👋

Gymkee
  • Funcionalidades
    Copiloto IA
    • Dwayne AI
    Fitness
    • Programas e treinos
    • Biblioteca de exercícios
    • On-demand
    Nutrição
    • Planos alimentares
    • Receitas
    Gestão de clientes
    • Acompanhamento de clientes
    • Avaliações
    • Hábitos
    • Gymkee Pay
    App do Cliente
    • Treinos
    • Nutrição
    • Avaliação
    • Hábitos
    • Acompanhamento
    Personalização
    • Branding personalizado
    • App white-label
    Todas as funcionalidades
  • Preços
  • Conteúdo
    Aprender & Descobrir
    • Biblioteca de exercícios
    • Blog
    • Vídeos YouTube
    • Podcast
    • Cursos gratuitos
    • Webinários
    Todas as funcionalidades
🇺🇸 English 🇫🇷 Français 🇪🇸 Español 🇩🇪 Deutsch 🇮🇹 Italiano 🇵🇹 Português 🇨🇳 中文 🇰🇷 한국어 🇯🇵 日本語 🇳🇱 Nederlands 🇹🇷 Türkçe 🇵🇱 Polski
Entrar Experimenta Gymkee grátis
Gymkee
  • Copiloto IA
    • Dwayne AI
    Fitness
    • Programas e treinos
    • Biblioteca de exercícios
    • On-demand
    Nutrição
    • Planos alimentares
    • Receitas
    Gestão de clientes
    • Acompanhamento de clientes
    • Avaliações
    • Hábitos
    • Gymkee Pay
    App do Cliente
    • Treinos
    • Nutrição
    • Avaliação
    • Hábitos
    • Acompanhamento
    Personalização
    • Branding personalizado
    • App white-label
    Todas as funcionalidades
  • Preços
  • Aprender & Descobrir
    • Biblioteca de exercícios
    • Blog
    • Vídeos YouTube
    • Podcast
    • Cursos gratuitos
    • Webinários
    Todas as funcionalidades
  • 🇺🇸 English
  • 🇫🇷 Français
  • 🇪🇸 Español
  • 🇩🇪 Deutsch
  • 🇮🇹 Italiano
  • 🇵🇹 Português
  • 🇨🇳 中文
  • 🇰🇷 한국어
  • 🇯🇵 日本語
  • 🇳🇱 Nederlands
  • 🇹🇷 Türkçe
  • 🇵🇱 Polski
Experimenta Gymkee grátis Entrar

Acordo de Processamento de Dados (DPA)

Last updated: 23 de março de 2026

Este documento está disponível em francês (versão oficial) e inglês. Em caso de discrepância, prevalece a versão francesa.

Ler em francês | Ler em inglês

This Data Processing Agreement (hereinafter referred to as "DPA") is entered into between:

The Data Controller: the Coach, an individual or legal entity, professional user of the Gymkee platform, acting as the data controller under the GDPR for the personal data of their Clients/Athletes (hereinafter the "Controller"),

And the Processor: KEEZOKU, a simplified joint-stock company (SAS) with a capital of €5,000.00, registered with the Paris R.C.S. under number 847 647 054, with its head office located at 60 rue François Ier, 75008 Paris, France, operating under the trade name "Gymkee" (hereinafter the "Processor" or "Gymkee").

This DPA is an integral part of Gymkee's General Terms of Use and Sale (GTU/GTS) and applies to the extent that Gymkee processes personal data on behalf of the Controller in the provision of Services.


ARTICLE 1 , DEFINITIONS

The terms used in this DPA have the meaning given to them by the General Data Protection Regulation (Regulation EU 2016/679, hereinafter "GDPR"), including:

  • "Personal Data": any information relating to an identified or identifiable natural person.
  • "Health Data": personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, revealing information about the person's health status (Art. 4(15) GDPR).
  • "Processing": any operation or set of operations performed on personal data, whether or not by automated means.
  • "Data Subject": the Client/Athlete whose data is processed.
  • "Data Breach": a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
  • "Sub-processor": any processor engaged by Gymkee to process personal data on behalf of the Controller.

ARTICLE 2 , PURPOSE AND SCOPE

2.1 Purpose

This DPA sets out the terms under which Gymkee, as a processor, processes personal data on behalf of the Controller, in accordance with Article 28 of the GDPR.

2.2 Data Processed

The categories of data processed by Gymkee on behalf of the Controller are:

Category Examples
Identification Data Name, first name, email address, Client's profile photo
Profile Data Date of birth, gender
Health Data (Art. 9 GDPR) Weight, height, body measurements, body fat percentage, BMI
Nutritional Data (Art. 9 GDPR) Caloric intake, macros, food journal, dietary preferences, allergies
Training Data (Art. 9 GDPR) Performance (weights, reps, time), heart rate, session history
Communication Data Messages exchanged between the Coach and the Client via the platform
Tracking Data Notes, assessments, goals, progress

2.3 Data Subjects

The data subjects are the Clients/Athletes of the Controller who use the Gymkee mobile app.

2.4 Processing Purposes

Gymkee processes personal data solely for the following purposes, on the Controller's instructions:

  • data hosting and storage;
  • making data available and displaying it via the mobile app;
  • transmitting data to the Controller via the Coach web app;
  • technical operations necessary for the provision of Services (backup, indexing, search);
  • processing payments between the Client and the Controller via Gymkee Pay.

2.5 Duration

This DPA is effective for the duration of the contractual relationship between the Controller and Gymkee. Obligations regarding data confidentiality and security survive the end of the contract.


ARTICLE 3 , OBLIGATIONS OF GYMKEE (PROCESSOR)

In accordance with Article 28(3) of the GDPR, Gymkee commits to:

3.1 Documented Instructions

Process personal data only on documented instructions from the Controller, including with regard to data transfers to a third country or an international organization, unless required by law to do so. In such a case, Gymkee will inform the Controller of that legal obligation before processing, unless prohibited by law.

If Gymkee considers an instruction from the Controller to be a violation of the GDPR or applicable regulations, Gymkee will immediately inform the Controller.

3.2 Confidentiality

Ensure that persons authorized to process personal data are under a contractual obligation of confidentiality or are subject to an appropriate legal obligation of confidentiality.

3.3 Security Measures (Art. 32 GDPR)

Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the particular nature of the health data processed, including:

Certified Hosting:

  • Data is hosted on Amazon Web Services (AWS) infrastructure in the eu-west-3 region (Paris, France), certified as a Health Data Host (HDS) in accordance with Article L.1111-8 of the French Public Health Code.

Technical Measures:

  • encryption of data in transit (TLS 1.2 minimum) and at rest (AES-256);
  • secure authentication and access management with the principle of least privilege;
  • logical separation of data between Controllers (secure multi-tenancy);
  • regular and encrypted backups with a disaster recovery plan;
  • intrusion monitoring and detection;
  • logging of data access;
  • separation of environments (development, testing, production);
  • regular security testing.

Organizational Measures:

  • data access limited to team members with an operational need;
  • staff training on best data protection practices;
  • security incident management procedure;
  • regular evaluation of security measures.

3.4 Sub-processors

a) The Controller generally authorizes Gymkee to engage sub-processors for personal data processing, subject to the following conditions.

b) Gymkee maintains an up-to-date list of its sub-processors, accessible at gymkee.com/legal/sub-processors. This list specifies the name, country, and function of each sub-processor.

c) Gymkee will inform the Controller by email of any addition or replacement of a sub-processor at least thirty (30) days before the change is implemented, allowing the Controller to object.

d) If the Controller objects to a new sub-processor for legitimate data protection reasons, the parties will discuss in good faith an alternative solution. If no solution is found within thirty (30) days, the Controller may terminate their Subscription.

e) Gymkee ensures contractually that each sub-processor is subject to data protection obligations at least equivalent to those provided in this DPA.

f) Gymkee remains fully liable to the Controller for the performance of its sub-processors' obligations.

3.5 Data Subject Rights

a) Gymkee will assist the Controller, as far as possible and considering the nature of the processing, in responding to data subjects' requests to exercise their rights (access, rectification, erasure, portability, restriction, objection).

b) If Gymkee directly receives a data subject's request to exercise their rights, Gymkee will inform the Controller as soon as possible and will not respond directly to the request, unless instructed otherwise by the Controller.

c) Gymkee provides technical features in the platform allowing the Controller to respond to access, rectification, and erasure requests independently (data export, Client deletion).

3.6 Security and Compliance Assistance

Gymkee will assist the Controller with:

  • notifying data breaches to the supervisory authority (Art. 33 GDPR);
  • communicating data breaches to data subjects (Art. 34 GDPR);
  • conducting data protection impact assessments (DPIA) where the type of processing requires it (Art. 35-36 GDPR).

3.7 Data Deletion or Return

a) At the end of the contractual relationship, at the Controller's request, Gymkee will:

  • return all personal data to the Controller in a structured, machine-readable format; and/or
  • delete all personal data and existing copies, at the Controller's choice.

b) Deletion will occur within thirty (30) days following the end of the contract, unless a legal obligation requires data retention.

c) Gymkee will provide the Controller with written confirmation of deletion upon request.

3.8 Audit

a) Gymkee will make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR.

b) The Controller (or a third-party auditor appointed by the Controller) may conduct audits, including inspections, to verify compliance with this DPA, subject to:

  • reasonable notice of thirty (30) days;
  • conducting during business hours;
  • non-disruption of Gymkee's operations;
  • the auditor's submission to confidentiality obligations.

c) Gymkee will contribute in good faith to these audits. The costs of the audit will be borne by the Controller, unless the audit reveals a substantial breach by Gymkee of this DPA.


ARTICLE 4 , OBLIGATIONS OF THE CONTROLLER (COACH)

The Controller commits to:

4.1 Lawfulness of Processing

a) Have a valid legal basis for each personal data processing carried out via Gymkee, in accordance with Articles 6 and 9 of the GDPR.

b) In particular, for health data (measurements, nutritional data, training data), the Controller must obtain the explicit consent of the data subject in accordance with Article 9(2)(a) of the GDPR, in a separate, specific, informed, and unambiguous manner.

c) Gymkee provides a consent collection mechanism in the mobile app. The Controller is responsible for verifying that this consent is properly collected before processing health data.

4.2 Informing Data Subjects

Inform their Clients transparently about the processing of their personal data via Gymkee, in accordance with Articles 13 and 14 of the GDPR, including:

  • the identity of the data controller (the Coach);
  • the purposes and legal bases of the processing;
  • the categories of data collected;
  • the fact that Gymkee (KEEZOKU) acts as a processor;
  • the data subjects' rights and how to exercise them;
  • the retention period.

4.3 Lawful Instructions

Only give Gymkee instructions that comply with the GDPR and applicable data protection regulations.

4.4 Notification of Requests

Notify Gymkee without undue delay of any data subject's request to exercise their rights, to the extent that this request requires Gymkee's technical assistance.


ARTICLE 5 , HEALTH DATA , SPECIFIC PROVISIONS

Given the particular nature of the health data processed via Gymkee:

5.1 Strict Purpose Limitation

Gymkee is prohibited from using Clients' health data for any purpose other than providing Services to the Controller, including:

  • not using health data for KEEZOKU's own product development;
  • not using health data for training AI models;
  • not using health data for non-anonymized statistical analyses;
  • not commercializing, selling, or licensing health data to third parties.

5.2 Enhanced Measures

In addition to the security measures provided in Article 3.3, health data benefits from the following enhanced measures:

  • logging of all access to health data;
  • strict access control limited to strictly necessary technical staff;
  • systematic encryption at rest with securely managed keys;
  • logical separation allowing targeted deletion of health data upon withdrawal of consent.

5.3 Withdrawal of Consent

In case of a Client's withdrawal of consent for processing their health data:

  • Gymkee will cease processing the concerned health data as soon as possible;
  • health data will be deleted within thirty (30) days following the withdrawal;
  • other personal data (identification data, communication data) will not be affected;
  • the Controller will be informed of the withdrawal.

ARTICLE 6 , DATA BREACH

6.1 Notification to the Controller

In the event of a personal data breach, Gymkee will notify the Controller as soon as possible and no later than forty-eight (48) hours after becoming aware of the breach.

6.2 Notification Content

The notification will contain, or be followed as soon as possible by, the following information:

  • the nature of the breach (categories and approximate number of data subjects, categories and approximate number of personal data records concerned);
  • the name and contact details of Gymkee's contact point;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and mitigate its effects.

6.3 Assistance

Gymkee will assist the Controller with notifying the supervisory authority (CNIL) within the 72-hour period provided for in Article 33 of the GDPR, as well as with communicating to data subjects as provided in Article 34.

6.4 Documentation

Gymkee will document any data breach, including the facts, its effects, and corrective measures taken, and will make this documentation available to the Controller.


ARTICLE 7 , INTERNATIONAL TRANSFERS

7.1 Principle

Gymkee processes personal data primarily within the European Economic Area (EEA).

7.2 Framed Transfers

When processing involves a transfer to a country outside the EEA (notably to the United States), this transfer is framed by:

  • an adequacy decision by the European Commission, where applicable;
  • the Standard Contractual Clauses (SCC) adopted by the European Commission (Implementing Decision 2021/914);
  • the EU-US Data Privacy Framework, where the sub-processor is certified;
  • additional technical measures (encryption in transit and at rest).

7.3 List of Sub-processors

The up-to-date list of sub-processors, including their location and applicable safeguards, is available at gymkee.com/legal/sub-processors.


ARTICLE 8 , LIABILITY

8.1 Gymkee's Liability

Gymkee is liable for damages caused by processing that does not comply with the obligations specifically incumbent on the processor under the GDPR, or where Gymkee has acted outside or contrary to the Controller's lawful instructions.

8.2 Limitation

Gymkee's liability under this DPA is subject to the limitations provided in Gymkee's GTU/GTS, to the extent permitted by applicable law.


ARTICLE 9 , GENERAL PROVISIONS

9.1 Hierarchy

In case of conflict between this DPA and Gymkee's GTU/GTS, this DPA prevails for matters related to personal data protection.

9.2 Amendments

Gymkee reserves the right to amend this DPA to reflect changes in applicable regulations or its processing practices. Any substantial amendment will be notified to the Controller by email at least thirty (30) days before it takes effect.

9.3 Governing Law and Jurisdiction

This DPA is governed by French law. The competent courts of Paris have exclusive jurisdiction over any dispute related to this DPA.


ARTICLE 10 , CONTACT

For any questions regarding this DPA:

KEEZOKU , Data Protection 60 rue François Ier, 75008 Paris, France Email: hello@gymkee.com


ANNEX A , LIST OF SUB-PROCESSORS

This list is also available at gymkee.com/legal/sub-processors.

Sub-processor Country Function Data Processed Safeguards
Amazon Web Services EMEA SARL EU (Ireland) Hosting, storage, infrastructure All data SCC + technical measures
MongoDB, Inc. (MongoDB Atlas) EU Database All application data SCC + encryption
Stripe Payments Europe, Ltd. EU (Ireland) Payment processing Payment data SCC + DPF
Cloudflare, Inc. United States Website hosting and CDN Navigation data SCC + DPF
Algolia EU Search (food, exercises) Food data, exercises SCC
Google LLC United States Analytics (GA4, GTM) Anonymized browsing data SCC + DPF
Meta Platforms, Inc. United States Advertising measurement (Meta Pixel) Anonymized conversion data SCC + DPF
Intercom, Inc. United States Customer support, messaging Identification data, messages SCC + DPF
FirstPromoter Netherlands Affiliate and referral tracking Referral data SCC
Twilio Inc. (Segment) United States Analytics (server-side) Anonymized usage data SCC + DPF
Expo (Expo.dev) United States Mobile app distribution Technical data SCC

Legend: SCC = Standard Contractual Clauses; DPF = EU-US Data Privacy Framework; HDS = Health Data Hosting

Gymkee

Gymkee ajuda personal trainers a construir um negócio de coaching profissional com programas de treino, planos nutricionais e gestão de clientes.

Funcionalidades

  • Dwayne AI
  • Programas e treinos
  • Biblioteca de exercícios
  • Planos alimentares
  • Biblioteca de receitas
  • Acompanhamento de clientes
  • Avaliações
  • Acompanhamento de hábitos
  • Programas sob demanda
  • Gymkee Pay
  • Branding personalizado
  • App white-label
  • Aplicativo Móvel do Cliente

Conteúdo

  • Avaliações
  • Blog
  • Vídeos YouTube
  • Podcast
  • Cursos gratuitos
  • Webinários

Produto

  • Todas as funcionalidades
  • Preços
  • Login Coach
  • FAQ
  • Help Center

Empresa

  • Sobre o Gymkee
  • Contacto

Comparar

  • Gymkee vs Trainerize
  • Gymkee vs TrueCoach
  • Gymkee vs My PT Hub
  • Gymkee vs Everfit
  • Gymkee vs PT Distinction
  • Gymkee vs Hexfit

Soluções

  • Software hyrox
  • Software personal trainer
  • App personal trainer
  • Aplicacao personal trainer
  • Software gestao clientes personal trainer
  • Software coaching online
  • Software nutricionista
  • Software treino presencial

Segue-nos

  • Instagram
  • YouTube

© 2026 Gymkee. Todos os direitos reservados.

  • Política de privacidade
  • Termos de serviço
  • Política de cookies
  • Aviso legal

0 kcal. Diet-friendly cookies.

We use cookies

We use cookies to analyze traffic and improve your experience. No non-essential cookies are placed without your consent.

Cookie policy