Legal — Template
Last updated August 14, 2026 · Template, not an executed agreement
This Data Processing Agreement ("DPA") is intended to supplement an agreement between an institutional customer (gym, academy, or college athletics/recreation program — the "Controller") and Fightprint ("Processor") for use of the Fightprint product. It describes how Fightprint processes personal data on the Controller's behalf.
The subject matter of this DPA is Fightprint's processing of personal data belonging to the Controller's students, athletes, members, or staff ("Data Subjects") in connection with the Controller's use of the Fightprint product. This DPA remains in effect for as long as Fightprint processes personal data on the Controller's behalf under the underlying agreement, and terminates as described in Section 11 below.
Fightprint processes personal data to: (a) authenticate individual accounts; (b) store and compute each individual's own training statistics (positions, transitions, and outcomes they log); (c) where a gym/institution has been granted consent by an individual member, surface room-level engagement signals (not individual performance data) on that institution's dashboard; and (d) send transactional email — account verification, password resets — related to the product. Fightprint does not process this data for advertising, does not run third-party analytics or tracking scripts against it, and does not sell it.
The Controller represents that it has a lawful basis for the personal data it submits or directs to Fightprint, and that it has provided any notices and obtained any consents required under applicable law before its members' data is processed by Fightprint — including the gym-level consent mechanism Fightprint's product itself provides for room-level dashboard visibility.
Fightprint uses one sub-processor: Burst, an email relay operated by Graylight Creative that sends through SendGrid, used solely to deliver transactional email (password resets and, optionally, a welcome message on newsletter signup). It does not receive training data. Fightprint will provide notice before adding a new sub-processor that will process the Controller's personal data. LEGAL REVIEW NEEDED — the specific notice period and the Controller's right to object to a new sub-processor should be defined by counsel.
Fightprint's security measures — authentication and password handling, encryption in transit, backups, infrastructure, monitoring, and rate limiting — are described in full, honestly and without embellishment, at fightprint.app/security. That page is incorporated into this DPA by reference and should be read alongside this section; it also discloses what is not yet in place (no MFA, no SSO, no completed SOC 2/ISO 27001 audit, no formal incident response plan).
LEGAL REVIEW NEEDED — this section requires confirmation of the physical location/jurisdiction of Fightprint's hosting infrastructure and, if the Controller or its Data Subjects are outside the United States, the appropriate transfer mechanism (e.g., Standard Contractual Clauses). Not filled in here because it should be verified and drafted by counsel rather than asserted informally.
Upon termination of the underlying agreement, Fightprint will, at the Controller's request, delete or return the Controller's personal data. Today this is a real but manual process — account and data deletion requests are handled by emailing [email protected] rather than through a self-serve export/delete tool. LEGAL REVIEW NEEDED — a specific deletion timeframe (e.g., "within 30 days of request") should be set by counsel and should reflect what Fightprint's backup retention (14-day rotating local backups, plus a broader nightly backup) can actually support — deleted data may persist in backups for up to that retention window before being fully purged.
Fightprint has not undergone a third-party security audit or certification (see Security Overview). LEGAL REVIEW NEEDED — the scope, frequency, notice period, and cost allocation for any Controller audit or assessment right should be negotiated and drafted by counsel; Fightprint has not previously supported a formal customer audit and any commitment here should be realistic about that.
LEGAL REVIEW NEEDED — not addressed in this template. Liability caps, indemnification obligations, and insurance requirements need to be negotiated and drafted by counsel for both parties; nothing in this document should be read as a liability commitment.
LEGAL REVIEW NEEDED — not addressed in this template. Governing law and venue need to be agreed and drafted by counsel.
To be completed once this document has been reviewed and finalized by counsel for both parties.
Signature
Name / Title / Date
Signature
Name / Title / Date
To discuss or negotiate this DPA: [email protected] or [email protected].