Data Processing Addendum
Last updated July 07, 2026
Introduction
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between Christoph Karl Knoll, trading as Lead Yourself First ("RepFit", "Processor", "we", "us", or "our") and the customer entity that subscribes to the RepFit service (the "Customer", "Controller", or "you").
This DPA applies whenever RepFit processes personal data on behalf of the Customer in the course of providing the Services.
This DPA is entered into automatically when the Customer accepts the Terms of Service and remains in force for as long as RepFit processes personal data on the Customer's behalf. A signed copy is available on request by writing to info@leadyourselffirst.coach.
1. Definitions
Terms used in this DPA carry the meaning given to them in the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") unless otherwise defined here.
- "Applicable Data Protection Law" means the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, and any other applicable law relating to the processing of personal data.
- "Customer Personal Data" means any personal data that RepFit processes on behalf of the Customer under the Terms of Service.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed under this DPA. In the context of RepFit, Data Subjects are typically the Customer's employees or team members who use the Services.
- "Services" means the RepFit behavioural rehearsal platform provided under the Terms of Service.
- "Standard Contractual Clauses" or "SCCs" means the Standard Contractual Clauses approved by the European Commission for the transfer of personal data to third countries, as they may be updated from time to time.
- "Sub-processor" means any third party engaged by RepFit to process Customer Personal Data on behalf of the Customer.
2. Subject matter and scope
RepFit processes Customer Personal Data as a processor on the Customer's behalf, solely for the purpose of providing the Services described in the Terms of Service.
The Customer acts as the controller in relation to Customer Personal Data.
The nature, purpose, categories of data, categories of data subjects, and duration of the processing are set out in Annex 1 to this DPA.
3. Processing instructions
RepFit will process Customer Personal Data only on documented instructions from the Customer.
The Terms of Service, this DPA, and the Customer's use of the Services constitute the Customer's complete and final instructions to RepFit for the processing of Customer Personal Data.
Any additional or alternative instructions must be agreed in writing.
If RepFit believes that an instruction infringes Applicable Data Protection Law, it will inform the Customer without delay.
4. Confidentiality
RepFit will ensure that personnel authorised to process Customer Personal Data are bound by appropriate obligations of confidentiality, whether by contract or by statute.
Access to Customer Personal Data is limited to personnel who require access to perform their duties in delivering the Services.
5. Security measures
RepFit will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
Current security measures include:
- Encryption of data in transit using industry-standard TLS.
- Encryption of data at rest in the primary database.
- Hashed passwords stored using industry-standard algorithms.
- Role-based access control at the application and database layer.
- Row-level security policies to enforce data isolation between organisations and between individual users.
- Documented access controls on database views and functions.
- Regular review of security configurations.
- Restriction of administrative access to authorised personnel.
Security measures may be updated over time to reflect changes in technology and threat landscape. Updated measures will provide a level of protection at least equivalent to the measures described above.
6. Sub-processors
The Customer authorises RepFit to engage sub-processors to process Customer Personal Data in connection with the Services.
The current list of sub-processors is maintained at https://tryrepfit.com/subprocessors.
RepFit will:
- Impose data protection obligations on each sub-processor that are no less protective than those in this DPA.
- Remain liable to the Customer for the acts and omissions of each sub-processor.
If RepFit adds, removes, or replaces a sub-processor, RepFit will notify the Customer by email at least fourteen (14) days before the change takes effect. The Customer may object to a new sub-processor on reasonable data protection grounds within fourteen (14) days of the notice by writing to info@leadyourselffirst.coach. The parties will work together in good faith to resolve any such objection.
7. Data subject rights
RepFit will provide reasonable assistance to the Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection.
Where a Data Subject contacts RepFit directly with such a request, RepFit will forward the request to the Customer without undue delay, unless the request relates solely to information that RepFit holds as a controller in its own right (for example, information related to billing).
8. Individual user data privacy commitment
RepFit makes a specific product commitment regarding the privacy of individual users within a Customer's organisation.
Where the Customer purchases the Services for its team, the individual user's rehearsal content, including patterns identified, interrupts logged, rebuilds practised, and self-ratings, remains private to that individual user.
The Customer, and any administrators, managers, or account owners acting on the Customer's behalf, may see whether individual team members are actively engaging with the Services. The Customer will not see the specific content a user has entered, the patterns a user has identified, or the ratings a user has recorded.
Where RepFit produces aggregate reports for the Customer or for internal product improvement, all data used is fully anonymised and cannot be linked back to any individual user.
This commitment is a core feature of the Services and cannot be overridden by a Customer request.
9. Personal data breach
RepFit will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.
The notification will include the information reasonably required for the Customer to meet its own notification obligations under Applicable Data Protection Law, including:
- The nature of the breach.
- The categories and approximate number of Data Subjects affected.
- The categories and approximate number of records affected.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach.
RepFit will cooperate with the Customer in the investigation, mitigation, and remediation of the breach.
10. Data protection impact assessment
RepFit will provide reasonable assistance to the Customer in carrying out data protection impact assessments and prior consultations with supervisory authorities, where required under Applicable Data Protection Law.
11. International data transfers
Where the processing of Customer Personal Data involves a transfer of personal data outside the European Economic Area, the United Kingdom, or Switzerland, the parties will rely on the Standard Contractual Clauses.
The Standard Contractual Clauses are incorporated into this DPA by reference and take effect automatically when required by Applicable Data Protection Law. Where the Standard Contractual Clauses require a party to select from optional clauses or modules, the parties agree to the following:
- Module Two (controller to processor) applies as between the Customer (as data exporter) and RepFit (as data importer).
- The optional docking clause is included.
- The governing law is the law of Spain.
- The competent supervisory authority is the Spanish Data Protection Authority (Agencia Española de Protección de Datos, AEPD).
RepFit will ensure that its sub-processors located outside the European Economic Area, the United Kingdom, or Switzerland are also bound by equivalent transfer safeguards.
12. Audit and information rights
The Customer may, at its own cost and no more than once per year, request information reasonably required to demonstrate RepFit's compliance with this DPA.
RepFit will respond to such requests within thirty (30) days.
Where a request cannot be satisfied by written information, and where required by Applicable Data Protection Law, RepFit will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to reasonable confidentiality obligations and reasonable notice.
Audits will be conducted in a manner that does not interfere with RepFit's normal business operations.
13. Return and deletion of personal data
On termination of the Services, the Customer may export its data through the Services or by requesting an export from RepFit within thirty (30) days of termination.
After the export period, or at the Customer's earlier written request, RepFit will delete or return all Customer Personal Data.
Customer Personal Data associated with individual user accounts will be deleted within ninety (90) days of account closure, unless a longer retention period is required by law (for example, retention of billing records required under Spanish tax law).
Backups containing Customer Personal Data are retained for up to thirty (30) days on a rolling basis and are then overwritten in the normal course of business.
14. Liability
Each party's liability arising under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
15. Governing law and jurisdiction
This DPA is governed by the laws of Spain.
The parties submit to the non-exclusive jurisdiction of the courts of Catalunya, Spain.
Where a Data Subject or supervisory authority has a right to bring proceedings in another jurisdiction under Applicable Data Protection Law, that right is not affected.
16. Order of precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Customer Personal Data.
In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
17. Contact
For matters relating to this DPA, please contact:
Christoph Karl Knoll (trading as Lead Yourself First)
Carrer de Trullols 10, 1-1
Barcelona, Catalunya 08035
Spain
Email: info@leadyourselffirst.coach
Annex 1 — Description of the processing
Nature and purpose of the processing
RepFit processes Customer Personal Data to provide the RepFit behavioural rehearsal service to the Customer and its authorised users. This includes account creation and authentication, delivery of the application, storage of user-entered rehearsal content, transactional communications, billing, and the production of aggregate engagement information for the Customer.
Categories of Data Subjects
- The Customer's employees, contractors, or team members who are invited to use the Services.
- The Customer's administrators and account owners.
- Individual sign-ups (in the case of self-serve subscriptions).
Categories of Personal Data
- Identifiers: full name, email address.
- Account credentials: hashed password.
- Organisational data: organisation name, role, seat status.
- Billing data (for the Customer): name, billing address, tax identification number, subscription and payment history.
- Rehearsal content: patterns identified, interrupts logged, rebuilds practised, self-ratings, timestamps.
- Communications: transactional emails sent, feedback responses submitted.
- Technical data: IP address, browser type, device type, session identifiers.
Sensitive Personal Data
None. RepFit does not process special categories of personal data under Article 9 of the GDPR.
Frequency of the processing
Continuous, for the duration of the Customer's subscription.
Duration of the processing
For the duration of the Customer's subscription, and for a further ninety (90) days after termination in respect of user account data.
Billing records are retained for seven (7) years to comply with Spanish tax law.
Retention
- User account data and rehearsal content: deleted within ninety (90) days of account closure.
- Feedback responses: deleted with the account.
- Billing records: seven (7) years (Spanish tax law).
- Backups: thirty (30) days rolling.
- Server logs: ninety (90) days.
Annex 2 — Sub-processors
The current list of sub-processors is maintained at https://tryrepfit.com/subprocessors.
Supabase, Inc.
Purpose: Application database, user authentication, edge functions.
Location: Data hosted in AWS eu-north-1 (Stockholm, Sweden). US parent company (Supabase Inc.).
Safeguards: Standard Contractual Clauses in place.