Version 1.0 — effective from 11 July 2026
This Data Processing Agreement (the "DPA") is concluded between the trainer using the DietCoach trainer panel (the "Controller") and Jacek Grecki, a natural person residing in the Netherlands and technical operator of the DietCoach application (the "Processor"). Contact: jacgre1981@gmail.com.
The DPA is concluded electronically and is accepted by the trainer during registration for the trainer panel, before any client data is entered. It forms an integral part of the Terms of Service.
With respect to the trainer's own account data — including authentication, security and application billing — the DietCoach operator remains an independent controller, and that processing is governed by the Privacy Policy rather than this DPA.
The subject matter of this DPA is the processing by the Processor of personal data of the Controller's clients, entered by the Controller into the DietCoach trainer panel. The processing lasts for the duration of the Controller's use of the DietCoach trainer panel and ends upon termination of that use, subject to section 13.
The Processor processes the client data solely to provide the functionality of the trainer panel: managing the Controller's clients and generating personalised diet plans on the Controller's behalf and according to the parameters entered by the Controller. The Processor does not process the client data for its own purposes.
The data subjects are the clients of the Controller whose data the Controller enters into the trainer panel.
The processing covers the following categories of the clients' personal data:
This data includes special-category data concerning health within the meaning of Art. 9 GDPR. The Controller is responsible for having a valid legal basis, including the clients' explicit consent where required, for this processing.
The Processor processes the client data only on the documented instructions of the Controller, including as regards transfers of data, unless required to do otherwise by Union or Member State law. The Controller's use of the trainer panel and the acceptance of this DPA constitute such documented instructions. If the Processor is required by law to process the data otherwise, it will inform the Controller of that legal requirement before processing, unless the law prohibits such information.
The Processor ensures that persons authorised to process the client data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Taking into account the state of the art, the nature of the processing and the risks to data subjects, the Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These include encryption of data in transit and access controls restricting database access by row-level security policies scoped to the owning trainer account, so that a trainer can access only their own clients' data.
The Controller grants the Processor general authorisation to engage sub-processors for the performance of specific processing activities. The Processor maintains an up-to-date list of sub-processors in the Annex to this DPA. The Processor informs the Controller of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object. The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those set out in this DPA and remains fully liable to the Controller for the performance of the sub-processor's obligations.
Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under the GDPR.
The Processor assists the Controller in ensuring compliance with the obligations relating to the security of processing, the notification of personal data breaches, the communication of breaches to data subjects, data protection impact assessments (DPIAs) and prior consultation with the supervisory authority, taking into account the nature of the processing and the information available to the Processor.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the client data. The notification, sent to the Controller's account e-mail or to jacgre1981@gmail.com, describes the nature of the breach and the information available, so as to enable the Controller to meet its own notification obligations.
The client data is deleted when the Controller deletes it in the trainer panel or deletes their trainer account. Upon the end of the provision of processing services, the Processor deletes the client data, unless Union or Member State law requires storage of the data. Deletion of the trainer account removes the associated clients, plans, targets, check-ins and related records.
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and in Art. 28 GDPR.
The Processor allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, within a reasonable scope and frequency. Audits are conducted with reasonable prior notice, during business hours, and in a manner that does not disproportionately disrupt the Processor's operations or compromise the confidentiality of other customers' data.
Some sub-processors may process the client data outside the European Economic Area. In such cases the transfer is carried out under appropriate safeguards, such as an adequacy decision or standard contractual clauses, depending on the provider concerned.
The Processor currently engages the following sub-processors for the processing of the client data:
Lemon Squeezy acts as Merchant of Record for payments under its own terms and is not a sub-processor of the trainer's client data. Diet plans are generated by the application's own logic; no external AI provider receives the client data.
Version 1.0, effective from 11 July 2026. The Processor may update this DPA and its Annex; material changes are communicated to the Controller and take effect in accordance with the notice given.