Vulkio–trainer Data Processing Agreement

Updated 24 September 2026 · Draft under review

Legal documents
Contents
Document in preparation

Testing draft. This document is not yet active; company and operational details must be completed before activation.

1. Parties and relationship to the service

This Data Processing Agreement (“DPA”) is intended for the trainer identified in the account and contract as controller and Vulkio SRL — company in formation as processor for the described operations. Vulkio registration, address and contact: —. Trainer details and contact are those communicated to clients and recorded in the contract.

This draft applies only after the annexes are completed, the document activated and validly accepted. It is not the European Commission’s standard contractual clauses and does not itself provide an international transfer mechanism.

2. Subject, nature, purpose and duration

Vulkio provides software infrastructure for coaching records and administration. Operations include instructed collection, storage, organisation, consultation, updating, authorised disclosure, export, restriction and deletion. Their purpose is to perform functions requested by trainers for their clients, without incompatible own-purpose use.

Processing lasts for the service followed by the period necessary for documented return or deletion. Operational schedules and retention exceptions belong in the retention annex, to be completed before activation.

3. Annex A — individuals and information

Individuals include adult clients, trainers and contacts involved in service administration. Records include names, contacts, profiles and avatars, bookings, attendance, messages, forms, plans, packages, commercial records, approved materials and permission evidence.

Special-category records include health information, body measurements, limitations/injuries and progress photographs revealing health. Processing is limited to authorised functions with proportionate safeguards. Frequency is continuous or on demand depending on the function. Unnecessary information must not be uploaded.

4. Controller instructions

Instructions are documented through the contract, authorised settings, application actions and verified requests. Vulkio must not expand purposes or disclose data outside instructions, including transfers, except where required by applicable law; it informs the trainer beforehand unless prohibited.

If an instruction appears to breach data protection law, Vulkio immediately informs the trainer and requests clarification. Trainers are responsible for lawful instructions, notices, legal bases and necessary consents. These responsibilities do not diminish Vulkio’s own duties.

5. Confidentiality and authorised personnel

People with access must have duties justifying it and contractual or statutory confidentiality obligations. Access is limited to necessary records and operations, withdrawn when no longer justified and cannot be used for personal interests or unauthorised publicity.

6. Annex B — technical and organisational measures

Implemented measures include authentication, trainer–client and access checks, private sensitive-media storage, consent checks before exports/publications and decision records. Ordinary avatars are separated from progress-photograph workflows.

Before activation, staff access administration, configured encryption, recovery and backup testing, vulnerability remediation, log review and incident procedures must also be documented. Unverified parameters, frequencies and owners are —. This annex does not certify an unverified standard or measure. Measures are reviewed according to risk and must not fall below legal requirements.

7. Annex C — subprocessors and changes

The provider notice must be completed with legal entities, services, roles, processing locations and transfers before it forms the authorised contractual list. Trainers authorise relevant subprocessors in writing.

General authorisation requires advance information about additions or replacements and a meaningful opportunity to object. Notice period and resolution procedure: —, to agree before activation. Unlimited acceptance of any provider is not presumed. Vulkio imposes equivalent protection obligations and remains responsible to the trainer for subprocessor performance as required by law.

8. International transfers

The Supabase project region is Ireland, but access and other providers require separate assessment. Transfers outside the EEA require documented instructions and a verified lawful mechanism, with necessary supplementary measures. Countries, recipients, mechanisms and safeguard documents are —, to complete before relevant transfers.

9. Individual requests and assistance

Vulkio forwards requests concerning processing on the trainer’s behalf and assists through appropriate measures with access, correction, erasure, restriction and portability. It does not respond on the trainer’s behalf without authorisation, except for its own legal duties.

Taking account of the processing and information available, Vulkio assists impact assessments, authority consultations, security and notifications. Contacts and operational escalation procedures are —, to complete so the trainer can meet statutory deadlines.

10. Personal data breaches

Vulkio notifies the trainer without undue delay after becoming aware of a breach affecting their records. As information becomes available, the notification covers the nature of the incident, categories and approximate numbers of affected people and records, likely consequences, measures taken or proposed and a contact.

Information may be supplied in stages without delaying initial notice until the full investigation is complete. Trainers determine authority and client notifications within their responsibilities. The parties cooperate to limit effects and preserve necessary records.

11. Return, deletion and Annex D — retention

On termination, at the controller’s choice, data is returned or deleted and copies removed except where retention is legally required. Export format, retrieval window, copy removal and confirmation procedure: —, to complete before activation.

Private 30-day preservation expressly chosen by a client on withdrawal does not allow coaching access during that period. Remaining backup records must be isolated from ordinary use and removed under a documented cycle. Relevant restrictions and deletions must be reapplied following restoration. Unverified schedules cannot be treated as unlimited retention rights.

12. Accountability, audit and liability

Vulkio makes compliance information available and allows audits, including inspections, by the trainer or their appointed auditor. Proportionate organisation protects other clients and security without removing effective verification. Frequency, notice and reasonable costs are agreed contractually without obstructing statutory duties.

Each party retains its legal liability, including towards individuals under GDPR Article 82. For processing on the trainer’s behalf, this DPA prevails over incompatible general terms. Changes do not take effect silently through replacement of the web page.