Legal
Data Processing Agreement
Version 1.0 · 7 October 2026 · current version
Two hosting regions in Annex 1 are being confirmed. This version applies once they are filled in.
Parties: the Customer (controller) and Valesco Ventures GmbH, Am Hochwald 5, 82319 Starnberg, Germany (processor), for the service CoachMyDeal.
1. Subject, duration, nature and purpose
1.1 The processor processes personal data on behalf of the controller to provide CoachMyDeal under the Terms of Service: storing deals, contacts and coaching conversations, generating coaching answers, summaries and forecasts with AI, and support.
1.2 Duration: as long as the main contract runs, plus the deletion periods in section 9.
2. Data and data subjects
- Data subjects: the Customer's users (sellers, managers, admins); contacts at the Customer's own customers and prospects, competitors' staff and other people named in deals.
- Data: names, job titles, business contact details, roles in a buying decision, notes and statements about them and their organisations, coaching conversations, usage logs.
- No special categories (Art. 9 GDPR) are intended; the Terms of Service forbid entering them.
3. Instructions
3.1 The processor processes the data only on documented instructions of the controller — given by these terms, the Terms of Service and the use of the Service's features — unless EU or member-state law requires otherwise (then the processor informs the controller beforehand where the law allows).
3.2 The processor informs the controller if it believes an instruction infringes data-protection law.
4. Confidentiality
Everyone at the processor with access to the data is bound to confidentiality.
5. Security
The processor takes the technical and organisational measures in Annex 2 (Art. 32 GDPR) and may adapt them, provided the level of protection is not reduced.
6. Sub-processors
6.1 The controller authorises the sub-processors in Annex 1.
6.2 The processor informs the controller of an intended new or replaced sub-processor at least 30 days in advance by email or in the app. The controller may object on reasonable data-protection grounds; if no solution is found, the controller may terminate the affected service at the time of the change.
6.3 The processor binds each sub-processor to the same data-protection obligations by contract and remains liable for them.
7. Transfers outside the EU/EEA
Some sub-processors are based in or access data from the USA. Transfers are based on the EU-US Data Privacy Framework where the recipient is certified, otherwise on the EU Standard Contractual Clauses, with supplementary measures where needed (Annex 1).
8. Assistance, breaches, audits
8.1 The processor helps the controller to answer data subjects' requests (access, correction, deletion, export) — mainly through the Service's own features — and with security, breach notification, impact assessments and prior consultation, as far as it concerns the processing.
8.2 The processor notifies the controller without undue delay, at the latest within 48 hours after becoming aware of a personal-data breach, with the information then available.
8.3 The processor makes available the information needed to show compliance with this agreement. Audits, including inspections, by the controller or an auditor bound to confidentiality are possible with reasonable notice, normally once a year, during business hours; the processor may first answer with documents or certifications. Each party bears its own costs, unless the audit reveals a material breach.
9. End of processing
After the main contract ends, the processor deletes the personal data (after the export period of 30 days in the Terms of Service), including copies, within a further 30 days, and backups when they expire within 30 days, unless the law requires storage. On request, deletion is confirmed in writing (email).
10. Liability and precedence
Liability follows Art. 82 GDPR and the limits of the Terms of Service, as far as legally permitted. In case of conflict, this agreement takes precedence over the Terms of Service on data protection.
---
Annex 1 — Sub-processors
| Sub-processor | Purpose | Location of processing | Transfer basis |
|---|---|---|---|
| Supabase, Inc. | database, authentication, file storage | being confirmed (the region of the production database) | DPF / SCCs (company in the USA) |
| Vercel Inc. | hosting of the web application | being confirmed (the region of the application's servers); global network for delivery | DPF / SCCs |
| Anthropic, PBC | AI model that generates coaching answers, summaries and analysis | USA | DPF / SCCs; under Anthropic's commercial terms, inputs and outputs are not used for training and are kept for up to 30 days (zero data retention available on request, not for every model) |
| Stripe Payments Europe Ltd | payment processing and invoicing — billing contacts and payment data only | Ireland / EU; Stripe, Inc. (USA) for some processing | DPF / SCCs; Stripe acts as processor for billing and as independent controller for fraud prevention and legal duties |
| IONOS SE | email (info@coachmydeal.com) | Germany | EU |
| (sign-in and service emails are sent through Supabase, above; an own email sender will be added here with 30 days' notice) |
Annex 2 — Technical and organisational measures (summary)
- Access control: each user sees only their own conversations; managers only their team's summaries; access rules enforced in the database (row-level security); admin access to production only for the processor's managing director, with two-factor authentication.
- Encryption: in transit (TLS) and at rest (provider encryption of database and storage).
- Separation: each customer's data separated by organisation in the database; test systems use no customer data.
- Availability: daily backups with point-in-time restore; hosting providers with redundant infrastructure.
- Keys and secrets: never stored in code; production keys held only by the managing director.
- AI calls: only the data needed for the answer is sent; spending limit on the AI account; logs without content where possible.
- Payment data: card and bank data are entered only at the payment provider and never reach our systems.
- Incident handling: monitoring of errors and unusual access; breach process per section 8.2.
- Staff: confidentiality obligations; access removed on leaving.
Versions
- 1.0 · 7 October 2026 (current)
- No earlier versions.