It sets out how we process personal data on your behalf, and it is the written contract required by Article 28 of the UK GDPR. You do not need to sign a separate copy, though we will sign one on request.
1. Who is who
Mat Track Ltd is registered in England and Wales under company number 16691859, at Unit 18 Gateway 1000, Whittle Way, Stevenage, England, SG1 2FP.
You, the gym, are the controller of your members' personal data. You decide what to collect and why. Mat Track Ltd is the processor. We act only on your instructions.
For our own business data, such as your account and billing details, we are the controller and our Privacy Policy applies.
2. What we process, and why
The details required by Article 28(3) are in Annex 1. In summary: we process the personal data your gym enters into Mat Track, or that your members enter themselves, for the sole purpose of providing the service described in our Terms, for as long as your account is open.
3. Our obligations
We will:
(a) Follow your instructions. We process personal data only on your documented instructions, which include your use of the platform's features and your settings. If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process data for another reason, we will tell you first unless the law forbids it.
(b) Keep it confidential. Everyone we authorise to access personal data is bound by a duty of confidentiality.
(c) Keep it secure. We maintain the technical and organisational measures in Annex 2, appropriate to the risk under Article 32.
(d) Control sub-processors. You give us general authorisation to use the sub-processors in Annex 3. We impose the same data protection obligations on each of them, and we remain liable to you for their performance. We will give you at least 30 days' notice by email before adding or replacing one. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you to find a solution; if we cannot, you may terminate the affected service without penalty.
(e) Help you answer your members. If a member contacts us directly to exercise their rights, we will refer them to you. We will help you respond, using the platform's own export and deletion tools where they do the job, and we will not charge for reasonable assistance.
(f) Help you meet your other duties. We will assist you with security, breach notification, data protection impact assessments and prior consultation, taking into account what we know and what is available to us.
(g) Tell you about breaches. If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 48 hours, with the detail you need for your own reporting.
(h) Return or delete at the end. When your account closes, you can export your data. After 30 days we will delete it from our live systems, and from backups within a further 90 days, unless the law requires us to keep it.
(i) Show our working. We will give you the information you reasonably need to show you comply with Article 28, and allow audits or inspections on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise.
4. Your obligations
You confirm that you have a lawful basis for the personal data you put into Mat Track, that you have given your members the privacy information they are entitled to, and that your instructions to us comply with data protection law. You are responsible for what you choose to collect, including through waiver and document features.
5. Special category data
Waivers and forms in Mat Track are free-form, which means you may choose to collect health or injury information. That is special category data under Article 9 and needs an Article 9 condition as well as a lawful basis before you collect it. We process it only as part of the document you have configured, apply the same security measures, and take no separate view of its content. If you intend to collect health information, take your own advice on the Article 9 condition first.
6. Children
Gyms commonly enrol junior members. Where you record data about a child, you are the controller and you are responsible for the fairness of that collection, including parental consent where it is required and age-appropriate privacy information. The platform supports family and group accounts so a parent can be the account holder. We apply the same protections to children's data as to adults', and we do not profile children or use their data for marketing.
7. International transfers
Your data is stored in the United Kingdom. Where a sub-processor in Annex 3 processes data outside the UK, we rely on UK adequacy regulations or on standard contractual clauses with the UK International Data Transfer Addendum. We will not transfer your data outside the UK on any other basis without telling you.
8. Liability
Liability under this agreement is subject to the limits in our Terms of Service, except where data protection law does not allow those limits to apply.
Annex 1: details of the processing
Subject matter: provision of the Mat Track gym management platform and member app.
Duration: for as long as your account is open, plus the deletion periods in clause 3(h).
Nature and purpose: storing, organising, retrieving, displaying, transmitting and deleting member records so you can run your gym: membership administration, attendance and check-in, class scheduling and booking, rank and grading records, billing, communication with members, waivers and documents, and analytics including attendance-based retention alerts.
Types of personal data: name; email address; phone number; profile photo; date of birth or age where you collect it; membership plan and status; family or guardian links; attendance and check-in records; class bookings; rank, belt and grading history; payment status and history; waiver and document content, which may include health or injury information if you choose to collect it; messages exchanged through the platform.
Categories of data subjects: your gym's members, including junior members; prospective members and leads; parents and guardians; your staff and coaches.
Annex 2: security measures
- Encryption of data in transit (TLS) and at rest.
- Row-level security so each gym's data is isolated and accessible only to that gym.
- Authentication by JSON Web Tokens; passwordless magic-link sign-in for members, so no member passwords are stored.
- Role-based access control, so gym staff see only what their role allows.
- Access to production systems limited to staff who need it, protected by multi-factor authentication.
- Regular backups, with restoration tested.
- Logging and monitoring of access to production systems.
- Confidentiality obligations for all personnel.
- Vulnerability patching of dependencies and infrastructure.
We may update these measures, provided the level of protection does not fall.
Annex 3: sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, sign-in email | United Kingdom |
| Vercel | Application and website hosting | Global edge network |
| Stripe | Card payments and subscription billing | UK, EU and US |
| GoCardless | Direct debit collection | UK and EU |
| Google (Gmail) | Sending platform email | UK, EU and US |
| HubSpot | Two-way CRM sync, only for Pro accounts that enable it | UK, EU and US |
The current list is always the one published on this page. To be notified of changes, email team@mattrack.io.
