Version: 1.0
Effective date: 1 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the subscribing nutritionist, dietitian, healthcare professional or clinic identified in the relevant GetNutria account, subscription, or order (“Customer” or “Controller”), and *, trading as GET NUTRIA, a business name registered in the Republic of Cyprus under Business Name Registration No. ΕΕ 63204 α, with its business address at 10 Nikou Karantoni, Akropoli, 2013 Nicosia, Cyprus (“GetNutria” or “Processor”).
1. Purpose and roles
1.1 The Customer determines the purposes and essential means of processing its clients' personal data through GetNutria and acts as controller for that data.
1.2 GetNutria processes Customer Personal Data on behalf of and under the documented instructions of the Customer and acts as processor, except where GetNutria independently processes limited data as a controller for account administration, billing, security, legal compliance or establishment of legal claims.
1.3 Each party will comply with the GDPR and applicable Cyprus data-protection law in relation to its responsibilities.
2. Definitions
“Applicable Data Protection Law” means Regulation (EU) 2016/679 (“GDPR”), applicable Cyprus implementing law and other binding data-protection requirements applicable to the processing.
“Customer Personal Data” means personal data processed by GetNutria on behalf of the Customer through the service.
“Security Incident” means a confirmed personal data breach affecting Customer Personal Data.
“Subprocessor” means another processor engaged by GetNutria to process Customer Personal Data.
3. Processing instructions
3.1 GetNutria will process Customer Personal Data only:
• to provide, secure, support and maintain the GetNutria service;
• as configured or initiated by authorised Customer users;
• as described in this DPA and the main service agreement;
• on additional documented instructions agreed by the parties; or
• where required by Union or Member State law, in which case GetNutria will inform the Customer before processing unless prohibited by law.
3.2 If GetNutria reasonably believes an instruction infringes Applicable Data Protection Law, it will inform the Customer and may suspend the affected processing until the issue is resolved.
3.3 The Customer instructs GetNutria to process Customer Personal Data for the duration of the service as described in Annex 1.
4. Customer responsibilities
The Customer is responsible for:
• ensuring it is authorised to collect and process Customer Personal Data;
• providing required privacy information to clients and other data subjects;
• identifying a valid Article 6 legal basis and, for health data, an applicable Article 9 condition;
• ensuring instructions to GetNutria are lawful;
• limiting data entered into GetNutria to what is relevant and necessary;
• managing user access and promptly removing access that is no longer required;
• responding to data-subject requests as controller; and
• configuring optional AI, communication and import features in a lawful and transparent manner.
5. Confidentiality and personnel
5.1 GetNutria will ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations.
5.2 Access will be limited to personnel who reasonably require it for support, security, maintenance, billing, incident response or legal compliance.
5.3 GetNutria personnel will not routinely inspect Customer Personal Data and will use the minimum access reasonably necessary for an authorised purpose.
6. Security measures
6.1 GetNutria will implement and maintain appropriate technical and organisational measures considering the nature, scope, context and purposes of processing and the risks to individuals.
6.2 The initial measures are described in Annex 2 and the GetNutria Security and Data Protection Overview (GDPR).
6.3 The Customer acknowledges that security measures may evolve as technology and risks change, provided the overall level of protection is not materially reduced.
7. Subprocessors
7.1 The Customer grants GetNutria general written authorisation to use the subprocessors listed in Annex 3 and in the current GetNutria Subprocessor List (GDPR).
7.2 GetNutria will impose data-protection obligations on subprocessors that provide materially equivalent protection for Customer Personal Data.
7.3 GetNutria will provide reasonable advance notice of a new or replacement subprocessor that materially processes Customer Personal Data.
7.4 The Customer may object on reasonable data-protection grounds within 14 calendar days. The parties will work in good faith to address the concern. If no reasonable alternative is available, either party may terminate the affected service in accordance with the main agreement.
7.5 GetNutria remains responsible for its subprocessors' performance of their data-protection obligations to the extent required by GDPR.
8. International transfers
8.1 GetNutria will configure the primary production database and file storage in the EEA and will use reasonable efforts to keep ordinary production processing in the EEA where the selected service supports it.
8.2 Where Customer Personal Data is transferred to or accessed from outside the EEA, GetNutria will ensure that the transfer is supported by one or more lawful mechanisms, including an applicable adequacy decision, the European Commission's 2021 Standard Contractual Clauses, or another valid safeguard.
8.3 Where appropriate to the risk, GetNutria will apply supplementary measures, including encryption in transit and at rest, data minimisation, access controls, provider due diligence and restrictions on the content transmitted to communications or support providers.
8.4 GetNutria will not intentionally send identifiable client health data to an AI provider unless the provider's contract expressly permits the intended special-category processing and the required residency, retention and transfer safeguards have been documented. At the initial launch, AI-assisted health-report extraction will remain disabled unless these requirements have been completed.
8.5 Details of relevant providers, locations and safeguards will be maintained in the current Subprocessor List.
9. Data-subject requests
9.1 Taking into account the nature of processing, GetNutria will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests under GDPR Chapter III.
9.2 If GetNutria receives a request relating primarily to Customer Personal Data, it will direct the requester to the Customer or notify the Customer, unless prohibited by law.
9.3 GetNutria will not independently respond on the Customer's behalf unless authorised or legally required.
10. Personal data breaches
10.1 GetNutria will notify the Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.
10.2 The notification will include available information reasonably required for the Customer's assessment, including:
• the nature of the incident;
• affected categories of data and individuals, where known;
• likely consequences;
• measures taken or proposed; and
• a contact point for further information.
10.3 Information may be provided in phases as the investigation progresses.
10.4 GetNutria's notification is not an admission of fault or liability.
10.5 The Customer is responsible for notifications to supervisory authorities and affected individuals as controller. GetNutria will provide reasonable assistance.
11. DPIAs and regulatory consultation
Taking into account the nature of processing and available information, GetNutria will provide reasonable assistance with data-protection impact assessments and prior consultation obligations relating to the Customer's use of the service.
12. Compliance information and audits
12.1 GetNutria will make available information reasonably necessary to demonstrate compliance with Article 28 obligations.
12.2 The parties will first use available policies, security summaries, questionnaires, certifications or independent reports where available.
12.3 If those materials are insufficient, the Customer may request an audit no more than once per year, unless a Security Incident or supervisory authority reasonably requires otherwise. Audits must:
• be conducted on reasonable notice;
• avoid disrupting operations;
• protect other customers' confidentiality and system security;
• be limited to relevant processing; and
• be at the Customer's cost unless material non-compliance is found.
13. Return and deletion
13.1 During the subscription, the Customer may access or export supported Customer Personal Data using available platform functions or by making a reasonable request.
13.2 Following termination, GetNutria will provide a data-export period of 30 calendar days, unless access is suspended for security or unlawful use.
13.3 After the export period, GetNutria will delete or anonymise Customer Personal Data from active systems within 30 calendar days after the export period ends, unless retention is legally required.
13.4 Residual copies in backups will be isolated from ordinary use and deleted through the normal backup-expiry cycle within 30 additional calendar days and, in all cases, no later than 90 calendar days after termination.
13.5 On request, GetNutria will provide reasonable confirmation of deletion.
14. Liability and precedence
Liability under this DPA is subject to the limitations in the main service agreement to the extent permitted by law. If this DPA conflicts with the main agreement regarding processing of Customer Personal Data, this DPA prevails.
15. Duration
This DPA begins when accepted and continues while GetNutria processes Customer Personal Data on behalf of the Customer.
Annex 1 — Processing details
Subject matter
Provision of a nutrition-practice management and client portal service.
Duration
For the Customer's subscription and the deletion/return period described in this DPA.
Nature and purposes
Hosting, organising, displaying, transmitting, backing up, securing, supporting, importing, exporting and deleting data used for client management, diet planning, body measurements, appointments, communications and related practice functions.
Categories of data subjects
• Clients and prospective clients of the Customer
• Parents, guardians or emergency contacts where entered
• Nutritionists, clinic staff and authorised users
Types of personal data
• Identity and contact information
• Account and authentication data
• Appointments and communications
• Diets, recipes, food information and professional notes
• Body measurements and progress records
• Uploaded documents and import results
• Audit and activity information
Special categories
Health, body-composition, dietary and related information that may reveal health status.
Frequency
Continuous or as initiated by authorised users.
Annex 2 — Initial technical and organisational measures
Measures must reflect actual production implementation and be verified before publication. They are intended to include:
• role-based and client-scoped access controls;
• unique user accounts and secure authentication;
• password hashing and protected sessions;
• encrypted network transport in production;
• least-privilege administrative access;
• logging of relevant security and administrative events;
• separation of production and development data;
• controlled backups and restoration procedures;
• vulnerability, dependency and patch-management processes;
• incident-response and breach-notification procedures;
• confidentiality obligations for authorised personnel;
• vendor and subprocessor due diligence;
• data export, retention and deletion procedures; and
• periodic testing or review of security controls.
Annex 3 — Authorised subprocessors
The authoritative list is the current GetNutria Subprocessor List (GDPR). Before publication, verify every production provider, service, location and transfer safeguard.
Electronic acceptance
The individual accepting this DPA confirms that they are authorised to bind the Customer. Electronic acceptance records may include the account, organisation, DPA version, locale and timestamp.