Skip to content

    Data Processing Agreement

    Last Updated: April 30, 2026

    Jump to section…

    Last Updated: April 30, 2026 Effective Date: As of the date of acceptance by the Coach Customer (see Section 15.1)

    This Data Processing Agreement (this "DPA") forms part of the agreement between FORMD APP LLC, a Florida limited liability company ("FORMD" or "Processor"), and the Coach Customer that has accepted FORMD's Terms of Service (the "Customer" or "Controller"). FORMD and Customer are each a "party" and together the "parties."

    This DPA governs FORMD's processing of Personal Data on behalf of Customer in connection with the Coach Platform (the "Services") and is incorporated into and forms part of the Terms of Service. In the event of any conflict between this DPA and the Terms of Service with respect to the processing of Personal Data subject to this DPA, this DPA prevails to the extent of the conflict.


    1. Definitions

    Capitalized terms used but not defined in this DPA have the meanings given in the Terms of Service. The following terms have the meanings below:

    • "Applicable Data Protection Law" means all data protection and privacy laws applicable to a party's processing of Personal Data under this DPA, including: (a) the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"); (b) the U.K. Data Protection Act 2018 and the U.K. GDPR; (c) the Swiss Federal Act on Data Protection ("FADP"); (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); (e) the Virginia Consumer Data Protection Act ("VCDPA"); (f) the Colorado Privacy Act ("CPA"); (g) the Connecticut Data Privacy Act ("CTDPA"); (h) the Florida Digital Bill of Rights ("FDBR"); (i) the Washington My Health My Data Act ("MHMDA"); and (j) any successor or analogous law.
    • "Athlete" or "Data Subject" means an individual end user of the Mobile App whose Personal Data is processed under this DPA.
    • "Customer Personal Data" means Personal Data of Athletes and other Data Subjects that FORMD processes on behalf of Customer through the Services. For the avoidance of doubt, Customer Personal Data does not include (i) Personal Data of Customer or Customer's Authorized Users in their capacity as Coach Customer/employees (which FORMD processes as Controller under the Privacy Policy) or (ii) Personal Data that FORMD processes as Controller for its own purposes (e.g., security, fraud prevention, product improvement using de-identified data) — see Section 4.4.
    • "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to GDPR, adopted by the European Commission Decision (EU) 2021/914 of 4 June 2021.
    • "International Transfer" means a transfer of Personal Data outside the European Economic Area, the United Kingdom, or Switzerland.
    • "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Applicable Data Protection Law.
    • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by FORMD.
    • "Processing" (and its cognates) has the meaning given in GDPR Art. 4(2).
    • "Special Category Data" means Personal Data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation, as defined in GDPR Art. 9. Fitness, exercise, heart-rate, HRV, and sleep data processed in the Services constitute "data concerning health" and are Special Category Data.
    • "Sub-processor" means any third party engaged by FORMD to process Customer Personal Data on FORMD's behalf in the course of providing the Services.
    • "UK Addendum" means the U.K. International Data Transfer Addendum to the EU SCCs, version B1.0, issued by the U.K. Information Commissioner's Office.

    The terms "Controller," "Processor," "Data Subject," and "Supervisory Authority" have the meanings given in GDPR.

    For CCPA/CPRA purposes, FORMD acts as a "service provider" to Customer and Customer is a "business." FORMD does not "sell" or "share" (as those terms are defined in CCPA/CPRA) Customer Personal Data, and the parties' agreement constitutes a service-provider agreement under Cal. Civ. Code § 1798.140(ag).


    2. Roles and Scope

    2.1 Roles

    The parties acknowledge that, with respect to Customer Personal Data, Customer is the Controller and FORMD is the Processor. Where Applicable Data Protection Law treats FORMD as a processor, service provider, or contractor and treats Customer as a controller, business, or covered entity, this DPA applies.

    2.2 Subject Matter, Duration, Nature, and Purpose

    The subject matter, duration, nature, and purpose of FORMD's processing of Customer Personal Data, the categories of Data Subjects and Personal Data, and the obligations and rights of Customer, are described in Annex I to this DPA.

    2.3 Scope of FORMD's Processing

    FORMD will process Customer Personal Data only:

    • (a) on documented instructions from Customer, including for the provision of the Services as described in the Terms of Service, the Privacy Policy, and the in-product configuration set by Customer;
    • (b) as necessary to comply with FORMD's legal obligations (in which case, where legally permitted, FORMD will inform Customer of the legal requirement before processing);
    • (c) for the limited purposes for which FORMD acts as Controller (Section 4.4), which are not subject to Customer's instructions but are governed by the Privacy Policy.

    Customer's documented instructions are: (i) the Terms of Service and this DPA; (ii) the configuration of the Services as set by Customer or its Authorized Users; (iii) any other written instructions from Customer that the parties mutually agree do not require new fees or change FORMD's obligations beyond those in the Terms of Service.

    2.4 Compliance with Customer Instructions

    If FORMD believes that an instruction from Customer infringes Applicable Data Protection Law, FORMD will inform Customer without undue delay and may suspend the affected processing pending resolution.


    3. Customer Obligations

    Customer represents, warrants, and covenants that:

    • Customer has provided all required notices to and obtained all required consents and authorizations from Athletes and other Data Subjects under Applicable Data Protection Law for the processing FORMD performs under this DPA, including consents required for Special Category Data and for International Transfers;
    • Customer's instructions to FORMD comply with Applicable Data Protection Law;
    • Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired the data;
    • Customer has and will maintain a lawful basis for the processing under GDPR Art. 6 and Art. 9 and the equivalent under other Applicable Data Protection Law;
    • Customer will respond to Data Subject requests directed to Customer in accordance with Applicable Data Protection Law and will use FORMD's tools and assistance under Section 7 to do so.

    4. FORMD Obligations

    4.1 Confidentiality

    FORMD ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

    4.2 Security

    FORMD implements and maintains the technical and organizational measures described in Annex II to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of Data Subjects.

    4.3 Personal Data Breach

    FORMD will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include the information required under GDPR Art. 33(3) to the extent reasonably available at the time and will be supplemented as additional information becomes available. FORMD will reasonably cooperate with Customer in responding to the Breach, including providing information needed for Customer to satisfy its own breach-notification obligations.

    4.4 FORMD as Independent Controller

    FORMD acts as an independent Controller (and not as Processor) for the following processing of personal data, which is governed by the Privacy Policy rather than this DPA:

    • Account, billing, and support data of Customer and its Authorized Users;
    • Security monitoring, fraud prevention, abuse detection, and audit logging;
    • Service performance monitoring, error logging, and platform optimization;
    • Aggregated and de-identified analytics for product improvement;
    • Compliance with FORMD's own legal obligations (e.g., tax, recordkeeping).

    For the avoidance of doubt, FORMD does not act as Customer's Processor for these purposes and does not require Customer's instructions to perform them.


    5. Sub-processors

    5.1 General Authorization

    Customer provides general authorization for FORMD to engage Sub-processors to process Customer Personal Data, subject to this Section 5.

    5.2 Initial Sub-processor List

    The Sub-processors approved as of the Effective Date are listed in Annex III.

    5.3 New Sub-processors

    FORMD will provide Customer with notice of the addition or replacement of any Sub-processor at least thirty (30) days before the new Sub-processor begins processing Customer Personal Data, by updating Annex III at tryformd.com/legal/sub-processors and (where Customer has subscribed) by email. Customer may, within fifteen (15) days of the notice, object to the new Sub-processor on reasonable grounds related to Applicable Data Protection Law.

    If Customer objects, the parties will work in good faith to resolve the objection (which may include FORMD modifying the Services to avoid use of the new Sub-processor for Customer Personal Data). If the parties cannot resolve the objection within thirty (30) days, Customer may terminate the affected portion of the Services as its sole and exclusive remedy and receive a pro-rata refund of pre-paid, unused fees for the affected portion.

    5.4 Flow-down of Obligations

    FORMD will impose on each Sub-processor data-protection obligations no less protective than those imposed on FORMD under this DPA, including obligations regarding security, confidentiality, breach notification, International Transfers, and audits. FORMD remains liable for the acts and omissions of its Sub-processors as if they were FORMD's own.


    6. International Transfers

    6.1 Mechanism for EU/UK/Swiss Transfers

    To the extent FORMD's processing of Customer Personal Data involves an International Transfer, the parties agree that:

    • (a) EU/EEA Transfers. The EU SCCs are incorporated into this DPA by reference. The parties agree that:

      • Module 2 (Controller-to-Processor) applies to transfers from Customer (as data exporter) to FORMD (as data importer);
      • Module 3 (Processor-to-Sub-processor) applies to onward transfers from FORMD to its Sub-processors;
      • Clause 7 (Docking Clause) applies;
      • Clause 9 — Option 2 (general written authorization) applies, with the time period for prior notice of Sub-processor changes being thirty (30) days as set out in Section 5.3;
      • Clause 11 — Optional language regarding independent dispute resolution is not included;
      • Clause 17 — Option 1 applies; the governing law is the law of Ireland;
      • Clause 18(b) — the courts of Ireland have jurisdiction;
      • The information required by Annexes I, II, and III of the EU SCCs is set out in Annexes I, II, and III to this DPA.
    • (b) U.K. Transfers. For Personal Data transferred from the U.K., the U.K. Addendum is incorporated and amends the EU SCCs as needed. Table 1: dates and parties as in this DPA. Table 2: the EU SCCs as set out in clause (a) above. Table 3: Annexes I, II, and III to this DPA. Table 4: neither party may end the Addendum on a permitted change in clause 18.

    • (c) Swiss Transfers. For Personal Data transferred from Switzerland, the EU SCCs apply with the modifications required by the FADP, including: references to the GDPR are read to also include the FADP; the term "member state" is read to also include Switzerland; the supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and Swiss law governs.

    6.2 Supplementary Measures

    The parties have considered the supplementary measures described in Annex II and have determined that, in combination with the EU SCCs, they provide essentially equivalent protection to Personal Data following an International Transfer.

    6.3 Additional Transfer Mechanisms

    FORMD may, at its option and with prior notice to Customer, rely on additional transfer mechanisms (e.g., the EU-U.S. Data Privacy Framework, where applicable to FORMD or any Sub-processor). Use of an additional mechanism does not relieve FORMD of any obligation under the EU SCCs that remains effective for the relevant transfer.


    7. Data Subject Rights

    7.1 Cooperation

    FORMD will provide Customer with reasonable assistance, taking into account the nature of the processing and the information available to FORMD, to enable Customer to respond to Data Subject requests under Applicable Data Protection Law (including rights of access, correction, deletion, restriction, objection, portability, and rights related to automated decision-making).

    7.2 In-Product Tools

    FORMD provides Coach Platform tools that allow Customer to view, export, correct, and delete Customer Personal Data of Connected Athletes. Use of these tools is the primary means by which Customer responds to Data Subject requests.

    7.3 Direct Requests to FORMD

    If FORMD receives a Data Subject request relating to Customer Personal Data, FORMD will (a) promptly forward the request to Customer (unless legally prohibited); (b) not respond to the request directly, except as legally required or to confirm that the request has been received and forwarded; and (c) provide reasonable assistance to Customer in responding.

    7.4 Costs

    FORMD will provide the assistance described in this Section 7 at no additional charge for the standard tools and reasonable cooperation. Where Customer's request requires significant additional engineering or operational work beyond standard tools, FORMD may charge time-and-materials at FORMD's then-current rates with prior written notice to Customer.


    8. Audits

    8.1 Audit Rights

    FORMD will make available to Customer all information necessary to demonstrate compliance with this DPA and Applicable Data Protection Law. The primary means of audit is FORMD's then-current security and compliance package, which includes:

    • This DPA and the security measures in Annex II;
    • FORMD's annual SOC 2 Type II report (when available; FORMD plans to pursue SOC 2 attestation and will share the report when available);
    • Penetration test summaries (with sensitive details redacted);
    • Sub-processor list and supporting documentation;
    • Written responses to Customer's reasonable security questionnaires (annually).

    8.2 On-Site Audits

    To the extent the materials in Section 8.1 are insufficient to demonstrate compliance, Customer may request an on-site audit no more than once per twelve (12) month period (and additionally, without limit, after a Personal Data Breach affecting Customer or upon a reasonable request by a Supervisory Authority). On-site audits will (a) be conducted on at least thirty (30) days' written notice; (b) take place during normal business hours; (c) be conducted by Customer or by a mutually agreed independent third-party auditor under confidentiality obligations no less protective than this DPA; (d) not unreasonably interfere with FORMD's operations; (e) be at Customer's cost (except where the audit reveals material non-compliance, in which case FORMD will reimburse Customer's reasonable audit costs); and (f) not require disclosure of information about other FORMD customers, FORMD's source code, or any information protected by FORMD's confidentiality obligations to third parties beyond what is reasonably necessary.

    8.3 Supervisory Authority Audits

    FORMD will cooperate with audits conducted by a competent Supervisory Authority where required by Applicable Data Protection Law.


    9. Return or Deletion of Customer Personal Data

    9.1 On Termination

    On termination or expiration of the Services for any reason, FORMD will, at Customer's option, return or delete all Customer Personal Data and existing copies, except to the extent FORMD is required by Applicable Data Protection Law to retain some or all of the Customer Personal Data. In that case, FORMD will inform Customer of the legal requirement, the categories of data retained, the period of retention, and the security measures applied.

    9.2 Customer Self-Service

    Before termination, Customer may export Customer Personal Data using the Coach Platform's export tools. After termination, the Coach has thirty (30) days to request export under Section 17.5 of the Terms of Service. Following that period, FORMD will delete or anonymize Customer Personal Data on the schedule in the Privacy Policy (Section 10), subject to backup and legal-hold exceptions.

    9.3 Backups and De-identified Data

    FORMD's routine backups containing Customer Personal Data are retained for up to thirty-five (35) days after Customer Personal Data is deleted from the production environment, after which the data is overwritten on the next backup cycle. Aggregated and de-identified data that no longer constitutes Personal Data may be retained indefinitely.


    10. Liability

    The aggregate liability of each party arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service. For the avoidance of doubt, Section 20(d) of the Terms of Service excludes from the liability cap any liability that cannot be excluded under Applicable Data Protection Law (including, where applicable, GDPR Art. 82).


    11. Governing Law and Jurisdiction

    Except as expressly set out otherwise in this DPA (including Section 6 with respect to the EU SCCs), this DPA is governed by the laws of the State of Florida, U.S., and disputes are resolved in accordance with Section 23 of the Terms of Service. The choice of Irish law in the EU SCCs (Clause 17 / 18) governs solely the EU SCCs themselves and does not displace the governing law of this DPA generally.


    12. Term and Termination

    This DPA takes effect on the Effective Date and continues for as long as FORMD processes Customer Personal Data on behalf of Customer. The provisions of this DPA that by their nature should survive termination (including Sections 9, 10, and 11) survive.


    13. Order of Precedence

    In case of conflict between this DPA and any other agreement between the parties (including the Terms of Service), the order of precedence is:

    1. The EU SCCs (and U.K. Addendum and Swiss adaptations) — but only with respect to the International Transfers they govern;
    2. This DPA;
    3. The Terms of Service;
    4. The Privacy Policy.

    14. Amendments

    FORMD may update this DPA from time to time to reflect changes in Applicable Data Protection Law, FORMD's operations, or new Sub-processors. Material updates will be communicated to Customer at least thirty (30) days before they take effect, and Customer's continued use of the Services after the effective date constitutes acceptance.


    15. Acceptance and Signature

    15.1 Acceptance by Click-Through

    This DPA is incorporated into the Terms of Service. Customer's acceptance of the Terms of Service constitutes acceptance of this DPA, without the need for a separate signature. The Effective Date of this DPA for a given Customer is the date on which Customer first accepts the Terms of Service.

    15.2 Counter-Signed DPA

    A Customer that requires a separately countersigned DPA may execute the signature block below and email a signed copy to legal@tryformd.com. FORMD will counter-sign and return within ten (10) business days.

    FORMD APP LLC                          CUSTOMER
    
    By: _______________________________    By: _______________________________
    Name: _____________________________    Name: _____________________________
    Title: ____________________________    Title: ____________________________
    Date: _____________________________    Date: _____________________________
                                           Customer Account Email: ___________
    

    A. List of Parties

    Data Exporter (Controller): Customer (the Coach Customer who accepted the Terms of Service).

    • Contact Person's name, position, and contact details: As provided in the Coach Account billing profile.
    • Activities relevant to the data transferred: Use of the Coach Platform to manage Connected Athletes, create and assign training plans, communicate with Athletes, and analyze Athlete performance.
    • Signature and date: Per Section 15.

    Data Importer (Processor): FORMD APP LLC

    • Address: Mailing address available upon written request to legal@tryformd.com, State of Florida, United States.
    • Contact: Adam Aboelmatty, FORMD APP LLC, legal@tryformd.com.
    • Activities relevant to the data transferred: Operation of the Coach Platform and Mobile App, processing of Athlete fitness and performance data on Customer's instructions, and provision of related Services.

    B. Description of Transfer

    Categories of Data Subjects:

    • Athletes (Connected Athletes who have accepted the Customer's invitation);
    • Authorized Users on the Customer's account (e.g., additional coaches);
    • Where applicable, Customer-designated administrative contacts.

    Categories of Personal Data:

    • Identification and contact data: name, email address, profile photo, date of birth (for age gating), gender, time zone, location (city/region);
    • Account data: account credentials (hashed passwords, auth tokens), preferences, settings;
    • Fitness and performance data (Special Category): height, weight, body composition, training history, workout logs, exercise selection, sets/reps/weights/durations, race results, splits, station baselines, race finish-time predictions, readiness scores, recovery metrics;
    • HealthKit-derived data (with the Athlete's separate, explicit consent): heart rate, HRV, sleep, activity;
    • Communications data: messages between Coach and Athlete, support tickets, in-product notifications;
    • Device and usage data: device identifiers, IP address, browser/app version, session timestamps, feature interactions;
    • Optional content: profile photos, Coach biography text.

    Special Category Data: Fitness, exercise, heart-rate, HRV, and sleep data are processed as data concerning health under GDPR Art. 9. The applied restrictions and safeguards include: explicit consent obtained from the Athlete; encryption in transit and at rest; access limited to authorized FORMD personnel and the Athlete's connected Coach; segregation from non-sensitive data where technically feasible; and the binding HealthKit commitments in the Privacy Policy.

    Frequency of the Transfer: Continuous, in connection with the Athlete's use of the Mobile App and the Customer's use of the Coach Platform.

    Nature of the Processing: Collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, restriction, erasure, and destruction of Personal Data, all as needed to operate the Services and execute Customer's instructions.

    Purposes of the Processing: Provide and operate the Coach Platform and Mobile App; enable Customer to coach the Athlete; generate training plans, predictions, and analytics; deliver communications between Coach and Athlete; process payments; maintain security, prevent abuse, and comply with law.

    Period of Retention: As set out in Section 10 of the Privacy Policy and Section 9 of this DPA.

    C. Competent Supervisory Authority

    For EU SCCs purposes, the competent Supervisory Authority is the Irish Data Protection Commission (consistent with the choice of Irish law in Clause 17 of the EU SCCs).

    For U.K. transfers, the competent authority is the Information Commissioner's Office (ICO).

    For Swiss transfers, the competent authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC).

    For U.S. state law purposes, the competent authority is the relevant state Attorney General or, in California, the California Privacy Protection Agency (CPPA).


    FORMD implements and maintains the following technical and organizational measures to ensure a level of security appropriate to the risk.

    1. Pseudonymization and Encryption

    • Encryption in transit: TLS 1.2 minimum (TLS 1.3 where supported) for all client-server connections; TLS 1.2+ between FORMD and Sub-processors;
    • Encryption at rest: AES-256 for database storage, file storage, and backups;
    • Pseudonymization: pseudonymous identifiers used in analytics and error logs to reduce reliance on direct identifiers.

    2. Confidentiality, Integrity, Availability, and Resilience

    • Role-based access control (RBAC) with least-privilege defaults;
    • Multi-factor authentication required for FORMD personnel access to production systems;
    • Production-environment access logged and reviewed;
    • Network segmentation between production, staging, and development;
    • Database row-level security policies enforce per-User and per-Coach access boundaries;
    • Disaster-recovery procedures including geographically distributed backups and restoration testing.

    3. Recovery From Incident

    • Documented incident-response runbook;
    • Backup retention up to thirty-five (35) days, with point-in-time recovery available for the production database;
    • Annual disaster-recovery test.

    4. Process for Regular Testing, Assessing, and Evaluating

    • Continuous dependency-vulnerability scanning;
    • Periodic penetration testing (frequency increasing with revenue and customer base);
    • Annual review and update of these technical and organizational measures;
    • Privacy and security training for all personnel with access to Customer Personal Data.

    5. Identification, Authentication, and Authorization

    • Customer authentication via Supabase Auth (email/password with bcrypt hashing; OAuth providers as applicable);
    • Strong password requirements and breach-password monitoring;
    • Session timeout and refresh-token rotation.

    6. Data Quality

    • Data minimization — only Personal Data needed for the specified purpose is collected;
    • Customer-facing tools to update or delete inaccurate Personal Data;
    • Validation of data inputs to prevent corruption.

    7. Limited Data Retention

    • Retention schedules as set out in the Privacy Policy and Section 9 of this DPA;
    • Automated deletion of expired data;
    • Deletion confirmed in audit logs.

    8. Accountability

    • Designated privacy contact (privacy@tryformd.com);
    • Records of processing activities maintained per GDPR Art. 30;
    • Sub-processor management process described in Section 5;
    • Personal Data Breach response process described in Section 4.3.

    9. Allow Data Portability and Deletion

    • Coach Platform export tools (CSV, JSON);
    • API endpoints for data access and deletion (where the API is included in the Subscription).

    10. Supplementary Measures for International Transfers

    • All Sub-processors with U.S. nexus operate under SCCs;
    • Encryption applied throughout the transfer chain;
    • Data minimization applied to International Transfers — data unnecessary for the recipient's processing is not transferred;
    • Transparency to Data Subjects via the Privacy Policy regarding the International Transfer mechanism.

    The following Sub-processors are approved to process Customer Personal Data as of the Effective Date.

    Sub-processorRoleCategories of DataHosting RegionTransfer Mechanism
    Supabase, Inc.Database, authentication, storageAll Customer Personal DataUS East (AWS)EU SCCs / UK Addendum / Swiss adaptations
    Stripe, Inc.Payment processing for Coach PlansCoach billing, payment metadataGlobal (US primary)EU SCCs / UK Addendum / Swiss adaptations
    RevenueCat, Inc.Mobile subscription stateMobile subscription identifiers and entitlement eventsUS (AWS)EU SCCs / UK Addendum
    Resend, Inc.Transactional emailRecipient email, message metadata, message contentUS (AWS)EU SCCs / UK Addendum
    Mixpanel, Inc.Product analyticsPseudonymous usage eventsUS (Google Cloud)EU SCCs / UK Addendum
    Functional Software, Inc. (Sentry)Error monitoringError events, stack traces, device metadataUSEU SCCs / UK Addendum
    Intercom, Inc.Customer support widgetSupport conversations, contact dataUS (AWS)EU SCCs / UK Addendum
    OpenAI, L.L.C.AI training-plan generationTraining preferences, baseline times, race goals (no raw HealthKit data)USEU SCCs; OpenAI configured to not use customer data for model training
    Cloudflare, Inc.Edge security and DDoS mitigationIP addresses, request metadataGlobal edgeEU SCCs / UK Addendum
    Vercel, Inc.Website hostingRequest logs, deployment metadataGlobal edgeEU SCCs / UK Addendum
    Expo (Expo Go / EAS)Mobile push notification delivery, OTA update distributionDevice push tokens, notification payload metadata, device identifiersUS (AWS)EU SCCs / UK Addendum
    Apple Inc.App distribution, in-app purchase, HealthKitApple ID transactional identifiers, purchase data, HealthKit data (with permission)USApple's published terms

    The current list is also published at tryformd.com/sub-processors and updated under Section 5.3.


    End of DPA.

    We use cookies

    We use strictly-necessary cookies to keep you signed in. With your permission, we also use analytics + support cookies to improve the product. Read our Privacy Policy.