Last updated: 2026-08-22
This Data Processing Agreement forms part of the Terms between Audunn, Jarlsberggade 5B, 4.2, 5000 Odense C, Denmark ("Processor") and the Coach accepting it ("Controller"). It applies when Processor handles Member personal data on Controller's documented instructions.
Processor provides the coaching platform, including storage, retrieval, member portals, configured communications, approved AI functions, support, security, and deletion. The Terms, Coach configuration, Approved AI Registry, and lawful written directions from Controller are documented instructions. Processor will tell Controller if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.
Processing continues while the Services are provided and for the limited period needed to complete deletion, return, security, billing, and legally required retention.
Data subjects can include Members, pre-account clients using a signed coaching form, visitors using a non-sensitive public embed, Coach personnel, and people represented in connected content.
Personal data can include identity, contact, account, messages, files, recordings, transcripts, goals, memories, trackers, check-ins, client and call records, integration results, device and usage data, and support records. Special-category data can include health and lifestyle information such as weight, nutrition, sleep, mood, injury, training, symptoms, and health-related messages.
Processor collects, records, organises, stores, retrieves, transmits, structures, generates, restricts, exports, and deletes data to provide the configured coaching service. AI processing can include response generation, embeddings, transcription, extraction, summarisation, retrieval, and scheduled coaching communications, but only through approved routes and on Controller's instructions.
Processor will:
Controller is responsible for lawful instructions, notices, legal bases, valid Article 9 conditions, data minimisation, accuracy, Member rights, and the appropriateness of the configured coaching purpose. Controller must not enable a model, provider, integration, or transfer that is not approved for the relevant data class. Controller must not invite minors to an AI feature.
Controller gives general written authorisation for subprocessors listed at /legal/ai-providers with status approved for the relevant data class. The register identifies purpose, location, safeguards, retention controls, and material route restrictions. Catalogue availability is not authorisation.
Processor will give advance notice of a proposed material subprocessor change and a meaningful opportunity to object on reasonable data-protection grounds. Processor will impose obligations that provide materially equivalent protection and remains responsible for a subprocessor's performance to the extent required by law.
Processor will not make a restricted transfer without a valid mechanism. Where required, the parties incorporate the applicable EU Standard Contractual Clauses and UK Addendum. Controller authorises Processor to complete modules and appendices consistently with this DPA. Transfer assessments and supplementary measures must be completed before a route is marked approved.
Current measures include TLS, provider-managed encryption at rest, encrypted secrets, role and tenant access controls, least-privilege service access, logging, rate limits, dependency review, backups, incident procedures, and protected deletion flows. Measures may change without reducing the protection required by law.
Processor will answer reasonable written compliance questions and provide available evidence. Audits must avoid exposing another customer's data, disrupting the Services, or compromising security. Each party bears its own ordinary costs. Controller bears exceptional costs caused by repeated or unusually burdensome requests unless a material Processor breach is found.
On termination, Controller may export available data before deletion. Processor deletes active Member data under the product deletion flow and removes remaining Processor copies within the documented schedule, except for lawful records and encrypted backups that age out under the applicable provider schedule.
This DPA controls over conflicting Terms for its subject matter. Danish law and the dispute terms in the Terms apply without limiting mandatory data-protection rights.