Last updated: 16 April 2026
Processor: TMDigital Studio Ltd ("we", "us"), the company operating InSync.
Controller: You — the personal trainer who has created an InSync account and processes client personal data through the platform.
This Data Processing Agreement ("DPA") is entered into between TMDigital Studio Ltd (the Processor) and you, the personal trainer using InSync (the Controller). It forms part of and supplements the Terms of Service.
This DPA reflects the requirements of Article 28 of UK GDPR, which requires that any processor processing personal data on behalf of a controller does so under a written contract setting out specific obligations.
By creating an InSync account, you agree to this DPA.
TMDigital Studio Ltd processes personal data on your behalf solely to provide the InSync coaching platform — including the coach portal and branded client mobile app. The processing is necessary to deliver the features you use: storing client records, workout and programme data, nutrition logs, and any other data you enter about your clients.
We process personal data by:
The personal data we process on your behalf includes the following categories:
Health and fitness data is special category data under UK GDPR. You are responsible for ensuring you have an appropriate lawful basis to process this data for your clients — typically explicit consent.
The data subjects whose personal data we process are your clients — the individuals you coach using InSync.
We process client personal data for the duration of your InSync subscription. Upon account closure or termination, client data will be deleted within 30 days unless you request earlier deletion.
As your data processor, we commit to the following:
Process only on your instructions
We will only process your clients' personal data to deliver InSync's features, as described in this DPA and the Terms of Service. We will not use client data for any other purpose, including advertising or profiling.
Ensure confidentiality
Any staff or contractors who access personal data are bound by confidentiality obligations. Access is limited to what is necessary to operate and maintain the platform.
Implement appropriate security measures
We use industry-standard technical and organisational measures to protect personal data, including encryption at rest and in transit, and strict access controls.
Assist with subject rights requests
If one of your clients contacts us directly with a subject rights request (access, erasure, portability, rectification), we will notify you promptly and help you respond within the required timeframes.
Notify you of data breaches
In the event of a personal data breach that affects your clients' data, we will notify you without undue delay and in any case within 72 hours of becoming aware, providing sufficient information for you to meet your own reporting obligations under UK GDPR.
Assist with your compliance obligations
We will provide reasonable assistance to help you comply with your data protection obligations, including data protection impact assessments where required.
Delete or return data on termination
Upon termination of your account, or on your written request, we will securely delete your clients' personal data within 30 days, unless applicable law requires us to retain it.
Make information available
We will make available any information reasonably necessary to demonstrate our compliance with this DPA, and we will cooperate with audits or inspections conducted by you or a mandated auditor, provided that any such audit is conducted with reasonable notice and at your cost.
We use the following approved sub-processor to deliver InSync:
| Sub-processor | Location | Purpose |
|---|---|---|
| Google LLC (Firebase) | USA / EU | Authentication, database (Firestore), and file storage |
By accepting this DPA, you grant us general authorisation to engage the sub-processors listed above. We will notify you of any changes to sub-processors with reasonable advance notice, giving you the opportunity to object before the new sub-processor is engaged.
We have entered into data processing agreements with our sub-processors that impose equivalent obligations to those set out in this DPA.
As the data controller, you are responsible for:
This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.
For any questions relating to this DPA or data protection matters, contact us at:
TMDigital Studio Ltd
support@insynctrainer.com