Last updated 13 August 2026
Data processing addendum
This addendum forms part of the coach terms of service and applies whenever Fullrack PT processes personal data on a coach’s behalf. It is written for a coaching practice, usually of one; the gym edition has its own addendum.
1. Roles
You, the coach, are the controller of your clients’ data. You decide what is collected and why. Scarecrow Innovations Ltd (Fullrack PT) is the processor. We act on your documented instructions — using the service is an instruction — and we never use your clients’ data for our own purposes. We do not sell it, we do not mine it, and we do not train anything on it.
There is one carve-out, and it runs the other way. The share link you can use to recommend Fullrack PT to another trainer is our marketing, not yours. If somebody fills that form in, their details go straight to our own systems — the form asks their consent, and it reads nothing from your database and writes nothing to it. For those leads we are the controller, and what we do with them is in our privacy notice. A client referring a friend to you is the opposite case: that lead is yours, it lands in your own admin list, and we are your processor for it like everything else.
Either way the rule above holds. Your clients’ data is never used for anything of ours.
2. Following your instructions
We process your clients’ data only on your instructions. Using the service is an instruction; so is anything you ask us for in writing. That covers moving data as well as handling it — we will not move your data to a different country or a different provider on our own initiative, and section 5 says where it sits today.
The exception is UK law. If a court order, a regulator or a statute requires us to do something else with your data, we will do it — but we will tell you before we do, unless the same law forbids us from telling you.
If we think one of your instructions breaks the UK GDPR or another data protection law, we will say so and we will not act on it until it is settled. That is not us marking your homework. It is the clause that keeps both of us out of trouble.
3. What we process, and why
| Category | Data | Why |
|---|---|---|
| Clients | Name, email, username, date of birth, join date | Accounts, bookings, the client-count band you pay on |
| Health — special category | Waiver and PAR-Q answers, medical conditions, emergency contact, weight, body composition, max heart rate | Safe training and your duty of care as their coach |
| Nutrition | Food diary entries, macro targets, adherence | Coaching |
| Activity | Sessions, bookings, check-ins, lifts, PRs, programmes, goals, messages | Running your practice |
| Media | Progress photos, voice notes, videos | Coaching — the check-in evidence your clients send you |
| Payments | Amount, date, method, Stripe reference | Your revenue record. No card numbers ever reach Fullrack PT — they stay with Stripe |
Health data is special-category data under Article 9 of the UK GDPR. It is collected behind its own explicit consent step, separate from the waiver, and the consent screen names you as the person holding it. Who can see it is set out in section 6.
The people behind those rows fall into three groups, and it is worth naming all three:
- Clients — the people you coach, including ones you have archived but not erased.
- Emergency contacts — the person a client names to be called if something happens to them in a session. Their name and phone number sit in the client’s health record. They usually did not fill the form in and may not know they are in there. That is data you hold about somebody else, and it is your job to be able to explain it.
- Referral leads — friends of clients who fill in your referral form. Name, a phone number or email address, your client’s name as the referrer, and whatever they type in the note.
We process all of it for one purpose: running your coaching app for you. The processing starts when your app goes live and ends 30 days after the subscription does — those 30 days being the export window in section 12.
4. Sub-processors
| Who | What they do | Where |
|---|---|---|
| Netlify | Hosting, serverless functions, and the database (Netlify Blobs) your practice’s data sits in | US, with UK/EU regions available |
| Stripe | Client payments under your own Stripe account. Fullrack PT receives webhook notifications, not card data. (Your own subscription to us is a separate, controller-side matter — it is in the privacy notice) | US / EU |
| Resend | Sending the app’s emails — client invites and account notices. Receives the recipient’s email address and the message itself | US |
| Open Food Facts | Barcode lookups for branded food products. A barcode is sent; no client data is | EU |
| Google, Apple, Mozilla | Delivering push notifications to a client’s own device — Google FCM on Chrome and Android, Apple APNs on Safari and iPhone, Mozilla autopush on Firefox. Each receives an endpoint identifier for that one device and a payload it cannot read, because the payload is encrypted between our server and the device | US / EU |
| Our email, if you contact support | US / EU |
The barcode scanner your clients use to log food is served from the app itself rather than a public CDN, so no third party is told which of your clients opened it. The lookup that follows sends a barcode number to Open Food Facts and nothing else.
We will give you 30 days’ notice before adding or changing a sub-processor. If you reasonably object you may cancel without penalty.
Every one of them is engaged under a written contract that puts the same data protection obligations on them as this addendum puts on us. If one of them fails, that is our failure — we stay fully liable to you for what they do with your clients’ data, exactly as if we had done it ourselves.
5. Sending data outside the UK
Netlify, Stripe, Resend and Google can process data outside the UK. For each of them we have entered into their own data processing terms, which incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. In that chain you are the exporter, we are your processor, and the provider is the importer.
We keep a transfer risk assessment covering those transfers and we will send it to you if you ask for it. If we ever move the service to a UK or EU region we will say so here, because it is the first thing anyone holding health data asks about.
6. Security
- PINs hashed with PBKDF2 (210,000 iterations, per-user salt). We cannot read a client’s PIN, or yours.
- HTTPS everywhere, with HSTS on, so nothing travels between a client’s phone and the app in the clear. Sessions expire after 30 days; media links use separate short-lived signed tokens.
- Your practice has its own database. Your data and your media live in stores of their own, reached only through your subdomain — another coach’s clients are not merely filtered out of your queries, they are not in your store. The application serving those stores is shared across coaches; that is how the price stays £15. The isolation between practices is enforced on every single request and is covered by automated tests that run before every deployment.
- At rest, Netlify encrypts the stores your data sits in. We do not add a second layer of our own encryption on top, so anyone holding valid credentials for those stores could read what is in them — which is why those credentials are the control that matters, and why they sit with one named person. PINs are the exception: hashed, and unreadable by anyone including us.
- Personal media is gated. A client’s progress photos, voice notes and videos can be opened by the client themselves and by their coach — in a one-coach practice, that means exactly two people.
- Health and waiver records are visible to you and to any staff account you create, because the person taking the session is the person who needs to know about the knee. If you add staff, everyone with that access is bound by the confidentiality your practice owes its clients; deactivating a staff account cuts the access off immediately — their very next request fails, even if their session has not expired.
- Opening a health record is not written to the activity log today. Exports, erasures, PIN resets, billing changes and payment events are. We would rather tell you that than let you assume the log covers more than it does.
- Daily automated snapshots, kept for 14 days, plus a one-click full export you can keep yourself. When a subscription ends, a final snapshot is taken before the 30-day clock runs, so the export window cannot be defeated by an accident in it.
- An activity log records PIN resets, billing changes, exports, erasures and every automated payment event. We keep it for at least 12 months.
- We rehearse a restore from a snapshot at least once a year, and write down how long it took, so that “we take backups” is a tested claim rather than a hopeful one.
7. Staff and confidentiality
Fullrack PT is one person. Thomas Green, director of Scarecrow Innovations Ltd, is the only individual with administrative access to the service, and he is personally bound by a written confidentiality undertaking covering everything he sees in it — during the contract and after it ends. There is no support team, no offshore desk and no rota of contractors holding a login.
If that ever changes, nobody gets access until they are under the same obligation in writing, and access stays limited to what support and maintenance actually require. “Everyone with access is bound by confidentiality” means considerably more when you can count them.
8. Your clients’ rights
We will help you meet a client’s request, by appropriate technical and organisational measures and as far as it is possible for us to do so. Most of the time you will not need us — the tools are in the app, so you can answer a client without waiting on anybody:
- Access and portability — Download their data on any client record produces everything held about them, as one machine-readable file you can hand over as it is. Their photos, voice notes and videos are downloadable from their record as the original files.
- Erasure — Erase this client permanently deletes their account, food diary, messages, photos, training log, programmes and goals, deletes their media files, and anonymises their bookings and payment rows so your session history and your books still add up. It requires the client’s name typed in full and is written to the activity log.
- Rectification — you can correct any record directly.
- Objection and restriction — you can deactivate an account so it cannot be signed into or booked against while you work out what to do with it, which is how a restriction request gets held in practice. A client can withdraw their own marketing consent from the privacy section of their account, and that consent is stored with the date they gave or withdrew it.
Two honest notes about erasure. The record that an erasure happened stays in the activity log, including the client’s name, the date and who did it — we keep it deliberately, because it is how either of us proves to a regulator that the request was actually carried out. And an erased client remains inside the daily snapshots until those age out of the 14-day cycle; after 14 days they are gone from those too.
If you need something the app cannot do — an unusual request, an awkward regulator letter, a client who says the export is incomplete — email us and we will come back to you within five working days, sooner if the clock you are on is shorter. Tell us the deadline you are working to and we will work to it.
If a client contacts us instead of you, we will point them to you and tell you it happened.
9. Breaches, and the rest of the help you can ask for
If we become aware of a personal data breach affecting your clients, we will tell you without undue delay and within 48 hours, with what we know, what we are doing, and what we would suggest you do. You decide whether the ICO and your clients need to be told — you are the controller.
We will also help you with the things around a breach, using the information we hold and to the extent you cannot get there without us: keeping the service secure in the first place (Article 32), telling your clients when a breach is serious enough to warrant it (Article 34), a data protection impact assessment if you carry one out (Article 35), and any prior consultation with the ICO that comes out of it (Article 36). In practice that means answering questions properly and quickly, not writing your assessment for you.
10. Audit
Ask us and we will give you the information you need to show that we are doing what this addendum says — a completed security questionnaire, our sub-processor terms, and whatever our providers publish about their own controls. That is usually the fastest way to an answer and it is where we would rather start.
If that is not enough, you can inspect. On 30 days’ written notice you or an auditor you appoint may audit our processing of your data, once a year, in working hours, without disrupting the service, and under a confidentiality agreement. Other coaches’ data is off limits. If something has gone wrong, or a regulator asks you to, the once-a-year limit does not apply. You cover the cost of your own audit unless it finds we have broken this addendum, in which case we cover it.
11. What you promise us
You are the controller, so some of this can only be true at your end. You confirm that:
- you have a lawful basis for everything you ask us to process, and that you can point to it;
- you have given your clients the privacy information the UK GDPR requires — who you are, what you collect, why, how long for, and who else touches it. The app ships with a client-facing privacy notice naming you as the controller, which you can use as it is or replace with your own;
- you rely on the app’s explicit Article 9 consent step for the health data your clients enter — or, if you collect health data another way, you have your own valid Article 9 condition, not pre-ticked, bundled or assumed;
- any client list you import is data you are entitled to hold, accurate as far as you know, and lawfully obtained from whatever you were using before;
- your instructions to us are lawful, and you will not ask us to do something that puts either of us in breach.
None of that is boilerplate. It is the line between the two of us. We can build the consent step, log the erasure and hold the data properly, but we cannot know whether the client list you brought over was yours to bring — and if it was not, that is on you and not on us. Section 10 of the coach terms says what happens then.
12. Deletion at the end
When your subscription ends, deletion is automatic and the timetable is fixed, because a self-serve product should not need you to negotiate an exit. Your app goes read-only and stays fully exportable for 30 days. About a week before the end we email you a reminder. On day 30 your clients’ data and media are deleted, your subdomain is released, and the snapshots age out of the 14-day cycle in the fortnight that follows — after which nothing of your practice remains with us. Restart inside the window and none of it happens.
If you want deletion sooner than day 30, email us and we will do it and confirm in writing. The one exception is anything UK law requires us to keep, which we will name if it ever applies. Today nothing does.