Skip to content

Legal

Data processing agreement

Last updated: 31 July 2026

This short-form data processing agreement (DPA) applies when you, the coach, use Helping to process your clients' personal data. It is incorporated into our terms of service. It was last updated on 31 July 2026.

Purpose & scope

This DPA forms part of, and is incorporated into, the terms of service between you and Helping. It applies where Helping processes Client Data (defined below) on your behalf to provide the Services. It is written to meet the requirements of Article 28 of the EU GDPR and the UK GDPR.

Roles

  • You (the Coach) are the controller. You determine the purposes and means of processing your clients' personal data.
  • Helping is the processor. We process that data only on your documented instructions to deliver the Services.
  • Client Data means the personal data of your clients that you cause Helping to process: names and identifiers, phone numbers, Telegram identifiers, check-in messages and replies, response, streak and engagement metrics, and timezones.

For your own account data, Helping is the controller; see our privacy policy.

Processor obligations

As your processor, Helping will:

  1. Process Client Data only on your documented instructions — namely the schedules, templates, channels, and settings you configure in the Services, and these terms — including any transfers of Client Data to a third country, unless we are required to do otherwise by law. If a legal obligation prevents us from following your instructions, we will inform you where the law permits.
  2. Ensure that personnel authorised to process Client Data are bound by confidentiality.
  3. Implement appropriate technical and organisational security measures (Article 32), including encryption in transit (TLS), encryption at rest, and field-level encryption for phone numbers, together with access controls on a least-privilege basis.
  4. Use subprocessors only under written terms that impose equivalent obligations, and only with appropriate notice.
  5. Assist you, so far as possible, with subject-rights requests, security-breach response, and data protection impact assessments.
  6. Delete or return Client Data at the end of the services, in line with the retention periods below.
  7. Make information available and contribute to audits to demonstrate compliance with this DPA.

Subprocessors

Our current subprocessors, and the purpose for which each is used, are:

  • Twilio (and Telnyx, where applicable)SMS delivery for check-ins and replies.
  • Telegram Messenger Inc.Telegram message delivery for check-ins and replies.
  • StripePayment processing and billing.
  • Self-hosted infrastructureHosting and storage of account and client data, on infrastructure the business controls (not a shared public cloud).
  • Glitchtip (or a Sentry-compatible service)Error monitoring and application diagnostics.

We will give you notice of any intended change to our subprocessors. You may object to a new subprocessor on reasonable data-protection grounds; if we cannot resolve your objection, you may end the affected services without penalty.

Audits

You may audit our compliance with this DPA, subject to reasonable notice and to confidentiality. You bear the cost of an audit unless it reveals non-compliance by us, in which case we bear the cost and put things right.

International transfers

Where Client Data is transferred outside the country in which it was collected, we will rely on an appropriate safeguard, such as the UK International Data Transfer Agreement (IDTA) or the European Commission's Standard Contractual Clauses, as applicable.

Security incident response

If we become aware of a personal-data breach affecting Client Data, we will notify you without undue delay, describe what we know, and take reasonable steps to contain and remediate it. We will also assist you with any obligation you have to notify regulators or affected individuals.

Duration

This DPA applies for the term of your account and for the retention period afterwards. On termination, Client Data is deleted or returned to you, and any remaining data is kept only briefly then anonymised — specifically, Client Data is retained for 30 days after a client is removed and then anonymised.

Order of precedence

If there is a conflict between this DPA and the terms of service on the subject of data protection, this DPA prevails.

Questions about this document? Email hello@helping.app.

Data processing agreement · Helping