How your data is processed.
The data processing agreement (DPA) for Good Either Way, plus every subprocessor we use — the whole list, no hidden vendors.
Last updated 15 July 2026.
The parties
Controller: you, or the organisation you represent (member, PT, employer, charity, or creator). Processor: App Fjord AS (org 915565476), Stålverkskroken 38, 0661 Oslo, Norway — the company behind Good Either Way. This DPA applies whenever we process personal data on your behalf and forms part of our Terms.
What we process, and why
Account email addresses and names; commitment and session records (self-reported); private proof photos (visible only to their owner unless the owner shares one with their exercise buddies; never reviewed); payment tokens (we never hold card numbers — Stripe does); support correspondence; and the aggregate statistics described in our Privacy page. Purpose: running the service you signed up for. Nothing is sold, rented, or used for third-party advertising, ever.
Our promises as processor
We process personal data only to provide the service; we apply the safeguards described on the Privacy page (encryption in transit, private storage with expiring links, least-access); we tell you without undue delay if we learn of a personal data breach affecting your data; we help with access and deletion requests (self-serve deletion is built in); and when you delete your account we delete your data for real.
Subprocessors — the full list
Salesforce/Heroku (application hosting, EU region) · Amazon Web Services (file storage on S3 and email via SES, eu-west-1 Ireland) · Stripe (payments, card storage, charity payouts — Stripe is an independent controller for its own KYC) · Cloudflare (DNS and network security in front of the site, plus cookieless visit counting on the public marketing pages — no cookies, no cross-site tracking, and never inside the app once you're signed in) · Google Fonts (font delivery on marketing pages; receives IP addresses only). Dormant unless switched on: Twilio (WhatsApp notifications — currently off). We'll update this list before adding anyone new.
International transfers
Hosting and storage sit in the EU (Heroku EU, AWS eu-west-1). Stripe, Cloudflare, and Google operate globally under standard contractual clauses. We serve Australia and Norway and operate from Norway (EEA), so GDPR-grade handling is the default for everyone, not a regional favour.
Sub-DPAs and audits
Each subprocessor is bound by its own data processing terms at least as protective as these. Want a signed copy of this DPA or have an audit question? Email hello@goodeitherway.com — a human answers.
Questions?
Email hello@goodeitherway.com. A human reads every one.