FROG FITNESSBohlin Tech

Personuppgiftsbiträdesavtal

Version 1.0 · Senast uppdaterad: 20 augusti 2026 · Bilaga 1 till PT-avtalet

Detta personuppgiftsbiträdesavtal ("PUB-avtalet") ingås enligt artikel 28.3 i EU:s dataskyddsförordning (GDPR) mellan dig som använder PT Access för din coachningsverksamhet ("PT:n", personuppgiftsansvarig) och Bohlin Tech (enskild firma, Sverige), som tillhandahåller plattformen Frog Fitness ("Biträdet"). PUB-avtalet är en integrerad del av PT-avtalet och godkänns samtidigt med det.

1. Bakgrund och roller

PT:n bedriver coachningsverksamhet och behandlar i den rollen personuppgifter om sina klienter. Plattformen används som verktyg för denna behandling. För klientuppgifter som behandlas inom PT:ns coachningsrelation är PT:n personuppgiftsansvarig och Biträdet personuppgiftsbiträde. För behandling som Biträdet utför för egna ändamål — klienternas egna Frog Fitness-konton, deras egen träningsloggning och Tjänstens drift — är Biträdet självständigt personuppgiftsansvarigt enligt sin integritetspolicy; sådan behandling omfattas inte av detta PUB-avtal.

2. Behandlingens föremål och varaktighet

Föremålet för behandlingen är tillhandahållandet av plattformstjänsterna enligt PT-avtalet. Behandlingen pågår så länge PT-avtalet gäller, samt därefter under den avvecklingsperiod som anges i punkt 10.

3. Behandlingens art och ändamål, uppgiftskategorier

Art och ändamålLagring, visning, strukturering, överföring och radering av klientuppgifter i syfte att låta PT:n leverera coachning via Plattformen (programtilldelning, uppföljning, kommunikation, kostplanering, betalning).
Kategorier av registreradePT:ns klienter (användare som kopplat sitt konto till PT:n).
Kategorier av personuppgifterNamn, e-post, profiluppgifter; träningsdata (pass, program, historik, anteckningar); kroppsdata (vikt, mått, kroppsfoton, veckocheckins); kostdata (måltider, makron, mål); meddelanden mellan PT och klient; referenser till betalningar (aldrig fullständiga kortuppgifter).
Känsliga uppgifterKropps- och kostdata kan utgöra hälsorelaterade uppgifter. Klienten styr själv, per kategori, om de delas med PT:n; delningen kan stängas av när som helst och upprätthålls tekniskt i Plattformens åtkomstregler.

4. Instruktioner

Biträdet behandlar klientuppgifterna endast enligt PT:ns dokumenterade instruktioner. Parterna är överens om att PT-avtalet, detta PUB-avtal och PT:ns användning av Plattformens funktioner utgör de fullständiga instruktionerna. Om Biträdet anser att en instruktion strider mot GDPR eller annan dataskyddslagstiftning ska Biträdet informera PT:n. Biträdet får behandla uppgifterna utanför instruktionerna endast om det krävs enligt unionsrätten eller svensk rätt, och ska i så fall informera PT:n innan behandlingen, om inte lagen förbjuder det.

5. Konfidentialitet

Biträdet säkerställer att personer med behörighet att behandla klientuppgifterna har åtagit sig konfidentialitet eller omfattas av lagstadgad tystnadsplikt.

6. Säkerhet (artikel 32)

Biträdet vidtar lämpliga tekniska och organisatoriska åtgärder för att skydda uppgifterna, bland annat:

7. Underbiträden

PT:n ger ett allmänt förhandstillstånd till att Biträdet anlitar underbiträden för driften av Plattformen. Vid detta avtals datum används:

UnderbiträdeBehandlingPlats
Google (Firebase)Hosting, databas, autentisering, fillagringEU/USA*
StripeBetalningsförmedlingEU/USA*
AnthropicAI-genererade coachningsförslagUSA*
ResendE-postnotiserUSA*
RevenueCatPrenumerationsstatus (app-köp)USA*

* Överföringar utanför EU/EES sker med stöd av EU–US Data Privacy Framework eller EU-kommissionens standardavtalsklausuler.

Biträdet informerar om planerade byten eller tillägg av underbiträden (via portalen eller e-post) så att PT:n kan invända. Vid befogad invändning som inte kan lösas har PT:n rätt att säga upp PT-avtalet. Biträdet ålägger varje underbiträde samma dataskyddsskyldigheter som i detta PUB-avtal och ansvarar fullt ut för underbiträdenas behandling.

8. Bistånd till PT:n

9. Personuppgiftsincidenter

Biträdet underrättar PT:n utan onödigt dröjsmål efter att ha fått kännedom om en personuppgiftsincident som rör klientuppgifter, och lämnar den information som skäligen behövs för att PT:n ska kunna uppfylla sin anmälningsskyldighet till tillsynsmyndigheten och de registrerade.

10. Radering vid avtalets upphörande

När PT-avtalet upphör förlorar PT:n åtkomsten till klientuppgifterna via coachytan. Eftersom klienternas konton och data ägs av klienterna själva och fortsätter finnas i deras egna Frog Fitness-konton, raderas inte klienternas egna konton — däremot raderas eller avidentifieras det som är specifikt för PT-relationen (kopplingen, PT:ns anteckningar och tilldelningar) inom 90 dagar, om inte lagring krävs enligt lag. PT:n kan före upphörandet begära ett utdrag av det material PT:n själv skapat.

11. Granskning

Biträdet ger PT:n tillgång till den information som skäligen krävs för att visa att skyldigheterna i artikel 28 GDPR fullgörs, och möjliggör och bidrar till granskningar. Granskning sker i första hand genom skriftlig dokumentation; inspektion på plats kräver 30 dagars varsel, får inte äventyra andra kunders säkerhet och sker på PT:ns bekostnad.

12. Ansvar och ersättning

Ansvarsfördelningen följer artikel 82 GDPR. I övrigt gäller ansvarsbegränsningen i PT-avtalet även för detta PUB-avtal, utom där tvingande rätt föreskriver annat. Ingen särskild ersättning utgår för biträdets åtaganden enligt detta avtal; de ingår i PT Access-prenumerationen.

13. Avtalstid och ändringar

PUB-avtalet gäller så länge Biträdet behandlar klientuppgifter för PT:ns räkning. Ändringar görs på samma sätt som ändringar i PT-avtalet (30 dagars varsel vid väsentliga ändringar).

14. Kontakt

Bohlin Tech (enskild firma), Sverige · info@frogfitness.se

Data Processing Agreement

Version 1.0 · Last updated: 20 August 2026 · Appendix 1 to the PT Agreement

This English translation is provided for convenience. In case of any discrepancy, the Swedish version prevails.

This data processing agreement (the "DPA") is entered into under Article 28(3) of the EU General Data Protection Regulation (GDPR) between you who use PT Access for your coaching business (the "PT", data controller) and Bohlin Tech (sole proprietorship, Sweden), which provides the Frog Fitness platform (the "Processor"). The DPA is an integral part of the PT Agreement and is accepted together with it.

1. Background and roles

The PT conducts a coaching business and, in that role, processes personal data about their clients. The Platform is used as a tool for this processing. For client data processed within the PT's coaching relationship, the PT is the data controller and the Processor is the data processor. For processing the Processor carries out for its own purposes — the clients' own Frog Fitness accounts, their own training logging and the operation of the Service — the Processor is an independent data controller under its privacy policy; such processing is not covered by this DPA.

2. Subject matter and duration of the processing

The subject matter of the processing is the provision of the platform services under the PT Agreement. The processing continues for as long as the PT Agreement is in force, and thereafter during the wind-down period set out in section 10.

3. Nature and purpose of the processing, data categories

Nature and purposeStorage, display, structuring, transfer and deletion of client data for the purpose of enabling the PT to deliver coaching via the Platform (program assignment, follow-up, communication, meal planning, payment).
Categories of data subjectsThe PT's clients (users who have linked their account to the PT).
Categories of personal dataName, email, profile details; training data (workouts, programs, history, notes); body data (weight, measurements, body photos, weekly check-ins); nutrition data (meals, macros, goals); messages between PT and client; references to payments (never full card details).
Sensitive dataBody and nutrition data may constitute health-related data. The client controls, per category, whether it is shared with the PT; sharing can be turned off at any time and is enforced technically in the Platform's access rules.

4. Instructions

The Processor processes the client data only on the PT's documented instructions. The parties agree that the PT Agreement, this DPA and the PT's use of the Platform's features constitute the complete instructions. If the Processor considers that an instruction infringes the GDPR or other data protection legislation, the Processor shall inform the PT. The Processor may process the data outside the instructions only where required by Union or Swedish law, and shall in that case inform the PT before processing, unless the law prohibits it.

5. Confidentiality

The Processor ensures that persons authorised to process the client data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Security (Article 32)

The Processor implements appropriate technical and organisational measures to protect the data, including:

7. Sub-processors

The PT gives general prior authorisation for the Processor to engage sub-processors for the operation of the Platform. As of the date of this agreement, the following are used:

Sub-processorProcessingLocation
Google (Firebase)Hosting, database, authentication, file storageEU/USA*
StripePayment processingEU/USA*
AnthropicAI-generated coaching suggestionsUSA*
ResendEmail notificationsUSA*
RevenueCatSubscription status (app purchases)USA*

* Transfers outside the EU/EEA take place on the basis of the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.

The Processor gives notice of planned replacements or additions of sub-processors (via the portal or email) so that the PT can object. In case of a justified objection that cannot be resolved, the PT has the right to terminate the PT Agreement. The Processor imposes the same data protection obligations as in this DPA on each sub-processor and remains fully liable for the sub-processors' processing.

8. Assistance to the PT

9. Personal data breaches

The Processor notifies the PT without undue delay after becoming aware of a personal data breach concerning client data, and provides the information reasonably needed for the PT to fulfil its notification obligations to the supervisory authority and the data subjects.

10. Deletion upon termination

When the PT Agreement ends, the PT loses access to the client data via the coach workspace. Since the clients' accounts and data are owned by the clients themselves and continue to exist in their own Frog Fitness accounts, the clients' own accounts are not deleted — however, what is specific to the PT relationship (the link, the PT's notes and assignments) is deleted or de-identified within 90 days, unless retention is required by law. Before termination, the PT may request an extract of the material the PT has created.

11. Audits

The Processor makes available to the PT the information reasonably necessary to demonstrate compliance with the obligations in Article 28 GDPR, and allows for and contributes to audits. Audits are conducted primarily through written documentation; on-site inspections require 30 days' notice, must not jeopardise other customers' security, and are at the PT's expense.

12. Liability and compensation

The allocation of liability follows Article 82 GDPR. Otherwise, the limitation of liability in the PT Agreement also applies to this DPA, except where mandatory law provides otherwise. No separate fee is charged for the Processor's undertakings under this agreement; they are included in the PT Access subscription.

13. Term and changes

The DPA applies for as long as the Processor processes client data on the PT's behalf. Changes are made in the same way as changes to the PT Agreement (30 days' notice for material changes).

14. Contact

Bohlin Tech (sole proprietorship), Sweden · info@frogfitness.se