Fightprint Start logging

Legal — Template

Data Processing Agreement

Last updated August 14, 2026 · Template, not an executed agreement

⚠
NEEDS LEGAL REVIEW BEFORE EXECUTION

This is a template, not a signed or signable contract as it stands. It lays out the sections a real DPA needs and fills in what's actually true about how Fightprint handles data today. It was assembled by the team that built the product, not by a lawyer. Clauses touching liability, indemnification, governing law, or breach-notification timelines are explicitly flagged below with LEGAL REVIEW NEEDED and should not be relied on until real counsel has written that language. Everything else — the factual descriptions of what's processed, how, and why — is accurate to the product as it exists, but the document as a whole still needs a lawyer's sign-off before either side executes it.

This Data Processing Agreement ("DPA") is intended to supplement an agreement between an institutional customer (gym, academy, or college athletics/recreation program — the "Controller") and Fightprint ("Processor") for use of the Fightprint product. It describes how Fightprint processes personal data on the Controller's behalf.

1.Parties

Controller
[Customer legal name] LEGAL REVIEW NEEDED — confirm correct contracting entity and notice address
Processor
Fightprint, a product operated by Graylight Creative LEGAL REVIEW NEEDED — confirm the exact contracting entity name/jurisdiction to use here

2.Subject matter and duration

The subject matter of this DPA is Fightprint's processing of personal data belonging to the Controller's students, athletes, members, or staff ("Data Subjects") in connection with the Controller's use of the Fightprint product. This DPA remains in effect for as long as Fightprint processes personal data on the Controller's behalf under the underlying agreement, and terminates as described in Section 11 below.

3.Nature and purpose of processing

Fightprint processes personal data to: (a) authenticate individual accounts; (b) store and compute each individual's own training statistics (positions, transitions, and outcomes they log); (c) where a gym/institution has been granted consent by an individual member, surface room-level engagement signals (not individual performance data) on that institution's dashboard; and (d) send transactional email — account verification, password resets — related to the product. Fightprint does not process this data for advertising, does not run third-party analytics or tracking scripts against it, and does not sell it.

4.Categories of data subjects

  • Individual end users of the Fightprint product (student-athletes, gym members) — must be 18 or older, per Fightprint's age requirement.
  • Gym/institution owners and staff who administer an academy account.

5.Categories of personal data

  • Account data: email address, hashed password, date of birth (used to verify the 18+ requirement), optional display name, belt rank, and weight class.
  • Training data: logged positions, transitions, outcomes, an optional training-partner identifier, and timestamps.
  • Gym affiliation and consent records: which gym a user is affiliated with, and the gym owner's consent status/timestamp for room-level dashboard access.
  • Security/operational data: IP address and timestamps tied to login, registration, and password-reset attempts — used only for abuse and rate-limiting purposes, not tracking or profiling.
  • Fightprint does not collect payment information, government ID numbers, health records, or biometric data.

6.Controller obligations

The Controller represents that it has a lawful basis for the personal data it submits or directs to Fightprint, and that it has provided any notices and obtained any consents required under applicable law before its members' data is processed by Fightprint — including the gym-level consent mechanism Fightprint's product itself provides for room-level dashboard visibility.

7.Processor obligations

  • Process personal data only as necessary to provide the Fightprint product and on the Controller's documented instructions.
  • Maintain the security measures described in Fightprint's Security Overview, which is incorporated into this DPA by reference and reflects Fightprint's actual current practices — honestly, including where those practices fall short of enterprise norms (single-server infrastructure, no completed third-party security audit).
  • Ensure personnel with access to personal data are subject to confidentiality obligations.
  • Assist the Controller, to the extent reasonably possible, in responding to Data Subject requests (access, correction, deletion) — Fightprint's current process for this is manual (a request to [email protected]), not yet a self-serve tool.
  • Notify the Controller of a personal data breach affecting the Controller's data. LEGAL REVIEW NEEDED — a specific notification timeframe (e.g., "without undue delay" vs. a fixed number of hours/days) needs to be set by counsel; Fightprint does not yet have a formal incident response process to commit to a specific internal timeline against (see Security Overview).

8.Sub-processors

Fightprint uses one sub-processor: Burst, an email relay operated by Graylight Creative that sends through SendGrid, used solely to deliver transactional email (password resets and, optionally, a welcome message on newsletter signup). It does not receive training data. Fightprint will provide notice before adding a new sub-processor that will process the Controller's personal data. LEGAL REVIEW NEEDED — the specific notice period and the Controller's right to object to a new sub-processor should be defined by counsel.

9.Security measures

Fightprint's security measures — authentication and password handling, encryption in transit, backups, infrastructure, monitoring, and rate limiting — are described in full, honestly and without embellishment, at fightprint.app/security. That page is incorporated into this DPA by reference and should be read alongside this section; it also discloses what is not yet in place (no MFA, no SSO, no completed SOC 2/ISO 27001 audit, no formal incident response plan).

10.International data transfers

LEGAL REVIEW NEEDED — this section requires confirmation of the physical location/jurisdiction of Fightprint's hosting infrastructure and, if the Controller or its Data Subjects are outside the United States, the appropriate transfer mechanism (e.g., Standard Contractual Clauses). Not filled in here because it should be verified and drafted by counsel rather than asserted informally.

11.Data return and deletion on termination

Upon termination of the underlying agreement, Fightprint will, at the Controller's request, delete or return the Controller's personal data. Today this is a real but manual process — account and data deletion requests are handled by emailing [email protected] rather than through a self-serve export/delete tool. LEGAL REVIEW NEEDED — a specific deletion timeframe (e.g., "within 30 days of request") should be set by counsel and should reflect what Fightprint's backup retention (14-day rotating local backups, plus a broader nightly backup) can actually support — deleted data may persist in backups for up to that retention window before being fully purged.

12.Audit rights

Fightprint has not undergone a third-party security audit or certification (see Security Overview). LEGAL REVIEW NEEDED — the scope, frequency, notice period, and cost allocation for any Controller audit or assessment right should be negotiated and drafted by counsel; Fightprint has not previously supported a formal customer audit and any commitment here should be realistic about that.

13.Liability and indemnification

LEGAL REVIEW NEEDED — not addressed in this template. Liability caps, indemnification obligations, and insurance requirements need to be negotiated and drafted by counsel for both parties; nothing in this document should be read as a liability commitment.

14.Governing law

LEGAL REVIEW NEEDED — not addressed in this template. Governing law and venue need to be agreed and drafted by counsel.

Where this stands This template exists so a procurement conversation can start from real, accurate facts instead of a blank page or a generic boilerplate DPA that doesn't match what Fightprint actually does. It is not a substitute for legal review, and Fightprint does not consider it binding until a version reviewed by counsel on both sides has been signed. See the related Security Overview and Privacy Policy for further detail.

15.Signatures

To be completed once this document has been reviewed and finalized by counsel for both parties.

Controller

Signature

Name / Title / Date

Processor — Fightprint

Signature

Name / Title / Date

Contact

To discuss or negotiate this DPA: [email protected] or [email protected].

Fightprint

Real ratios, not vibes. Every roll, spar, and match logged and scored against real outcomes — across BJJ, MMA, wrestling, judo, sambo, boxing, kickboxing, and muay thai.

Get updates

Product

  • How it works
  • Sports
  • Methodology
  • Log in

Company

  • About
  • For gyms
  • Contact
  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Security
  • Data Processing Agreement

© 2026 Fightprint

Built for the mat, the cage, and the mud.