Data processing agreement (Art. 28 GDPR)
If you use zenyogi to host your website and member data, you are the controller and zenyogi is the processor. This page is the standard DPA. Email scott@zenyogi.io with studio name, address, and who should sign for a copy in your studio’s name.
- Processor
- Scott Brown
- scott@zenyogi.io
- Address
- 5425 Marsh Rd, 53558 McFarland, US
This data processing agreement (DPA) is the Art. 28 GDPR contract between the studio that uses zenyogi (controller) and Scott Brown, trading as zenyogi (processor).
It is concluded in electronic form (Art. 28(9) GDPR) when the studio uses zenyogi or confirms this DPA. On request, zenyogi will issue a copy naming the studio (legal name, address, signatory) — email scott@zenyogi.io.
§ 1 Subject matter and duration
The processor processes personal data to provide zenyogi: hosted studio website, schedule, booking, waitlist, member and teacher admin, email, shop, videos, challenges, and related payment flows.
The DPA lasts for as long as the studio uses zenyogi, plus the time needed to delete or return data after the end of the service.
§ 2 Nature and purpose
The processor processes data only on the studio’s documented instructions so the studio can run its site, sell classes, keep bookings, and email students.
The processor’s own purposes (for example billing the studio’s zenyogi account) are outside this DPA.
§ 3 Types of data and data subjects
Data subjects and data types are listed in Annex A.
§ 4 Documented instructions
The processor processes personal data only on documented instructions from the controller, including transfers to a third country, unless Union or Member State law requires otherwise.
Instructions are given through the software, by email to the address in the legal notice, or in this DPA. If the processor believes an instruction is unlawful, it tells the studio without undue delay.
§ 5 Confidentiality
Anyone who can access the data is bound to confidentiality and may process it only as needed for their task.
§ 6 Security of processing
The processor implements appropriate technical and organisational measures under Art. 32 GDPR. The current measures are in Annex B. The studio will be told of any material weakening of those measures.
§ 7 Sub-processors
The studio gives general written authorisation to use the sub-processors in Annex C.
zenyogi will announce a new or replacement sub-processor at least 14 days in advance on this page or by email. The studio may object on reasonable data-protection grounds. If it does not object, the change is authorised.
Sub-processors are bound to equivalent data-protection duties. Stripe, PayPal, and SumUp are used only if the studio connects them; those providers’ own DPAs also apply.
§ 8 Data-subject rights
The processor helps the studio fulfil access, rectification, erasure, restriction, portability, and objection, using the tools in the product (including export and deletion from the studio account) where those tools exist.
§ 9 Assistance with Articles 32 to 36
The processor assists the studio with security, breach notification, communication to data subjects, and data-protection impact assessments, to the extent the information is available to the processor.
§ 10 Personal-data breach
If a breach affects data under this DPA, the processor notifies the studio without undue delay after becoming aware of it, with the information the studio needs for Art. 33 and 34 GDPR that the processor has at that time.
§ 11 Deletion and return
When processing ends, the processor deletes the studio’s data or returns it, as the studio chooses, unless Union or Member State law requires storage.
During the term, the studio can export and request deletion of member profiles through the account features.
§ 12 Information and audits
The processor makes available the information needed to show compliance with this DPA and allows audits, including inspections, by the studio or an auditor mandated by the studio.
Audits are announced in good time, must not disrupt operations unreasonably, and take place at most once per year unless there is a concrete reason (for example a breach). Confidentiality and trade secrets are respected.
§ 13 International transfers
The processor is established in the United States. Sub-processors in Annex C may also process data in the US or other third countries.
Transfers rely on an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified) or on the European Commission’s standard contractual clauses (Decision 2021/914), Module 2 and/or Module 3, plus supplementary measures where required.
By using zenyogi the studio instructs the processor to make those transfers as needed to provide the service.
§ 14 Liability
Liability follows Art. 82 GDPR and applicable law. The processor is liable to the studio for damage caused by processing that breaches this DPA or the GDPR, to the extent the processor is at fault.
§ 15 Term and termination
This DPA applies while the studio uses zenyogi and ends when the service agreement ends, without ending deletion, confidentiality, or audit duties that by their nature continue.
§ 16 Final provisions
zenyogi will publish changes to this DPA on this page or by email. If the studio does not object on data-protection grounds within 14 days, the new version applies.
If a clause is invalid, the rest of the DPA stays in force. The GDPR applies. Where extra national law is needed, German law applies for studios established in the EU or EEA.
This page shows the DPA in the selected language. If a translation differs, the German text applies for studios in Germany or Austria; otherwise the English text applies.
Annex A — Processing
Categories of data subjects: students and other studio customers; teachers and studio staff the studio adds to zenyogi; emergency contacts if the studio stores them.
Types of personal data: name, email, phone, address, date of birth, locale, marketing and reminder opt-in, waiver acceptance, bookings, waitlist, attendance, memberships and purchases, notes the studio writes, teacher profile data, and payment status. Card numbers stay with the payment provider the studio connected. The studio may also store images or videos that show people.
Annex B — Technical and organisational measures
The processor maintains at least the following:
- Encryption in transit (HTTPS/TLS) for the application
- Access limited to authenticated studio accounts; roles for studio and teachers
- Studio data separated by businessId in the database
- Encryption at rest where the hosting and database providers offer it
- Regular backups through the database provider (Convex)
- Confidentiality for people with support access
- Export and deletion of member profiles from the studio account
- Security logging to the usual extent of the services used
Annex C — Sub-processors
List as of 2026-08-25. Marketing trackers on zenyogi.io (such as Vercel Analytics or Microsoft Clarity) do not process the studio’s member data and are outside this DPA.
- Convex, Inc. — Database, backend functions, and authentication. Location: United States.
- Vercel Inc. — Application hosting and CDN. Location: United States / global edge.
- Cloudflare, Inc. — Object storage (R2) for images and videos. Location: United States / Cloudflare network.
- Resend, Inc. — Transactional and studio email. Location: United States.
- Stripe, Inc. / Stripe Payments Europe, Ltd. — Card payments when the studio connects Stripe. Location: EU / United States. Only if the studio uses Stripe. Stripe’s own DPA also applies.
- PayPal (Europe) S.à r.l. et Cie, S.C.A. / PayPal, Inc. — Payments when the studio connects PayPal. Location: EU / United States. Only if the studio uses PayPal. PayPal’s own DPA also applies.
- SumUp Limited — Payments when the studio connects SumUp. Location: EU / United Kingdom. Only if the platform has enabled SumUp and the studio uses it.