Effective Date: 19 May 2026 · Version: 1.0
Data Processing Agreement (DPA)
Effective Date: 19 May 2026 | Version: 1.0 Legal Basis: Art. 28 GDPR
Between
the Controller: The user of the coachHelp platform (coach / consultant)
and
the Processor: coachHelp Email: privacy@couchhelp.eu
Preamble
The Controller uses the coachHelp platform to support their coaching activities. In the course of use, personal data of the Controller's clients is processed. This agreement governs the contractual relationship within the meaning of Art. 28 GDPR.
1. Definitions
For the purposes of this agreement, the following definitions apply:
- Personal Data: Any information relating to an identified or identifiable natural person, in particular name, contact details, communication content, and AVGS-related data of the Controller's clients.
- Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means.
- Controller: The user of the Platform who determines the purposes and means of the processing of personal data.
- Processor: coachHelp, who processes personal data on behalf of the Controller.
2. Subject Matter and Duration of Processing
2.1 Subject Matter
The subject matter of this agreement is the provision of the AI-powered coaching platform coachHelp, including:
- Storage and management of client data
- AI-based text classification and draft generation
- WhatsApp communication via the Business API
- Management of commitments and session protocols
- Provision of analytics and reporting functions
2.2 Categories of Data Processed
- Identification data (name, phone number)
- Communication data (message content, chat histories)
- Commitment data ("Promises", session protocols)
- AVGS-related data (status, reports)
- Usage data (timestamps, activity logs)
2.3 Duration
This agreement begins with the Controller's registration on the Platform and ends with the deletion of the account plus a retention period of 30 days. It is automatically extended with continued use.
3. Obligations of the Processor
coachHelp undertakes to:
3.1 Processing Only on Instruction
Personal data shall be processed solely on documented instructions from the Controller, including this agreement and applicable data protection laws. If coachHelp believes that an instruction violates data protection provisions, it shall inform the Controller without delay.
3.2 Confidentiality
Personnel involved in processing are obliged to maintain confidentiality. This obligation continues after termination of employment. coachHelp ensures that personnel only access personal data to the extent necessary.
3.3 Security Measures
coachHelp implements appropriate technical and organisational measures (TOMs) to protect personal data:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Role-based access controls (Row-Level Security in Supabase)
- Secure authentication via Clerk
- Regular security updates and monitoring
3.4 Support of the Controller
coachHelp supports the Controller in fulfilling its obligations under the GDPR, in particular:
- Responding to data subject requests (Art. 15-22 GDPR)
- Conducting data protection impact assessments
- Notifying of data breaches
3.5 Deletion and Return
After termination of processing activities, coachHelp shall delete all personal data of the Controller, unless statutory retention obligations require otherwise. At the Controller's request, the data shall be returned in a structured format.
3.6 Data Breaches
coachHelp shall notify the Controller without delay in the event of personal data breaches and support the Controller in fulfilling its notification obligations to supervisory authorities and data subjects.
4. Sub-Processors
4.1 Approved Sub-Processors
coachHelp uses the following sub-processors to fulfil this agreement:
| Sub-Processor | Location | Service | Contract |
|---|---|---|---|
| Supabase Inc. | San Francisco, USA (DB: Frankfurt, DE) | Database storage, authentication | DPA pursuant to Art. 28 GDPR |
| Anthropic PBC | San Francisco, USA | AI text processing | DPA + SCCs |
| Vercel Inc. | San Francisco, USA | Hosting, CDN | SCCs |
| Clerk Inc. | San Francisco, USA | User authentication | SCCs |
4.2 Obligations Towards Sub-Processors
coachHelp ensures that sub-processors have contractually undertaken the same data protection obligations as coachHelp. This includes in particular:
- Processing only on instruction
- Adherence to appropriate security measures
- Confidentiality obligations
- Deletion obligations after termination of contract
4.3 Controller's Right to Object
The Controller has the right to object to a new sub-processor in writing within 14 days of notification. If the Controller raises substantiated concerns, the parties shall seek an amicable solution. If no agreement can be reached, the Controller has the right to terminate the use of the affected services.
5. International Data Transfers
5.1 Transfers to Third Countries
Some sub-processors (Anthropic PBC, Vercel Inc., Clerk Inc.) are based in the USA. When transferring personal data to the USA, the following safeguards apply:
- Standard Contractual Clauses (SCCs): The transfer is based on Standard Contractual Clauses approved by the EU Commission (2021/914).
- EU-US Data Privacy Framework: Where applicable, sub-processors rely on the EU-US Data Privacy Framework.
5.2 Additional Measures
In light of the Schrems II ruling of the CJEU of 16 July 2020, coachHelp has implemented additional protective measures:
- Encryption of sensitive data before transfer
- Minimisation of transferred data volumes
- Review of legal frameworks in the USA
The Controller acknowledges that transferring data to the USA carries a residual risk despite these measures, and accepts this risk with full knowledge of the facts.
6. Security Measures
6.1 Technical Measures
- Encryption: TLS 1.3 for data transmission, AES-256 for data at rest
- Access control: Row-Level Security (RLS) in the database, role-based permissions
- Authentication: Secure password storage, optional two-factor authentication
- Network security: Firewall, DDoS protection via Vercel
6.2 Organisational Measures
- Regular staff training
- Documented access logs
- Incident response plan for data protection incidents
- Regular backups with encrypted storage
6.3 Data Breach Management
In the event of a data breach:
- Immediate investigation and containment
- Notification of the Controller within 24 hours
- Documentation of the incident
- Implementation of corrective measures
7. Support of the Controller
coachHelp supports the Controller with:
7.1 Access Requests
Providing the necessary information to respond to data subject access requests pursuant to Art. 15 GDPR.
7.2 Data Export
Upon request, coachHelp shall provide the Controller's personal data in a structured, commonly used, and machine-readable format (CSV, JSON).
7.3 Audit Rights
The Controller has the right to conduct an audit of compliance with this agreement once per year. The audit shall be carried out in consultation with coachHelp and must not unreasonably disturb operations.
8. Contract Term and Termination
8.1 Term
This agreement enters into force upon the Controller's registration on the Platform and runs for an indefinite period.
8.2 Termination
Both parties may terminate this agreement by deleting the account or discontinuing the Platform. In the event of discontinuation, 30 days' notice will be given.
8.3 Consequences of Termination
After termination:
- All personal data of the Controller will be deleted within 90 days
- The Controller may request a data export before deletion
- Audit logs are retained for 7 years in accordance with statutory requirements
9. Deletion and Return of Data
9.1 Deletion
After termination of the agreement, coachHelp shall delete all personal data processed on behalf of the Controller. This includes:
- Client data
- Communication content
- Usage logs
- Backups (within the backup rotation)
9.2 Exceptions
The following are exempt from deletion:
- Audit logs: 7 years (statutory requirement pursuant to DEKRA/TÜV for AVGS)
- Data for which a statutory retention obligation exists
- Anonymised data that no longer relates to identifiable persons
9.3 Export Before Deletion
The Controller may request a complete export of their data before deletion. The export will be provided in JSON or CSV format.
10. Authorised Persons
10.1 Controller (User)
The Controller is the registered user of the Platform. Changes of contact person must be communicated to the Processor.
10.2 Data Protection Officer
coachHelp currently does not have a data protection officer appointed, as this is not mandatory pursuant to Art. 37 GDPR.
10.3 Contact
For inquiries regarding this agreement: Email: privacy@couchhelp.eu
11. Dispute Resolution
11.1 Written Complaints
Complaints should be sent in writing to privacy@couchhelp.eu. We will respond within 30 days.
11.2 Applicable Law
This agreement is governed by the laws of the Federal Republic of Germany.
11.3 Jurisdiction
The place of jurisdiction for all disputes is the seat of the operator, provided the Controller is a merchant. Otherwise, the statutory places of jurisdiction apply.
12. Appendices
Appendix A: List of Sub-Processors
(Updatable at privacy@couchhelp.eu)
As of 19 May 2026:
- Supabase Inc. (Database, Frankfurt)
- Anthropic PBC (AI processing, USA)
- Vercel Inc. (Hosting, USA/EU)
- Clerk Inc. (Authentication, USA)
Appendix B: Technical and Organisational Measures (TOMs)
Detailed description of security measures pursuant to Section 6.
Appendix C: Data Categories and Retention Periods
| Category | Retention Period | Basis |
|---|---|---|
| Account data | Account active + 30 days | Contract |
| Client data | Account active + 30 days | Contract |
| Audit logs | 7 years | Statutory (DEKRA) |
| Log data | 30 days | Legitimate interest |
Last Updated: 19 May 2026