Last updated: 2026-08-22
This policy explains how Audunn, Jarlsberggade 5B, 4.2, 5000 Odense C, Denmark handles personal data through the Services. Contact: audunn@realaudunn.com.
For a Coach's account, security, billing, fraud prevention, legal compliance, and essential service analytics, we act as controller. For Member coaching data processed on a Coach's documented instructions, the Coach normally acts as controller and we normally act as processor. A third-party provider may have its own controller responsibilities for account or service data under its terms.
Depending on the features used, data can include:
Vercel Web Analytics is used for aggregate product traffic measurement. Sentry receives error and performance diagnostics. We do not use advertising cookies or sell personal data.
We process account and service data to perform the contract, secure and operate the Services, support users, bill for the Services, prevent fraud, meet legal duties, and improve reliability. Depending on the purpose, the basis is contract, legal obligation, or legitimate interests balanced against individual rights.
For Member coaching data, we follow the Coach's documented instructions. The Coach is responsible for the lawful basis for ordinary personal data. Health and other GDPR Article 9 data require an additional Article 9 condition. The platform consent flow is designed to record explicit consent, but the Coach must decide whether consent is valid and appropriate for the Coach's circumstances.
We do not use identifiable Member coaching content to train our own general-purpose model. Product evaluation and routing improvement must use synthetic or irreversibly anonymised material unless a separate lawful basis, notice, and role assessment exists.
Before an AI response is generated, the Services may send the selected provider the current message, relevant history, attached files, the Coach's instructions and knowledge, Member records selected for context, and results from connected tools. Separate calls may create embeddings, transcribe audio, extract structured records, title a conversation, prepare a recap, or perform another disclosed product function.
The model owner, actual inference provider, and routing service may be different companies. Only entries marked approved for the relevant data class in /legal/ai-providers may be used. Availability in a provider or gateway catalogue is not approval. Stealth, secret, prerelease, beta, and unreviewed models must not process personal data.
AI is not a human or doctor. Output can be wrong. Material health recommendations require human review and the platform does not permit solely automated decisions with legal or similarly significant effects.
Where health data is used, the Member receives a clear controller notice and chooses one explicit action. The primary action grants health-data collection and approved AI processing. A visible secondary action grants health-data collection for manual coaching without AI. No choice is preselected. We record the Member, wording version, time, each granted consent kind, and any withdrawal time. The choice remains active while the person is a client. A material change to the processing statement requires a new choice.
A client may receive a signed check-in link before creating an account. Before the first health question or file upload, the client must verify the email held by the Coach, confirm that they are at least 18, receive the applicable Terms and privacy notices, and make one explicit choice between AI-assisted and manual coaching. Both choices expressly cover health-data collection. Only the primary choice covers AI processing. The link is authorization to open one form. It is not proof of identity, age, or consent by itself. When the same verified email becomes a Member account in the same workspace, the active choice and original evidence are linked to that account instead of being requested again.
Withdrawal stops future consent-based processing at the server boundary once recorded. It does not make earlier lawful processing unlawful. A Member can withdraw in the member privacy page or contact the Coach. The Coach must stop any processing outside the platform that depended on the withdrawn consent.
The public website embed is anonymous and is not approved for health or other sensitive personal data. Visitors must not submit health information, financial account information, government identifiers, or other sensitive data. The embed discloses that it uses AI before the first interaction. Messages may be stored for the chat session and made available to the Coach.
The current recipient and subprocessor register is at /legal/ai-providers. Depending on configuration, recipients can include:
An enabled integration receives only the data needed for the requested function, subject to its actual permissions and provider behavior. A Coach must not enable a provider for Member data until it is approved in the registry.
The primary database region is configured in the EEA. Some recipients can process data outside the EEA. A transfer is permitted only when supported by an adequacy decision or appropriate safeguards, such as executed Standard Contractual Clauses plus any required transfer assessment and supplementary measures. The registry records the verified mechanism for each approved route. We do not claim a mechanism is complete until the relevant documents are held.
Account and workspace data is kept while the account is active. A Member account deletion removes the active Member record and dependent application records through the product's deletion flow. A scheduled workspace deletion uses the date shown in workspace settings and then removes the active workspace records. Billing, security, audit, and legal records may be retained where required or reasonably necessary for those purposes.
Provider transient copies, logs, and backups follow the approved provider contract and the retention schedule in the register. Deletion from the active application does not imply immediate erasure from every encrypted backup. Backup copies must age out under the applicable provider schedule and must not be restored except for disaster recovery.
Safeguards include encrypted transport, provider-managed database encryption at rest, encrypted integration credentials and AI keys, tenant isolation, role-based access, rate limits, audit records, incident handling, and restricted support access. These measures are designed to reduce risk, but no service can guarantee absolute security.
Depending on location and circumstances, a person may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent, and may complain to a supervisory authority. Members should contact their Coach first because the Coach normally controls Member coaching data. We assist the Coach under the DPA. Requests concerning our controller activities may be sent to audunn@realaudunn.com.
Strictly necessary authentication and security storage keeps a person signed in and protects a session. Vercel Web Analytics is configured without advertising identifiers. Optional third-party integrations may have their own storage practices when opened or connected.
We will provide notice of material changes where required. Contact audunn@realaudunn.com. As we are established in Denmark, an Article 27 representative is not required for our EEA establishment.