Data Processing Addendum
You are the controller of your client data; we process it only on your instructions. These are the terms that govern that relationship.
Effective September 2, 2026 · Last updated September 2, 2026
1. Scope and Roles
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you ("Customer") and Coach Manuals ("Coach Manuals", "we") and applies whenever we process personal data on your behalf through the Service.
Roles. For personal data relating to the individuals you coach ("Client Data"), you are the controller (or "business") and we are the processor (or "service provider"). For your own account and billing data, we act as controller under our Privacy Policy.
By using the Service to process Client Data you accept this DPA. No signature is required; if your organisation needs a countersigned copy, contact us.
2. Definitions
"Data Protection Laws" means all privacy and data-protection laws applicable to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA), and other United States state privacy statutes.
"Personal Data", "controller", "processor", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR, and equivalent terms in other Data Protection Laws are read accordingly.
"Subprocessor" means any third party engaged by us to process Client Data.
3. Our Obligations
We will:
- process Client Data only on your documented instructions, which consist of this DPA, the Terms of Service, and your use of the features of the Service, unless required otherwise by law (in which case we will inform you unless the law prohibits it);
- not sell Client Data, not share it for cross-context behavioural advertising, not retain, use or disclose it for any purpose other than performing the Service, and not combine it with data from other sources except as permitted by Data Protection Laws;
- not use Client Data to train publicly available foundation models;
- ensure that personnel authorised to process Client Data are bound by confidentiality obligations and receive appropriate training;
- implement and maintain the technical and organisational measures described in Annex II;
- inform you if, in our opinion, an instruction infringes Data Protection Laws; and
- make available the information reasonably necessary to demonstrate compliance with this DPA.
4. Annex I — Details of the Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Coach Manuals platform, including AI generation of coaching materials, client record management, progress logging and check-ins. |
| Duration | For the term of your subscription, plus the retention periods set out in the Privacy Policy. |
| Nature and purpose | Collection, storage, organisation, retrieval, transmission to the AI subprocessor for generation, display, sharing by link at your direction, backup, and deletion. |
| Categories of data subject | The individuals you coach, and any person to whom you send a share or check-in link. |
| Categories of personal data | Identifiers (name, email, contact details); coaching attributes (goals, fitness level, training location, equipment); dietary preferences; injuries and self-reported health notes; body measurements and progress logs; session notes; check-in responses; generated materials containing the above. |
| Special-category / sensitive data | Health-related information may be included where you choose to enter it. No data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric identifiers, or sexual orientation is requested by the Service. |
| Frequency of processing | Continuous, for the duration of the subscription. |
| Transfers | To the subprocessors listed in Annex III, all located in the United States. |
5. Annex II — Technical and Organisational Security Measures
We maintain the following measures, and may update them provided the level of protection is not reduced:
- Encryption of data in transit using TLS, and encryption at rest by our hosting and database providers.
- Password hashing with a modern, salted algorithm; we never store plaintext passwords.
- Session-based authentication with signed, HTTP-only cookies and server-side session revocation.
- Role-based access control separating coach accounts, client-facing share links and administrative access.
- Unguessable, revocable capability tokens for public share and check-in links, excluded from our error-monitoring telemetry.
- Sanitisation of user-supplied HTML at both write and render time, backed by a restrictive Content-Security-Policy on public pages.
- Bot protection on authentication endpoints and rate limiting on sensitive routes.
- Self-hosted error monitoring configured to exclude request bodies, cookies and credentials.
- Administrative access within the application is restricted to designated accounts and recorded in an append-only audit log.
- Regular dependency updates and prompt remediation of reported vulnerabilities.
We review these measures periodically and in response to material changes in the Service or the threat landscape.
7. Assistance with Data Subject Requests
The Service gives you direct access to view, correct, export and delete Client Data, which is normally sufficient to answer a data subject request yourself.
Where it is not, we will provide reasonable assistance, taking into account the nature of the processing, so that you can respond within statutory time limits.
If we receive a request directly from one of your clients, we will not respond substantively; we will refer the person to you and inform you promptly, unless the law requires otherwise.
We will also provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, where required by Articles 35 and 36 GDPR.
8. Personal Data Breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Client Data.
The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the information is not all available at once, we will provide it in phases.
We will not notify your data subjects or any regulator on your behalf unless you instruct us to do so or the law requires it of us directly. Notification is not an acknowledgement of fault or liability.
9. Deletion and Return
You can delete Client Data at any time from within the Service.
On termination or expiry of your subscription, we will delete Client Data within 90 days, except for copies in routine backups (overwritten within 35 days) and any data we are required by law to retain, which remains subject to this DPA for as long as it is held.
On written request made before deletion, we will provide an export of Client Data in a commonly used machine-readable format.
10. Audits and Compliance Information
On reasonable written request, no more than once in any 12-month period, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including a written description of our security measures and answers to a reasonable security questionnaire.
Where Data Protection Laws entitle you to conduct an on-site audit, it must be at your cost, on at least 30 days written notice, during business hours, subject to confidentiality obligations, and conducted so as not to disrupt our operations or the confidentiality of other customers data. An audit may be carried out by an independent auditor appointed by you and reasonably acceptable to us.
11. International Transfers
We process Client Data in the United States.
Where you transfer personal data subject to the EU GDPR to us, the European Commission Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply, with: Clause 7 (docking) included; Clause 9 option 2 (general written authorisation, 30 days notice); Clause 11 optional independent dispute resolution excluded; Clause 17 governed by the law of Ireland; and Clause 18 disputes heard by the courts of Ireland. Annexes I, II and III to the Clauses are populated by the corresponding annexes of this DPA.
Where the UK GDPR applies, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with the tables completed by reference to this DPA and Part 2 ending the Addendum where it is superseded. Where Swiss law applies, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the Federal Data Protection and Information Commissioner is the competent authority.
If a transfer mechanism is invalidated, we will work with you in good faith to implement a lawful alternative.
12. United States State Privacy Terms
For processing subject to the CCPA, we act as a service provider. We certify that we understand and will comply with the restrictions in Section 3 above, and specifically that we will not sell or share personal information, will not retain, use or disclose it outside the direct business relationship, and will not combine it with personal information from other sources except as permitted.
You have the right to take reasonable and appropriate steps to ensure we use personal information in a manner consistent with your obligations, and to stop and remediate unauthorised use.
For processing subject to other United States state privacy laws, we act as a processor and will comply with the corresponding obligations those laws impose on processors, including duties of confidentiality, subprocessor flow-down, assistance with rights requests and security.
13. Your Obligations as Controller
You warrant that:
- you have a lawful basis for the processing you instruct, and have given all required notices and obtained all required consents from your clients;
- your instructions comply with Data Protection Laws;
- the Client Data you enter is accurate and limited to what is necessary for the purpose;
- you will not enter protected health information subject to HIPAA, payment card numbers, government identifiers, biometric data or precise geolocation; and
- you will keep share and check-in links confidential and revoke them when they are no longer required.
You are responsible for your own use of the Service, including who you grant access to and what you distribute.
14. Liability, Precedence and Changes
Each party liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, to the extent permitted by law.
In the event of a conflict, the Standard Contractual Clauses prevail over this DPA in respect of transfers governed by them; this DPA prevails over the Terms of Service in respect of the processing of Client Data; and the Terms of Service govern everything else.
We may update this DPA to reflect changes in law, the Service or our subprocessors, provided the change does not materially reduce the protections it provides. Material changes are notified as described in the Terms of Service.
This DPA is governed by the law stated in the Terms of Service (the State of Florida), except where the Standard Contractual Clauses require otherwise.
15. Contact
Questions about this DPA, subprocessor objections, audit requests and breach enquiries: contact@coachmanuals.com.
