Coach Manuals LogoCoach Manuals
Legal

Data Processing Addendum

You are the controller of your client data; we process it only on your instructions. These are the terms that govern that relationship.

Effective September 2, 2026 · Last updated September 2, 2026

1. Scope and Roles

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you ("Customer") and Coach Manuals ("Coach Manuals", "we") and applies whenever we process personal data on your behalf through the Service.

Roles. For personal data relating to the individuals you coach ("Client Data"), you are the controller (or "business") and we are the processor (or "service provider"). For your own account and billing data, we act as controller under our Privacy Policy.

By using the Service to process Client Data you accept this DPA. No signature is required; if your organisation needs a countersigned copy, contact us.

This DPA is not a HIPAA Business Associate Agreement. The Service must not be used for protected health information subject to HIPAA, and we do not enter into business associate agreements.

2. Definitions

"Data Protection Laws" means all privacy and data-protection laws applicable to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA), and other United States state privacy statutes.

"Personal Data", "controller", "processor", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR, and equivalent terms in other Data Protection Laws are read accordingly.

"Subprocessor" means any third party engaged by us to process Client Data.

3. Our Obligations

We will:

  • process Client Data only on your documented instructions, which consist of this DPA, the Terms of Service, and your use of the features of the Service, unless required otherwise by law (in which case we will inform you unless the law prohibits it);
  • not sell Client Data, not share it for cross-context behavioural advertising, not retain, use or disclose it for any purpose other than performing the Service, and not combine it with data from other sources except as permitted by Data Protection Laws;
  • not use Client Data to train publicly available foundation models;
  • ensure that personnel authorised to process Client Data are bound by confidentiality obligations and receive appropriate training;
  • implement and maintain the technical and organisational measures described in Annex II;
  • inform you if, in our opinion, an instruction infringes Data Protection Laws; and
  • make available the information reasonably necessary to demonstrate compliance with this DPA.

4. Annex I — Details of the Processing

ItemDetail
Subject matterProvision of the Coach Manuals platform, including AI generation of coaching materials, client record management, progress logging and check-ins.
DurationFor the term of your subscription, plus the retention periods set out in the Privacy Policy.
Nature and purposeCollection, storage, organisation, retrieval, transmission to the AI subprocessor for generation, display, sharing by link at your direction, backup, and deletion.
Categories of data subjectThe individuals you coach, and any person to whom you send a share or check-in link.
Categories of personal dataIdentifiers (name, email, contact details); coaching attributes (goals, fitness level, training location, equipment); dietary preferences; injuries and self-reported health notes; body measurements and progress logs; session notes; check-in responses; generated materials containing the above.
Special-category / sensitive dataHealth-related information may be included where you choose to enter it. No data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric identifiers, or sexual orientation is requested by the Service.
Frequency of processingContinuous, for the duration of the subscription.
TransfersTo the subprocessors listed in Annex III, all located in the United States.

5. Annex II — Technical and Organisational Security Measures

We maintain the following measures, and may update them provided the level of protection is not reduced:

  • Encryption of data in transit using TLS, and encryption at rest by our hosting and database providers.
  • Password hashing with a modern, salted algorithm; we never store plaintext passwords.
  • Session-based authentication with signed, HTTP-only cookies and server-side session revocation.
  • Role-based access control separating coach accounts, client-facing share links and administrative access.
  • Unguessable, revocable capability tokens for public share and check-in links, excluded from our error-monitoring telemetry.
  • Sanitisation of user-supplied HTML at both write and render time, backed by a restrictive Content-Security-Policy on public pages.
  • Bot protection on authentication endpoints and rate limiting on sensitive routes.
  • Self-hosted error monitoring configured to exclude request bodies, cookies and credentials.
  • Administrative access within the application is restricted to designated accounts and recorded in an append-only audit log.
  • Regular dependency updates and prompt remediation of reported vulnerabilities.

We review these measures periodically and in response to material changes in the Service or the threat landscape.

6. Annex III — Authorised Subprocessors

You give general written authorisation for us to engage the subprocessors listed below, each of which is bound by written terms that impose data-protection obligations no less protective than this DPA.

SubprocessorPurposeLocation
Google LLC (Gemini API)AI generation of manual, guide and habit-tracker content from the prompts and client attributes you submit.United States
Stripe, Inc.Subscription billing, payment processing and invoicing.United States
Resend, Inc.Delivery of transactional email (account, billing, credit and check-in notifications).United States
Cloudflare, Inc.Turnstile bot protection on authentication forms; network and DNS services.United States / global edge network
Vercel Inc. (Blob storage)Storage and delivery of uploaded images, where blob storage is enabled.United States
Hosting and database providerApplication hosting, managed PostgreSQL database and backups.United States

The current list is maintained at Subprocessors. We will give at least 30 days notice before adding or replacing a subprocessor. You may object on reasonable data-protection grounds within that period by emailing us; if we cannot accommodate the objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid, unused fees.

We remain liable to you for the performance of each subprocessor obligations.

7. Assistance with Data Subject Requests

The Service gives you direct access to view, correct, export and delete Client Data, which is normally sufficient to answer a data subject request yourself.

Where it is not, we will provide reasonable assistance, taking into account the nature of the processing, so that you can respond within statutory time limits.

If we receive a request directly from one of your clients, we will not respond substantively; we will refer the person to you and inform you promptly, unless the law requires otherwise.

We will also provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, where required by Articles 35 and 36 GDPR.

8. Personal Data Breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Client Data.

The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the information is not all available at once, we will provide it in phases.

We will not notify your data subjects or any regulator on your behalf unless you instruct us to do so or the law requires it of us directly. Notification is not an acknowledgement of fault or liability.

9. Deletion and Return

You can delete Client Data at any time from within the Service.

On termination or expiry of your subscription, we will delete Client Data within 90 days, except for copies in routine backups (overwritten within 35 days) and any data we are required by law to retain, which remains subject to this DPA for as long as it is held.

On written request made before deletion, we will provide an export of Client Data in a commonly used machine-readable format.

10. Audits and Compliance Information

On reasonable written request, no more than once in any 12-month period, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including a written description of our security measures and answers to a reasonable security questionnaire.

Where Data Protection Laws entitle you to conduct an on-site audit, it must be at your cost, on at least 30 days written notice, during business hours, subject to confidentiality obligations, and conducted so as not to disrupt our operations or the confidentiality of other customers data. An audit may be carried out by an independent auditor appointed by you and reasonably acceptable to us.

11. International Transfers

We process Client Data in the United States.

Where you transfer personal data subject to the EU GDPR to us, the European Commission Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply, with: Clause 7 (docking) included; Clause 9 option 2 (general written authorisation, 30 days notice); Clause 11 optional independent dispute resolution excluded; Clause 17 governed by the law of Ireland; and Clause 18 disputes heard by the courts of Ireland. Annexes I, II and III to the Clauses are populated by the corresponding annexes of this DPA.

Where the UK GDPR applies, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with the tables completed by reference to this DPA and Part 2 ending the Addendum where it is superseded. Where Swiss law applies, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the Federal Data Protection and Information Commissioner is the competent authority.

If a transfer mechanism is invalidated, we will work with you in good faith to implement a lawful alternative.

12. United States State Privacy Terms

For processing subject to the CCPA, we act as a service provider. We certify that we understand and will comply with the restrictions in Section 3 above, and specifically that we will not sell or share personal information, will not retain, use or disclose it outside the direct business relationship, and will not combine it with personal information from other sources except as permitted.

You have the right to take reasonable and appropriate steps to ensure we use personal information in a manner consistent with your obligations, and to stop and remediate unauthorised use.

For processing subject to other United States state privacy laws, we act as a processor and will comply with the corresponding obligations those laws impose on processors, including duties of confidentiality, subprocessor flow-down, assistance with rights requests and security.

13. Your Obligations as Controller

You warrant that:

  • you have a lawful basis for the processing you instruct, and have given all required notices and obtained all required consents from your clients;
  • your instructions comply with Data Protection Laws;
  • the Client Data you enter is accurate and limited to what is necessary for the purpose;
  • you will not enter protected health information subject to HIPAA, payment card numbers, government identifiers, biometric data or precise geolocation; and
  • you will keep share and check-in links confidential and revoke them when they are no longer required.

You are responsible for your own use of the Service, including who you grant access to and what you distribute.

14. Liability, Precedence and Changes

Each party liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, to the extent permitted by law.

In the event of a conflict, the Standard Contractual Clauses prevail over this DPA in respect of transfers governed by them; this DPA prevails over the Terms of Service in respect of the processing of Client Data; and the Terms of Service govern everything else.

We may update this DPA to reflect changes in law, the Service or our subprocessors, provided the change does not materially reduce the protections it provides. Material changes are notified as described in the Terms of Service.

This DPA is governed by the law stated in the Terms of Service (the State of Florida), except where the Standard Contractual Clauses require otherwise.

15. Contact

Questions about this DPA, subprocessor objections, audit requests and breach enquiries: contact@coachmanuals.com.