Personuppgiftsbiträdesavtal
Detta personuppgiftsbiträdesavtal ("PUB-avtalet") ingås enligt artikel 28.3 i EU:s dataskyddsförordning (GDPR) mellan dig som använder PT Access för din coachningsverksamhet ("PT:n", personuppgiftsansvarig) och Bohlin Tech (enskild firma, Sverige), som tillhandahåller plattformen Frog Fitness ("Biträdet"). PUB-avtalet är en integrerad del av PT-avtalet och godkänns samtidigt med det.
1. Bakgrund och roller
PT:n bedriver coachningsverksamhet och behandlar i den rollen personuppgifter om sina klienter. Plattformen används som verktyg för denna behandling. För klientuppgifter som behandlas inom PT:ns coachningsrelation är PT:n personuppgiftsansvarig och Biträdet personuppgiftsbiträde. För behandling som Biträdet utför för egna ändamål — klienternas egna Frog Fitness-konton, deras egen träningsloggning och Tjänstens drift — är Biträdet självständigt personuppgiftsansvarigt enligt sin integritetspolicy; sådan behandling omfattas inte av detta PUB-avtal.
2. Behandlingens föremål och varaktighet
Föremålet för behandlingen är tillhandahållandet av plattformstjänsterna enligt PT-avtalet. Behandlingen pågår så länge PT-avtalet gäller, samt därefter under den avvecklingsperiod som anges i punkt 10.
3. Behandlingens art och ändamål, uppgiftskategorier
| Art och ändamål | Lagring, visning, strukturering, överföring och radering av klientuppgifter i syfte att låta PT:n leverera coachning via Plattformen (programtilldelning, uppföljning, kommunikation, kostplanering, betalning). |
|---|---|
| Kategorier av registrerade | PT:ns klienter (användare som kopplat sitt konto till PT:n). |
| Kategorier av personuppgifter | Namn, e-post, profiluppgifter; träningsdata (pass, program, historik, anteckningar); kroppsdata (vikt, mått, kroppsfoton, veckocheckins); kostdata (måltider, makron, mål); meddelanden mellan PT och klient; referenser till betalningar (aldrig fullständiga kortuppgifter). |
| Känsliga uppgifter | Kropps- och kostdata kan utgöra hälsorelaterade uppgifter. Klienten styr själv, per kategori, om de delas med PT:n; delningen kan stängas av när som helst och upprätthålls tekniskt i Plattformens åtkomstregler. |
4. Instruktioner
Biträdet behandlar klientuppgifterna endast enligt PT:ns dokumenterade instruktioner. Parterna är överens om att PT-avtalet, detta PUB-avtal och PT:ns användning av Plattformens funktioner utgör de fullständiga instruktionerna. Om Biträdet anser att en instruktion strider mot GDPR eller annan dataskyddslagstiftning ska Biträdet informera PT:n. Biträdet får behandla uppgifterna utanför instruktionerna endast om det krävs enligt unionsrätten eller svensk rätt, och ska i så fall informera PT:n innan behandlingen, om inte lagen förbjuder det.
5. Konfidentialitet
Biträdet säkerställer att personer med behörighet att behandla klientuppgifterna har åtagit sig konfidentialitet eller omfattas av lagstadgad tystnadsplikt.
6. Säkerhet (artikel 32)
Biträdet vidtar lämpliga tekniska och organisatoriska åtgärder för att skydda uppgifterna, bland annat:
- kryptering av data under överföring,
- åtkomstkontroll genom autentisering och behörighetsregler på databasnivå, inklusive tekniskt upprätthållda delningsspärrar per datakategori,
- separation mellan klienters, PT:s och administratörers behörigheter,
- löpande säkerhetskopiering samt loggning av administrativ åtkomst.
7. Underbiträden
PT:n ger ett allmänt förhandstillstånd till att Biträdet anlitar underbiträden för driften av Plattformen. Vid detta avtals datum används:
| Underbiträde | Behandling | Plats |
|---|---|---|
| Google (Firebase) | Hosting, databas, autentisering, fillagring | EU/USA* |
| Stripe | Betalningsförmedling | EU/USA* |
| Anthropic | AI-genererade coachningsförslag | USA* |
| Resend | E-postnotiser | USA* |
| RevenueCat | Prenumerationsstatus (app-köp) | USA* |
* Överföringar utanför EU/EES sker med stöd av EU–US Data Privacy Framework eller EU-kommissionens standardavtalsklausuler.
Biträdet informerar om planerade byten eller tillägg av underbiträden (via portalen eller e-post) så att PT:n kan invända. Vid befogad invändning som inte kan lösas har PT:n rätt att säga upp PT-avtalet. Biträdet ålägger varje underbiträde samma dataskyddsskyldigheter som i detta PUB-avtal och ansvarar fullt ut för underbiträdenas behandling.
8. Bistånd till PT:n
- Biträdet bistår PT:n, med hänsyn till behandlingens art, att svara på registrerades begäranden (tillgång, rättelse, radering, dataportabilitet m.m.). Klienterna kan dessutom själva utöva flera av rättigheterna direkt i Tjänsten, inklusive fullständig kontoradering.
- Biträdet bistår PT:n med att fullgöra skyldigheterna enligt artiklarna 32–36 GDPR (säkerhet, incidenthantering, konsekvensbedömningar), med hänsyn till den information Biträdet har tillgång till.
9. Personuppgiftsincidenter
Biträdet underrättar PT:n utan onödigt dröjsmål efter att ha fått kännedom om en personuppgiftsincident som rör klientuppgifter, och lämnar den information som skäligen behövs för att PT:n ska kunna uppfylla sin anmälningsskyldighet till tillsynsmyndigheten och de registrerade.
10. Radering vid avtalets upphörande
När PT-avtalet upphör förlorar PT:n åtkomsten till klientuppgifterna via coachytan. Eftersom klienternas konton och data ägs av klienterna själva och fortsätter finnas i deras egna Frog Fitness-konton, raderas inte klienternas egna konton — däremot raderas eller avidentifieras det som är specifikt för PT-relationen (kopplingen, PT:ns anteckningar och tilldelningar) inom 90 dagar, om inte lagring krävs enligt lag. PT:n kan före upphörandet begära ett utdrag av det material PT:n själv skapat.
11. Granskning
Biträdet ger PT:n tillgång till den information som skäligen krävs för att visa att skyldigheterna i artikel 28 GDPR fullgörs, och möjliggör och bidrar till granskningar. Granskning sker i första hand genom skriftlig dokumentation; inspektion på plats kräver 30 dagars varsel, får inte äventyra andra kunders säkerhet och sker på PT:ns bekostnad.
12. Ansvar och ersättning
Ansvarsfördelningen följer artikel 82 GDPR. I övrigt gäller ansvarsbegränsningen i PT-avtalet även för detta PUB-avtal, utom där tvingande rätt föreskriver annat. Ingen särskild ersättning utgår för biträdets åtaganden enligt detta avtal; de ingår i PT Access-prenumerationen.
13. Avtalstid och ändringar
PUB-avtalet gäller så länge Biträdet behandlar klientuppgifter för PT:ns räkning. Ändringar görs på samma sätt som ändringar i PT-avtalet (30 dagars varsel vid väsentliga ändringar).
14. Kontakt
Bohlin Tech (enskild firma), Sverige · info@frogfitness.se
Data Processing Agreement
This English translation is provided for convenience. In case of any discrepancy, the Swedish version prevails.
This data processing agreement (the "DPA") is entered into under Article 28(3) of the EU General Data Protection Regulation (GDPR) between you who use PT Access for your coaching business (the "PT", data controller) and Bohlin Tech (sole proprietorship, Sweden), which provides the Frog Fitness platform (the "Processor"). The DPA is an integral part of the PT Agreement and is accepted together with it.
1. Background and roles
The PT conducts a coaching business and, in that role, processes personal data about their clients. The Platform is used as a tool for this processing. For client data processed within the PT's coaching relationship, the PT is the data controller and the Processor is the data processor. For processing the Processor carries out for its own purposes — the clients' own Frog Fitness accounts, their own training logging and the operation of the Service — the Processor is an independent data controller under its privacy policy; such processing is not covered by this DPA.
2. Subject matter and duration of the processing
The subject matter of the processing is the provision of the platform services under the PT Agreement. The processing continues for as long as the PT Agreement is in force, and thereafter during the wind-down period set out in section 10.
3. Nature and purpose of the processing, data categories
| Nature and purpose | Storage, display, structuring, transfer and deletion of client data for the purpose of enabling the PT to deliver coaching via the Platform (program assignment, follow-up, communication, meal planning, payment). |
|---|---|
| Categories of data subjects | The PT's clients (users who have linked their account to the PT). |
| Categories of personal data | Name, email, profile details; training data (workouts, programs, history, notes); body data (weight, measurements, body photos, weekly check-ins); nutrition data (meals, macros, goals); messages between PT and client; references to payments (never full card details). |
| Sensitive data | Body and nutrition data may constitute health-related data. The client controls, per category, whether it is shared with the PT; sharing can be turned off at any time and is enforced technically in the Platform's access rules. |
4. Instructions
The Processor processes the client data only on the PT's documented instructions. The parties agree that the PT Agreement, this DPA and the PT's use of the Platform's features constitute the complete instructions. If the Processor considers that an instruction infringes the GDPR or other data protection legislation, the Processor shall inform the PT. The Processor may process the data outside the instructions only where required by Union or Swedish law, and shall in that case inform the PT before processing, unless the law prohibits it.
5. Confidentiality
The Processor ensures that persons authorised to process the client data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6. Security (Article 32)
The Processor implements appropriate technical and organisational measures to protect the data, including:
- encryption of data in transit,
- access control through authentication and database-level permission rules, including technically enforced sharing restrictions per data category,
- separation between client, PT and administrator permissions,
- continuous backups and logging of administrative access.
7. Sub-processors
The PT gives general prior authorisation for the Processor to engage sub-processors for the operation of the Platform. As of the date of this agreement, the following are used:
| Sub-processor | Processing | Location |
|---|---|---|
| Google (Firebase) | Hosting, database, authentication, file storage | EU/USA* |
| Stripe | Payment processing | EU/USA* |
| Anthropic | AI-generated coaching suggestions | USA* |
| Resend | Email notifications | USA* |
| RevenueCat | Subscription status (app purchases) | USA* |
* Transfers outside the EU/EEA take place on the basis of the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
The Processor gives notice of planned replacements or additions of sub-processors (via the portal or email) so that the PT can object. In case of a justified objection that cannot be resolved, the PT has the right to terminate the PT Agreement. The Processor imposes the same data protection obligations as in this DPA on each sub-processor and remains fully liable for the sub-processors' processing.
8. Assistance to the PT
- The Processor assists the PT, taking into account the nature of the processing, in responding to data subjects' requests (access, rectification, deletion, data portability, etc.). Clients can also exercise several of these rights themselves directly in the Service, including full account deletion.
- The Processor assists the PT in fulfilling the obligations under Articles 32–36 GDPR (security, incident handling, impact assessments), taking into account the information available to the Processor.
9. Personal data breaches
The Processor notifies the PT without undue delay after becoming aware of a personal data breach concerning client data, and provides the information reasonably needed for the PT to fulfil its notification obligations to the supervisory authority and the data subjects.
10. Deletion upon termination
When the PT Agreement ends, the PT loses access to the client data via the coach workspace. Since the clients' accounts and data are owned by the clients themselves and continue to exist in their own Frog Fitness accounts, the clients' own accounts are not deleted — however, what is specific to the PT relationship (the link, the PT's notes and assignments) is deleted or de-identified within 90 days, unless retention is required by law. Before termination, the PT may request an extract of the material the PT has created.
11. Audits
The Processor makes available to the PT the information reasonably necessary to demonstrate compliance with the obligations in Article 28 GDPR, and allows for and contributes to audits. Audits are conducted primarily through written documentation; on-site inspections require 30 days' notice, must not jeopardise other customers' security, and are at the PT's expense.
12. Liability and compensation
The allocation of liability follows Article 82 GDPR. Otherwise, the limitation of liability in the PT Agreement also applies to this DPA, except where mandatory law provides otherwise. No separate fee is charged for the Processor's undertakings under this agreement; they are included in the PT Access subscription.
13. Term and changes
The DPA applies for as long as the Processor processes client data on the PT's behalf. Changes are made in the same way as changes to the PT Agreement (30 days' notice for material changes).
14. Contact
Bohlin Tech (sole proprietorship), Sweden · info@frogfitness.se