Skip to content
DPA

Data Processing Addendum

This public DPA summary describes how Afrastic processes customer-controlled data for the platform. Customer-specific signed agreements control where they differ.

Last updated / June 29, 2026

[01]

Roles

For customer-controlled gym and member data, the customer generally acts as the controller or business responsible for deciding why and how the data is used. Afrastic acts as a processor or service provider by processing that data to provide the platform.

Afrastic may act as an independent controller for limited business data such as account administration, billing, fraud prevention, security, legal compliance, and direct customer relationship management.

[02]

Processing details

  • Subject matter: operation of the Afrastic gym management platform.
  • Duration: the customer subscription term plus retention, backup, legal, and dispute-resolution periods.
  • Purpose: provide members, billing, attendance, communication, reporting, platform management, support, security, and related SaaS operations.
  • Data subjects: staff users, gym members, gym administrators, partners, platform users, support contacts, and website visitors.
  • Data categories: identity, contact, role, gym operations, billing, payment status, attendance, communication logs, support, device, usage, and security data.
[03]

Customer instructions

Afrastic processes customer data according to the customer agreement, product configuration, documented instructions, and lawful support or security needs. Customers are responsible for ensuring instructions are lawful and that required notices or consents have been provided.

[04]

Confidentiality and access

Afrastic limits customer-data access to personnel and service providers who need access to operate, secure, support, or improve the platform. Personnel and providers are expected to handle customer data under confidentiality obligations.

[05]

Security measures

  • Role-based access controls and tenant-scoped data design.
  • Authentication, password reset, optional 2FA, and session controls.
  • Audit logs, security event tracking, platform health checks, and operational backup practices.
  • Administrative processes for account lifecycle, support access, incident response, and service monitoring.
[06]

Subprocessors

Afrastic may use subprocessors to provide hosting, database, storage, messaging, email, monitoring, analytics, backup, and support functions. The public subprocessor page describes categories and change notice expectations.

[07]

Assistance

Afrastic will provide reasonable assistance, within the service functionality and applicable agreement, for customer requests related to data access, correction, export, deletion, security, and compliance obligations.

[08]

Security incidents

Afrastic will notify affected customers of a confirmed security incident involving customer data as required by the applicable agreement and law. Customers are responsible for downstream notices to their own staff, members, or regulators unless otherwise agreed.

[09]

Return and deletion

Upon termination, customers may request export or deletion of customer data subject to technical feasibility, backup cycles, legal retention, security, fraud prevention, and unpaid account obligations.