Audunn

Data Processing Agreement

Last updated: 2026-07-16

This Data Processing Agreement ("DPA") is part of the Terms between Audunn ("Processor", "we") and the creator who signed up ("Controller", "you"). It governs our processing of your End Users' personal data under the GDPR, UK GDPR, and equivalent laws.

1. Roles

You determine the purposes and means of processing your End Users' personal data through the agents you configure and deploy. We act on your documented instructions, set out in the Terms, our docs, and any reasonable written instructions you give.

2. Scope and duration

We process End User personal data for the life of your account: storing and retrieving messages, generating AI responses via Anthropic (with your key), delivering chat history, and running the platform. Data categories: End User email, message content, optional saved facts, and usage metadata.

3. Our obligations

We will: (a) process only on your documented instructions; (b) keep personnel bound by confidentiality; (c) apply appropriate technical and organizational measures (encryption at rest and in transit, access controls, encrypted keys); (d) help you respond to data-subject requests via dashboard tooling; (e) notify you without undue delay of a personal data breach; (f) make available information needed to show compliance; (g) delete or return End User data at the end of the service, unless the law requires retention.

4. Sub-processors

You give general authorization for us to use sub-processors: Anthropic (Claude AI, via your key), Supabase (database/auth/storage), Stripe (payments), Resend (email), Vercel (hosting). Each AI call runs under Anthropic's API terms, which prohibit training on your inputs or outputs. We will tell you of any intended change and give you a chance to object. We do not use China-based AI providers.

5. International transfers

Where End User data is transferred from the EEA/UK/Switzerland to the US, transfers rely on Standard Contractual Clauses and applicable frameworks executed with each sub-processor.

6. Data-subject rights

We give you dashboard tooling to export an End User's data, delete an End User and their data, and act on correction requests.

7. Security measures

TLS/HTTPS for all connections; AES-256-GCM encryption at rest for keys and sensitive fields; password hashing via Supabase Auth; encrypted database via Supabase.

8. Breach notification

We will notify you within 72 hours of becoming aware of a personal data breach affecting End User data, describing the breach, the data affected, likely consequences, and our response.

9. Your responsibilities

You must have a lawful basis to process End User data, give them a privacy notice, collect any required consent, include the AI disclosure required by the EU AI Act, and comply with the privacy laws that apply to you.

10. Termination

This DPA ends when the Terms end. On termination we delete End User personal data within 30 days, except where the law requires retention.

11. Conflict

If this DPA conflicts with the Terms about processing End User personal data, this DPA prevails. Liability is subject to the limits in the Terms.

By accepting the Terms at signup, you accept this DPA.

Terms of ServicePrivacy PolicyData Processing Agreement
The Profitable Coach