coach[corrie}

CoachCorrie.ai -- Data Processing Agreement

Version 1.3 - 2026-08-05 - Consent version dpa-1.3

1. Parties, roles, and precedence

This Data Processing Agreement ("DPA") is between the Coach accepting it (the "Controller") and Paragon Consulting FZE, P.O. Box 393313, Fujairah, United Arab Emirates (the "Processor"), and forms part of the Terms of Service. It governs all processing of personal data the Processor performs on the Controller's behalf in providing the CoachCorrie.ai platform. Where this DPA and the Terms conflict on data processing, this DPA prevails. "GDPR" means Regulation (EU) 2016/679; "personal data", "processing", "data subject", and "personal data breach" carry their GDPR meanings.

The Processor is established outside the European Union. Its representative in the Union under Article 27 of the GDPR is Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria, reachable at https://app.prighter.com/portal/15292804891 quoting reference ID-15292804891. The same entity is the Processor's authorised representative under Article 22 of the EU AI Act.

2. Scope of processing

Subject matter: hosting and AI-assisted processing of coaching Engagement Data. Duration: the term of the Terms of Service plus the wind-down period in §8. Nature and purpose: the operations in Annex A, performed solely to provide the platform's documented features to the Controller. The Processor processes Engagement Data only on the Controller's documented instructions -- given through the platform's features and settings -- unless EU or member-state law requires otherwise, in which case the Processor informs the Controller before processing unless that law forbids it. The Processor will inform the Controller immediately if, in its opinion, an instruction infringes the GDPR.

3. Processor obligations

The Processor shall: (a) ensure everyone it authorises to process Engagement Data is bound by confidentiality; (b) implement and maintain the technical and organisational measures in Annex B, reviewing them as risk evolves and never reducing the overall level of protection; (c) assist the Controller, insofar as possible and taking the nature of processing into account, in answering data-subject rights requests, and in the Controller's obligations under GDPR Articles 32-36 (security, breach notice, DPIA, prior consultation); (d) make available the information necessary to demonstrate compliance with Article 28 and allow audits per §9; and (e) maintain a record of processing activities under Article 30(2).

No training. The Processor shall not use Engagement Data or Outputs to train, fine-tune, or evaluate any machine-learning model -- its own or any third party's -- and shall contractually ensure its sub-processors are bound to the same. Engagement Data is used to generate content only within the engagement it belongs to.

4. Isolation as an instruction

The Controller's standing documented instruction includes the platform's isolation model: no data from any of the Controller's engagements may be used to generate content for any other engagement, and no data from the Controller's vault may be disclosed to, mixed with, or used for any other tenant. The Processor treats any violation of this instruction as a personal data breach under §7 regardless of whether data left its infrastructure.

5. Sub-processors

The Controller grants general written authorisation for the sub-processors in Annex C. The Processor will give at least 30 days' notice of any intended addition or replacement, during which the Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service and export its data under §8. The Processor imposes data-protection obligations on each sub-processor no less protective than this DPA and remains fully liable to the Controller for their performance.

6. Location and transfers

Engagement Data is stored and processed exclusively in the European Union (AWS eu-central-1). The Processor shall not transfer Engagement Data outside the European Economic Area except: (a) as necessary for AI inference via the sub-processor in Annex C under the safeguards stated there; and (b) to the extent that access to Engagement Data from outside the EEA (including by the Processor's UAE-based personnel) constitutes a transfer under Chapter V GDPR, in which case the parties incorporate by reference the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), with the Clauses' Annexes deemed completed by the corresponding sections of this DPA (Annex I by §§1-2 and Annexes A and C; Annex II by Annex B), and with the following supplementary measures: EU-only storage, encryption in transit and at rest, per-engagement row-level-security isolation, and logged, role-restricted access. No transfer relies on an adequacy decision for the UAE, because none exists. [Subject to counsel review.]

7. Personal data breach

The Processor shall notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Engagement Data, with the information Article 33(3) requires so far as then known, supplemented as it becomes available; shall document every breach and its remediation; and shall reasonably cooperate in the Controller's own notifications. The Processor's internal standard is a documented breach/no-breach determination by a named owner within 24 hours of detection, defaulting to "breach" when in doubt.

8. Deletion and return

During the 30 days after the Terms end, the Controller may export its Engagement Data in machine-readable form through the platform's export features or on request. After that window, the Processor deletes Engagement Data within 90 days, except that pseudonymized integrity-log entries may be retained under the layered-retention schedule disclosed at collection (GDPR Article 17(3)(e)) and data whose retention EU or member-state law requires. Deletion is performed as an audited erasure operation and is certified in writing on request.

9. Audit

On 30 days' written notice, not more than once in any 12-month period (and additionally after any personal data breach affecting the Controller), the Controller may audit the Processor's compliance with this DPA -- by written questionnaire, by review of the Processor's documentation and test evidence (including the isolation test suite results), or, where those are insufficient, by an on-site or remote inspection under confidentiality. The Processor may satisfy audit requests with current third-party attestations where they cover the scope in question.

10. Liability and law

Liability under this DPA follows the Terms of Service, save that nothing limits either party's liability to data subjects under GDPR Article 82. This DPA is governed by the law governing the Terms of Service -- the laws of the Dubai International Financial Centre (DIFC), United Arab Emirates -- and any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the DIFC Courts.

Annex A -- Description of processing

Data subjects: Executive Athletes; sponsors and sponsor personnel; 360° feedback raters; third parties mentioned in session content (including family members, as stated by the EA and never elaborated).

Categories of data: identity and role data; session transcripts and notes; uploaded artefacts (documents, assessments, psychometrics); Executive Athlete reflection-journal entries (typed, or transcribed from a voice memo as described under Operations); goals, progress, and coaching-domain content; KPI and ROI inputs; derived report content. Session content is treated as if GDPR Article 9 special-category data were present, with hard suppression of special-category detail in recall surfaces.

Operations -- session capture and artefacts (text-only): session capture arrives as text. The platform ingests transcripts from the Controller's connected capture tools, pasted or uploaded transcript files, and uploaded documents, with deterministic text extraction. No audio or video is ingested, stored, or transcribed on this path: the Processor performs no transcription of session recordings.

Operations -- Executive Athlete voice memos (transient audio): the one operation that touches audio. Where the Controller has enabled the Executive Athlete reflection journal and the Executive Athlete's recorded consent covers voice memos (consent version ea-journal-consent-1.1 or later), the Executive Athlete may record a voice memo, which is transcribed at upload by the speech-to-text service named in Annex C (EU region, batch operation). The recording exists only for the duration of that operation: the application deletes the transient storage copy, the transcript working copy, and the job record in the same operation that produced them; a failed cleanup is surfaced as an error rather than left as silent retention; and a one-day storage-lifecycle expiry backstops the deletion. No audio is ever persisted. The transcript becomes a journal entry only after the Executive Athlete reviews and confirms it, and every such entry is marked as machine-transcribed.

Operations -- generation and derived content: storage; chunking, embedding, and retrieval within the engagement's own namespace; AI-assisted drafting of coach-facing reports, nudges, reflection questions, and pre-session preparation briefs; rendering and export; deletion. Stored pre-session preparation briefs are derived Engagement Data (append-only) and are covered by this DPA's retention and erasure terms like all other Engagement Data. The coach-only personal-context recall brief is a distinct feature and is never persisted: it is composed on demand from the engagement's own record, displayed, and discarded, leaving only a content-free audit event.

Annex B -- Technical and organisational measures

Annex C -- Authorised sub-processors

Amazon Web Services EMEA SARL -- cloud hosting and storage; email delivery (Amazon SES); speech-to-text transcription of Executive Athlete voice memos (Amazon Transcribe, eu-central-1, transient processing as described in Annex A); text embeddings for retrieval (Amazon Bedrock, EU region). All EU regions. Safeguards: GDPR-compliant Data Processing Addendum; EU residency configuration.

Anthropic -- large-language-model inference via commercial API. Safeguards: commercial terms excluding use of customer content for model training; [inference region/endpoint and transfer mechanism -- counsel to confirm the SCC position]. The embedding path runs on Amazon Bedrock in-region (see the AWS entry above), so no embedding processing leaves the EU.

[Placeholder] -- changes to this list follow §5 notice-and-objection.

Apply for a coach account · Contact · Sign in

EU GDPR representative — Prighter EU Rep GmbH, Vienna EU AI Act authorised representative — Prighter EU Rep GmbH, Vienna