Skip to content

Data processing agreement

The Article 28 agreement between you as controller of your clients' data and onTrainer as your processor. It forms part of the terms of service.

Previous versions
  • No previous versions. This is the first one in force.
Also in Romanian

1Parties and roles

In plain language

For your clients' data, you are the controller and onTrainer is your processor. Putting that in writing is what Article 28 of the GDPR requires, and this agreement is it.

It covers personal data about your clients. It does not cover your own account data, for which onTrainer is the controller and the privacy policy applies.

2Subject matter, duration, nature and purpose

The subject matter is the provision of the onTrainer workspace and the app. The duration is the life of your subscription plus any retention period set out below.

The nature of the processing is collection, storage, organisation, retrieval, display, transmission to the client's own device, and erasure. The purpose is to let you run your coaching practice, and nothing else. We do not use your clients' data to train models, to profile people for our own purposes, or for advertising.

3Types of personal data and categories of data subject

Categories of data subject

  • Your clients
  • People you invite who have not yet accepted

Types of personal data

TypeDetailSpecial category
Identity and contactName, email, languageNo
Coaching recordsPrograms, sessions, bookings, creditsNo
Intake and check-in answersWhatever your forms askYes, where a form asks about health
Medical flagsFlags you or your forms raise on a profileYes
Health dataHeart rate, sleep, workouts and similarYes, Article 9
Derived health signalsRisk flags and alert historyYes
TechnicalDevice, IP address, timestampsNo

Because special category data is in scope, both parties rely on the client's explicit consent under Article 9(2)(a), recorded in the product.

4Your instructions

We process client personal data only on your documented instructions. Using the product as designed is an instruction. Anything beyond that requires a written instruction from you.

If we believe an instruction breaches data protection law, we will tell you and may pause that processing until it is resolved.

If we are ever required by law to process data beyond your instructions, we will tell you first unless the law forbids it.

5Confidentiality

Everyone we allow near client personal data is bound by a duty of confidentiality, is trained on handling it, and gets access only to what their role requires.

6Security measures

The measures below are the technical and organisational measures referred to in Article 32. They are also Annex II to this agreement.

  • Encryption in transit for all connections, and encryption at rest for the database, backups and stored files.
  • Tenant isolation enforced in the database itself through row-level security, so a query cannot cross workspace boundaries.
  • Two-factor authentication on coach accounts.
  • Role-based access control, with administrative access limited, logged and reviewed.
  • An append-only audit log of administrative actions, including any support access to a workspace.
  • Automated backups, with restoration tested on a schedule.
  • Separate environments for development and production, with no production personal data used in development.

7Sub-processors

You give general authorisation for the sub-processors listed below. This list is also Annex III.

Each sub-processor is bound by obligations no weaker than those in this agreement, and we remain responsible to you for what they do.

8Helping you answer your clients

Your clients will bring their requests to you, because you are their controller. The product gives you and them the tools to answer most of them directly: export, correction, deletion and consent withdrawal are all flows in the product.

Where a request needs something the product does not do, we will help you within a reasonable time.

9Personal data breaches

Reporting the breach to the supervisory authority and, where required, to affected clients, is your responsibility as controller. We will give you what you need to do it.

10Impact assessments and prior consultation

Because the product processes health data at scale, a data protection impact assessment is likely to be required. We will give you the information about our processing that you need in order to carry one out.

11Deletion and return

You can export your clients' data at any time while the workspace is open.

Separately, and while the workspace is open, leaving the Online Coach tier permanently deletes health history collected under that tier, including derived flags and alert history. This is an instruction you give when you confirm the downgrade.

12Audits

We will make available the information needed to show we meet these obligations, and will allow an audit by you or an auditor you appoint.

13International transfers

Client personal data is stored in the European Union. Where a sub-processor operates outside it, the transfer relies on an adequacy decision or on standard contractual clauses, with a transfer impact assessment where one is required.

14Annexes

Annex I, the details of the processing, is sections 2 and 3 of this agreement. Annex II, the technical and organisational measures, is section 6. Annex III, the sub-processors, is section 7.

Every version of this agreement is kept and dated. The version in force is named at the top of this page.