<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1244923805528197&amp;ev=PageView&amp;noscript=1">

What is a Sub-Processor?

A sub-processor is a third party data processor that Exos engages to process personal data to assist Exos with delivering “Exos Offerings” (as defined in our privacy policy).

Exos may be considered a "processor" or a "controller," within the meaning of applicable data protection law, of the data that these sub-processors process: (a) when an Exos client (e.g., employer) facilitates access to the Exos Offerings, Exos serves as a “data processor” of the data that clients transmit to Exos in their corporate capacity (e.g., list of employees eligible to access the Offerings) and (b) when an end user or “Member” accesses the Offerings (fitness/wellness services), Exos serves as controller of the data it collects directly from those Members as individuals. Where Exos serves as controller, it provides privacy rights as described in its privacy policy (e.g., right to delete and access data).

 

Contractual Safeguards

The list below includes the Exos sub-processors that process data for our "Digital Services," as defined in our Terms of Service. Exos may be considered a "processor" or a "controller" within the meaning of the GDPR of the data processed by these sub-processors, depending on the circumstances.

 

Contractual Safeguards

If you are an Exos client and wish to sign onto the Exos Data Processing Agreement with regard to the data over which you act as controller, please contact legal-notices@teamexos.com.

Additionally, please be assured that Exos requires its sub-processors to satisfy privacy and security obligations consistent with those described in the Exos Privacy Policy such as to:

  • process personal data following Exos’ documented instructions;
  • promptly inform Exos about relevant security matters; and
  • cooperate with Exos to assist with fulfilling data privacy requests.

 

Exos requires sub-processors to satisfy customary privacy and security obligations that are no less rigorous than those offered by Exos in the Exos Data Protection Addendum (“DPA”). If you are a corporate subscriber to an Exos solution and wish to enter into our DPA, please email your account manager.

 

Process to Engage New Sub-processor

Exos will update this webpage whenever it adds sub-processors, and if you have entered into a Data Processing Agreement with Exos, it will also email your address for notices contained in such agreement.  

 

Affiliates as Sub-processor

To the extent that you are a Member (end user of fitness/wellness services) and use Exos Offerings outside of the United States, Exos may process your personal data via its affiliate located in the applicable country. In addition, depending on the Offering you use, Exos may process your personal data via an applicable US affiliate. Exos affiliates include:

Affiliate Name

Registered Location

Affiliate Name

Registered Location

AP Global Services, LLC

Delaware

EXOS AP Arizona, LLC

Georgia

Athletes' Performance, Inc.

Delaware

EXOS AP Los, Angeles, LLC

Delaware

Athletes’ Performance Elite, LLC

Delaware

EXOS AP San Diego, LLC

Delaware

Athletes’ Performance Florida, LLC

Delaware

EXOS AP Texas, LLC

Delaware

Athletes’ Performance Germany GMBH

Germany

EXOS Community Health Services, LLC

New Jersey

Athletes’ Performance Hong Kong Limited

Hong Kong

EXOS Community Services, LLC

New Jersey

Athletes’ Performance International, LLC.

Delaware

EXOS Corporate Health Services, LLC

New Jersey

Athletes’ Performance Management Consultancy Limited

Beijing

Exos Health Holdings, LLC.

Delaware

Athletes’ Performance UK Limited

United Kingdom

EXOS Human Capital, LLC

Delaware

Core Performance Centers, LLC

Delaware

EXOS Tactical, LLC

Delaware

CP International LLC (Singapore Branch)

Singapore

EXOS Works Malaysia

Malaysia

CP International, LLC

Delaware

EXOS Works Mexico

Mexico

CP International, LLC (Ireland Branch)

Ireland

Exos Works, Inc.

New Jersey

CP International, LLC (Zurich Branch)

Switzerland

France CP (Bld)

France

CP Japan

Japan

   



Third Parties as Sub-processors

Depending on the Exos Offering you use, one or more of the following sub-processes may process your personal data:

Sub/Processor

Processes Client or Member Data

Purpose

Data Processed

Location Data Storage

Applicable Exos Offering

Data Safeguards

Amazon RDS

Both

Data storage

All information collected via the applicable Offering

USA

Fit

Risk and Compliance whitepaper


AWS Privacy Notice

Amazon Web Services

Both

Cloud computing and storage

All information collected via the applicable Offering

USA

Fit

Risk and Compliance whitepaper

AWS Privacy Notice

Auth0

Both

Registration and authentication

  • First and Last Name
  • Email Address
  • User ID

US and EEA

Fit

Auth0 Security, Privacy & Compliance


Auth0 GDPR Compliance


Auth0/Okta Privacy Policy

AWS Cognito

Both

Authentication

  • Email Address
  • User Demographics

USA

Fit

Risk and Compliance whitepaper


AWS Privacy Notice

AWS DynamoDB

Member

Data Storage

  • First and Last Name
  • Email Address
  • Activity Data (booking history)

USA

Fit

Risk and Compliance whitepaper


AWS Privacy Notice

Branch.IO

Member

Deep Linking

  • User information 
  • Cookies
  • IP Address

USA

Fit

Branch.IO Security & Privacy


Branch.IO Privacy Policy

BridgeAthletic

Member

Training program creation

  • First and last name
  • Email address
  • Performance data
  • Daily questionnaire
  • Coach notes
  • Movement video

USA

Exos sport performance centers, Google personal training

Bridge Athletic Privacy Policy


Bridge Athletic Terms of Service

Calendly

Member

Consultation scheduling

  • Unique ID
  • Scheduling Data

USA

Fit

Calendly Privacy Policy

Cloudflare

Both

Web Application Firewall

  • IP Address
  • Georeferencing Data

USA

Fit, Coach Hub

Cloudflare Compliance Page


GDPR Compliance Page

CookieYes

Both

Cookie Compliance

  • IP Address
  • Cookie Data 

UK

Exos’ websites

CookieYes Privacy Policy

Cronofy

Member

Calendar Scheduling

  • Email Address
  • Unique ID
  • Scheduling Data

USA

Perform, Fit

Cronofy Security & Privacy

DariMotion

Member

Musculoskeletal analysis scanner

  • First and last name
  • Email address
  • 3D Motion capture data

USA

Exos sport performance centers

DariMotion Privacy Policy

DOMO

Both

Data analytics 

  • Contact Information
  • Fitness and Health Data
  • User Event Log Data

USA

Perform, Fit

DOMO Privacy Policy

Hubspot

Both

Customer relationship management

  • Email Address
  • Contact Information
  • User Demographics

Germany, USA

Perform, Fit

Hubspot Privacy Policy


Hubspot Security, Privacy, and Control

Iterable

Member

Marketing/Targeted Communications

  • First and Last Name
  • User Contact Information
  • IP address

USA

Fit

Iterable Privacy Policy

Ixcela

Member

Metabolite assessment

  • First and Last Name
  • Demographics
  • Date of Birth
  • Email address

USA

Exos sport performance centers

Ixcela Privacy Policy



Kitman Labs

Member

Athlete management system

  • First and Last Name
  • Demographics
  • Date of Birth
  • Performance Data
  • Email address

US and EEA

Exos sport performance centers

Kitman Labs Privacy Policy 

LaunchDarkly

Member

Monitoring and tracking

  • Email Address 
  • User interactions with Exos’ Digital Solution Features

"anywhere where we or one of our service providers has services"

Perform, Fit

LaunchDarkly Terms & Policies

Looker

Both

Data analytics

  • Contact Information
  • Fitness and Health Data
  • User Event Log Data

USA

Perform, Fit

Looker Privacy Policy

Mindbody Online

Both

MMS, Class scheduling, Payment

  • First and Last Name
  • Email Address 
  • Birthday
  • User Demographics 
  • Scheduling Information 
  • Purchase History
  • Payment information

USA

Fit

Mindbody Online Privacy Policy

Mixpanel

Member

Analytics and usage tracking

  • User activity throughout Exos Digital Solutions 

USA

Perform, Fit

Mixpanel Privacy Policy

Paypal

Member

Payment

  • First and Last Name
  • Payment Information
  • Address
  • IP Address

USA

Fitness Center Management

Paypal Privacy Policy 

Paysimple

Member

Payment

  • First and Last Name
  • Payment Information
  • Address
  • IP Address

USA

Fitness Center Management

Paysimple Privacy Policy


Paysimple Security Certifications  

Perch

Member

Force Velocity Profiling

  • First and Last Name

USA

Exos sport performance centers

Perch Privacy Policy 

Qualtrics

Member

Surveys

  • First and Last Name
  • Email Address
  • IP Address

USA

Perform, Fit

Qualtrics Privacy Statement


Qualtrics Security Statement

Rapsodo

Member

Pitching and Hitting Mechanics

  • First and Last Name
  • Email Address
  • Demographics
  • Video

USA

Exos sport performance centers

 

Sendgrid

Member

Transactional emails

  • Email Address
  • User Demographics

USA

Perform, Fit

Sendgrid Security


Sendgrid Privacy Policy

Sentry

Member

Security

  • Email Address
  • User Demographics

USA "and other countries where Sentry or its affiliates, future subsidiaries or service providers maintain facilities"

Fit

Sentry Privacy Policy

Snowflake

Member

Data management

  • First and Last Name
  • Email Address 
  • Birthday
  • User Demographics 
  • Scheduling Information 
  • Purchase History
  • User Activity

USA

Perform, Fit

Snowflake Privacy Policy


Snowflake Security and Trust Center

Split.io

Member

Monitoring and tracking

  • Email Address 
  • User interactions with Exos’ Digital Solution Features

USA

Fit

Split.io Privacy Policy

Storyblok

Member

Content management system

  • First and Last Name
  • Email Address
  • Interests regarding Exos’ website users or contents user’s communications with Exos from form the fills included on Exos’ website

Germany

Perform, Fit 

Storyblok Privacy Policy

Stripe

Member

Payment

  • First and Last Name
  • Payment Information
  • Address
  • IP Address

"We may transfer your Personal Data to countries other than your own country, including to the United States."

Perform

Stripe Privacy Center


Stripe Privacy Policy

Wistia

Member

Video hosting

  • IP Address
  • User Video Content Usage Data

USA

Perform, Fit

Wistia Privacy Policy



Vald Performance

Member

Force and Strength assessment

  • First and Last Name
  • Demographics
  • Date of Birth

USA and EEA

Exos sport performance centers

Vald Performance 

Zendesk

Member

Data subject request and support request manager

  • Name
  • Email address
  • Account type
  • Country
  • IP address
  • DSAR reports
  • User cookie preferences

USA

Fit

Compliance Certifications and Memberships


Privacy Policy

ZoneIn

Member

Nutrition meal planning and analysis tool

  • First and Last Name
  • Demographics
  • Date of Birth
  • Dietary intake
  • Email address

USA

Exos sport performance centers

ZoneIn Privacy Policy 

Zoom

Member

Default video solution for classes & consults

  • Email Address
  • User Contact Information
  • User Demographics
  • Zoom Chat log

USA

Perform, Fit

Privacy & Security for Zoom


Zoom Privacy Statement

VERSION HISTORY