Data Processing Agreement
Version 1.0
Effective 30 June 2026
Last updated 30 June 2026
1. Background and roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Podyx Pte. Ltd. ("Podyx", "Processor") and the Studio that accepts the Terms ("you", "Controller"). It applies to Podyx's processing of personal data relating to your End Users that we process on your behalf in providing the Services ("End User Personal Data").
For End User Personal Data, you are the controller and Podyx is the processor. Where data protection law treats Podyx as an independent controller of certain data (for example, our own account and billing data), our Privacy Policy applies to that data, not this DPA.
If there is a conflict between this DPA and the Terms on the subject of data protection, this DPA prevails.
2. Definitions
"Data Protection Law" means all privacy and data protection laws that apply to the processing under this DPA, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and Singapore's Personal Data Protection Act (PDPA), as applicable.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR. "Sub-processor" means any third party we engage to process End User Personal Data. "Standard Contractual Clauses" or "SCCs" means the clauses approved for lawful international transfers under the applicable Data Protection Law.
3. Scope and duration of processing
We process End User Personal Data only to provide the Services and only for as long as the Terms are in force, plus any retention period set out in this DPA and the Privacy Policy. The subject matter, nature, purpose, duration, categories of data, and categories of data subjects are set out in Annex 1.
4. Your responsibilities as Controller
You confirm that: you have a lawful basis to collect and process End User Personal Data and to have us process it; you have given your End Users any required notices and obtained any required consents; your instructions to us comply with Data Protection Law; and the End User Personal Data you put into the Services is accurate and lawfully obtained. You are responsible for the privacy and cookie notices on your booking page and for responding to your End Users about their data.
5. Our responsibilities as Processor
We will:
5.1 Process on instructions. Process End User Personal Data only on your documented instructions, including those given through the Services, unless required by law to do otherwise, in which case we will notify you unless the law prohibits it.
5.2 Confidentiality. Ensure that personnel authorised to process the data are bound by confidentiality obligations.
5.3 Security. Implement the technical and organisational measures set out in Annex 2, appropriate to the risk.
5.4 Assist you. Taking into account the nature of the processing, provide reasonable assistance to help you respond to Data Subject requests and meet your obligations on security, breach notification, and data protection impact assessments.
5.5 Data Subject requests. Promptly notify you if we receive a request from one of your End Users to exercise their rights, and not respond directly except to confirm the request relates to you, unless legally required or authorised by you.
5.6 Breach notification. Notify you without undue delay after becoming aware of a Personal Data Breach affecting End User Personal Data, and provide the information you reasonably need to meet your own notification obligations.
5.7 Deletion or return. On termination, delete or return End User Personal Data in line with the one hundred and eighty (180) day retention and deletion process described in the Terms and Privacy Policy, unless retention is required by law.
5.8 Records and demonstrating compliance. Make available information reasonably necessary to demonstrate compliance with this DPA.
6. Sub-processors
You give general authorisation for us to engage Sub-processors to process End User Personal Data. Our current Sub-processors are listed in Annex 3, which we may update from time to time as our Services evolve. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.
7. International transfers
The Services are hosted on Amazon Web Services, and End User Personal Data is currently processed and stored in the United States, with the region subject to change as we operate the Services. Where providing the Services involves transferring End User Personal Data across borders, we use a lawful transfer mechanism, such as an adequacy decision or the relevant Standard Contractual Clauses, and apply appropriate safeguards.
8. Audits
We will make available the information needed to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, no more than once a year except where required by a regulator or following a Personal Data Breach, subject to confidentiality and to not unreasonably disrupting our operations. We may satisfy audit requests by providing third-party certifications or reports where available.
9. Liability and general
Each party's liability under this DPA is subject to the limitations of liability in the Terms. This DPA is governed by the same law and dispute resolution terms as the Terms (Singapore law, SIAC arbitration with the court carve-out). If any part of this DPA is invalid, the rest remains in effect.
Annex 1 — Details of processing
Subject matter: Provision of the Podyx booking and studio operations platform to the Controller.
Nature and purpose: Hosting, storage, and processing of End User Personal Data to enable bookings, payment routing, scheduling, communications, packages, promotions, and related studio operations features.
Duration: For the term of the Terms, plus the 180-day post-cancellation retention period, unless longer retention is legally required.
Categories of data subjects: The Controller's End Users (the Studio's customers and prospective customers) and, where applicable, the Controller's staff users.
Categories of personal data: Identification and contact data (name, email, phone); booking and session data (history, attendance, preferences); transaction and purchase metadata (amounts, payment method type, status, promo and credit usage; full card data is held by the payment processor, not Podyx); communications and notification data; and any additional information the Controller chooses to collect through configurable fields.
Special category data: Not intended. The Controller must not use the Services to process special category data except where lawful and agreed in writing.
Annex 2 — Technical and organisational security measures
- Encryption of data in transit (TLS) and encryption at rest for stored data.
- Role-based access controls and least-privilege access for staff.
- Authentication controls, including hashed credentials and secure login.
- Network and application security controls, logging, and monitoring.
- Regular backups and a documented restoration process.
- Vulnerability management and patching.
- Personnel confidentiality obligations and security awareness.
- Incident response and breach handling procedures.
- Vendor due diligence for Sub-processors.
Annex 3 — List of Sub-processors
- Amazon Web Services — Cloud hosting and storage
- Stripe — Subscription billing and payment routing
- Square — Payment routing
- Google — Calendar sync and maps
- Intercom — Customer support and in-product messaging
- Resend — Transactional and notification email