Audunn

Data Processing Agreement

Last updated: 2026-08-22

This Data Processing Agreement forms part of the Terms between Audunn, Jarlsberggade 5B, 4.2, 5000 Odense C, Denmark ("Processor") and the Coach accepting it ("Controller"). It applies when Processor handles Member personal data on Controller's documented instructions.

1. Subject matter and instructions

Processor provides the coaching platform, including storage, retrieval, member portals, configured communications, approved AI functions, support, security, and deletion. The Terms, Coach configuration, Approved AI Registry, and lawful written directions from Controller are documented instructions. Processor will tell Controller if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.

2. Duration

Processing continues while the Services are provided and for the limited period needed to complete deletion, return, security, billing, and legally required retention.

3. People and data

Data subjects can include Members, pre-account clients using a signed coaching form, visitors using a non-sensitive public embed, Coach personnel, and people represented in connected content.

Personal data can include identity, contact, account, messages, files, recordings, transcripts, goals, memories, trackers, check-ins, client and call records, integration results, device and usage data, and support records. Special-category data can include health and lifestyle information such as weight, nutrition, sleep, mood, injury, training, symptoms, and health-related messages.

4. Nature and purpose

Processor collects, records, organises, stores, retrieves, transmits, structures, generates, restricts, exports, and deletes data to provide the configured coaching service. AI processing can include response generation, embeddings, transcription, extraction, summarisation, retrieval, and scheduled coaching communications, but only through approved routes and on Controller's instructions.

5. Processor obligations

Processor will:

6. Controller obligations

Controller is responsible for lawful instructions, notices, legal bases, valid Article 9 conditions, data minimisation, accuracy, Member rights, and the appropriateness of the configured coaching purpose. Controller must not enable a model, provider, integration, or transfer that is not approved for the relevant data class. Controller must not invite minors to an AI feature.

7. Subprocessors

Controller gives general written authorisation for subprocessors listed at /legal/ai-providers with status approved for the relevant data class. The register identifies purpose, location, safeguards, retention controls, and material route restrictions. Catalogue availability is not authorisation.

Processor will give advance notice of a proposed material subprocessor change and a meaningful opportunity to object on reasonable data-protection grounds. Processor will impose obligations that provide materially equivalent protection and remains responsible for a subprocessor's performance to the extent required by law.

8. International transfers

Processor will not make a restricted transfer without a valid mechanism. Where required, the parties incorporate the applicable EU Standard Contractual Clauses and UK Addendum. Controller authorises Processor to complete modules and appendices consistently with this DPA. Transfer assessments and supplementary measures must be completed before a route is marked approved.

9. Security measures

Current measures include TLS, provider-managed encryption at rest, encrypted secrets, role and tenant access controls, least-privilege service access, logging, rate limits, dependency review, backups, incident procedures, and protected deletion flows. Measures may change without reducing the protection required by law.

10. Audit and assistance costs

Processor will answer reasonable written compliance questions and provide available evidence. Audits must avoid exposing another customer's data, disrupting the Services, or compromising security. Each party bears its own ordinary costs. Controller bears exceptional costs caused by repeated or unusually burdensome requests unless a material Processor breach is found.

11. Deletion and return

On termination, Controller may export available data before deletion. Processor deletes active Member data under the product deletion flow and removes remaining Processor copies within the documented schedule, except for lawful records and encrypted backups that age out under the applicable provider schedule.

12. Conflict and governing terms

This DPA controls over conflicting Terms for its subject matter. Danish law and the dispute terms in the Terms apply without limiting mandatory data-protection rights.

Terms of ServicePrivacy PolicyConsumer Health Data Privacy PolicyData Processing AgreementCoach privacy and AI guidanceApproved AI and subprocessor registry