Data Processing Agreement for Pros
Last updated: October 3, 2026
1. Parties and roles
The controller is the Pro. The processor is Euscopia.net SRL, company number BE0825968361 (“Euscopia”). Registered address: Rue Haie du Loup 6, 5024 Marche-les-Dames, Belgium.
This DPA only covers personal data about Movers that Euscopia processes on the Pro's behalf. For its own purposes (Pro accounts, billing, security, support, website), Euscopia is a controller; see the Privacy Policy.
2. Subject matter, duration and purpose
Euscopia hosts and synchronises the Pro's roster, groups, programs and program assignments so the Pro can manage Movers across devices and share programs with them. The processing lasts as long as the Pro account exists, plus the 30-day deletion period described in clause 10. Annex A gives the details.
3. Instructions
Euscopia processes the data only on the Pro's documented instructions, which are this DPA and the Pro's use of the ProMovum features, unless EU or Member State law requires otherwise (in which case Euscopia informs the Pro, unless the law forbids it). Euscopia tells the Pro if it believes an instruction breaches the GDPR.
4. Confidentiality
Euscopia makes sure that people authorised to process the data are bound by confidentiality.
5. Security
Euscopia applies the technical and organisational measures listed in Annex B, appropriate to the risk (Article 32 GDPR), and keeps them up to date.
6. Sub-processors
The Pro gives Euscopia a general authorisation to use the sub-processors listed in Annex C. Euscopia will inform Pros of any intended addition or replacement by email at least 30 days in advance and by updating Annex C. A Pro may object on reasonable data-protection grounds; if the matter cannot be resolved, the Pro may delete its account. Euscopia imposes data-protection obligations on its sub-processors that are equivalent to this DPA and remains responsible for them.
7. International transfers
Euscopia only transfers data outside the EEA in line with Chapter V of the GDPR. The main data stores are in the EU (see Annex C). Where Google processes limited data outside the EEA, it relies on approved safeguards such as the Standard Contractual Clauses or the EU–U.S. Data Privacy Framework.
8. Assistance
Taking into account the nature of the processing, Euscopia helps the Pro, by appropriate technical and organisational means, to respond to requests from Movers exercising their GDPR rights, and to meet its obligations on security, breach notification, data protection impact assessments and prior consultation. If a Mover contacts Euscopia directly about data held for a Pro, Euscopia will refer the Mover to the Pro and inform the Pro where appropriate.
9. Personal data breaches
Euscopia notifies the Pro without undue delay after becoming aware of a personal data breach affecting the Pro's data, with the information it has to help the Pro meet its own notification duties.
10. Deletion and return
When a Pro deletes its account, deletion is scheduled for 30 days later, and the Pro can cancel it by signing back in. After 30 days, Euscopia permanently deletes the Pro's data from its systems, including the roster and Mover pseudos. Before then, on written request, Euscopia will provide a copy of the Pro's roster data in a commonly used format where technically feasible. Google removes deleted data from its own systems within its standard deletion period, and Euscopia may keep data where the law requires it.
11. Audits and information
Euscopia makes available the information necessary to show compliance with this DPA and allows reasonable audits by the Pro or an auditor it appoints, on reasonable prior notice, at most once a year unless a breach requires otherwise, at the Pro's cost, under confidentiality and without disrupting the service. Euscopia may satisfy an audit request by sharing the relevant third-party certifications and reports of its sub-processors.
12. The Pro's responsibilities
As controller, the Pro is responsible for:
- having a valid legal basis, and where health data is involved a valid condition under Article 9 GDPR, for the data it enters;
- informing its Movers about the processing, and obtaining any required consent, including the authorisation of a parent or guardian for Movers under 16;
- entering as little identifying and health information as possible: pseudos must not contain a full name where unnecessary, a diagnosis, operation details or any health condition, and the same applies to program names, summaries and other free text;
- keeping the data accurate and removing Movers it no longer needs to manage;
- answering Movers' requests about their data and giving lawful instructions.
13. Liability
Each party is liable for damage caused by its own breach of this DPA or of the GDPR. In line with Article 82 GDPR, Euscopia is liable for damage caused by processing only where it has not complied with obligations of the GDPR that are specifically directed to processors, or where it has acted outside or contrary to the Pro's lawful instructions. This clause does not affect the rights of Movers or of supervisory authorities. Between the parties, any recourse is allocated according to each party's share of responsibility.
- Cap: subject to the exceptions below, Euscopia's total liability to the Pro under or in connection with this DPA, for all events in a contract year taken together, is limited to the greater of (a) the fees the Pro paid for its Pro plan in the 12 months before the event giving rise to the claim, and (b) the annual price of the lowest paid Pro plan.
- Excluded damage: Euscopia is not liable for indirect or consequential damage, such as loss of profit, revenue, clients or reputation.
- No limitation: nothing in this DPA limits or excludes liability for intentional misconduct, gross negligence, fraud, death or personal injury, or any liability that cannot be limited under applicable law.
- The Pro's responsibility: the Pro will hold Euscopia harmless from third-party claims, including claims by Movers, to the extent they result from the Pro's breach of clause 12 or from unlawful instructions.
14. Governing law, jurisdiction and language
This DPA is governed by Belgian law. The courts of Namur (Belgium) have exclusive jurisdiction over any dispute arising from it, without prejudice to mandatory rules of law and to the rights of Movers and supervisory authorities. If this DPA conflicts with other terms on personal data, this DPA prevails. The French version of this DPA is the reference version; if a translation differs from it, the French version prevails.
15. Changes and contact
We may update this DPA; we will update the date above and, for material changes, inform Pros by email. Questions: fitexo@googlegroups.com.
Annex A — Details of the processing
- Nature and purpose: storage, retrieval, synchronisation, transmission and deletion of roster, group, program and assignment data, so the Pro can manage Movers and share programs.
- Data subjects: the Movers (clients, patients or athletes) that the Pro manages.
- Categories of data: random Mover ID; Mover pseudo chosen by the Pro; assigned program (copy); group membership; access start and end dates; share-link status; and any free text the Pro enters in program names, summaries or exercise descriptions.
- Special categories: not requested by ProMovum, but information that reveals a health context may result from the Pro's entries (for example a program assigned to a pseudo).
- Not processed: exercise results, repetitions, pain scores, fatigue scores and heart rate stay on the Mover's device and are not uploaded to the ProMovum cloud as part of normal operation.
- Duration: the life of the Pro account plus the 30-day deletion period.
Annex B — Security measures
- Encrypted transport of data between the apps, the website and the servers.
- Authenticated access (Sign in with Apple or Google) and access-control rules so that a Pro's roster can only be read and written by that Pro's account.
- Subscription records and security counters can only be written by server-side code, not by the apps.
- Firebase App Check integrated in the apps.
- Data minimisation and pseudonymisation: random Mover IDs and Pro-chosen pseudos instead of real identities.
- Separation of exercise results (kept on the Mover's device) from cloud data.
- Scheduled, recoverable account deletion followed by permanent deletion of the account's data.
- Rate limiting of public endpoints using hashed IP addresses rather than raw addresses.
Annex C — Sub-processors
- Google (Firebase and Google Cloud): Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, Cloud Functions for Firebase, Firebase App Check and Firebase Hosting. Purpose: hosting, storage, authentication and server-side processing of the data described in Annex A. Location: Firestore in the EU multi-region “eur3”; Cloud Storage and Cloud Functions in the EU; some Google services (such as Authentication, Hosting's global network, and Google's logging and support systems) may process limited data outside the EEA under the safeguards described in clause 7. Terms: Google Cloud Data Processing Addendum.
Apple and Google, as providers of sign-in, the App Store and Google Play, act as independent controllers for sign-in and purchases. They are not sub-processors for Mover data.