INCORPORATED PT TERMS
MyElitePT PT Data Processing Addendum
Version DPA-2026-09-11 · MYELITEPT LTD
Company no. 17390377 · 97 Cheadle Road, Cheadle Hulme, Stockport, SK8 5DQ, United Kingdom
1. Parties, roles and scope
This Addendum forms part of the PT Terms between MYELITEPT LTD and the PT business identified in the acceptance record. For the processing covered here, the party determining its purposes and means is the Controller and the party acting only on its documented instructions is the Processor. UK data-protection law, including the UK GDPR and Data Protection Act 2018 as amended, applies.
MyElitePT is controller for its own account, security, billing, marketplace, support and AI Coach purposes. A PT is normally an independent controller for professional coaching decisions and the records they determine. When MyElitePT hosts, organises or communicates a PT’s records solely to provide the functions requested by that PT, the PT is Controller and MyElitePT is Processor. This Addendum does not reclassify either party’s independent purposes. Any processing in the opposite direction must be identified in documented instructions before it starts.
2. Processing details
The subject matter is account-linked coaching administration. Its purpose is to provide the selected hosting, retrieval, programme and log administration, messaging, booking, support, export and deletion functions. The processing involves collecting, storing, organising, retrieving, sharing with authorised recipients and deleting the relevant records.
Data subjects are leads, clients, PTs and authorised business or support contacts. Personal data may include identity and contact details, goals, availability, health and PAR-Q answers, programmes, progress, photographs, messages, appointments, consent and audit records, and payment status. Only categories necessary for the selected service may be processed. Health information requires the applicable special-category condition as well as an Article 6 lawful basis.
Processing lasts for the relevant service relationship and the time needed to return or delete the data under section 9. The Controller may issue lawful instructions, obtain compliance information, exercise the audit rights below and choose return or deletion. Retention for either party’s independent legal obligations is outside processing on the other party’s instructions and must have its own lawful basis and safeguards.
3. Instructions and confidentiality
The Processor acts only on the Controller’s documented lawful instructions, including instructions about international transfers. The agreed service, account settings and authorised service requests constitute instructions within their stated scope. If UK law requires other processing, the Processor informs the Controller of that requirement before processing unless the law prohibits notification on important public-interest grounds.
The Processor immediately informs the Controller if an instruction appears to infringe data-protection law and does not carry out an unlawful instruction. It ensures that people authorised to process the data are bound by confidentiality or an appropriate statutory duty, with access limited to their duties.
4. Security
The Processor implements appropriate technical and organisational measures under Article 32, taking account of the processing, available technology, implementation costs and risks to people. Measures include role- and relationship-based access, secure authentication, encrypted transport, protected credentials, private controlled access to sensitive media, account separation, data minimisation, security monitoring, incident handling, updates and tested recovery and erasure procedures.
Measures must protect confidentiality, integrity, availability and resilience, support timely recovery and be assessed regularly. Security information supplied for verification must not expose another customer’s data or credentials. Changes must not materially reduce the agreed level of protection.
5. Subprocessors
The Controller gives general written authorisation for MyElitePT to use the processors identified on its published service-provider list for the stated functions. This does not authorise a PT to use unrelated external tools with client data. The Processor gives advance written notice of an intended addition or replacement, including its function and relevant locations, and a reasonable opportunity to object on data-protection grounds before the new processing starts.
The parties will consider a reasonable objection and a compliant alternative. If it cannot be resolved, the affected processing must not be imposed on the Controller; the parties will arrange cessation of the affected service and return or deletion of its data. Each subprocessor must be bound by written obligations providing equivalent data protection. The Processor remains responsible to the Controller for that subprocessor’s performance of those obligations.
6. International transfers
The Processor must not make a restricted international transfer except on documented instructions and with a lawful UK transfer mechanism. As applicable, this includes an adequacy regulation, the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses, together with required assessments and supplementary safeguards. The Processor provides relevant safeguard information on request, protecting confidential and third-party information where necessary.
7. Rights, assessments and regulatory assistance
Taking account of the nature of the processing, the Processor assists through appropriate technical and organisational measures with requests for access, correction, erasure, restriction, portability and objection. It promptly forwards a request concerning the Controller’s processing and does not answer on the Controller’s behalf unless instructed or required by law.
Taking account of the information available, the Processor assists with security, breach assessment and notification, data-protection impact assessments and prior consultation under Articles 32–36. Each party cooperates with lawful regulator requests without preventing the other party or an individual from exercising their rights.
8. Personal-data breaches
The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data. The notice includes available details of the nature, affected data and people, likely consequences, contact point, and measures taken or proposed. Information may be supplied in phases without avoidable delay. The Processor contains the incident, preserves relevant evidence and cooperates with the Controller’s response. The Controller remains responsible for its own regulatory and individual-notification decisions.
9. Return, deletion and recovery copies
At the end of the affected services, the Processor, at the Controller’s choice, returns or deletes the personal data and deletes existing copies unless UK law requires retention. It confirms completion on reasonable request. Data awaiting deletion from rolling recovery copies is put beyond ordinary use, protected, and deleted at the end of the documented recovery period. A restoration must reapply relevant deletions before restored data is made available. Data retained because of a legal requirement must be restricted to that purpose.
10. Compliance information and audits
The Processor makes available the information needed to demonstrate compliance with Article 28 and allows and contributes to audits and inspections by the Controller or its appointed auditor. The parties coordinate reasonable notice, scope and secure access without obstructing a necessary audit, regulatory investigation or urgent incident response. An audit must protect other customers’ confidentiality and system security; those protections must not make the audit right ineffective.
11. Controller obligations
The Controller establishes and documents lawful purposes, Article 6 bases and any Article 9 condition; provides required privacy information; issues proportionate instructions; collects only necessary information; keeps it accurate; and handles rights and complaints. It maintains appropriate security for its own users, devices and any systems outside MyElitePT. Neither party may use this Addendum as permission for unrelated marketing, disclosure or unsafe coaching.
12. Priority and contact
This Addendum takes priority over conflicting service wording about processing on instructions. Mandatory data-protection law and applicable transfer clauses prevail. Nothing excludes an individual’s statutory rights, regulatory powers or liability that cannot lawfully be excluded. The PT Terms govern other matters to the extent consistent with these protections. Data-protection requests and notices to MyElitePT may be sent to privacy@myelitept.app.
Named providers and transfer information: Service providers & subprocessors.