Data processing agreement

The Article 28 terms under which we process your clients' personal data on your instructions.

Updated

Roles

You are the controller. We are the processor. When you use Agonos to coach people, you decide whose data goes in, what is recorded and for how long. We process it only to provide the service and only on your documented instructions — your use of the product being the ordinary form those instructions take.

For your own account data — your name, your login, your invoices — we are the controller, and the privacy notice covers it.

This agreement forms part of the terms of service and applies automatically to every customer. No signature is required for it to bind us; if your own compliance process needs a countersigned copy, write to contact@agonos.app.

Scope of the processing

Subject matter. Providing the Agonos coaching platform.

Duration. For as long as your subscription lasts, plus the deletion window described below.

Nature and purpose. Hosting, storing, transmitting and displaying the data you enter, so that you can programme, message, track and bill the people you coach.

Categories of data subject. Your clients, and the coaches and staff you invite into your organisation.

Categories of personal data. Identity and contact details; training programmes, session logs and performance data; body measurements and progress photographs where you record them; messages between coach and client; scheduling and attendance; billing status.

Special category data. Health-related information — injuries, physical limitations, body measurements — where you choose to record it. You are responsible for having a lawful basis and an Article 9 condition for doing so, and for telling the people concerned.

Our obligations

We will:

  • process personal data only on your instructions, and tell you if we believe an instruction breaks data protection law;
  • keep it confidential, and bind everyone with access to the same duty;
  • apply the security measures described below;
  • not engage a subprocessor without the notice set out here;
  • help you respond to data subject requests, and to your obligations on security, breach notification and impact assessments;
  • delete or return the data when the service ends;
  • give you the information you reasonably need to demonstrate compliance.

Breach. If we suffer a personal data breach we will tell you without undue delay and with what we know at the time, so that you can meet your own 72-hour deadline. We will not wait until we have the full picture to make the first contact.

Subprocessors

You give general authorisation for the subprocessors below. Each is bound by terms no less protective than these.

Subprocessor Purpose Location
Supabase Database, authentication, file storage European Union (Frankfurt)
Vercel Application hosting and delivery Global edge, EU regions for compute
Stripe Payment and subscription processing EU and US
Apple (APNs) Push notification delivery to iOS devices Apple's infrastructure
Google (FCM) Push notification delivery to Android devices Google's infrastructure

Changes. We will give you at least 30 days' notice before adding or replacing a subprocessor. If you have a reasonable data protection objection, tell us within that period and we will work to resolve it; if we cannot, you may terminate the affected part of the service and be refunded the unused balance.

International transfers

Customer data is stored in the European Union. Where a subprocessor processes data outside the EEA, the transfer is covered by the European Commission's standard contractual clauses together with that subprocessor's supplementary technical and organisational measures.

Push notifications are the routine exception: the title and body of an alert pass through Apple's or Google's infrastructure to reach a device, which is the only delivery route either platform offers. We keep the content of notifications minimal for exactly this reason.

Security measures

  • Encryption of data in transit, and at rest by our hosting provider.
  • Row-level security on every table, enforcing per-organisation isolation inside the database rather than in application code.
  • Access to production data restricted to the personnel who need it.
  • Authentication with hashed credentials; no readable password storage.
  • Backups, and a documented route to restore from them.
  • Change control through version-controlled deployments.

We do not currently hold ISO 27001 or SOC 2 certification, and we would rather say so than imply otherwise.

Assistance and audit

Data subject requests. Requests from your clients come to you first, because you are their controller. The product gives you the means to export, correct and delete their records yourself. Where you need more, contact@agonos.app will get it.

Audit. We will answer reasonable written questions about this agreement and provide the documentation we hold. Where that is genuinely insufficient for a legal obligation you are under, we will agree an audit on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise.

Deletion and return

You can export your data at any time while the account is live. On termination we delete customer data after a short recovery window, except where a legal obligation — accounting records, principally — requires us to keep something for longer. Ask and we will confirm what remains and why.

Liability and changes

The liability provisions of the terms of service apply to this agreement. Where this agreement and the terms conflict on data protection, this agreement wins.

We may update this page to reflect a change in the service or in the law. The date at the top tells you which version you are reading, and subprocessor changes follow the notice period above.

Questions: contact@agonos.app.

Get your evenings back.

Start for free