Data processing agreement
The Article 28 agreement between you as controller of your clients' data and onTrainer as your processor. It forms part of the terms of service.
Previous versions
- No previous versions. This is the first one in force.
1Parties and roles
In plain language
For your clients' data, you are the controller and onTrainer is your processor. Putting that in writing is what Article 28 of the GDPR requires, and this agreement is it.
It covers personal data about your clients. It does not cover your own account data, for which onTrainer is the controller and the privacy policy applies.
2Subject matter, duration, nature and purpose
The subject matter is the provision of the onTrainer workspace and the app. The duration is the life of your subscription plus any retention period set out below.
The nature of the processing is collection, storage, organisation, retrieval, display, transmission to the client's own device, and erasure. The purpose is to let you run your coaching practice, and nothing else. We do not use your clients' data to train models, to profile people for our own purposes, or for advertising.
3Types of personal data and categories of data subject
Categories of data subject
- Your clients
- People you invite who have not yet accepted
Types of personal data
| Type | Detail | Special category |
|---|---|---|
| Identity and contact | Name, email, language | No |
| Coaching records | Programs, sessions, bookings, credits | No |
| Intake and check-in answers | Whatever your forms ask | Yes, where a form asks about health |
| Medical flags | Flags you or your forms raise on a profile | Yes |
| Health data | Heart rate, sleep, workouts and similar | Yes, Article 9 |
| Derived health signals | Risk flags and alert history | Yes |
| Technical | Device, IP address, timestamps | No |
Because special category data is in scope, both parties rely on the client's explicit consent under Article 9(2)(a), recorded in the product.
4Your instructions
We process client personal data only on your documented instructions. Using the product as designed is an instruction. Anything beyond that requires a written instruction from you.
If we believe an instruction breaches data protection law, we will tell you and may pause that processing until it is resolved.
If we are ever required by law to process data beyond your instructions, we will tell you first unless the law forbids it.
5Confidentiality
Everyone we allow near client personal data is bound by a duty of confidentiality, is trained on handling it, and gets access only to what their role requires.
6Security measures
The measures below are the technical and organisational measures referred to in Article 32. They are also Annex II to this agreement.
- Encryption in transit for all connections, and encryption at rest for the database, backups and stored files.
- Tenant isolation enforced in the database itself through row-level security, so a query cannot cross workspace boundaries.
- Two-factor authentication on coach accounts.
- Role-based access control, with administrative access limited, logged and reviewed.
- An append-only audit log of administrative actions, including any support access to a workspace.
- Automated backups, with restoration tested on a schedule.
- Separate environments for development and production, with no production personal data used in development.
7Sub-processors
You give general authorisation for the sub-processors listed below. This list is also Annex III.
Each sub-processor is bound by obligations no weaker than those in this agreement, and we remain responsible to you for what they do.
8Helping you answer your clients
Your clients will bring their requests to you, because you are their controller. The product gives you and them the tools to answer most of them directly: export, correction, deletion and consent withdrawal are all flows in the product.
Where a request needs something the product does not do, we will help you within a reasonable time.
9Personal data breaches
Reporting the breach to the supervisory authority and, where required, to affected clients, is your responsibility as controller. We will give you what you need to do it.
10Impact assessments and prior consultation
Because the product processes health data at scale, a data protection impact assessment is likely to be required. We will give you the information about our processing that you need in order to carry one out.
11Deletion and return
You can export your clients' data at any time while the workspace is open.
Separately, and while the workspace is open, leaving the Online Coach tier permanently deletes health history collected under that tier, including derived flags and alert history. This is an instruction you give when you confirm the downgrade.
12Audits
We will make available the information needed to show we meet these obligations, and will allow an audit by you or an auditor you appoint.
13International transfers
Client personal data is stored in the European Union. Where a sub-processor operates outside it, the transfer relies on an adequacy decision or on standard contractual clauses, with a transfer impact assessment where one is required.
14Annexes
Annex I, the details of the processing, is sections 2 and 3 of this agreement. Annex II, the technical and organisational measures, is section 6. Annex III, the sub-processors, is section 7.
Every version of this agreement is kept and dated. The version in force is named at the top of this page.