Audunn

Data Processing Agreement

Last updated: 2026-08-19

This Data Processing Agreement ("DPA") is part of the Terms between Audunn ("Processor", "we") and the creator who signed up ("Controller", "you"). It governs our processing of your Members' personal data under the GDPR, UK GDPR, and equivalent laws.

1. Roles

You determine the purposes and means of processing your Members' personal data through the agents you configure and deploy. We act on your documented instructions, set out in the Terms, our docs, and any reasonable written instructions you give.

2. Scope and duration

We process Member personal data for the life of your account: storing and retrieving messages, generating AI responses via the AI provider you select (with your key), delivering chat history, and running the platform. Data categories include: Member email and name; message content (including any health and lifestyle information a Member enters, such as body weight, food, sleep, mood, injuries and training logs); saved facts and goals; tracker entries; synced DM content where enabled; and usage metadata. These may include special categories of personal data under Article 9, namely data concerning health, which you instruct us to process for the coaching you provide. A processing annex is at the end of this DPA.

3. Our obligations

We will: (a) process only on your documented instructions; (b) keep personnel bound by confidentiality; (c) apply appropriate technical and organizational measures (encryption at rest and in transit, access controls, encrypted keys) as required by Article 32; (d) help you respond to data-subject requests via dashboard tooling; (e) notify you without undue delay of a personal data breach and assist with your Article 33/34 duties; (f) make available the information necessary to demonstrate compliance; (g) delete or return Member data at the end of the service, unless the law requires retention; (h) **allow for and contribute to audits**, including inspections, conducted by you or an auditor you mandate. We may satisfy this by providing our current security documentation and answering reasonable written audit questions, and by an on-site inspection where legally required, on reasonable notice and subject to confidentiality.

3a. Support access

Our staff may access Controller data, including by signing in to a Member account, solely to provide support you or a Member requests, or to investigate a security or integrity issue. Such access is least-privilege, logged, visible to you, and is a processing activity authorized by these instructions.

4. Sub-processors

You give general authorization for us to use sub-processors: Anthropic (Claude AI, via your key, the default), Supabase (database/auth/storage), Vercel (hosting), Stripe (payments), Resend (email), Unipile (DM sync where enabled), Apify (content statistics where enabled), and Telegram (bot messaging where you enable it). Where you or a Member selects a non-default AI provider and supplies a key for it, that provider is also a sub-processor for your data: OpenAI (United States), Google (United States), Moonshot AI, which operates Kimi (China), and xAI (United States). Each AI call runs under the selected provider's API terms. Anthropic's and OpenAI's prohibit training on your inputs or outputs; other providers' terms differ and a free tier may be used to improve their models, so review them before enabling one. We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor and a chance to object on reasonable data-protection grounds.

5. International transfers

Where Member data is transferred from the EEA/UK/Switzerland to the US, transfers rely on Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework, executed with each sub-processor. Selecting Kimi transfers Member data to China, which has no adequacy decision; that transfer relies on Standard Contractual Clauses together with a transfer impact assessment, and as Controller you decide whether to make it.

6. Data-subject rights

We give you dashboard tooling to export a Member's data, delete a Member and their data, and act on correction requests.

7. Security measures

TLS/HTTPS for all connections; AES-256-GCM encryption at rest for keys and sensitive fields; password hashing via Supabase Auth; encrypted database via Supabase; least-privilege, logged support access.

8. Breach notification

We will notify you within 72 hours of becoming aware of a personal data breach affecting Member data, describing the breach, the data affected, likely consequences, and our response.

9. Your responsibilities

You must have a lawful basis to process Member data, give them a privacy notice, obtain any required consent, including explicit consent for health or other special-category data, include the AI disclosure required by the EU AI Act, disclose in your own privacy notice any non-default AI provider you select and where it processes data, and comply with the privacy laws that apply where your Members live.

10. Termination

This DPA ends when the Terms end. On termination we delete Member personal data within 30 days, except where the law requires retention.

11. Conflict

If this DPA conflicts with the Terms about processing Member personal data, this DPA prevails. Liability is subject to the limits in the Terms.

Annex: details of processing

By accepting the Terms at signup, you accept this DPA.

Terms of ServicePrivacy PolicyData Processing AgreementCoach Guidance: collecting client data safely