Legal
Data processing agreement
How LuxArte Ltd processes personal data on behalf of clubs that use MOTVIVO (GDPR Article 28).
Version 1.0 · Last updated: 5 October 2026
This Data Processing Agreement (“DPA”) is between the club, studio or other business that uses MOTVIVO (the “Club”) and LuxArte Ltd, Michail Koutsofta, 17, Anarita 8502, Cyprus, company registration no. HE 465325, VAT ID 60097364M (“LuxArte”, “we”), which provides MOTVIVO. It forms part of the agreement under which the Club uses MOTVIVO (the “Agreement”) and applies from the moment the Club accepts it, for as long as LuxArte processes personal data for the Club.
It sets out how LuxArte processes personal data on the Club’s behalf, as required by Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Cyprus Law 125(I)/2018. Terms such as “controller”, “processor”, “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given in the GDPR.
1. Roles
- The Club is the controller of the personal data of its members, prospective members, gift voucher recipients and staff that is entered into or collected through MOTVIVO (“Club Data”). The Club decides why and how Club Data is used.
- LuxArte is the Club’s processor for Club Data and processes it only to provide MOTVIVO to the Club.
- LuxArte is a separate controller for the contact, account and billing details of the Club’s owners and administrators that it uses to run its relationship with the Club (contract, support, invoicing, service notices), as described in its privacy policy at motvivo.com/privacy. That processing is outside this DPA.
2. Instructions
- LuxArte processes Club Data only on the Club’s documented instructions. The Agreement, this DPA and the Club’s use and configuration of MOTVIVO (for example the settings it chooses, the emails it sends and the data it enters) are the Club’s complete instructions. Further instructions must be in writing and consistent with the Agreement.
- LuxArte may process Club Data otherwise only where EU or Member State law requires it; in that case it informs the Club before processing unless that law prohibits it.
- LuxArte tells the Club promptly if, in its opinion, an instruction infringes data protection law.
- LuxArte does not sell Club Data, does not use it for advertising and does not use it to build profiles of members for itself. It may use Club Data in aggregated, anonymised form that does not identify any person or the Club to measure and improve MOTVIVO.
3. Confidentiality
LuxArte ensures that everyone it authorises to process Club Data is bound by confidentiality and only has access to the extent needed for their role.
4. Security
LuxArte implements and maintains the technical and organisational measures in Annex II, appropriate to the risk, including those required by Article 32 GDPR. LuxArte may update these measures as technology develops, provided the overall level of protection is not reduced.
5. Support access
LuxArte staff do not look at Club Data in the ordinary course of business. Where the Club asks for help, or where it is needed to keep MOTVIVO running securely, authorised LuxArte staff may open a support session in the Club’s account. Support sessions are limited in time (one hour unless extended for a stated reason), visibly marked in the Club’s staff app, and recorded with their reason in LuxArte’s audit log and in the Club’s own activity log.
6. Sub-processors
- The Club gives LuxArte general authorisation to engage sub-processors. The current sub-processors are listed in Annex III.
- LuxArte informs the Club at least 30 days before adding or replacing a sub-processor, by email to the Club’s administrators or by notice in MOTVIVO. The Club may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Club may end the Agreement for the affected service before the change takes effect, with a pro-rata refund of prepaid fees for the remaining period.
- LuxArte imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible to the Club for its sub-processors’ performance.
7. International transfers
Club Data is stored and processed on servers in the European Union (Germany). Where a sub-processor processes Club Data outside the European Economic Area, LuxArte ensures that the transfer is covered by an adequacy decision (such as the EU-U.S. Data Privacy Framework for certified recipients) or by the European Commission’s Standard Contractual Clauses, together with any supplementary measures needed.
8. Helping the Club with data subjects’ rights
MOTVIVO gives the Club tools to respond to requests from data subjects, including viewing and correcting a person’s details, exporting their bookings and history, and erasing a person (the person can also delete their own account in the booking app). Where the Club cannot respond using these tools, LuxArte assists the Club, taking into account the nature of the processing. If LuxArte receives a request directly from a data subject about Club Data, it passes it to the Club without undue delay and does not respond itself except to confirm that it has been passed on.
9. Helping the Club with its other obligations
Taking into account the nature of the processing and the information available to it, LuxArte assists the Club with its obligations on security, personal data breach notification, data protection impact assessments and prior consultation with the supervisory authority (Articles 32 to 36 GDPR), mainly by providing the information in this DPA and its annexes and by answering reasonable questions.
10. Personal data breaches
- LuxArte notifies the Club without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Club Data.
- The notice describes, as far as then known, the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken or proposed. Where not all information is available at once, LuxArte provides it in phases as it becomes available.
- LuxArte takes reasonable steps to contain and remedy the breach and to prevent it from happening again. Notifying a breach is not an admission of fault.
11. Health data and other special categories
If the Club switches on MOTVIVO’s health questionnaire, the Club processes data concerning health. The Club is responsible for deciding whether it needs this data, for the questions it asks and for having a lawful basis; MOTVIVO collects members’ explicit consent before they answer and limits who in the Club can see the answers. The Club should not otherwise enter special categories of personal data (for example in notes or messages) unless it is necessary and lawful.
12. The Club’s responsibilities
- The Club has a lawful basis for the processing it instructs and provides its members and staff with the information required by Articles 13 and 14 GDPR (for example in its own privacy notice).
- The Club ensures that the Club Data it enters is accurate and limited to what is necessary, and that its instructions comply with data protection law.
- The Club keeps its staff accounts secure, gives staff only the roles they need and removes access for people who leave.
13. End of the service: deletion and return
Until the Agreement ends, the Club can export its data from MOTVIVO. After it ends, LuxArte deletes Club Data within 30 days, unless EU or Member State law requires it to keep it, and confirms the deletion on request. Copies in backups are overwritten in the normal backup cycle (currently 14 days) and are not restored except to recover the service.
14. Information and audits
LuxArte makes available the information needed to show compliance with Article 28 GDPR, including this DPA, its annexes and answers to reasonable security questionnaires. Where that is not enough, the Club (or an independent auditor bound by confidentiality, appointed by the Club) may audit LuxArte’s compliance once a year, or after a personal data breach, on at least 30 days’ written notice, during business hours and without disrupting the service or accessing other customers’ data. Each party bears its own costs, unless the audit reveals a material breach of this DPA by LuxArte.
15. Liability, precedence and law
- Each party’s liability under this DPA is subject to the limitations in the Agreement, except where the law does not allow liability to be limited. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR.
- If this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails.
- LuxArte may update this DPA to reflect changes in law or in MOTVIVO, giving the Club at least 30 days’ notice of material changes. Changes do not reduce the protection of Club Data.
- This DPA is governed by the laws of the Republic of Cyprus, and the courts of Cyprus have jurisdiction, without prejudice to the powers of supervisory authorities.
Annex I: Details of the processing
| Subject matter | Providing MOTVIVO, software for running a fitness club: timetable, bookings, waitlists, memberships, credit packs, gift vouchers, challenges, check-in, messages, emails, insights and online payments. |
| Duration | For as long as the Agreement runs, then until deletion under section 13. |
| Nature and purpose | Storing, organising, displaying, analysing for the Club and sending (by email and in the booking app) Club Data so that the Club can sell, schedule and run its classes and services and communicate with its members. |
| Data subjects | The Club’s members and prospective members (people who create an account or are created by staff), people who buy or receive gift vouchers, and the Club’s staff (owners, managers, front desk, trainers). |
| Personal data | Name, email address, phone number (optional); account and sign-in data (hashed passwords, sessions, device and browser type); bookings, waitlist places, attendance and class ratings and comments; memberships, credit packs and their use, gift vouchers, challenge participation; records of online purchases (amount, item, status; card details are handled by Stripe, not stored in MOTVIVO); messages between the member and the Club; marketing consent and how the member heard about the Club; email delivery log; staff roles and activity log entries; signed waivers. |
| Special categories | Only if the Club switches on the health questionnaire: members’ answers to the Club’s health questions (data concerning health), collected with explicit consent and visible only to the Club’s managers and front desk. |
| Frequency | Continuous, while the Club uses MOTVIVO. |
| Retention | As the Club decides while it uses MOTVIVO (it can archive or erase people at any time); after the Agreement ends, under section 13. Health answers are deleted when the person is erased. |
Annex II: Technical and organisational measures
- Hosting and location: servers in a professional data centre of Hetzner Online GmbH in Germany (ISO/IEC 27001 certified); the database is not reachable from the internet.
- Encryption: all connections use HTTPS/TLS; passwords are stored only as salted hashes; secrets for two-step verification are encrypted at rest.
- Separation of clubs: every record belongs to one club, and every request is limited to the signed-in user’s club in the application; members’ sign-ins are kept separate per club.
- Access control in MOTVIVO: role-based permissions (admin, manager, front desk, trainer, member) enforced on the server; health answers visible only to roles with the health permission.
- LuxArte staff access: a separate platform console with two-step verification and account lockout; support sessions in a club are time-limited, visibly marked and logged with a reason; server access only by key, for named administrators.
- Logging: append-only audit logs of financially relevant actions, staff overrides, plan changes and support access, which cannot be altered.
- Availability and recovery: nightly database backups kept for 14 days; releases can be rolled back.
- Secure development: code changes are reviewed and covered by automated tests, including tests that each club’s data stays separate; dependencies are kept up to date.
- Data minimisation and erasure: optional fields are optional; erasing a person anonymises them and removes their free text, messages and health answers while keeping records that others depend on (such as the bookings ledger) without identifying them.
- Email: sent through an authenticated EU provider (SPF, DKIM, DMARC); emails contain only what is needed for their purpose.
- Payments: card payments are made on Stripe’s hosted checkout; card numbers never pass through or are stored by MOTVIVO.
- People: confidentiality obligations for everyone with access; access is removed when no longer needed.
Annex III: Sub-processors
| Sub-processor | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany | Hosting of MOTVIVO servers, database and backups |
| Cloudflare, Inc. | USA (EU-U.S. Data Privacy Framework; Standard Contractual Clauses) | Delivery and protection of MOTVIVO’s web traffic (TLS, DDoS protection); routing of emails sent to @motvivo.com addresses |
| Sendinblue SAS (Brevo) | France | Delivery of emails sent by MOTVIVO (booking confirmations, invitations, messages, receipts) |
| Zoho Corporation B.V. | Netherlands (EU data centres) | LuxArte’s support mailboxes, where emails the Club or its members send to us are received |
Online payments. When the Club connects its own Stripe account, payments are processed by Stripe (Stripe Payments Europe, Limited, Ireland) under the Club’s own agreement with Stripe. At the Club’s instruction, MOTVIVO sends Stripe the member’s email address and what is being bought, and receives the payment result.
Questions about this DPA: [email protected] · LuxArte Ltd, Michail Koutsofta, 17, Anarita 8502, Cyprus, company registration no. HE 465325, VAT ID 60097364M.