Version 1.0 · Effective 13 September 2026 · Part of the Customer Terms. Applies to every coaching business that subscribes to Coach Vault, wherever it is based.
This Data Processing Addendum ("DPA") forms part of the Coach Vault Customer Terms (app.getcoachvault.com/customer-terms) between Coach Vault Pty Ltd (ACN 697 844 705, "Coach Vault", "we", "us") and the coaching business that subscribes ("you"). It applies automatically, wherever your business is based, from the moment we hold any personal data about your clients on your behalf. It says what we do with that data, what we promise, what you are responsible for, and how that data may lawfully travel from your clients' country to our servers. If this DPA and the Customer Terms ever conflict on anything about personal data, this DPA wins.
1. Who is who
You are the controller of the personal data about your clients and your team that you put into Coach Vault, or that they enter at your invitation ("Client Data"). Under other laws the same role is called the APP entity (Australia), the responsible party (South Africa), the business (California) or the personal data controller (Indonesia). You decide why and how Client Data is used.
We are your processor. Under other laws the same role is called the operator (South Africa) or the service provider (California). We process Client Data only to provide Coach Vault to you, on your instructions, and for nothing else.
For your own account, billing and support information we are the controller, and our Privacy Policy covers that.
Your instructions to us are: this DPA, the Customer Terms, the settings you choose in the app, and the features you and your clients use. If you need something different, email admin@getcoachvault.com. If an instruction would break the law that applies to us, or we can't do it, we'll tell you within 5 business days rather than quietly ignoring it.
2. What we process for you
Annex 1 sets out the detail. In short:
Health information is special category data (UK and EU), special personal information (South Africa), specific personal data (Indonesia) and consumer health data (some US states). Coach Vault can hold weight, body measurements, progress photos, sleep, steps and heart-rate readings from devices a client connects, menstrual cycle tracking (separately opt-in), injuries and medical notes, and blood pressure or blood results a client chooses to enter. Because of that, you need your clients' explicit consent before you collect it. Section 5 explains who does what.
- Subject matter: running your coaching business through Coach Vault.
- Duration: for as long as you subscribe, plus the 30-day wind-down in the Customer Terms.
- Purpose: delivering your coaching to your clients, which includes programs, nutrition, check-ins, messaging, progress tracking, community features, notifications, payments you take through the app, and any AI drafting feature you switch on.
- Whose data: your clients, your team members, and people you invite who may not go on to sign up.
- What data: identity and contact details; account and device details; training, nutrition and habit entries; check-in answers; messages and community posts; and health information, which is set out in the next paragraph.
3. What we promise
- Instructions only. We process Client Data only on your instructions, unless a law that applies to us requires otherwise. If it does, we'll tell you before we act unless that law stops us.
- Confidentiality. Everyone who works for us and can reach Client Data is bound by confidentiality, and gets access only to what their job needs.
- Security. We keep the measures in Annex 2, and we won't lower them while you subscribe.
- Sub-processors. You give us general permission to use the sub-processors listed in Annex 3. We'll email you at least 30 days before we add or replace one. If you object on reasonable data-protection grounds and we can't resolve it with you, you can cancel your subscription and we'll refund any prepaid fees for the period after cancellation. Every sub-processor is bound by written terms at least as protective as this DPA, and we remain responsible to you for what they do.
- Your clients' requests. If a client contacts us directly to access, correct, export or delete their data, we'll pass the request to you within 5 business days and won't act on it ourselves unless you ask us to or the law requires it. The app gives you export and deletion tools so most requests never need us.
- Helping you comply. We'll give you the information you reasonably need for a data protection impact assessment, a consultation with a regulator, or a breach assessment.
- Breaches. If we become aware of a personal data breach affecting Client Data, we'll tell you without undue delay and in any case within 48 hours of confirming it, with what we know at that point: what happened, whose data, the likely consequences, and what we're doing about it. We'll keep you updated as we learn more. Notifying your regulator and your clients is your decision and your job; we'll help you do it.
- Deleting and returning data. Before your subscription ends you can export everything. We keep Client Data for 30 days after your subscription ends so you can come back or finish exporting, then we delete it, except billing records and anything the law makes us keep. On written request we'll confirm in writing that deletion is done.
- Audits. Once in any 12 months, on 30 days' written notice, we'll answer a reasonable security questionnaire and share the evidence we hold, including our sub-processors' certifications. If your regulator requires more than that, we'll cooperate with an audit at a mutually agreed time, under confidentiality, at your cost.
- Records. We keep a record of the processing we carry out for you and will show it to a regulator that asks.
- Government and court demands. If a government body or court demands Client Data, we'll challenge what we lawfully can, tell you unless we're prohibited from doing so, and hand over only what is strictly required.
4. What you promise
- You have a lawful basis for everything you ask us to process, and you've told your clients what you collect and why. Your branded privacy page does this for you; keep the business details on it correct.
- You get and keep your clients' explicit consent to their health information being collected and used, before they start (section 5), and you can produce it if asked.
- Your instructions comply with the law that applies to you.
- You put into Coach Vault only what your coaching needs. You don't use it for anyone under 18 unless the law where you are allows it and you hold the parental consent it requires.
- You tell us promptly if you become aware of a security problem on your side, such as a lost phone that was signed in, or a shared password.
5. Health information consent
Getting your clients' consent is your responsibility, not ours. The relationship with each client is yours, so the consent is between you and them. Where the law needs explicit consent for health information (for example Article 9 of the UK GDPR and the EU GDPR, section 27 of POPIA in South Africa, Indonesia's Personal Data Protection Law, or Washington's My Health My Data Act), get it before the client starts, in your own client terms, sign-up form or onboarding, and keep a record.
Tell your clients that their information is stored and processed by Coach Vault on your behalf. Your branded privacy page in the app already says this.
If you'd like help, we can switch on an optional consent screen for your clients. It asks each client to tick an unticked box before using the app, and records the version of the text, the time and the device. Ask us at admin@getcoachvault.com. Using it is your choice, and it doesn't change who is responsible.
A client can withdraw consent at any time by deleting their account from Settings, or by asking you. If a client asks us, we'll pass it to you under section 3.
6. Where data goes, and how that is lawful
Client Data is stored in Sydney, Australia (Supabase, on Amazon Web Services). The sub-processors in Annex 3 that operate in the United States handle the limited information described there.
Australia does not hold a UK or EU adequacy decision. So, for Client Data about people in those places, the following transfer terms are incorporated into this DPA and apply between you (as data exporter) and us (as data importer):
Our onward transfers to the US sub-processors in Annex 3 are covered by our own contracts with them, which contain the EU Standard Contractual Clauses or rely on their certification under the EU-US Data Privacy Framework and its UK extension.
If a transfer mechanism above is invalidated, we'll work with you to put a lawful replacement in place promptly, and you can cancel with a refund of prepaid fees if we can't.
- United Kingdom: the International Data Transfer Addendum to the EU Standard Contractual Clauses, version B1.0, issued by the Information Commissioner under s.119A of the Data Protection Act 2018. Table 1 is completed with the parties to the Customer Terms; Table 2 refers to the EU Standard Contractual Clauses described below; Table 3 is completed by Annexes 1, 2 and 3 of this DPA; in Table 4, neither party may end the Addendum when the ICO issues a revised version.
- European Economic Area: the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor). The optional docking clause (Clause 7) is not included. Under Clause 9, Option 2 (general written authorisation) applies with 30 days' notice. The optional wording in Clause 11 is not included. Under Clauses 13, 17 and 18 the law and courts of Ireland apply. Annexes I, II and III of the Clauses are completed by Annexes 1, 2 and 3 of this DPA.
- Switzerland: the same Clauses apply, with the Federal Data Protection and Information Commissioner as competent authority, references to the GDPR read as references to the Swiss Federal Act on Data Protection, and Swiss law and courts for Swiss data subjects.
- Everywhere else: Annex 4 sets out the transfer basis for each country we currently serve.
7. Liability
The liability cap in the Customer Terms applies to this DPA. Where the data-protection law that applies to you doesn't allow that cap for a particular claim, the cap applies to the fullest extent that law allows. Nothing in this DPA limits a person's rights against either of us under data-protection law.
8. How long this lasts, and changes
This DPA applies for as long as we process Client Data for you. If the law changes, we'll update this DPA and email you at least 30 days before the change takes effect, unless a shorter period is required by law. Each version is dated, and the current one is always at app.getcoachvault.com/customer-terms/dpa.
9. Contact
Data-protection questions, breach reports and audit requests go to admin@getcoachvault.com. Our postal address is Coach Vault Pty Ltd, Mermaid Beach, Queensland, Australia. We'll acknowledge within 2 business days.
Annexes
Annex 1. Details of the processing
- Data exporter (controller): the coaching business subscribing to Coach Vault, at the address on its account. Activities: coaching its clients through Coach Vault.
- Data importer (processor): Coach Vault Pty Ltd, Mermaid Beach, Queensland, Australia. Activities: providing the Coach Vault software and hosting.
- Categories of data subjects: the controller's clients; the controller's coaches and staff; people the controller invites who don't sign up.
- Categories of personal data: name, email, phone, date of birth, gender, height; account settings and device tokens; training, nutrition, habit and supplement entries; check-in answers and progress photos; messages and community posts; payment records for services bought through the app.
- Special category and sensitive data: health information as described in section 2, including weight and body measurements, progress photos, sleep, steps and heart-rate readings from connected devices, menstrual cycle tracking (opt-in), injuries and medical notes, blood pressure and blood results. Collected on the consent the controller obtains under section 5. Never used for advertising, never sold, never used to train AI models.
- Frequency: continuous, for as long as the subscription runs.
- Nature of the processing: storage, display to the controller and its clients, transmission between them, notification delivery, and generation of drafts by an AI feature when the controller switches one on.
- Purpose: delivering the controller's coaching services to its clients.
- Retention: for the life of the subscription, then 30 days, then deletion, except billing records and anything the law requires us to keep. A client can delete their own account and data at any time.
- Sub-processor transfers: as set out in Annex 3, for the purposes listed there only.
- Competent supervisory authority (EU): the authority for the EU member state where the controller is established, or, where the controller is outside the EU, the authority where its EU representative is established. For the UK, the Information Commissioner's Office.
Annex 2. Security measures
- Encryption: every connection uses TLS. Database and file storage are encrypted at rest by our hosting provider.
- Tenant isolation: row-level security in the database means one coaching business's data is never returned to another, enforced by the database itself, not just by application code.
- Access control: clients see only their own data; coaches see only their own clients; team members see only what the head coach grants. Our staff reach production data only through support tools that record who did what, and only when support requires it.
- Credentials: privileged database keys are held only in the hosting environment, never shipped in the app. Client passwords are hashed by Supabase Auth; sign-in also supports one-time codes; sessions expire.
- Backups: automated daily database backups by our hosting provider, kept in the same Australian region.
- Change control: every change runs through an automated test suite before release, and production releases are batched outside client hours.
- Monitoring: application and hosting error logs are reviewed; deployment history is retained.
- People: staff and contractors are under confidentiality obligations and lose access when they leave.
- Suppliers: sub-processors are chosen for their security certifications (SOC 2 Type II and ISO 27001 where held) and bound by written terms.
- Resilience: hosting spans multiple availability zones in Sydney, and we maintain a documented approach to restoring service from backups.
Annex 3. Sub-processors
Changes to this list are notified 30 days in advance under section 3.
- Supabase, Inc. (United States company; data held on Amazon Web Services in Sydney, Australia). Database, authentication and file storage. All Client Data.
- Vercel Inc. (United States). Application hosting; server functions run in Sydney, with some requests routed through Vercel's edge network in the United States. Client Data in transit.
- Resend, Inc. (United States). Transactional email delivery. Name, email address and the content of the email.
- Apple Inc. (United States). Push notifications to iPhone and iPad. Device token and notification text.
- Google LLC, Firebase Cloud Messaging (United States). Push notifications to Android. Device token and notification text.
- Anthropic, PBC (United States). AI drafting features, only when the controller or a client uses one. The information needed for that feature only. Not used to train models. Cycle data is never sent.
- Stripe, Inc. (United States). Payment processing for the controller's subscription and, where the controller takes client payments through the app, for those payments. Name, email and payment details.
Annex 4. Country-specific terms
- Australia: we are an APP entity under the Privacy Act 1988 and handle Client Data in line with the Australian Privacy Principles. Because we hold data in Australia, no overseas disclosure by you occurs when you use Coach Vault.
- United Kingdom: the UK GDPR and the Data Protection Act 2018 apply. Section 6 sets out the transfer terms. Complaints may go to the Information Commissioner's Office.
- European Economic Area: the GDPR applies. Section 6 sets out the transfer terms. Complaints may go to the supervisory authority in your country.
- United States: we are your service provider under the California Consumer Privacy Act as amended. We do not sell or share personal information, do not retain, use or disclose it outside the business purpose in this DPA, do not combine it with data from other sources except as the CCPA permits a service provider to, and certify that we understand these restrictions. You may take reasonable steps to stop and remediate unauthorised use. For Washington's My Health My Data Act and similar state laws, you obtain the consent those laws require for collecting and sharing consumer health data (section 5); we will not sell it or use it for geofencing. Coach Vault is not a HIPAA covered entity or business associate and does not sign business associate agreements; if your practice is a HIPAA covered entity, do not use Coach Vault for protected health information.
- Canada: the Personal Information Protection and Electronic Documents Act and equivalent provincial laws apply, including Quebec's Law 25. We provide protection comparable to that required in Canada through this DPA, and will give you the information you need for a transfer assessment. Complaints may go to the Office of the Privacy Commissioner of Canada.
- South Africa: the Protection of Personal Information Act applies. As your operator we process Client Data only with your knowledge and authorisation, treat it as confidential, secure it as section 19 requires, and notify you immediately where there are reasonable grounds to believe it has been accessed or acquired by an unauthorised person (section 22). This DPA is the agreement section 21 requires. For section 72, this DPA binds us to protections substantially similar to POPIA. Complaints may go to the Information Regulator.
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 applies (and DIFC or ADGM data-protection law where your business is registered in one of those free zones). Transfers to Australia rest on the contractual protections in this DPA and the consent you obtain under section 5.
- Indonesia: Law No. 27 of 2022 on Personal Data Protection applies. Health information is specific personal data and is processed on the explicit consent you obtain under section 5. As your processor we act on your instructions; transfers outside Indonesia rest on the protections in this DPA and that consent.
- Singapore: the Personal Data Protection Act 2012 applies. This DPA satisfies the transfer limitation obligation by binding us to a comparable standard of protection.
- New Zealand: the Privacy Act 2020 applies. This DPA provides the comparable safeguards Information Privacy Principle 12 requires.
- Anywhere else: this DPA applies, and we'll add country terms as we start serving customers there. Ask us if your regulator needs something specific.
Coach Vault Pty Ltd · ACN 697 844 705 · Mermaid Beach, Queensland, Australia · admin@getcoachvault.com