ข้อตกลงการประมวลผลข้อมูล
ข้อตกลงนี้จัดทำเป็นภาษาอังกฤษ ฉบับภาษาอังกฤษถือเป็นฉบับที่มีผลผูกพัน
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between Coachito LLC and every trainer, gym or coaching business that uses Onyx Coach to manage its clients. It sets out the terms required by Article 28 of the GDPR for the personal data of your clients that we process on your behalf. It is concluded through acceptance of the Service Agreement incorporating this DPA, or through a separate written agreement, including electronic acceptance or confirmation by email. A separate handwritten signature is not required where the agreement is validly concluded electronically.
Signed copy. If your organisation needs a signed copy, use the print button above to save this page as a PDF. It ends with an execution page where you enter your legal name, registered address and registration number and both parties sign. Send the signed PDF to [email protected] and we countersign and return it within five business days.
Parties
Processor: Coachito LLC, a domestic limited liability company organised under the laws of the State of Wyoming, United States of America, Wyoming filing ID 2025-001823358, operating the Onyx Coach service (the "Processor", "we"). Principal office and mailing address: 30 N Gould St Ste N, Sheridan, WY 82801, USA. Contact for data protection: [email protected]. Contact person: Daniel Dopiriak, Owner. Representative in the European Union under Article 27 GDPR: Coachito s. r. o., Oravská 7597/8, 080 01 Prešov, Slovakia, company ID (IČO) 55903681, [email protected].
Controller: the trainer, gym or coaching business that holds the Onyx Coach trainer account, identified by the name and contact details on that account (the "Controller", "you").
Service Agreement: the Onyx Coach Terms of Service accepted by the Controller when creating the trainer account, together with any subscription plan in force.
1. Purpose, scope and definitions
1.1 This DPA sets out the terms on which the Processor processes personal data on behalf of the Controller in connection with the Onyx Coach service, consisting of the trainer web application, the Onyx Coach mobile applications used by the Controller's clients, and the related backend and interfaces (the "Service").
1.2 This DPA is intended to satisfy Article 28(3) of Regulation (EU) 2016/679 (the "GDPR") and forms part of the Service Agreement.
1.3 Terms defined in the GDPR have the same meaning here. "Client Data" means personal data relating to the Controller's clients and other data subjects that the Controller, or a client acting at the Controller's invitation, enters into or generates through the Service. "Sub-processor" means a third party engaged by the Processor to process Client Data.
1.4 Where this DPA and the Service Agreement conflict on a matter of data protection, this DPA prevails. Where this DPA and the standard contractual clauses in Annex IV conflict, those clauses prevail.
2. Roles of the parties
2.1 The Controller is the controller of Client Data. The Processor processes Client Data as a processor on the Controller's behalf.
2.2 The Processor acts as an independent controller, and this DPA does not apply, for the following processing, which is governed by the Privacy Policy:
- the Controller's own account, contact and billing data;
- the account that each client holds directly with the Processor in order to use the Onyx Coach applications, including authentication, acceptance of the Processor's terms, any subscription the client buys from the Processor directly, and storage and display of the client's own workout records for their personal use of that account;
- product analytics and error diagnostics that the Processor generates to operate and improve the Service, in aggregated or pseudonymised form;
- processing the Processor must carry out to comply with its own legal obligations.
2.3 Processing that enables the Controller to deliver coaching, including accessing clients' workout history and managing programmes, check-ins, measurements, notes and messages on the Controller's behalf, is governed by this DPA. Separately, the Processor acts as controller when providing the client's own account and personal workout history under clause 2.2, including while the client is linked to a trainer. The role depends on the purpose of the processing. The DPA continues to apply to data processed on the Controller's behalf until its return or deletion is completed.
2.4 Ending the client's link to the Controller ends the Controller's access through that link. The client's own workout history remains in their personal account under their direct relationship with the Processor. This does not authorise the Processor to retain data held solely on the Controller's behalf for its own purposes. Processing for the client's own account requires its own lawful basis under Article 6 GDPR and, where health data is involved, an applicable condition under Article 9(2) GDPR, as described in the Privacy Policy.
3. Description of the processing
3.1 The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the categories of personal data are described in Annex I.
4. Instructions
4.1 The Processor processes Client Data only on documented instructions from the Controller, unless required to do otherwise by Union or Member State law to which the Processor is subject. In that case the Processor informs the Controller of the legal requirement before processing, unless the law prohibits this on important grounds of public interest.
4.2 The Service Agreement, this DPA, and the Controller's configuration and use of the Service's features constitute the Controller's complete instructions. Further instructions may be given in writing, including by email to [email protected], and must be within the scope of the Service.
4.3 The Processor informs the Controller without delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law.
5. Obligations of the Controller
5.1 The Controller is responsible for the lawfulness of the processing, including a valid legal basis under Article 6 GDPR, and for providing its clients with the information required by Articles 13 and 14 GDPR.
5.2 The Controller acknowledges that Client Data includes data concerning health within the meaning of Article 9 GDPR, such as body weight, body measurements, body composition estimates, progress and check-in photographs, and notes about injuries or wellbeing. The Controller is responsible for meeting a condition under Article 9(2) GDPR, ordinarily the explicit consent of the client, before entering such data into the Service or asking a client to do so.
5.3 The Controller uses the Service's access controls responsibly, keeps its login credentials confidential, and enters into the Service only data it is entitled to process.
6. Confidentiality
6.1 The Processor ensures that persons authorised to process Client Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process Client Data only to the extent needed to provide the Service and to comply with this DPA.
7. Security of processing
7.1 The Processor implements the technical and organisational measures described in Annex II to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the fact that Client Data includes health data.
7.2 The Processor may update Annex II from time to time provided the overall level of protection is not reduced.
7.3 The Processor grants access to Client Data to its personnel only to the extent strictly necessary for operating, maintaining and supporting the Service.
8. Sub-processors
8.1 The Controller gives the Processor general authorisation to engage the Sub-processors listed in Annex III. This page is the Processor's published list of Sub-processors.
8.2 The Processor informs the Controller of any intended addition or replacement of a Sub-processor at least 30 days in advance, by email to the Controller's account email address and by updating Annex III. The Controller may object on reasonable, documented data protection grounds within that period. If the parties cannot resolve the objection in good faith, the Controller may terminate the affected part of the Service without penalty.
8.3 The Processor imposes on each Sub-processor, by written contract, data protection obligations that are in substance the same as those in this DPA, and remains fully liable to the Controller for the performance of the Sub-processor's obligations.
8.4 On request, the Processor provides the Controller with a copy of the data protection terms concluded with a Sub-processor, redacted for commercial information where necessary.
8.5 Where the Controller connects a third-party service to its account, for example an external AI assistant through the Service's integration features, the Processor transmits Client Data to that service on the Controller's instruction. That service is engaged by the Controller, is not a Sub-processor, and the Controller is responsible for selecting it, for the lawful basis and safeguards of that transfer, and for any contract it requires. The Controller can revoke such a connection at any time in its settings.
9. International transfers
9.1 Coachito LLC is the contracting legal entity, incorporated in Wyoming, United States. The Processor's owner operates the Service from Thailand and may access Client Data from Thailand where necessary for administration, maintenance and support. The primary coaching databases and media storage use the EU locations listed in Annex III. Authentication, notifications, AI and other supporting services have the separate processing locations described in that annex, including locations outside the European Economic Area.
9.2 Client Data is transferred to, or accessed from, a third country only where Annex III or clause 9.1 discloses this, and only under a valid safeguard in Chapter V GDPR, such as an adequacy decision, the EU-US Data Privacy Framework, or the standard contractual clauses adopted by the European Commission. The Processor ensures the same for each Sub-processor.
9.3 Because the Processor is established outside the European Economic Area, the parties conclude the standard contractual clauses in Commission Implementing Decision (EU) 2021/914, Module Two (transfer controller to processor), as set out in Annex IV, with the Controller as data exporter and the Processor as data importer. The clauses are incorporated by reference and take effect on the date this DPA takes effect. The annexes of this DPA serve as the annexes of those clauses.
9.4 The Processor must include administrative access from Thailand in the assessment of the applicable transfer safeguards and in its documented instructions and access restrictions. Any intended administrative access from an additional country must be disclosed to the Controller in advance and meet clause 9.2 before that access begins.
9.5 Clause 9.3 and Annex IV apply where the Controller is subject to the GDPR. Where the Controller is subject to the UK GDPR, the Clauses apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0), with the Information Commissioner as competent supervisory authority and the law and courts of England and Wales for the purposes of Clauses 17 and 18. Where the Controller is subject to neither the GDPR nor the UK GDPR, clause 9.3 and Annex IV do not apply and this DPA applies, with the necessary changes, under the data protection law that applies to the Controller.
10. Assistance to the Controller
10.1 The Processor forwards to the Controller, within five business days, any request it receives from a data subject relating to Client Data, and does not respond to it except to refer the data subject to the Controller, unless the Processor is the controller for that request under clause 2.2.
10.2 The Processor assists the Controller in responding to requests under Articles 15 to 22 GDPR through the correction and account-management features available in the Service and through support at [email protected]. Support handles export requests and any further access, correction, restriction or deletion instructions that cannot be completed through the Service.
10.3 Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in complying with Articles 32 to 36 GDPR, including security, breach notification, data protection impact assessments and prior consultation of a supervisory authority.
10.4 Assistance that goes beyond the features of the Service and takes more than a reasonable amount of effort may be charged at reasonable, proportionate rates agreed in advance. Fees must not prevent the exercise of rights under this DPA or delay assistance required to meet applicable data protection deadlines.
11. Personal data breaches
11.1 The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Data. Notification goes to the Controller's account email address.
11.2 The notification describes, as far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Information that is not yet available is provided in phases without undue further delay.
11.3 The Processor cooperates with the Controller and takes reasonable steps to contain, investigate and remedy the breach. The Controller remains responsible for notifying the supervisory authority and data subjects where required.
12. Information and audits
12.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and this DPA.
12.2 The Processor allows and contributes to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller and bound by confidentiality. Routine audits take place at reasonable intervals, normally once in any twelve month period and on 30 days' written notice. Additional audits and shorter notice are permitted where there are indications of non-compliance, following a personal data breach, where required by a supervisory authority, or where otherwise reasonably necessary to verify compliance. The parties cooperate to protect other customers' data and avoid unreasonable disruption.
12.3 The Processor may provide written answers, documentation, and relevant independent certifications or audit reports, including those of its infrastructure Sub-processors, to support the review. These materials do not replace the Controller's right to verify the Processor's own compliance. The Controller decides whether further remote or on-site inspection is necessary and appropriate, taking account of the evidence provided and relevant security considerations.
12.4 The Controller bears its own auditor's costs. Any fees charged by the Processor for audit assistance must be reasonable, proportionate and agreed in advance, and must not prevent or discourage the exercise of the Controller's audit rights. Cost discussions must not delay an urgent audit required under clause 12.2.
13. Export, return and deletion of data
13.1 The Controller may request an export by contacting support at [email protected]. Support prepares the export; it is not a self-service download in the application. The standard export includes the Controller's client list, those clients' workout history that the Controller is authorised to receive, and the exercises created by the Controller. The export is provided in a commonly used machine-readable format, with the format and delivery arrangements confirmed by support when handling the request.
13.2 The Controller can remove a client from its account through the Service. Removing the link, or closing the Controller's account, ends the Controller's access through that relationship. It does not delete the client's own account or the workout history held there for the client's personal use. That processing continues under clauses 2.2 and 2.4 and the Privacy Policy. The client can exercise their own access and deletion rights with the Processor.
13.3 When the provision of processing services on the Controller's behalf ends, the Processor must, at the Controller's choice, return or delete all personal data processed on that behalf and delete existing copies, unless Union or Member State law requires storage. Return or deletion of this data is completed without undue delay and within 90 days after that processing ends. The Controller should send its instructions to [email protected] before the processing ends; in the absence of return instructions, the Processor deletes the data within that period. Backup copies remain protected, are excluded from ordinary use and are removed within the backup rotation in Annex II. If a backup is restored, the Processor must reapply the deletion instructions. The client's own workout records retained for the separate purpose in clause 13.2 are not data retained solely on the Controller's behalf.
13.4 The Controller should request its standard export before closing its account or removing the relevant client links. Any later request is limited to data still held on the Controller's behalf and which it is authorised to receive. The standard export in clause 13.1 does not limit the Controller's right to the return of all personal data processed on its behalf under clause 13.3, or the assistance required by clause 10. Other Client Data needed for those purposes can be requested from support. Trainer-created exercises that contain no personal data are included in the standard export for convenience and are not otherwise subject to this DPA.
14. Liability
14.1 Each party is liable towards data subjects in accordance with Article 82 GDPR. Between the parties, the limitations of liability in the Service Agreement apply to this DPA, except that they do not limit either party's liability for fines imposed on it or for claims resulting from its own wilful misconduct or gross negligence.
15. Term and termination
15.1 This DPA takes effect when the Controller accepts the Service Agreement incorporating it or separately agrees to this DPA, including electronically or by email. It remains in force for as long as the Processor processes Client Data on the Controller's behalf, including during return and deletion.
15.2 Either party may terminate the Service Agreement in accordance with its terms if the other party is in material breach of this DPA and does not cure the breach within 30 days of written notice. Clauses 6, 13 and 14 survive termination.
16. Final provisions
16.1 This DPA is governed by the law of the EU Member State in which the Controller is established, without prejudice to the mandatory provisions of the GDPR, and the courts of that Member State have jurisdiction over disputes arising from it. Where the Controller is established in the United Kingdom, the law and courts of England and Wales apply. Where the Controller is established elsewhere, the governing law and jurisdiction clause of the Service Agreement applies.
16.2 The Processor may update this DPA to reflect changes in law or in the Service and gives the Controller at least 30 days' notice by email before an updated version takes effect. No update reduces the protection required by Article 28 GDPR. If the Controller objects on reasonable data protection grounds, it may terminate the Service Agreement before the change takes effect without penalty; continued use of the Service after that date constitutes acceptance. Updates to technical and organisational measures under clause 7.2 and Sub-processor changes under clause 8 follow the procedures in those clauses.
16.3 If any provision is invalid, the remaining provisions remain in force and the parties replace the invalid provision with a valid one that comes closest to its purpose.
16.4 Notices under this DPA are sent by email: to the Processor at [email protected] and to the Controller at the email address of its Onyx Coach trainer account.
Annex I. Description of the processing
Subject matter
Provision of the Onyx Coach coaching platform, through which the Controller manages its clients' training programmes, tracks their workouts and progress, runs check-ins, communicates with them and schedules sessions.
Duration
The term of the Service Agreement, plus the deletion period in clause 13.
Nature of the processing
Collection through the applications, storage, organisation, display to the Controller and to the client concerned, transmission between the Controller and the client (messaging, notifications, email), backup, deletion, and, when the Controller uses the AI assistant features, automated analysis of a client's training data to answer the Controller's questions.
Purpose
Enabling the Controller to deliver personal training and coaching services to its clients.
Data subjects
- Clients of the Controller, being natural persons the Controller coaches and has invited to the Service or created in it.
- Members of the Controller's team, where the Controller adds them to its account.
Categories of personal data
- Identity and contact data: name, email address, phone number where provided, profile photo.
- Demographic data: date of birth or age, sex, height.
- Health and body data (Article 9): body weight, body measurements, body fat estimates, progress and check-in photographs, check-in answers about sleep, energy, soreness and injuries, and free-text notes.
- Training data: assigned programmes, scheduled sessions, workout logs (exercises, sets, repetitions, load, duration, perceived effort, completion), goals and preferences.
- Nutrition data where the Controller or client enters it.
- Communications: messages exchanged between the Controller and the client within the Service.
- Technical data: device push tokens, time zone, language, application version, and IP addresses in server logs.
- Payment data, only where the Controller charges the client through the Service: payment status and amounts. Card details are collected by the payment provider directly and never stored by the Processor.
Special categories
Data concerning health, as listed above. Safeguards applied: explicit consent obtained by the Controller under clause 5.2, access limited to the Controller and the client concerned by database security rules, encryption in transit and at rest, private storage with short-lived signed URLs for photographs, and the further measures in Annex II.
Frequency and retention
Continuous, for as long as the Controller and its clients use the Service. Processing on the Controller's behalf lasts for the Service Agreement and the relevant coaching relationship, followed by return or deletion under clause 13. The client's own workout history is retained separately for the client's personal account as described in clauses 2.2, 2.4 and 13.2 and the Privacy Policy.
Annex II. Technical and organisational measures
Encryption
- All data in transit between the applications, the backend and Sub-processors is encrypted with TLS.
- All data at rest is encrypted by the hosting providers by default (Google Cloud and Amazon Web Services server-side encryption with AES-256).
Access control and authentication
- Trainers and clients authenticate through Firebase Authentication using email and password, Google sign-in or Sign in with Apple. Onyx Coach does not require two-factor authentication for customer accounts. When a customer signs in with Google or Apple, authentication is handled by that provider under its account security settings. Passwords are never stored by the Processor in readable form.
- Database security rules restrict every trainer account to the clients linked to it, and every client to their own data. Every backend request is authenticated with a verified identity token.
- Firebase App Check tokens are verified on requests to the AI API routes.
- Internal administrative access is limited to named personnel and granted through role claims. Two-factor authentication is enforced on all internal Google Cloud, Amazon Web Services and GitHub administrator accounts.
Photographs and media
- Client photographs, exercise videos and images and other uploads are stored in Amazon S3 in Frankfurt. Uploads are accepted only through short-lived signed upload URLs issued to an authenticated user, and no bucket is publicly listable.
- Check-in and progress photographs are kept in a dedicated private bucket that is not publicly readable, and are served only through short-lived signed URLs issued to the authenticated client or the linked trainer.
Data location
- The primary coaching databases and media storage use the EU locations listed in Annex III. Authentication and other supporting services process data at the separate locations disclosed there. The Processor's owner may access Client Data from Thailand for administration, maintenance and support, subject to clause 9 and the applicable safeguards in Annex IV.
Availability and backup
- The primary database runs on managed, replicated infrastructure across multiple EU data centres.
- Point-in-time recovery with a seven day window and weekly scheduled backups retained for 98 days are enabled, so accidental deletion or corruption can be reversed. Deleted data leaves the backups in the ordinary rotation, within 98 days at most.
Secrets and change management
- API keys and credentials are held in Google Secret Manager and are never committed to source code.
- All source code is version controlled. Production is deployed only through an automated CI pipeline, not from individual machines.
- Development and production run in separate cloud projects. Production Client Data is not used in development.
Logging and monitoring
- Application error reports are captured in Sentry, in its EU data region, and retained for up to 90 days. Server logs in Google Cloud Logging are retained for up to 30 days.
- Logs are used to operate and secure the Service and are accessible only to authorised personnel.
Deletion
- Clients can request deletion of their own account in the application or through support. Trainers can remove client links through the Service; this ends coaching access while the client's own account and workout history remain. Return and deletion of data processed on the trainer's behalf are handled under clause 13, with backup copies removed within the backup rotation.
Organisational measures
- All persons with access to Client Data are bound by confidentiality obligations and have access only on a need-to-know basis.
- Personal data breaches are handled under the procedure in clause 11.
- Sub-processors are selected only where they offer GDPR-compliant data processing terms and independently audited infrastructure (ISO 27001, SOC 2).
Annex III. Sub-processors
Sub-processors that process Client Data on behalf of the Processor. Providers the Processor uses for its own purposes under clause 2.2 (for example its billing and product analytics tools) are covered by the Privacy Policy and are not listed here.
The locations below distinguish storage of the primary coaching records from processing by supporting services and provider support teams. The EU region selected for a database or storage bucket applies to that service; it does not determine the location of authentication, notifications or AI processing. Each entry applies to processing of Client Data on the Controller's behalf; processing of direct account data under clause 2.2 remains governed by the Privacy Policy. The contact for each Sub-processor is the data protection contact published in that provider's data processing terms.
| Sub-processor | Service and purpose | Client Data involved | Location and safeguard |
|---|---|---|---|
| Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland, with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, as parent | Regional hosting: Cloud Firestore database (EU multi-region eur3), Realtime Database for messaging (Belgium, europe-west1), Cloud Functions backend (Frankfurt, europe-west3), and Cloud Storage for a minority of uploads (EU multi-region) | All categories in Annex I except most photographs and media files, which are held by Amazon Web Services below | Primary database and storage locations: EU, as specified in this row. Google support and other processing outside the selected regions are governed by the Google Cloud Data Processing Addendum and its international transfer terms. |
| Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA: Firebase Authentication | Account authentication, including email and password, Google sign-in and Sign in with Apple | Identity and contact data needed for sign-in, authentication identifiers and security metadata such as IP addresses and user agents | USA. Firebase Authentication operates from US data centres, independently of the database region. Firebase Data Processing and Security Terms, with applicable international transfer safeguards. See Firebase's location information. |
| Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA: Firebase supporting services | Cloud Messaging for push notifications, Remote Config for application settings, and App Check for application attestation | Device and installation identifiers, push tokens and notification payloads, configuration attributes, and attestation data | Global processing, including outside the EU, where Google and its service providers operate. These services are not restricted to the coaching database's EU region. Firebase Data Processing and Security Terms and applicable Google data processing terms govern international transfers. |
| Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA: Gemini API | AI features: generating exercise metadata, search embeddings, and assistant answers that reference a client's training data when the Controller uses the assistant | Training data and check-in data included in the Controller's request; no photographs | Global processing, including the USA. Google's paid-service terms permit temporary storage or caching where Google or its agents maintain facilities. Google's Data Processing Addendum governs processing and transfers, including standard contractual clauses where applicable. Under the paid-service terms, prompts and responses are not used to improve Google's products or train its models. See Gemini API paid-service terms. |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg | Primary media storage: S3 object storage and application hosting in Frankfurt (eu-central-1) for client photographs (check-in and progress photos, profile pictures), exercise videos and images, and other uploads | Photographs, videos and other media files | Media storage and application hosting: Frankfurt, Germany (eu-central-1). International access and transfers by AWS are governed by the AWS Data Processing Addendum and its standard contractual clauses where applicable. |
| OneSignal, Inc., 201 S. B St., Suite 200, San Mateo, CA 94401, USA | Delivery of push notifications to the mobile applications | Device push tokens, notification text (for example a reminder or a new message alert) | USA. Standard contractual clauses in OneSignal's Data Processing Addendum, or the EU-US Data Privacy Framework while OneSignal's certification is active |
| Brevo (Sendinblue SAS), 7 rue de Madrid, 75008 Paris, France | Email delivery for service notifications and, where enabled, client communication | Name, email address, email content | Database hosting: France, Germany and Belgium, as described in Brevo's location information. Processing and any international transfers are governed by Brevo's DPA. |
| Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Error monitoring for the applications and backend, EU data region (Frankfurt) | User identifier, device and application details, technical context of errors | Data stored in the EU; support access from the USA under Sentry's DPA and standard contractual clauses |
| Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland | Payment processing, only where the Controller charges clients through the Service | Name, email address, payment amounts and status. Card details go to Stripe directly | EU, with transfers to Stripe, Inc. (USA) under Stripe's DPA and standard contractual clauses |
Annex IV. Standard contractual clauses
The standard contractual clauses for the transfer of personal data to third countries in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "Clauses"), Module Two (transfer controller to processor), are incorporated into this DPA by reference and are deemed concluded between the Controller as data exporter and the Processor as data importer on the date this DPA takes effect. The official text is published at eur-lex.europa.eu/eli/dec_impl/2021/914/oj. The Clauses are not modified. The parties make the following selections:
| Clause 7 | The optional docking clause applies. |
| Clause 9(a) | Option 2, general written authorisation. The data importer informs the data exporter of changes to its sub-processors at least 30 days in advance, as set out in clause 8.2 of this DPA. |
| Clause 11(a) | The optional language on an independent dispute resolution body does not apply. |
| Clause 13 | The supervisory authority of the EU Member State in which the data exporter is established is the competent supervisory authority. |
| Clause 17 | Option 1. The Clauses are governed by the law of the EU Member State in which the data exporter is established. |
| Clause 18(b) | Disputes are resolved by the courts of the EU Member State in which the data exporter is established. |
| Annex I.A | The Parties section of this DPA. |
| Annex I.B | Annex I of this DPA. The data importer is Coachito LLC, incorporated in the United States. Transfers occur in the course of providing the Service for the duration of the Service Agreement and include its owner's administrative access from Thailand as needed for administration, maintenance and support, and the Sub-processing at the locations disclosed in Annex III. |
| Annex I.C | The supervisory authority identified under Clause 13. |
| Annex II | Annex II of this DPA. |
| Annex III | Annex III of this DPA. |
The documented assessment required by Clause 14 must address Coachito LLC's incorporation in the United States, its owner's administrative access from Thailand, and the processing and onward transfers disclosed in Annex III. It must consider the relevant laws and practices, access to readable data, the nature of the Client Data, the technical and organisational measures, and any supplementary measures needed before the relevant transfers begin. The parties must review the assessment when circumstances materially change. The data importer must make the assessment available to the data exporter on request and comply with Clause 15 in relation to public authority requests.
Execution
This copy of the DPA is concluded between Coachito LLC, identified in the Parties section above, and the Controller identified here. The Controller's details below replace the reference to the trainer account in the Parties section for the purposes of this signed copy and of Annex I.A of the standard contractual clauses.
| Controller legal name | |
| Registered address | |
| Registration number | |
| Data protection contact (email) | |
| Onyx Coach trainer account email |
Contact
Coachito LLC
Wyoming filing ID: 2025-001823358
Principal office and mailing address:
30 N Gould St Ste N
Sheridan, WY 82801
USA
[email protected]
Representative in the EU under Article 27 GDPR
Coachito s. r. o.
Oravská 7597/8
080 01 Prešov
Slovakia
Company ID (IČO) 55903681
[email protected]