Last updated 13 August 2026

Data processing addendum

This addendum forms part of the coach terms of service and applies whenever Fullrack PT processes personal data on a coach’s behalf. It is written for a coaching practice, usually of one; the gym edition has its own addendum.

1. Roles

You, the coach, are the controller of your clients’ data. You decide what is collected and why. Scarecrow Innovations Ltd (Fullrack PT) is the processor. We act on your documented instructions — using the service is an instruction — and we never use your clients’ data for our own purposes. We do not sell it, we do not mine it, and we do not train anything on it.

There is one carve-out, and it runs the other way. The share link you can use to recommend Fullrack PT to another trainer is our marketing, not yours. If somebody fills that form in, their details go straight to our own systems — the form asks their consent, and it reads nothing from your database and writes nothing to it. For those leads we are the controller, and what we do with them is in our privacy notice. A client referring a friend to you is the opposite case: that lead is yours, it lands in your own admin list, and we are your processor for it like everything else.

Either way the rule above holds. Your clients’ data is never used for anything of ours.

2. Following your instructions

We process your clients’ data only on your instructions. Using the service is an instruction; so is anything you ask us for in writing. That covers moving data as well as handling it — we will not move your data to a different country or a different provider on our own initiative, and section 5 says where it sits today.

The exception is UK law. If a court order, a regulator or a statute requires us to do something else with your data, we will do it — but we will tell you before we do, unless the same law forbids us from telling you.

If we think one of your instructions breaks the UK GDPR or another data protection law, we will say so and we will not act on it until it is settled. That is not us marking your homework. It is the clause that keeps both of us out of trouble.

3. What we process, and why

CategoryDataWhy
ClientsName, email, username, date of birth, join dateAccounts, bookings, the client-count band you pay on
Health — special categoryWaiver and PAR-Q answers, medical conditions, emergency contact, weight, body composition, max heart rateSafe training and your duty of care as their coach
NutritionFood diary entries, macro targets, adherenceCoaching
ActivitySessions, bookings, check-ins, lifts, PRs, programmes, goals, messagesRunning your practice
MediaProgress photos, voice notes, videosCoaching — the check-in evidence your clients send you
PaymentsAmount, date, method, Stripe referenceYour revenue record. No card numbers ever reach Fullrack PT — they stay with Stripe

Health data is special-category data under Article 9 of the UK GDPR. It is collected behind its own explicit consent step, separate from the waiver, and the consent screen names you as the person holding it. Who can see it is set out in section 6.

The people behind those rows fall into three groups, and it is worth naming all three:

We process all of it for one purpose: running your coaching app for you. The processing starts when your app goes live and ends 30 days after the subscription does — those 30 days being the export window in section 12.

4. Sub-processors

WhoWhat they doWhere
NetlifyHosting, serverless functions, and the database (Netlify Blobs) your practice’s data sits inUS, with UK/EU regions available
StripeClient payments under your own Stripe account. Fullrack PT receives webhook notifications, not card data. (Your own subscription to us is a separate, controller-side matter — it is in the privacy notice)US / EU
ResendSending the app’s emails — client invites and account notices. Receives the recipient’s email address and the message itselfUS
Open Food FactsBarcode lookups for branded food products. A barcode is sent; no client data isEU
Google, Apple, MozillaDelivering push notifications to a client’s own device — Google FCM on Chrome and Android, Apple APNs on Safari and iPhone, Mozilla autopush on Firefox. Each receives an endpoint identifier for that one device and a payload it cannot read, because the payload is encrypted between our server and the deviceUS / EU
GoogleOur email, if you contact supportUS / EU

The barcode scanner your clients use to log food is served from the app itself rather than a public CDN, so no third party is told which of your clients opened it. The lookup that follows sends a barcode number to Open Food Facts and nothing else.

We will give you 30 days’ notice before adding or changing a sub-processor. If you reasonably object you may cancel without penalty.

Every one of them is engaged under a written contract that puts the same data protection obligations on them as this addendum puts on us. If one of them fails, that is our failure — we stay fully liable to you for what they do with your clients’ data, exactly as if we had done it ourselves.

5. Sending data outside the UK

Netlify, Stripe, Resend and Google can process data outside the UK. For each of them we have entered into their own data processing terms, which incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. In that chain you are the exporter, we are your processor, and the provider is the importer.

We keep a transfer risk assessment covering those transfers and we will send it to you if you ask for it. If we ever move the service to a UK or EU region we will say so here, because it is the first thing anyone holding health data asks about.

6. Security

7. Staff and confidentiality

Fullrack PT is one person. Thomas Green, director of Scarecrow Innovations Ltd, is the only individual with administrative access to the service, and he is personally bound by a written confidentiality undertaking covering everything he sees in it — during the contract and after it ends. There is no support team, no offshore desk and no rota of contractors holding a login.

If that ever changes, nobody gets access until they are under the same obligation in writing, and access stays limited to what support and maintenance actually require. “Everyone with access is bound by confidentiality” means considerably more when you can count them.

8. Your clients’ rights

We will help you meet a client’s request, by appropriate technical and organisational measures and as far as it is possible for us to do so. Most of the time you will not need us — the tools are in the app, so you can answer a client without waiting on anybody:

Two honest notes about erasure. The record that an erasure happened stays in the activity log, including the client’s name, the date and who did it — we keep it deliberately, because it is how either of us proves to a regulator that the request was actually carried out. And an erased client remains inside the daily snapshots until those age out of the 14-day cycle; after 14 days they are gone from those too.

If you need something the app cannot do — an unusual request, an awkward regulator letter, a client who says the export is incomplete — email us and we will come back to you within five working days, sooner if the clock you are on is shorter. Tell us the deadline you are working to and we will work to it.

If a client contacts us instead of you, we will point them to you and tell you it happened.

9. Breaches, and the rest of the help you can ask for

If we become aware of a personal data breach affecting your clients, we will tell you without undue delay and within 48 hours, with what we know, what we are doing, and what we would suggest you do. You decide whether the ICO and your clients need to be told — you are the controller.

We will also help you with the things around a breach, using the information we hold and to the extent you cannot get there without us: keeping the service secure in the first place (Article 32), telling your clients when a breach is serious enough to warrant it (Article 34), a data protection impact assessment if you carry one out (Article 35), and any prior consultation with the ICO that comes out of it (Article 36). In practice that means answering questions properly and quickly, not writing your assessment for you.

10. Audit

Ask us and we will give you the information you need to show that we are doing what this addendum says — a completed security questionnaire, our sub-processor terms, and whatever our providers publish about their own controls. That is usually the fastest way to an answer and it is where we would rather start.

If that is not enough, you can inspect. On 30 days’ written notice you or an auditor you appoint may audit our processing of your data, once a year, in working hours, without disrupting the service, and under a confidentiality agreement. Other coaches’ data is off limits. If something has gone wrong, or a regulator asks you to, the once-a-year limit does not apply. You cover the cost of your own audit unless it finds we have broken this addendum, in which case we cover it.

11. What you promise us

You are the controller, so some of this can only be true at your end. You confirm that:

None of that is boilerplate. It is the line between the two of us. We can build the consent step, log the erasure and hold the data properly, but we cannot know whether the client list you brought over was yours to bring — and if it was not, that is on you and not on us. Section 10 of the coach terms says what happens then.

12. Deletion at the end

When your subscription ends, deletion is automatic and the timetable is fixed, because a self-serve product should not need you to negotiate an exit. Your app goes read-only and stays fully exportable for 30 days. About a week before the end we email you a reminder. On day 30 your clients’ data and media are deleted, your subdomain is released, and the snapshots age out of the 14-day cycle in the fortnight that follows — after which nothing of your practice remains with us. Restart inside the window and none of it happens.

If you want deletion sooner than day 30, email us and we will do it and confirm in writing. The one exception is anything UK law requires us to keep, which we will name if it ever applies. Today nothing does.