The Mindful Space: Coaching HubLegal
Data Processing Addendum
Last updated: 4 August 2026
1. When this addendum applies
This addendum forms part of the Terms & Conditions between you (the "Coach") and The Mindful Narrative ("we", "us"). It applies whenever you use The Mindful Space: Coaching Hub (the "Service") to record or process personal data about your clients. It takes effect automatically when you create a coach account — no signature is required.
2. Roles of the parties
- For the content you create about your clients — coaching notes and session records, goals, metrics, workout and nutrition plans, progress photos, agreements, feedback and invoices — you are the controller and we are your processor. You decide what you record, why, and for how long, and you are responsible for having a lawful basis to do so.
- For the data we need in order to run the Service itself — your account, your subscription, security logs, support requests and platform-level communications — we are the controller, as described in our Privacy Notice.
- Clients' private reflections are visible only to the client who wrote them and are excluded from every coach-facing view, export and analytics surface. Neither you nor we use them for any other purpose.
3. Our obligations as processor
- Instructions. We process client personal data only to provide the Service to you, in line with these terms, and as required by law.
- Confidentiality. Personnel with access are bound by confidentiality obligations and access is limited to those who need it.
- Security. We maintain appropriate technical and organisational measures, including encryption in transit, row-level database access controls scoped to each coach–client relationship, encrypted storage of third-party access tokens, and audit logging of administrator actions.
- Sub-processors. We use the sub-processors listed in section 6 and impose equivalent data protection obligations on them. We will give reasonable notice through the Service before adding a new sub-processor that materially affects client data.
- Data subject requests. If a client contacts us directly about data you control, we will refer them to you and assist you in responding. The Service also gives every user a self-service data export and account deletion.
- Assistance. We will help you, so far as reasonably possible, with data protection impact assessments and with security incident handling.
- Breach notification. We will notify you without undue delay after becoming aware of a personal data breach affecting your client data, with the information you need to meet your own reporting duties.
- Deletion and return. Deleting your coach account removes your workspace content from the Service, subject to short-lived backups and to records we must retain by law.
- Audit. On reasonable written request, and no more than once a year, we will provide the information you need to verify our compliance with this addendum.
4. Your obligations as controller
- Give your clients your own privacy information, explaining what you record about them, why, and for how long.
- Ensure you have a lawful basis for the data you record, including an appropriate condition — normally explicit consent — for health-related information such as body metrics, nutrition data, injury notes and progress photos.
- Record only what you need for coaching, and delete what you no longer need.
- Respond to your clients' access, correction, deletion and portability requests. You can use the client's own in-app export, or ask us for help.
- Keep your credentials secure and remove client links when a coaching relationship ends.
5. When a client deletes their account
A client can delete their own account at any time. This erases their profile, messages, reflections, goals, metrics, plans, photos and appointments. Records you need for your own legal and accounting obligations — invoices, credit notes, memberships, delivered-session records and signed agreements — are retained in anonymised form: the client's name is replaced with "Deleted client" and signature, IP and device details are removed. You remain responsible for retaining or deleting those records in line with your own obligations.
6. Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase (hosting, database, authentication, file storage) | Stores and processes all workspace data | EU / UK |
| Cloudflare (application hosting and delivery) | Serves the application and routes requests | Global edge |
| Resend / Lovable email delivery | Sends transactional and notification emails | EU / US |
| Paddle.com Market Ltd | Merchant of Record for coach subscriptions, tax and invoicing | UK / EU / US |
| Stripe | Optional card payments on coach-issued client invoices (independent controller) | EU / US |
| Google (Calendar API, Google sign-in) | Optional calendar sync and social sign-in | EU / US |
| Web push services (Apple, Google, Mozilla) | Delivers browser push notifications where enabled | Global |
7. International transfers
Where a sub-processor processes personal data outside the UK/EEA, we rely on appropriate safeguards such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or an adequacy decision.
8. Duration and precedence
This addendum lasts as long as we process client personal data for you. If it conflicts with the Terms & Conditions on the processing of client personal data, this addendum prevails.