Annex: Data Processing Agreement (AVV / DPA)
Annex to the Coach Terms of Service, referred to in § 9.1 of those Coach Terms.
Agreement on processing of personal data on behalf of a controller pursuant to Art. 28 GDPR
Last updated: 16 August 2026
Contract language: English. A German translation may be provided for information only; the English version prevails (§ 14.5).
Parties
Controller ("Coach", "you")
The natural or legal person who has registered a Coach account on the Platform under the Coach Terms. Your identity, address and contact details are those stated in your Coach account, which you undertake to keep current.
Processor ("Tremo", "we", "us")
Mucha Solutions UG (haftungsbeschränkt), trading as Tremo
Zwillingstrasse 4, 80807 München, Germany
Amtsgericht München, HRB 315278
Represented by the Geschäftsführer: Adrian Malucha
Email: muchasolutions.info@gmail.com · Phone: +420 601 359 752
Data subjects are the Coach's Clients, and any other individuals whose personal data the Coach enters into the Platform.
1. Subject matter, roles, and scope
1.1 Roles. For the personal data described in § 2 (the "Coach Data"), the Coach is the controller within the meaning of Art. 4(7) GDPR and Tremo is the processor within the meaning of Art. 4(8) GDPR. This mirrors Coach Terms § 9.1, Client Terms § 10.2 and Privacy Policy § 1.
1.2 Data subjects. The Clients of the Coach are the data subjects. Where the Coach enters data about third parties (for example an emergency contact or the legal guardian of a minor Client), those persons are data subjects likewise.
1.3 What this DPA does not cover. Tremo is an independent controller for the account, registration, booking, billing, security, diagnostic and platform-operation data it processes to run the Platform, and for its own legal obligations (including bookkeeping and DAC7 / Plattformen-Steuertransparenzgesetz reporting under Coach Terms § 8). That processing is governed by the Privacy Policy, not by this DPA. Each party is separately responsible for its own controller processing; this DPA does not create joint controllership under Art. 26 GDPR.
1.4 Payments. Payments are processed via Stripe Connect using Direct Charges (Coach Terms § 5.1). Stripe acts as an independent controller for parts of the payment flow, under the Coach's own Stripe Connected Account Agreement. Payment data is not Coach Data under this DPA and Tremo is not the Coach's processor for it.
1.5 Conclusion. This DPA is concluded in electronic form (Art. 28(9) GDPR) when the Coach accepts the Coach Terms, and forms an integral part of them. It takes effect on that date and runs for as long as the Coach Terms are in force (§ 14.1).
1.6 Precedence. Where a provision of this DPA conflicts with the Coach Terms on a matter of data protection, this DPA prevails. On all other matters — in particular fees, liability, indemnity and termination — the Coach Terms prevail. Neither document limits mandatory rights of data subjects or the powers of supervisory authorities.
2. Nature, purpose, duration, categories
2.1 Subject matter and nature of processing. Hosting, storage, structuring, retrieval, display, transmission between the Coach and their connected Clients, backup, and erasure of the Coach Data, by automated means, within the Tremo mobile app and tremocoach.com (the "Platform").
2.2 Purpose. Solely to make the Platform's coaching functionality available to the Coach so that the Coach can deliver coaching services to their Clients. Tremo does not process Coach Data for its own purposes, and in particular does not use it for profiling, advertising, resale, or for training artificial-intelligence or machine-learning models.
2.3 Duration. For the term of the Coach Terms, plus the deletion periods in § 10.
2.4 Categories of data subjects.
- Clients of the Coach, connected to the Coach via referral code;
- where entered by the Coach: legal guardians, emergency contacts, or other third parties named by the Coach.
2.5 Categories of personal data.
- identification and contact data of Clients as shown to the Coach (name, profile photo, email address, date of birth);
- training records, session notes, plans, and free-text comments created by the Coach about a Client;
- documents and files the Coach uploads and shares with a Client;
- body metrics and training-related figures (weight, height and similar);
- attendance, credits, and session history within the Coach–Client relationship;
- messages exchanged between the Coach and the Client through the Platform.
2.6 Special categories (Art. 9 GDPR). Body metrics, health notes, injury or rehabilitation information and similar entries may constitute health data under Art. 9 GDPR. The Coach must ensure a valid Art. 9(2) condition — as a rule the data subject's explicit consent under Art. 9(2)(a) — before entering such data, and must be able to evidence it. Tremo applies the measures in Appendix 1 to such data but is not responsible for the Coach's legal basis.
2.7 Minors. Where a Client is under 16, the Coach must confirm that verifiable parental consent under Art. 8(1) GDPR has been obtained before that Client's data is processed through the Platform (Privacy Policy § 10).
3. Instructions of the controller
3.1 Tremo processes Coach Data only on documented instructions from the Coach, including as regards transfers to a third country, unless required to do so by Union or Member State law to which Tremo is subject. In that case Tremo informs the Coach of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).
3.2 Initial instruction. The Coach Terms, this DPA including its Appendices, and the Coach's use of the ordinary functions of the Platform (creating, editing, sharing, exporting and deleting records) constitute the Coach's complete initial instruction.
3.3 Further instructions. Individual instructions beyond § 3.2 must be given in text form to muchasolutions.info@gmail.com. Tremo will confirm receipt. Instructions that exceed the technical functionality of the Platform, or that require development effort, may be declined or made subject to a separate agreement on cost; Tremo will say so without undue delay and state the reason.
3.4 Unlawful instructions. If Tremo is of the opinion that an instruction infringes the GDPR or other Union or Member State data protection provisions, it will inform the Coach without undue delay (Art. 28(3), second subparagraph, GDPR) and may suspend execution of that instruction until it is confirmed or amended.
3.5 No own use. Tremo will not copy, extract, or use Coach Data outside the purpose in § 2.2. Aggregated, fully anonymised statistics from which no data subject can be re-identified are not personal data and are not restricted by this section.
4. Confidentiality
4.1 Tremo ensures that persons authorised to process Coach Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). The obligation survives the end of their engagement.
4.2 Access to Coach Data is limited to personnel and sub-processors who need it to perform the services, on a least-privilege basis, and is logged.
4.3 Where the Coach is subject to a professional secrecy obligation under § 203 StGB, the Coach must inform Tremo before entering data covered by it, so that the requirements of § 203(4) StGB can be arranged.
5. Security of processing (Art. 32 GDPR)
5.1 Tremo implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in force at the date of this DPA are set out in Appendix 1.
5.2 The measures are subject to technical progress. Tremo may change them, provided the agreed level of protection is not reduced. Material changes will be documented and, on request, communicated to the Coach.
5.3 The Coach is responsible for the security of its own devices, credentials and end of the connection, and must not share Coach account access with third parties.
6. Sub-processors (Art. 28(2), (4) GDPR)
6.1 General authorisation. The Coach grants Tremo general written authorisation to engage sub-processors. The sub-processors approved at the date of this DPA are listed in Appendix 2.
6.2 Notice of changes. Tremo will inform the Coach of any intended addition or replacement of a sub-processor at least 30 days in advance, by email or in-app notice.
6.3 Objection. The Coach may object to a change on reasonable data-protection grounds within 14 days of the notice. If the parties cannot agree on a solution, the Coach may terminate the Coach Terms with effect from the date the change takes effect, in accordance with Coach Terms § 12.1. No further claim arises from the objection.
6.4 Flow-down. Tremo imposes on each sub-processor, by contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Coach for the performance of the sub-processor's obligations (Art. 28(4) GDPR).
6.5 Not sub-processing. Services obtained as ancillary services without access to Coach Data (for example telecommunications, postal services, maintenance of hardware not containing Coach Data), and services where the provider acts as an independent controller (in particular Stripe under § 1.4), are not sub-processing within the meaning of this section.
7. Third-country transfers
7.1 Coach Data is stored on infrastructure located in the European Union (Ireland).
7.2 Where a sub-processor listed in Appendix 2 processes personal data outside the EU/EEA, the transfer is safeguarded by the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with, where required, supplementary measures, and/or by an adequacy decision including the EU–US Data Privacy Framework.
7.3 Tremo will not transfer Coach Data to a third country other than under § 7.2 without the Coach's prior instruction.
8. Assistance to the controller
8.1 Data subject rights (Art. 28(3)(e) GDPR). Taking into account the nature of the processing, Tremo assists the Coach by appropriate technical and organisational measures, insofar as possible, in fulfilling the Coach's obligation to respond to requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). The Platform's export, edit and delete functions are the primary means of that assistance.
8.2 Requests received by Tremo. Where a data subject addresses a request concerning Coach Data to Tremo directly, Tremo will not respond on the merits but will forward the request to the Coach without undue delay and inform the data subject that the Coach is the controller. This matches the statement to Clients in Client Terms § 10.2.
8.3 Art. 32–36 GDPR (Art. 28(3)(f)). Tremo assists the Coach, taking into account the nature of processing and the information available to it, in ensuring compliance with the obligations on security of processing, personal data breach notification, data protection impact assessments, and prior consultation of the supervisory authority.
8.4 Cost. Assistance is free of charge where it can be delivered through the standard functions of the Platform or where the cause lies within Tremo's sphere. For assistance going materially beyond that, Tremo may charge a reasonable fee based on time spent, notified in advance.
9. Personal data breaches
9.1 Tremo notifies the Coach without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Coach Data (Art. 33(2) GDPR).
9.2 The notification will describe, as far as known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the information cannot be provided at once, it will be provided in phases without undue further delay.
9.3 Tremo takes reasonable steps to contain and remediate the breach, and documents it.
9.4 Notification to authorities and data subjects is the Coach's responsibility as controller (Art. 33(1), Art. 34 GDPR). Tremo will not notify a supervisory authority or data subjects on the Coach's behalf unless legally obliged to, or unless the Coach so instructs in text form.
10. Deletion and return of data (Art. 28(3)(g) GDPR)
10.1 Coach's choice. On termination of the Coach Terms, the Coach may choose whether Tremo returns the Coach Data (as a machine-readable export) or deletes it. The choice must be communicated in text form before termination takes effect, or within 30 days thereafter.
10.2 Default. If no choice is made within that period, Tremo deletes the Coach Data and existing copies.
10.3 Timing. Deletion is carried out without undue delay and in any event within 90 days of the end of the period in § 10.1. Data held in encrypted backups is deleted when the backup expires in the ordinary backup cycle, and remains subject to §§ 4 and 5 until then.
10.4 Legal retention. Tremo retains Coach Data where Union or Member State law requires storage, in particular under German commercial and tax law (§ 147 AO, § 257 HGB), consistent with Coach Terms § 12.5 and Privacy Policy § 8. Data retained on that basis is blocked from ordinary processing and used only for the purpose requiring its retention.
10.5 Client-side deletion. A Client's exercise of their own rights against Tremo as controller (for example deletion of their Tremo account) may render Coach Data relating to that Client inaccessible or incomplete. The Coach is responsible for keeping its own records where it needs them for its own legal purposes, as also noted in Coach Terms § 11.3.
10.6 On request, Tremo confirms deletion in text form.
11. Audit rights (Art. 28(3)(h) GDPR)
11.1 Tremo makes available to the Coach all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Coach or an auditor mandated by the Coach.
11.2 Primary means. Tremo satisfies this obligation in the first instance by providing this DPA with its Appendices, its records of processing insofar as they relate to Coach Data, and any current certifications, audit reports or security documentation of Tremo or its sub-processors.
11.3 On-site inspection. Where that information is not sufficient, the Coach may carry out an inspection during normal business hours, with at least 30 days' prior notice in text form, not more than once per calendar year (unless there is a specific indication of a breach or an authority so requires), without disrupting operations, and subject to the auditor being bound to confidentiality and not being a competitor of Tremo.
11.4 The Coach bears its own costs of an inspection. Tremo may charge a reasonable fee for time spent supporting inspections beyond the first day per year, unless the inspection reveals a material breach by Tremo.
12. Obligations and warranties of the Coach
12.1 The Coach is responsible for the lawfulness of the processing it instructs, including the legal basis under Art. 6 and, where applicable, Art. 9 GDPR (§ 2.6), and for informing its Clients under Art. 13 and 14 GDPR about the Coach's own processing.
12.2 The Coach uses Client data only for the purpose of delivering its coaching services and does not export Client contact data for unrelated marketing, in accordance with Coach Terms §§ 9.2 and 9.3.
12.3 The Coach maintains its own record of processing activities where required (Art. 30(1) GDPR), appoints a data protection officer where required, and is responsible for any data protection impact assessment relating to its own processing.
12.4 The Coach must not enter data into free-text fields that is manifestly excessive or irrelevant to the coaching relationship (data minimisation, Art. 5(1)(c) GDPR).
13. Liability
13.1 Liability between the parties is governed by Coach Terms § 13, which applies to this DPA in full, including the indemnity in § 13.5 in respect of claims arising from the Coach's own processing or instructions.
13.2 Art. 82 GDPR is unaffected: liability towards data subjects and the internal apportionment between controller and processor follow Art. 82(2) to (5) GDPR and cannot be limited by this DPA to the detriment of a data subject.
13.3 Fines imposed on one party under Art. 83 GDPR are borne by that party, save for a right of recourse where the other party's culpable breach of this DPA caused them.
14. Final provisions
14.1 Term. This DPA begins with the Coach Terms and ends when they end, except that §§ 4, 10, 11 and 13 survive to the extent necessary.
14.2 Amendments. Tremo may amend this DPA in accordance with the change procedure in Coach Terms § 14, and will additionally amend it without a right of objection where mandatory law, a supervisory authority decision, or a new set of standard contractual clauses so requires. Appendices 1 and 2 may be updated under §§ 5.2 and 6.2 respectively.
14.3 Form. Amendments require text form. This also applies to any waiver of the text-form requirement.
14.4 Severability. If any provision is or becomes invalid, the validity of the remainder is unaffected. The invalid provision is replaced by one that comes closest to its economic and data-protection purpose.
14.5 Language. The contract language is English; a German translation is for information only and the English version prevails, except where mandatory law requires otherwise (Coach Terms § 15.1).
14.6 Governing law. German law applies, in accordance with Coach Terms § 15.2, without prejudice to mandatory provisions of the GDPR.
Appendix 1 — Technical and Organisational Measures (Art. 32 GDPR)
1.1 Pseudonymisation and encryption (Art. 32(1)(a))
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all connections between app/browser, API and database; HSTS on tremocoach.com |
| Encryption at rest | AES-256 encryption of database volumes and object storage at the hosting provider |
| Credential storage | Email sign-in by one-time code or by password, at the user's choice. Authentication is performed by the authentication service of the backend sub-processor (Appendix 2, No. 1), which stores passwords only as salted cryptographic hashes and never in plain text. Tremo operates no separate credential store and has no access to plain-text passwords. Session tokens are short-lived and rotated |
| Secrets management | Production API keys and service credentials are held in the provider's encrypted secret store and excluded from source control; no production credential is contained in the application source code |
| Pseudonymisation | Internal identifiers (UUIDs) are the primary key for all Coach Data records; diagnostic and error reports reference these identifiers rather than names, and personal data is not written to logs beyond what is necessary to diagnose the event |
1.2 Confidentiality — access control
| Measure | Implementation |
|---|---|
| Physical access | Data centres operated by the hosting provider (ISO 27001 / SOC 2 certified); no Tremo-operated server rooms |
| System access | Individual named accounts; multi-factor authentication enforced on all administrative accounts (hosting, database, email, code repository, app stores) |
| Data access | Row Level Security in the database: a Coach can access only records of Clients connected to that Coach; a Client can access only their own records |
| Least privilege | Production access limited to personnel who require it; separation of production and development environments; no production data in test environments |
| Access logging | Administrative and API access to the production database and infrastructure is logged by the hosting sub-processor and is reviewable for that provider's retention period. Tremo does not operate a separate application-level audit trail of record-by-record access |
| Offboarding | Access revoked without undue delay at the end of an engagement |
| Devices | Full-disk encryption, screen lock and current OS/security updates on all devices used to access production systems |
1.3 Integrity — transfer and input control
| Measure | Implementation |
|---|---|
| Transfer control | All data transfer over encrypted channels; no transfer of Coach Data on portable media |
| Input control | Creation and modification timestamps are recorded for Coach Data records; every write is attributable to an authenticated account because the database access rules described under "Data access" permit writes only in the name of the authenticated user |
| Change control | Version-controlled source code with a complete, documented change history; changes are reviewed before release to production and are rolled out in stages through internal and beta distribution channels (TestFlight, Google Play internal testing) before general release |
| Separation control | Logical multi-tenant separation enforced at database level per Coach and per Coach–Client relationship |
1.4 Availability and resilience (Art. 32(1)(b), (c))
| Measure | Implementation |
|---|---|
| Backups | Automated daily backups, encrypted, retained for a defined period; restore procedure tested periodically |
| Redundancy | Managed, redundant infrastructure at the hosting provider |
| Monitoring | Availability and error monitoring at the hosting provider; application crash, exception and performance reporting through a dedicated error-tracking sub-processor (Appendix 2, No. 7) with alerting; in-app error boundaries capture unhandled exceptions |
| Business continuity | Documented recovery procedure with defined recovery point and recovery time objectives |
| Protection against loss | Deletion of Coach Data by a Coach subject to confirmation; soft-delete window where technically implemented |
1.5 Regular testing, assessment and evaluation (Art. 32(1)(d))
| Measure | Implementation |
|---|---|
| Review cycle | Review of these measures at least annually and on any material change to the Platform |
| Dependency management | Automated dependency vulnerability scanning; security patches applied without undue delay by severity |
| Incident process | Documented personal data breach process aligned with § 9 of this DPA, including a 48-hour notification path |
| Sub-processor review | Data protection and security posture of sub-processors reviewed before engagement and periodically thereafter |
| Records | Record of processing activities under Art. 30(2) GDPR maintained for processing carried out on behalf of Coaches |
1.6 Data protection by design and by default (Art. 25 GDPR)
| Measure | Implementation |
|---|---|
| Minimisation | Only fields required for the coaching function are mandatory; body metrics and similar are optional |
| Default settings | Client data visible by default only to the connected Coach and the Client |
| Consent | Fields capable of containing special-category data — in particular body metrics, health notes and injury or rehabilitation information — are never mandatory. The user decides in each case whether to enter them and may skip them entirely without any loss of function. Securing, obtaining and evidencing the condition under Art. 9(2) GDPR for such data is the Coach's responsibility under §§ 2.6 and 12.1 |
| Deletion and export | Account deletion and a machine-readable export of the user's own data are available as self-service functions in the Platform; an export can additionally be requested at the contact address in § 3.3 |
Appendix 2 — Approved Sub-processors
Sub-processors engaged by Tremo at the date stated above, authorised under § 6.1 of this DPA. Changes are notified under § 6.2.
| # | Sub-processor (legal entity) | Registered seat | Service / processing activity | Categories of data | Processing location | Transfer mechanism (outside EU/EEA) | Provider DPA |
|---|---|---|---|---|---|---|---|
| 1 | Supabase Inc. | USA (infrastructure in EU) | Backend, authentication, database, file storage | All Coach Data (§ 2.5) | EU — Ireland | n/a for hosting; SCC for support access | https://supabase.com/legal/dpa |
| 2 | Amazon Web Services EMEA SARL | Luxembourg | Underlying cloud infrastructure for the backend provider | All Coach Data (encrypted at rest) | EU — Ireland | n/a | https://aws.amazon.com/compliance/gdpr-center/ |
| 3 | Resend (Plus Five Five, Inc.) | USA | Transactional and system email delivery | Email address, name, system email content | USA | EU Standard Contractual Clauses | https://resend.com/legal/dpa |
| 4 | Vercel Inc. | USA | Hosting and CDN for tremocoach.com | Technical data, IP address, server logs | USA / global edge | SCC / EU–US Data Privacy Framework | https://vercel.com/legal/dpa |
| 5 | Apple Distribution International Ltd. / Apple Inc. | Ireland / USA | App distribution, push notification delivery, in-app diagnostics | Device identifiers, push tokens, diagnostic data | EU / USA | EU–US Data Privacy Framework / SCC | https://www.apple.com/legal/privacy/ |
| 6 | Google Ireland Ltd. / Google LLC | Ireland / USA | App distribution (Play), push notification delivery (FCM) | Device identifiers, push tokens, diagnostic data | EU / USA | EU–US Data Privacy Framework / SCC | https://business.safety.google/gdprprocessorterms/ |
| 7 | Functional Software, Inc. (trading as Sentry) | USA | Application error, crash and performance reporting | Technical and diagnostic data, device and operating system information, IP address, internal user identifier (UUID), stack traces and event breadcrumbs | EU — Frankfurt (Sentry EU data region) | EU Standard Contractual Clauses for support access from the USA | https://sentry.io/legal/dpa/ |
Not sub-processors (§ 6.5): Stripe Payments Europe, Ltd. and Stripe, Inc. act as independent controllers for the payment flow under the Coach's own Stripe Connected Account Agreement (Coach Terms § 5.2, Privacy Policy § 5). Listed here for transparency only.
Processor: Mucha Solutions UG (haftungsbeschränkt) · Zwillingstrasse 4, 80807 München, Germany · Amtsgericht München HRB 315278 · Geschäftsführer: Adrian Malucha · muchasolutions.info@gmail.com · +420 601 359 752. "Tremo" is a brand of Mucha Solutions UG and not a separate legal entity.