Mana Data Processing Agreement

Mana Technology AB, org. nr 559449-7637, Grankottevägen 47, 181 47 Lidingö, Sweden · legal@getmana.app

Version 2.0 · Effective 1 October 2026

1. Scope and roles

This agreement governs Mana's processing of personal data on behalf of the Customer and is part of the Mana Terms of Service, using the terms defined there. It is accepted when the Customer creates an account; no signature is required. Where it conflicts with the Terms of Service, this agreement prevails on data protection.

For Customer Data the Customer is the controller and Mana is the processor. The Customer is responsible for the lawfulness of its instructions and of the data it puts into the Platform, and for the information it gives its Users.

2. Details of the processing

Subject matterMana's provision of the Platform to the Customer
DurationThe term of the Terms of Service, plus the 60-day export period under its section 12.4 and up to 30 days after that for deletion
Nature and purposeBooking and schedule management, membership administration, facilitation of payments, communication with Users on the Customer's behalf, and reporting to the Customer
Categories of personal dataName, email, phone, date of birth, gender, profile image, booking and attendance records, membership data, payment transaction references, preferences, communication records, identity verification notes recorded by the Customer, any health-related notes a User volunteers and the Customer chooses to record (special category data, for which the Customer answers as controller), IP address and device data
Categories of data subjectsUsers who book, purchase from or otherwise interact with the Customer through the Platform

3. Mana's obligations

3.1 Instructions. Mana processes Customer Data only on the Customer's documented instructions, including as to transfers to third countries. The Terms of Service, this agreement and the Customer's use of the Platform's functions are those instructions. Where EU or member state law requires Mana to process without instruction, Mana informs the Customer beforehand unless that law forbids it. Mana informs the Customer if it considers an instruction to infringe data protection law.

3.2 Confidentiality. Everyone Mana authorises to process Customer Data is bound by confidentiality.

3.3 Security. Mana maintains technical and organisational measures appropriate to the risk under Article 32 GDPR, including encryption in transit and at rest, access control and authentication, logging, regular security testing, incident response, and staff training.

3.4 Data subject rights. Mana notifies the Customer without undue delay of any request it receives from a data subject concerning Customer Data and does not respond directly unless instructed by the Customer or required by law. Mana assists the Customer in meeting such requests through the Platform's functions and, where those are insufficient, by appropriate technical and organisational measures, taking account of the nature of the processing. Assistance is free unless the request is manifestly unfounded or excessive.

3.5 Further assistance. Taking account of the nature of the processing and the information available to it, Mana assists the Customer with security, breach notification to authorities and data subjects, data protection impact assessments and prior consultation, as required by Articles 32 to 36 GDPR.

3.6 Breach notification. Mana notifies the Customer without undue delay, and aims to do so within 72 hours, after becoming aware of a personal data breach affecting Customer Data, describing the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Mana cooperates in investigating and remedying the breach. Notification is not an admission of liability.

3.7 Deletion or return. When the provision of services ends, Mana deletes Customer Data at the end of the period in section 2, or returns it at the Customer's choice, unless EU or member state law requires retention. The export functions described in section 12.4 of the Terms of Service satisfy the return obligation.

3.8 Audit. Mana makes available the information needed to demonstrate compliance with Article 28 GDPR, and allows and contributes to audits by the Customer or an auditor it appoints. Audits require 30 days' notice, take place no more than once a year unless a breach or a supervisory authority gives cause, may not disturb operations unreasonably or expose other customers' data or Mana's confidential information, and are at the Customer's cost. Mana may respond first with current certifications, audit reports or compliance documentation, and the Customer accepts these where they reasonably answer the request.

4. Sub-processors

The Customer gives general authorisation for Mana to engage sub-processors. The current list is published at getmana.app/legal/subprocessors and is available from legal@getmana.app.

Mana updates that page and notifies the Customer by email or in the Platform at least 30 days before adding or replacing a sub-processor. The Customer may object within that period on reasonable grounds relating to data protection. If Mana cannot accommodate the objection, the Customer's sole remedy is to terminate the affected services without penalty before the change takes effect.

Mana imposes on each sub-processor data protection obligations no less protective than those in this agreement, and remains fully liable to the Customer for a sub-processor's performance.

5. International transfers

Mana does not transfer Customer Data outside the EEA unless a mechanism under Chapter V GDPR applies, such as an adequacy decision or the European Commission's standard contractual clauses with any supplementary measures needed. The transfer mechanism used for each sub-processor is stated on the sub-processor page.

6. Mana Account Data is outside this agreement

Mana is an independent controller, not a processor, for Mana Account Data. This includes account and profile data, social connections between Users, User-to-User interactions, booking history across studios, activity statistics and data derived from these, as well as aggregated and anonymised data, Marketplace data, and data Mana collects for its own purposes such as website analytics and marketing.

Mana processes that data under the Mana Privacy Policy and answers for it independently. It falls outside this agreement, is not subject to the Customer's instructions or to section 3.7, and is never included in a Customer export, as set out in section 8.3 of the Terms of Service. The same booking may exist both as Customer Data and, as part of a User's cross-studio history, as Mana Account Data; deleting the Customer's records does not delete Mana's.

7. Liability, term and law

Liability under this agreement is subject to the limits in section 11 of the Terms of Service. The Customer indemnifies Mana for costs and claims arising from the Customer's instructions or use of the Platform in breach of data protection law, except to the extent caused by Mana's own breach.

This agreement lasts as long as Mana processes Customer Data on the Customer's behalf. Swedish law applies, and section 14 of the Terms of Service governs disputes.