Data Processing Agreement
Version 2026-09-27
Roles
For athlete training data, the organisation is controller and the Bastyra operator is processor. For Bastyra accounts, billing, fraud prevention and support, each party acts as described in the Privacy Policy.
Instructions and purpose
Bastyra processes athlete data only to host, secure, support and provide the contracted service, on documented instructions expressed through authorised use of the application.
Confidentiality and security
Access is limited to authorised persons under confidentiality duties. Measures include tenant isolation, least privilege, encrypted transport, credential separation, monitoring, backups and periodic testing.
Subprocessors
The organisation authorises Supabase, Vercel, Stripe, Sentry, OpenAI when IA Coach is used, and necessary push-delivery infrastructure. Bastyra remains responsible for processor obligations and will give notice of material subprocessor changes.
Assistance
Bastyra will reasonably assist with data-subject requests, security incidents, impact assessments and regulator enquiries. The organisation remains responsible for lawful collection, notices, accuracy and its users.
Deletion and return
On termination, the organisation may request an export during the communicated window. Data is then deleted or anonymised unless law requires retention; backup copies expire under the backup schedule.
Audit
Bastyra will provide information reasonably necessary to demonstrate Article 28 GDPR compliance. Audits must protect other customers, security and confidentiality and be proportionate.