Developer Platform Terms

The terms that govern use of the Stridee API, including the Article 28 data processing terms between You as controller and Stridee as processor.

Last updated: August 25, 2026


These terms apply if You access the Stridee API through the Stridee Developer Platform at platform.stridee.fit (the "Platform"). They are additional to Our Terms & Conditions, which continue to apply in full; where the two conflict, these prevail for Platform use only.

"You" means the business with a Platform account; "End User" means an individual who uses Your product and authorizes a connection to a wearable provider; "Provider" means Garmin, COROS, Polar, Wahoo, Zepp or another provider We integrate; "End User Data" means personal data relating to an End User that We process through the API on Your behalf; "GDPR" means Regulation (EU) 2016/679, together with the UK GDPR and the Swiss Federal Act on Data Protection, each as applicable.

Accepting these terms — by completing checkout or by making a signed call to the API — accepts them in writing in electronic form for the purposes of Article 28(9) of the GDPR.

The processing

Subject matterConnecting End Users to Providers and delivering their wearable data to You through the API
DurationThe term of these terms, plus the deletion period in (g)
Nature and purposeCollection, storage, normalisation, transmission to You and erasure, solely to provide the API to You
Categories of data subjectYour End Users
Type of personal dataConnection identifiers and Provider authorization tokens, and the wearable data an End User authorizes: activity and workout records including precise geolocation, and daily wellness records. This is data concerning health under Article 9(1). We hold no name, email address or postal address for an End User

Roles

You are the controller of End User Data and We are Your processor. You decide which End Users to connect, which Providers to name, what data to request, and when to disconnect or delete. We process End User Data only to provide the API to You and for no purpose of Our own, and We are not joint controllers with You.

We are a separate and independent controller of Your account and billing details, Our API request logs, and the record of an End User's acceptance of Our disclosure screen; Our Privacy Policy governs those. A Provider is an independent controller under its own agreement with the End User and is not Our sub-processor.

Your obligations

You warrant that You have a lawful basis under Article 6 for each purpose for which You instruct Us, that You have given End Users the information required by Articles 13 and 14 including that We are a recipient, and that Your instructions do not infringe the GDPR.

Because End User Data includes health data, You warrant that You hold and can evidence a condition under Article 9(2) — ordinarily the End User's explicit consent under Article 9(2)(a) — before You identify that End User to the API, and that You will disconnect them promptly when their consent is withdrawn.

You indemnify Us to the extent a claim arises from Your lack of a valid Article 6 basis or Article 9(2) condition, from Your instructions, or from Your failure to disconnect an End User whose authorization has ended. The cap in the "Limitation of Liability" section of Our Terms & Conditions does not limit either party's liability to a data subject under Article 82 of the GDPR, which cannot be capped by contract.

Our obligations as processor

This section gives effect to Article 28(3).

(a) Instructions. We process End User Data only on Your documented instructions, including as to transfers — these terms, Our documentation, and the calls You make — unless required otherwise by law, in which case We will tell You first unless the law forbids it. We will immediately inform You if We consider an instruction infringes the GDPR.

(b) Confidentiality. Our personnel are bound by confidentiality obligations.

(c) Security. We take the measures required by Article 32. You are responsible for Your signing keys and for any endpoint You register.

(d) Sub-processors. You give Us general written authorisation to engage sub-processors under Article 28(2). Our current sub-processors are listed at stridee.fit/terms/subprocessors, which forms part of these terms. We give 30 days' notice before adding or replacing one, and You may object on reasonable data-protection grounds; if the objection cannot be resolved either party may terminate the affected part of these terms with a refund of fees paid in advance for it. We impose equivalent obligations on each sub-processor and remain liable to You for its performance.

(e) Data subject rights. We assist You, so far as possible, in responding to requests under Chapter III. We have no relationship with Your End Users and cannot verify their identity; a request reaching Us is referred to You.

(f) Breaches. We assist You with Articles 32 to 36 and will notify You of a personal data breach affecting End User Data without undue delay and within 48 hours of becoming aware of it. Notifying a supervisory authority or data subjects is Yours to do.

(g) Deletion. On termination We delete End User Data, or return it if You ask in writing within 30 days, completing within 90 days subject to backup expiry. Where the same Provider activity was delivered to more than one Developer, deleting Your access removes Your grant, Your activity identifier and every link from Your End User to that file, ending the processing carried out on Your behalf; the file itself is retained only while another Developer remains entitled to it. Our API request logs are Our own controller data, kept 30 days, and carry no End User Data payloads.

(h) Audits. We make available the information needed to demonstrate compliance with Article 28 and contribute to audits by You or Your auditor: once per twelve months unless a breach or a supervisory authority requires otherwise, on 30 days' notice, during business hours, under confidentiality, with no access to another Developer's data. We may answer with an existing third-party report or completed questionnaire where that reasonably does so.

Developer Platform Terms | Stridee