Effective 16 August 2026
This is the Article 28 GDPR data processing agreement for trainers in the EEA and the United Kingdom. It is incorporated into the Terms of Service by reference and takes effect without a separate signature. This English text is the binding version of this agreement. Trainers in Korea are covered by Korean data protection law and the Privacy Policy instead.
You, the trainer, are the controller. Soksu is the processor. The client records you put into the Service — names, contact details, session notes, body-composition figures, pain and injury logs, photos — are data whose purposes and means you decide. We store and process them on your behalf.
For your own trainer account data (login credentials, billing details, support correspondence, product usage), Soksu is the controller. That part is governed by the Privacy Policy, not this agreement.
Soksu processes client records only on your documented instructions. Your use of the Service — entering, sending, deleting — constitutes those instructions, and this agreement together with the Terms of Service defines their scope.
Where applicable law requires processing, we may do so, and we will tell you beforehand unless the law forbids it. If we consider an instruction to infringe the GDPR or other applicable data protection law, we will tell you and may suspend that instruction.
We do not use client records for our own purposes. In particular we do not use them to train AI models. AI-assisted session notes are generated only when you ask for them and only for that request.
Everyone with access to client records is bound by confidentiality obligations, and access is limited to what is necessary to operate the Service.
Soksu implements technical and organisational measures appropriate to the risk, as required by Article 32 GDPR.
How you distribute a client viewing link is your responsibility. Anyone holding the link can read that client's records, so send it only to the client. If you suspect a link has been shared further, you can issue a new one from the Service.
You give general authorisation for Soksu to engage the sub-processors listed in Article 5 of the Privacy Policy, which names each one and what it processes.
We give you at least 30 days' notice, in the Service or by email, before adding or replacing a sub-processor. If you object within that period and we cannot offer a reasonable alternative, you may terminate without penalty.
We impose obligations equivalent to this agreement on every sub-processor and remain responsible to you for their performance.
Client records are stored and processed in the Republic of Korea. Transfers from the EEA and the UK to Korea rely on adequacy — European Commission Decision (EU) 2022/254, confirmed as still adequate on its periodic review of 23 July 2026, and the UK's Data Protection (Adequacy) (Republic of Korea) Regulations 2022.
Soksu observes the Supplementary Rules (PIPC Notification No. 2021-5) on which the EU decision is conditioned. If an adequacy decision is suspended, repealed, invalidated or allowed to lapse, we will without undue delay enter into the then-current Standard Contractual Clauses or, for UK transfers, the ICO International Data Transfer Agreement or Addendum, which are deemed incorporated into this agreement from that moment.
Some sub-processors are located in the United States and elsewhere, as listed in the Privacy Policy. The same principles apply to those transfers.
Requests from your clients to access, correct, delete or port their data are directed to you, as controller. Soksu assists you, by technical and organisational measures, in answering them.
If such a request reaches us directly we will not act on it — we pass it to you. Acting on it ourselves, without being the controller, would itself be a breach.
If we become aware of a personal data breach affecting client records, we will notify you without undue delay and give you what you need to notify your supervisory authority: the nature of the breach, the categories and approximate volume of data affected, the likely consequences and the measures taken.
Where you carry out a data protection impact assessment or a prior consultation, we assist you reasonably, within the information available to us.
Pain and injury logs, body-composition figures and body photos may be data concerning health under Article 9 GDPR. You warrant that, before putting such data into the Service, you have a condition under Article 9(2) — in practice the client's explicit consent.
That consent must be obtained separately from the consent to your training contract. Soksu cannot obtain it on your behalf.
If you enter records concerning a minor, you warrant that you hold whatever guardian consent the law of that client's country requires.
On termination you have 30 days to export your client records. After that we delete them, and copies held in backups fall out of the backup rotation within 90 days.
Where applicable law requires us to retain data, we keep it for that period only, and the protections in this agreement continue to apply to it.
Soksu makes available the information necessary to demonstrate compliance with this agreement and allows for and contributes to audits by you or an auditor you appoint. Audits take place on reasonable notice during normal business hours, and are scoped so that other trainers' data stays protected.
Where this agreement conflicts with the Terms of Service, this agreement prevails as regards the processing of client records. Governing law and jurisdiction follow Article 13 of the Terms of Service, and nothing here affects any mandatory protection you have as a consumer.
Questions: healthjangbu@gmail.com