practice.coach
How it worksPricingAboutContact
Log inStart free
Legal

Data Processing Agreement (DPA)

Effective date: June 11, 2026

This Data Processing Agreement (the "DPA") governs the processing of personal data under Article 28 of Regulation (EU) 2016/679 (GDPR) where you upload personal data about your real coaching clients or other third parties to the Practice.coach platform. This DPA forms part of the Terms of Service and the Privacy Policy and takes effect when you begin using the platform for such processing.

1. Parties and Roles

Controller: you, the platform user, who determines the purposes and means of processing your clients' data.

Processor: MMXXV Labs s.r.o., Company ID (IČO) 11945320, registered office at Hasičská 930/53, Hrabůvka, 700 30 Ostrava, Czech Republic, registered in the Regional Court in Ostrava, Section C, Insert 87316.

With respect to your own account and user data we act as an independent controller — that is governed by the Privacy Policy, not this DPA.

2. Subject Matter, Duration, Nature and Purpose

We process personal data solely to provide the platform under the Terms of Service — in particular storing and displaying transcripts and notes, generating AI evaluations, and maintaining session history. Processing lasts for the duration of your account and ends with deletion of data under Section 10.

3. Categories of Data Subjects and Personal Data

Data subjects: your coaching clients and other individuals referenced in uploaded content.

Categories of data: identification and contact details, coaching session content (transcripts, notes, evaluations), and potentially special categories of data (e.g. health data) if you choose to upload them. You are responsible for the lawfulness of uploading special categories of data.

4. Our Obligations as Processor

  • We process data only on your documented instructions (including for international transfers), unless required otherwise by law.
  • We ensure persons authorized to process the data are bound by confidentiality.
  • We implement appropriate technical and organizational measures under Article 32 GDPR (see Section 7).
  • We assist you in fulfilling obligations to data subjects and in ensuring security, breach notification, and impact assessments (Articles 32–36 GDPR).
  • On termination of the service we delete or return the data per Section 10.
  • We make available the information necessary to demonstrate compliance with these obligations.

5. Sub-processors

You give us general authorization to engage the sub-processors listed below. We will inform you of any intended change at least 14 days in advance and give you the opportunity to object.

  • Supabase — database and file storage
  • Vercel — application hosting
  • Google (Gemini API) — AI generation and evaluation of content
  • xAI — voice features (text-to-speech and speech transcription)
  • Stripe — payment processing (billing data only)
  • Resend — transactional email delivery

We impose on each sub-processor the same data protection obligations as set out in this DPA.

6. International Transfers

Where a sub-processor processes data outside the EEA (e.g. in the United States), the transfer is safeguarded by the EU Standard Contractual Clauses and, where the sub-processor is certified, the EU–US Data Privacy Framework.

7. Technical and Organizational Measures

  • Encryption in transit (TLS/HTTPS) and at rest
  • Access control on a need-to-know basis and user authentication
  • Logical data isolation between accounts (server-side ownership checks)
  • Regular backups and vulnerability monitoring

8. Personal Data Breach

We will notify you of a personal data breach without undue delay after becoming aware of it and provide the information necessary for you to meet your notification obligations to the supervisory authority.

9. Data Subject Rights

We assist you, by appropriate technical and organizational measures, in responding to data subject requests (access, rectification, erasure, portability, objection). If we receive such a request directly, we will forward it to you.

10. Deletion or Return of Data

On termination of the service — at the latest within 30 days of account closure — we will delete the data unless retention is required by law. On request, we will let you export your data before deletion.

11. Audits and Information

On request we will provide the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits conducted by you or a mandated auditor, to a reasonable extent and with reasonable notice.

12. Liability and Governing Law

Liability is subject to the limitations set out in the Terms of Service. This DPA is governed by the laws of the Czech Republic. In the event of a conflict with the Terms of Service on matters of personal data processing, this DPA prevails.

Contact: privacy@mmxxvlabs.io

practice.coach

Where you grow as a coach.

·
Product
  • How it works
  • Session reflection
  • Practice with an AI client
  • Pricing
  • What's new
Company
  • About
  • Contact
  • Blog
  • Privacy & data protection
  • Terms of Service
practice.coach — built in Ostrava !!!© 2026 MMXXV Labs