Effective Date: 19 May 2026 · Version: 1.0

Data Processing Agreement (DPA)

Effective Date: 19 May 2026 | Version: 1.0 Legal Basis: Art. 28 GDPR


Between

the Controller: The user of the coachHelp platform (coach / consultant)

and

the Processor: coachHelp Email: privacy@couchhelp.eu


Preamble

The Controller uses the coachHelp platform to support their coaching activities. In the course of use, personal data of the Controller's clients is processed. This agreement governs the contractual relationship within the meaning of Art. 28 GDPR.

1. Definitions

For the purposes of this agreement, the following definitions apply:

  • Personal Data: Any information relating to an identified or identifiable natural person, in particular name, contact details, communication content, and AVGS-related data of the Controller's clients.
  • Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means.
  • Controller: The user of the Platform who determines the purposes and means of the processing of personal data.
  • Processor: coachHelp, who processes personal data on behalf of the Controller.

2. Subject Matter and Duration of Processing

2.1 Subject Matter

The subject matter of this agreement is the provision of the AI-powered coaching platform coachHelp, including:

  • Storage and management of client data
  • AI-based text classification and draft generation
  • WhatsApp communication via the Business API
  • Management of commitments and session protocols
  • Provision of analytics and reporting functions

2.2 Categories of Data Processed

  • Identification data (name, phone number)
  • Communication data (message content, chat histories)
  • Commitment data ("Promises", session protocols)
  • AVGS-related data (status, reports)
  • Usage data (timestamps, activity logs)

2.3 Duration

This agreement begins with the Controller's registration on the Platform and ends with the deletion of the account plus a retention period of 30 days. It is automatically extended with continued use.

3. Obligations of the Processor

coachHelp undertakes to:

3.1 Processing Only on Instruction

Personal data shall be processed solely on documented instructions from the Controller, including this agreement and applicable data protection laws. If coachHelp believes that an instruction violates data protection provisions, it shall inform the Controller without delay.

3.2 Confidentiality

Personnel involved in processing are obliged to maintain confidentiality. This obligation continues after termination of employment. coachHelp ensures that personnel only access personal data to the extent necessary.

3.3 Security Measures

coachHelp implements appropriate technical and organisational measures (TOMs) to protect personal data:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Role-based access controls (Row-Level Security in Supabase)
  • Secure authentication via Clerk
  • Regular security updates and monitoring

3.4 Support of the Controller

coachHelp supports the Controller in fulfilling its obligations under the GDPR, in particular:

  • Responding to data subject requests (Art. 15-22 GDPR)
  • Conducting data protection impact assessments
  • Notifying of data breaches

3.5 Deletion and Return

After termination of processing activities, coachHelp shall delete all personal data of the Controller, unless statutory retention obligations require otherwise. At the Controller's request, the data shall be returned in a structured format.

3.6 Data Breaches

coachHelp shall notify the Controller without delay in the event of personal data breaches and support the Controller in fulfilling its notification obligations to supervisory authorities and data subjects.

4. Sub-Processors

4.1 Approved Sub-Processors

coachHelp uses the following sub-processors to fulfil this agreement:

Sub-ProcessorLocationServiceContract
Supabase Inc.San Francisco, USA (DB: Frankfurt, DE)Database storage, authenticationDPA pursuant to Art. 28 GDPR
Anthropic PBCSan Francisco, USAAI text processingDPA + SCCs
Vercel Inc.San Francisco, USAHosting, CDNSCCs
Clerk Inc.San Francisco, USAUser authenticationSCCs

4.2 Obligations Towards Sub-Processors

coachHelp ensures that sub-processors have contractually undertaken the same data protection obligations as coachHelp. This includes in particular:

  • Processing only on instruction
  • Adherence to appropriate security measures
  • Confidentiality obligations
  • Deletion obligations after termination of contract

4.3 Controller's Right to Object

The Controller has the right to object to a new sub-processor in writing within 14 days of notification. If the Controller raises substantiated concerns, the parties shall seek an amicable solution. If no agreement can be reached, the Controller has the right to terminate the use of the affected services.

5. International Data Transfers

5.1 Transfers to Third Countries

Some sub-processors (Anthropic PBC, Vercel Inc., Clerk Inc.) are based in the USA. When transferring personal data to the USA, the following safeguards apply:

  • Standard Contractual Clauses (SCCs): The transfer is based on Standard Contractual Clauses approved by the EU Commission (2021/914).
  • EU-US Data Privacy Framework: Where applicable, sub-processors rely on the EU-US Data Privacy Framework.

5.2 Additional Measures

In light of the Schrems II ruling of the CJEU of 16 July 2020, coachHelp has implemented additional protective measures:

  • Encryption of sensitive data before transfer
  • Minimisation of transferred data volumes
  • Review of legal frameworks in the USA

The Controller acknowledges that transferring data to the USA carries a residual risk despite these measures, and accepts this risk with full knowledge of the facts.

6. Security Measures

6.1 Technical Measures

  • Encryption: TLS 1.3 for data transmission, AES-256 for data at rest
  • Access control: Row-Level Security (RLS) in the database, role-based permissions
  • Authentication: Secure password storage, optional two-factor authentication
  • Network security: Firewall, DDoS protection via Vercel

6.2 Organisational Measures

  • Regular staff training
  • Documented access logs
  • Incident response plan for data protection incidents
  • Regular backups with encrypted storage

6.3 Data Breach Management

In the event of a data breach:

  1. Immediate investigation and containment
  2. Notification of the Controller within 24 hours
  3. Documentation of the incident
  4. Implementation of corrective measures

7. Support of the Controller

coachHelp supports the Controller with:

7.1 Access Requests

Providing the necessary information to respond to data subject access requests pursuant to Art. 15 GDPR.

7.2 Data Export

Upon request, coachHelp shall provide the Controller's personal data in a structured, commonly used, and machine-readable format (CSV, JSON).

7.3 Audit Rights

The Controller has the right to conduct an audit of compliance with this agreement once per year. The audit shall be carried out in consultation with coachHelp and must not unreasonably disturb operations.

8. Contract Term and Termination

8.1 Term

This agreement enters into force upon the Controller's registration on the Platform and runs for an indefinite period.

8.2 Termination

Both parties may terminate this agreement by deleting the account or discontinuing the Platform. In the event of discontinuation, 30 days' notice will be given.

8.3 Consequences of Termination

After termination:

  • All personal data of the Controller will be deleted within 90 days
  • The Controller may request a data export before deletion
  • Audit logs are retained for 7 years in accordance with statutory requirements

9. Deletion and Return of Data

9.1 Deletion

After termination of the agreement, coachHelp shall delete all personal data processed on behalf of the Controller. This includes:

  • Client data
  • Communication content
  • Usage logs
  • Backups (within the backup rotation)

9.2 Exceptions

The following are exempt from deletion:

  • Audit logs: 7 years (statutory requirement pursuant to DEKRA/TÜV for AVGS)
  • Data for which a statutory retention obligation exists
  • Anonymised data that no longer relates to identifiable persons

9.3 Export Before Deletion

The Controller may request a complete export of their data before deletion. The export will be provided in JSON or CSV format.

10. Authorised Persons

10.1 Controller (User)

The Controller is the registered user of the Platform. Changes of contact person must be communicated to the Processor.

10.2 Data Protection Officer

coachHelp currently does not have a data protection officer appointed, as this is not mandatory pursuant to Art. 37 GDPR.

10.3 Contact

For inquiries regarding this agreement: Email: privacy@couchhelp.eu

11. Dispute Resolution

11.1 Written Complaints

Complaints should be sent in writing to privacy@couchhelp.eu. We will respond within 30 days.

11.2 Applicable Law

This agreement is governed by the laws of the Federal Republic of Germany.

11.3 Jurisdiction

The place of jurisdiction for all disputes is the seat of the operator, provided the Controller is a merchant. Otherwise, the statutory places of jurisdiction apply.

12. Appendices

Appendix A: List of Sub-Processors

(Updatable at privacy@couchhelp.eu)

As of 19 May 2026:

  1. Supabase Inc. (Database, Frankfurt)
  2. Anthropic PBC (AI processing, USA)
  3. Vercel Inc. (Hosting, USA/EU)
  4. Clerk Inc. (Authentication, USA)

Appendix B: Technical and Organisational Measures (TOMs)

Detailed description of security measures pursuant to Section 6.

Appendix C: Data Categories and Retention Periods

CategoryRetention PeriodBasis
Account dataAccount active + 30 daysContract
Client dataAccount active + 30 daysContract
Audit logs7 yearsStatutory (DEKRA)
Log data30 daysLegitimate interest

Last Updated: 19 May 2026