FormaCore Data Processing Agreement (DPA)
Effective Date: 01.09.2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between FormaCore LLC (registration ID 405872854), registered at Georgia, Tbilisi, Zaza Panaskertel-Tsitsishvili Street, Building 1, Apartment 180 ("Processor," "FormaCore," "we") and the Customer ("Controller"), and applies to FormaCore's processing of Personal Data of the Controller's Members on the Controller's behalf, under the Law of Georgia "On Personal Data Protection."
1. Definitions
"Personal Data" — any information relating to an identified or identifiable natural person processed by FormaCore on behalf of the Controller through the Service.
"Processing" — has the meaning given under the Law of Georgia "On Personal Data Protection."
"Data Subjects" — the Controller's Members, staff, or other individuals whose Personal Data is processed through the Service.
"Subprocessor" — any third party engaged by FormaCore to process Personal Data on the Controller's behalf.
2. Roles and Statutory Compliance
Each party shall comply with its respective obligations under the Law of Georgia "On Personal Data Protection." FormaCore acts as Data Processor; Controller acts as Data Controller for Member data processed through the Service. FormaCore's obligations are limited to operating the Service; Controller remains responsible for the lawfulness of its data collection, the information and consent it obtains from Data Subjects, and the content it submits, uploads, or sends through the Service.
3. Subject Matter, Duration, and Nature of Processing
Subject matter: Provision of the FormaCore platform for management of Controller's fitness/wellness business, including membership, scheduling, payments, and Member communications.
Duration: For the term of the subscription, plus the post-termination export/retention period described in Section 8.
Nature and purpose: Storage, retrieval, organization, and transmission of Personal Data as directed by Controller through the Service's features (member management, bookings, payment tracking, email communications via Resend, reporting).
4. Categories of Data Subjects and Personal Data
Data Subjects: Members of Controller's business; Controller's staff users where applicable.
Categories of Personal Data: identification data (name, date of birth, contact details); membership and attendance records; payment and billing history related to memberships; email communications sent or received through the platform; data voluntarily submitted by Members via the Member Portal or mobile app.
Controller determines what Personal Data is submitted and is responsible for its accuracy and the lawful basis for its collection.
5. Processor Obligations
FormaCore shall:
- Process Personal Data only on Controller's documented instructions, including as set out in the Terms of Service and this DPA, unless otherwise required by law — and will inform Controller if an instruction appears to conflict with applicable law;
- Ensure personnel authorized to process Personal Data are bound by confidentiality obligations;
- Implement appropriate technical and organizational security measures (Section 7);
- Assist Controller, so far as reasonably possible, in responding to Data Subject requests;
- Notify Controller without undue delay, and in any event within 48 hours of becoming aware, of a Personal Data breach affecting Controller's data — so Controller can meet its own 72-hour notification obligation to the Personal Data Protection Service;
- Make available information reasonably necessary to demonstrate compliance with this DPA;
- Delete or return Personal Data to Controller at the end of the subscription per Section 8, unless retention is required by law.
6. Subprocessors
Controller authorizes FormaCore to engage the following Subprocessors, and any additional Subprocessors reasonably necessary to provide the Service:
FormaCore will notify Controller of any new Subprocessor materially involved in processing Personal Data, or of a change to an existing one, at least 7 days before the change takes effect, allowing Controller to raise a reasonable objection on data-protection grounds. Continued use of the Service after that period constitutes acceptance. FormaCore remains responsible for each Subprocessor's compliance with obligations equivalent to those in this DPA. FormaCore will keep this table current and publish it at www.formacore.io for reference by Controllers and Members.
7. Security Measures
FormaCore implements measures including encryption of data in transit, access controls limiting data access to authorized personnel, secure hosting infrastructure, and periodic review of these measures as risks evolve.
8. Data Return and Deletion
Upon termination or expiration of the subscription:
- Controller may export its Personal Data for 3 months following termination.
- After this period, FormaCore will delete or anonymize remaining Personal Data from active systems within a reasonable timeframe, except where retention is required by law (e.g., financial/accounting records).
- Backup copies are purged per FormaCore's standard backup rotation schedule.
9. International Transfers
Where Personal Data is transferred outside Georgia via a Subprocessor, FormaCore will ensure the destination country offers an adequate level of protection, or that appropriate contractual safeguards are in place, consistent with the Law of Georgia "On Personal Data Protection."
10. Audit Rights
Upon reasonable written request, no more than once per year (unless required by a supervisory authority or following a security incident, and with at least 30 days' advance notice), FormaCore will provide Controller with information reasonably necessary to demonstrate compliance with this DPA — which may include relevant documentation or a written questionnaire response — in lieu of an on-site audit.
11. Liability and Precedence
Liability under this DPA is subject to the limitations set out in the Terms of Service, except where such limitation is not permitted under the Law of Georgia "On Personal Data Protection." In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA prevails.
12. Contact
FormaCore
Georgia, Tbilisi, Zaza Panaskertel-Tsitsishvili Street, Building 1, Apartment 180
Data Protection Contact: info@formacore.io

