Data Protection Impact Assessment

Version 2026-05-11 · Last updated 11 May 2026

This DPIA summary describes the processing carried out by FitDesk and the safeguards we apply. Trainers using FitDesk as data controllers can rely on it as a starting point for their own DPIA where one is required (for example because they handle health-related data about their Clients on a large scale).

1. Description of processing

  • Nature: SaaS platform hosting personal data on managed cloud infrastructure (Supabase / Cloudflare).
  • Scope: account, profile, booking, payment, messaging, workout, progress and analytics data.
  • Context: personal trainers and their clients, primarily in the UK and EU.
  • Purposes: running an independent training business - bookings, payments, communication, training plans, progress tracking.

2. Necessity and proportionality

  • Data fields are limited to what is needed to operate each feature.
  • Special category (health) data is only stored where the Trainer enters it, and Trainers are required to obtain a lawful basis (typically explicit consent) from the Client.
  • Retention is limited and deletion is available on request.

3. Risks identified and mitigations

Unauthorised access to Client records

  • Row Level Security ensures Trainers can only see their own Clients' data.
  • Two-factor authentication is available for all accounts.
  • Server functions enforce role-based authorisation in addition to RLS.

Data breach at a sub-processor

  • Sub-processors are limited to reputable providers (Supabase, Stripe, Cloudflare, Resend) with their own ISO/SOC certifications.
  • Personal data is encrypted at rest and in transit.
  • Breach notification process targets < 72 hours to the affected controller.

Excessive data collection

  • Optional fields are clearly marked.
  • Free-text fields include guidance to discourage entering more sensitive data than necessary.

International transfers

  • UK IDTA / EU SCCs in place with all relevant sub-processors.
  • Encryption applied as a supplementary measure.

Misuse by an authorised user

  • Audit log records significant writes (deletions, restorations, payment changes).
  • Soft-delete with restore window for accidental deletions.

4. Residual risk

After applying the mitigations above we assess the residual risk to the rights and freedoms of data subjects as low to medium. We continue to monitor risk through ongoing security scanning, incident reviews and customer feedback.

5. Review

This DPIA is reviewed at least annually and whenever a material change is made to the Service. Questions or feedback can be sent to privacy@fitdesk.co.uk.