Data processing agreement
Version 1.0. Last updated: 3 September 2026
This data processing agreement (the "DPA") is entered into between TriageMethod Ltd, a company registered in Ireland and trading as TriageFit ("TriageFit", "we", "us"), and the organisation that purchases a TriageFit seat pack (the "Customer"). It forms part of the corporate terms of service under which TriageFit provides seat packs to the Customer (the "Agreement") and takes effect on the date of the Customer's first seat pack purchase. If your procurement process requires a countersigned copy, contact us at info@triagemethod.com and we will arrange one.
1. Definitions
"GDPR" means Regulation (EU) 2016/679, together with any national law supplementing it that applies to the processing under this DPA. "Controller", "processor", "personal data", "data subject", "processing" and "personal data breach" have the meanings the GDPR gives them.
"Roster Data" means the personal data the Customer provides to TriageFit, or TriageFit generates for the Customer, to administer the Customer's seat pack: the name and work email address of each person the Customer invites, each invitation's state including whether it has been redeemed, each seat's state, and the associated dates.
"Member Data" means the personal data of a person who holds a TriageFit account, arising from that person's own use of the Service, including their intake, training, nutrition, check-ins, messages and any health data they share.
2. Scope of this DPA
This DPA governs Roster Data only. TriageFit processes Roster Data on the Customer's behalf as the Customer's processor, and the Customer is the controller of it.
3. Member Data is outside this DPA
When a person accepts a seat they open, or connect, a TriageFit account of their own. From that moment TriageFit is an independent controller of their Member Data under its own privacy policy, health data within it is processed only with that person's own explicit consent, and the member exercises their data-protection rights directly with TriageFit. The Customer is not a controller of Member Data, does not instruct its processing, and does not receive it: what the Customer receives about its people is Roster Data as defined above, together with aggregate reporting from which individuals cannot be read, as described in clause 4. Each person is told, at the point they redeem an invitation, exactly what the Customer can see about them.
4. Details of the processing
- Subject matter. Administration of the Customer’s TriageFit seat pack.
- Duration. The term of the Agreement, plus the deletion period in clause 11.
- Nature and purpose. Issuing seat invitations by email, tracking invitation redemption and seat state, presenting the roster to the Customer’s authorised administrators, producing aggregate participation and progress reporting for the Customer, and administering the pack’s billing. Aggregate reporting is subject to a suppression floor: a figure is released only when at least five distinct members contributed to it.
- Categories of data subjects. The Customer’s employees and other personnel the Customer invites to seats.
- Categories of personal data. Name, work email address, invitation state including redemption, seat state, and associated dates. No special categories of personal data are processed as Roster Data.
5. Instructions
TriageFit processes Roster Data only on the Customer's documented instructions, unless Union or Member State law requires otherwise, in which case TriageFit informs the Customer of that legal requirement before processing, unless that law prohibits doing so on important grounds of public interest. The Agreement, this DPA and the Customer's use of the Service's administrative controls, such as inviting a person or revoking a seat, are the Customer's complete instructions. TriageFit informs the Customer if, in its opinion, an instruction infringes the GDPR.
6. Confidentiality
TriageFit ensures that every person it authorises to process Roster Data is bound by a contractual or statutory duty of confidentiality.
7. Security
TriageFit implements and maintains appropriate technical and organisational measures for the risk, in line with Article 32 GDPR, including encryption of data in transit, encryption at rest, role-based access control with object-level authorisation checks, audit logging of sensitive reads, rate limiting and encrypted backups. The current measures are described in the security overview, which TriageFit keeps up to date as the measures evolve and may improve but not materially weaken during the term.
8. Sub-processors
The Customer gives TriageFit general written authorisation to engage the sub-processors listed at /business/subprocessors, which is the current, complete list. TriageFit will update that page and notify the Customer's billing contact by email at least 30 days before a new sub-processor processes Roster Data, or an existing one materially changes what it does. If the Customer reasonably objects on data-protection grounds within that period and the parties cannot resolve the objection, the Customer may terminate the Agreement in respect of the affected service before the change takes effect. TriageFit imposes data-protection obligations on each sub-processor no less protective than this DPA and remains fully liable to the Customer for each sub-processor's performance.
9. Assistance
Taking into account the nature of the processing, TriageFit assists the Customer with appropriate technical and organisational measures in responding to data subjects exercising their rights over Roster Data, and, taking into account the information available to it, assists the Customer in meeting its obligations under Articles 32 to 36 GDPR, including security, breach notification, data protection impact assessments and prior consultation. Requests from members about Member Data are answered by TriageFit directly as its controller, per clause 3.
10. Personal data breaches
TriageFit notifies the Customer without undue delay after becoming aware of a personal data breach affecting Roster Data, and the notification describes, so far as then known, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for more information, supplemented as further information becomes available.
11. Deletion and return
Following the end of the Agreement, TriageFit will, at the Customer's written choice, delete or return the Roster Data it processes on the Customer's behalf, and delete existing copies, unless Union or Member State law requires their storage. Where the Customer expresses no choice within 30 days of the end of the Agreement, TriageFit deletes. Member Data is unaffected: it belongs to the member relationship described in clause 3, and a member whose funded seat ends keeps their account and their rights over their own data.
12. International transfers
TriageFit processes Roster Data in the European Union wherever it controls the processing region, as recorded per provider on the sub-processor list. Where a listed sub-processor processes personal data outside the European Economic Area, TriageFit ensures the transfer is covered by a valid transfer mechanism under Chapter V GDPR, such as an adequacy decision or standard contractual clauses, before the processing occurs.
13. Audit and information
TriageFit makes available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, starting with this procurement pack, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor the Customer mandates. Audits beyond the written pack require 30 days' notice, run at the Customer's cost during business hours without disrupting the Service, respect the confidentiality of other customers' and members' data, and occur at most once in any 12-month period unless a supervisory authority requires more, or a personal data breach affecting Roster Data has occurred in that period.
14. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. If this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails.
15. Term and governing law
This DPA applies for as long as TriageFit processes Roster Data under the Agreement, and clause 11 survives its end. It is governed by the law of Ireland, and the parties submit to the jurisdiction of the Irish courts.
Getting a signed copy
This DPA binds by incorporation from your first seat pack purchase, so no signature is needed for it to apply. If your organisation needs a countersigned instrument on file, write to info@triagemethod.com from your billing contact address and we will exchange signatures on this version.