GetNutriaGetNutria
FeaturesΔυνατότητεςAI ToolsΕργαλεία AIHow it worksΠώς λειτουργείBook a Free DemoΚλείστε δωρεάν demo
EN
Book a Free DemoΚλείστε δωρεάν demo
EN
← Legal & Privacy Centre

Data Processing Agreement (GDPR Article 28)Σύμβαση Επεξεργασίας Δεδομένων (GDPR, Άρθρο 28)

Version 1.0 · Published 19 July 2026 · Effective 1 August 2026

Certain proprietor, tax and contact details are pending final confirmation and will be updated before the full commercial launch.Ορισμένα στοιχεία ιδιοκτήτη, φορολογικά στοιχεία και στοιχεία επικοινωνίας βρίσκονται υπό τελική επιβεβαίωση και θα ενημερωθούν πριν από την πλήρη εμπορική διάθεση.
Contents / Περιεχόμενα
  1. 1. Purpose and roles
  2. 2. Definitions
  3. 3. Processing instructions
  4. 4. Customer responsibilities
  5. 5. Confidentiality and personnel
  6. 6. Security measures
  7. 7. Subprocessors
  8. 8. International transfers
  9. 9. Data-subject requests
  10. 10. Personal data breaches
  11. 11. DPIAs and regulatory consultation
  12. 12. Compliance information and audits
  13. 13. Return and deletion
  14. 14. Liability and precedence
  15. 15. Duration
  16. Annex 1 — Processing details
  17. Annex 2 — Initial technical and organisational measures
  18. Annex 3 — Authorised subprocessors
  19. Electronic acceptance

Version: 1.0

Effective date: 1 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the subscribing nutritionist, dietitian, healthcare professional or clinic identified in the relevant GetNutria account, subscription, or order (“Customer” or “Controller”), and *, trading as GET NUTRIA, a business name registered in the Republic of Cyprus under Business Name Registration No. ΕΕ 63204 α, with its business address at 10 Nikou Karantoni, Akropoli, 2013 Nicosia, Cyprus (“GetNutria” or “Processor”).

1. Purpose and roles

1.1 The Customer determines the purposes and essential means of processing its clients' personal data through GetNutria and acts as controller for that data.

1.2 GetNutria processes Customer Personal Data on behalf of and under the documented instructions of the Customer and acts as processor, except where GetNutria independently processes limited data as a controller for account administration, billing, security, legal compliance or establishment of legal claims.

1.3 Each party will comply with the GDPR and applicable Cyprus data-protection law in relation to its responsibilities.

2. Definitions

“Applicable Data Protection Law” means Regulation (EU) 2016/679 (“GDPR”), applicable Cyprus implementing law and other binding data-protection requirements applicable to the processing.

“Customer Personal Data” means personal data processed by GetNutria on behalf of the Customer through the service.

“Security Incident” means a confirmed personal data breach affecting Customer Personal Data.

“Subprocessor” means another processor engaged by GetNutria to process Customer Personal Data.

3. Processing instructions

3.1 GetNutria will process Customer Personal Data only:

• to provide, secure, support and maintain the GetNutria service;

• as configured or initiated by authorised Customer users;

• as described in this DPA and the main service agreement;

• on additional documented instructions agreed by the parties; or

• where required by Union or Member State law, in which case GetNutria will inform the Customer before processing unless prohibited by law.

3.2 If GetNutria reasonably believes an instruction infringes Applicable Data Protection Law, it will inform the Customer and may suspend the affected processing until the issue is resolved.

3.3 The Customer instructs GetNutria to process Customer Personal Data for the duration of the service as described in Annex 1.

4. Customer responsibilities

The Customer is responsible for:

• ensuring it is authorised to collect and process Customer Personal Data;

• providing required privacy information to clients and other data subjects;

• identifying a valid Article 6 legal basis and, for health data, an applicable Article 9 condition;

• ensuring instructions to GetNutria are lawful;

• limiting data entered into GetNutria to what is relevant and necessary;

• managing user access and promptly removing access that is no longer required;

• responding to data-subject requests as controller; and

• configuring optional AI, communication and import features in a lawful and transparent manner.

5. Confidentiality and personnel

5.1 GetNutria will ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations.

5.2 Access will be limited to personnel who reasonably require it for support, security, maintenance, billing, incident response or legal compliance.

5.3 GetNutria personnel will not routinely inspect Customer Personal Data and will use the minimum access reasonably necessary for an authorised purpose.

6. Security measures

6.1 GetNutria will implement and maintain appropriate technical and organisational measures considering the nature, scope, context and purposes of processing and the risks to individuals.

6.2 The initial measures are described in Annex 2 and the GetNutria Security and Data Protection Overview (GDPR).

6.3 The Customer acknowledges that security measures may evolve as technology and risks change, provided the overall level of protection is not materially reduced.

7. Subprocessors

7.1 The Customer grants GetNutria general written authorisation to use the subprocessors listed in Annex 3 and in the current GetNutria Subprocessor List (GDPR).

7.2 GetNutria will impose data-protection obligations on subprocessors that provide materially equivalent protection for Customer Personal Data.

7.3 GetNutria will provide reasonable advance notice of a new or replacement subprocessor that materially processes Customer Personal Data.

7.4 The Customer may object on reasonable data-protection grounds within 14 calendar days. The parties will work in good faith to address the concern. If no reasonable alternative is available, either party may terminate the affected service in accordance with the main agreement.

7.5 GetNutria remains responsible for its subprocessors' performance of their data-protection obligations to the extent required by GDPR.

8. International transfers

8.1 GetNutria will configure the primary production database and file storage in the EEA and will use reasonable efforts to keep ordinary production processing in the EEA where the selected service supports it.

8.2 Where Customer Personal Data is transferred to or accessed from outside the EEA, GetNutria will ensure that the transfer is supported by one or more lawful mechanisms, including an applicable adequacy decision, the European Commission's 2021 Standard Contractual Clauses, or another valid safeguard.

8.3 Where appropriate to the risk, GetNutria will apply supplementary measures, including encryption in transit and at rest, data minimisation, access controls, provider due diligence and restrictions on the content transmitted to communications or support providers.

8.4 GetNutria will not intentionally send identifiable client health data to an AI provider unless the provider's contract expressly permits the intended special-category processing and the required residency, retention and transfer safeguards have been documented. At the initial launch, AI-assisted health-report extraction will remain disabled unless these requirements have been completed.

8.5 Details of relevant providers, locations and safeguards will be maintained in the current Subprocessor List.

9. Data-subject requests

9.1 Taking into account the nature of processing, GetNutria will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests under GDPR Chapter III.

9.2 If GetNutria receives a request relating primarily to Customer Personal Data, it will direct the requester to the Customer or notify the Customer, unless prohibited by law.

9.3 GetNutria will not independently respond on the Customer's behalf unless authorised or legally required.

10. Personal data breaches

10.1 GetNutria will notify the Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.

10.2 The notification will include available information reasonably required for the Customer's assessment, including:

• the nature of the incident;

• affected categories of data and individuals, where known;

• likely consequences;

• measures taken or proposed; and

• a contact point for further information.

10.3 Information may be provided in phases as the investigation progresses.

10.4 GetNutria's notification is not an admission of fault or liability.

10.5 The Customer is responsible for notifications to supervisory authorities and affected individuals as controller. GetNutria will provide reasonable assistance.

11. DPIAs and regulatory consultation

Taking into account the nature of processing and available information, GetNutria will provide reasonable assistance with data-protection impact assessments and prior consultation obligations relating to the Customer's use of the service.

12. Compliance information and audits

12.1 GetNutria will make available information reasonably necessary to demonstrate compliance with Article 28 obligations.

12.2 The parties will first use available policies, security summaries, questionnaires, certifications or independent reports where available.

12.3 If those materials are insufficient, the Customer may request an audit no more than once per year, unless a Security Incident or supervisory authority reasonably requires otherwise. Audits must:

• be conducted on reasonable notice;

• avoid disrupting operations;

• protect other customers' confidentiality and system security;

• be limited to relevant processing; and

• be at the Customer's cost unless material non-compliance is found.

13. Return and deletion

13.1 During the subscription, the Customer may access or export supported Customer Personal Data using available platform functions or by making a reasonable request.

13.2 Following termination, GetNutria will provide a data-export period of 30 calendar days, unless access is suspended for security or unlawful use.

13.3 After the export period, GetNutria will delete or anonymise Customer Personal Data from active systems within 30 calendar days after the export period ends, unless retention is legally required.

13.4 Residual copies in backups will be isolated from ordinary use and deleted through the normal backup-expiry cycle within 30 additional calendar days and, in all cases, no later than 90 calendar days after termination.

13.5 On request, GetNutria will provide reasonable confirmation of deletion.

14. Liability and precedence

Liability under this DPA is subject to the limitations in the main service agreement to the extent permitted by law. If this DPA conflicts with the main agreement regarding processing of Customer Personal Data, this DPA prevails.

15. Duration

This DPA begins when accepted and continues while GetNutria processes Customer Personal Data on behalf of the Customer.

Annex 1 — Processing details

Subject matter

Provision of a nutrition-practice management and client portal service.

Duration

For the Customer's subscription and the deletion/return period described in this DPA.

Nature and purposes

Hosting, organising, displaying, transmitting, backing up, securing, supporting, importing, exporting and deleting data used for client management, diet planning, body measurements, appointments, communications and related practice functions.

Categories of data subjects

• Clients and prospective clients of the Customer

• Parents, guardians or emergency contacts where entered

• Nutritionists, clinic staff and authorised users

Types of personal data

• Identity and contact information

• Account and authentication data

• Appointments and communications

• Diets, recipes, food information and professional notes

• Body measurements and progress records

• Uploaded documents and import results

• Audit and activity information

Special categories

Health, body-composition, dietary and related information that may reveal health status.

Frequency

Continuous or as initiated by authorised users.

Annex 2 — Initial technical and organisational measures

Measures must reflect actual production implementation and be verified before publication. They are intended to include:

• role-based and client-scoped access controls;

• unique user accounts and secure authentication;

• password hashing and protected sessions;

• encrypted network transport in production;

• least-privilege administrative access;

• logging of relevant security and administrative events;

• separation of production and development data;

• controlled backups and restoration procedures;

• vulnerability, dependency and patch-management processes;

• incident-response and breach-notification procedures;

• confidentiality obligations for authorised personnel;

• vendor and subprocessor due diligence;

• data export, retention and deletion procedures; and

• periodic testing or review of security controls.

Annex 3 — Authorised subprocessors

The authoritative list is the current GetNutria Subprocessor List (GDPR). Before publication, verify every production provider, service, location and transfer safeguard.

Electronic acceptance

The individual accepting this DPA confirms that they are authorised to bind the Customer. Electronic acceptance records may include the account, organisation, DPA version, locale and timestamp.

GetNutriaGetNutria

The all-in-one platform for nutritionists and dietitians. Manage clients, create diet plans, track progress, and communicate — all in one place.Η all-in-one πλατφόρμα για διαιτολόγους και διατροφολόγους. Διαχειριστείτε πελάτες, δημιουργήστε διαιτολόγια, παρακολουθήστε την πρόοδο και επικοινωνήστε — όλα σε ένα μέρος.

hello@getnutria.com

ProductΠροϊόν

  • FeaturesΔυνατότητες
  • AI ToolsΕργαλεία AI
  • How it worksΠώς λειτουργεί
  • Book a Free DemoΚλείστε δωρεάν demo

CompanyΕταιρεία

  • Sign inΣύνδεση
  • support@getnutria.com
  • sales@getnutria.com

Legal & PrivacyΝομικά & Απόρρητο

  • Privacy (GDPR)
  • Terms
  • DPA (GDPR Article 28)
  • Cookies
  • Subprocessors
  • Security
  • Legal Centre

© 2026 GetNutria. All rights reserved.Με την επιφύλαξη παντός δικαιώματος.