Data Processing Addendum
This DPA forms part of the Terms of Service between you (the "Controller" — the coach, studio, or business operating the account) and Punch Monk Inc. (the "Processor"). It governs Punch Monk's processing of personal data on your behalf.
1 · Roles
You determine the purposes and means of processing client data. Punch Monk processes that data only on your documented instructions, as set out in the product UI and the Terms of Service.
2 · Subject matter
Personal data of your clients: name, contact, body metrics, training logs, progress photos, payment records, optional wearables data, optional medical intake (PAR-Q, injuries).
3 · Subprocessors
We use the following subprocessors. We give 30 days' notice before adding or replacing any of them.
- AWS — infrastructure hosting
- Supabase — primary database, storage, auth
- Stripe — international card processing
- Razorpay — Indian card and UPI processing
- Resend — transactional email
- Firebase Cloud Messaging — push notifications
- Apple Push Notification Service — iOS push
- Google Cloud Speech (optional) — voice-note transcription, only if enabled
4 · Security
- TLS 1.2+ in transit; AES-256 at rest.
- Backups encrypted, retained 30 days, stored in a separate region.
- Least-privilege access; named-engineer audit trail.
- Annual penetration test; quarterly internal review.
5 · Data subject requests
If a client of yours exercises a GDPR / DPDP / CCPA right and contacts us directly, we will forward the request to you and provide the technical means to respond. You remain the controller.
6 · Breach notification
We will notify you within 72 hours of becoming aware of a personal data breach affecting your account, with the information required to meet your own notification obligations.
7 · Data return and deletion
On termination, you can export all client data via the in-app tool. After 90 days, we permanently delete from primary systems and within a further 90 days from backups.
8 · International transfers
Where data leaves your home jurisdiction (e.g., to a subprocessor in another country), we rely on Standard Contractual Clauses (EU 2021/914) or equivalent safeguards. Available on request.
9 · Audit
Once per year, on 30 days' written notice, you may audit our compliance with this DPA via written questionnaire or a SOC 2 report (when available).
10 · Contact
Data protection officer: [email protected].