Data Processing Agreement
Last updated: 11 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Helia AI GmbH, Rossertstr. 34, 65817 Eppstein, Germany ("Relay", "Processor") and the customer that uses Relay to manage its athletes ("Customer", "Controller"). It applies automatically when the Customer accepts the Terms of Service. A countersigned copy is available on request from team@relayathletic.com.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Customer Personal Data" means personal data that Relay processes on behalf of the Customer when providing the Service, as described in Annex 1.
2. Roles and Scope
The Customer is the controller of Customer Personal Data and Relay is its processor. This DPA does not cover personal data for which Relay is itself the controller, such as the account and billing data of the Customer's own users; that data is described in our Privacy Policy.
The Customer is responsible for the lawfulness of the processing it instructs, including informing its athletes, obtaining explicit consent under Art. 9(2)(a) GDPR where it records health data (for example wellness questionnaire answers or injury notes), and obtaining parental consent for minors where required.
3. Instructions
Relay processes Customer Personal Data only on the Customer's documented instructions, which are given by this DPA, the Terms of Service, the Customer's use and configuration of the Service, and any further written instructions agreed between the parties. Relay processes Customer Personal Data otherwise only where required by EU or member state law, in which case it informs the Customer before processing unless that law prohibits it. Relay informs the Customer without undue delay if it believes an instruction infringes data protection law.
4. Confidentiality
Relay ensures that everyone authorised to process Customer Personal Data is bound by confidentiality, either contractually or by law, and receives appropriate data protection and security training.
5. Security
Relay implements the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk, as required by Art. 32 GDPR. Relay may update these measures as technology develops, provided the overall level of protection is not reduced.
6. Sub-processors
The Customer gives general authorisation for Relay to engage sub-processors. The current list is published at trust.relayathletic.com/subprocessors (Annex 3). Relay notifies the Customer by email at least 14 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service and receives a pro-rata refund of prepaid fees for the remaining term.
Where Relay must replace a sub-processor urgently for reasons of security or service continuity, it may do so without prior notice. It then notifies the Customer within 3 business days, and the Customer's right to object applies from that notice.
Relay imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable to the Customer for the performance of its sub-processors' obligations.
7. International Transfers
Relay stores Customer Personal Data in Google Cloud in Frankfurt, Germany. Where a sub-processor processes Customer Personal Data outside the European Economic Area, Relay ensures a transfer mechanism under Chapter V GDPR is in place: an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified) or the EU Standard Contractual Clauses.
8. Data Subject Requests
Relay forwards to the Customer without undue delay any request it receives from a data subject about Customer Personal Data and does not respond to it except on the Customer's instruction. Taking into account the nature of the processing, Relay assists the Customer with appropriate technical and organisational measures to respond to requests to exercise data subject rights.
9. Further Assistance
Taking into account the nature of the processing and the information available to it, Relay assists the Customer in meeting its obligations under Art. 32 to 36 GDPR, including data protection impact assessments and prior consultation with a supervisory authority.
10. Personal Data Breaches
Relay notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Relay provides further information as it becomes available and takes reasonable steps to contain the breach.
11. Deletion and Return
During the term, the Customer can delete Customer Personal Data in the Service or ask Relay to delete it. On request before the end of the Service, Relay provides an export of Customer Personal Data in a commonly used, machine-readable format. Within 30 days after the end of the Service, Relay deletes Customer Personal Data unless EU or member state law requires its storage. Deleted data is removed from backups as they expire, within 7 days.
12. Audits
Relay makes available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR. The Customer will first rely on Relay's written documentation, security policies and any available certifications or audit reports. Where these are not sufficient, the Customer may carry out an audit or have one carried out by an independent auditor bound by confidentiality, no more than once in any 12 months, with at least 30 days' notice, during business hours, and at the Customer's own cost. Audits by a competent supervisory authority are not limited by this section.
13. Liability
Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the limitations of liability in the Terms of Service apply to this DPA to the extent permitted by law.
14. Term, Precedence and Governing Law
This DPA applies for as long as Relay processes Customer Personal Data. In the event of a conflict, this DPA prevails over the Terms of Service on data protection matters, and any Standard Contractual Clauses prevail over this DPA. Where the parties have signed a Business Associate Agreement, it prevails for protected health information under HIPAA. This DPA is governed by the laws of the Federal Republic of Germany, and the courts of Frankfurt am Main, Germany have exclusive jurisdiction.
Annex 1: Details of Processing
- Subject matter and duration: Provision of the Relay Service for the term of the Terms of Service.
- Nature of processing: Hosting, storage, retrieval, transmission, display, analysis, AI-assisted processing, backup and deletion.
- Purpose: Enabling the Customer to plan, deliver and track athletic training, communicate with its athletes, and use AI features.
- Data subjects: The Customer's athletes; the Customer's coaches and staff; other people the Customer adds to the Service.
- Categories of personal data: Name and contact details; team and roster information; training programs, workouts, sets, loads and results; performance and readiness data, including questionnaire answers, body measurements and device results (for example from force plates); coach notes; chat messages, images, videos and files; AI chat messages and voice input; usage and device data.
- Special categories: Depending on how the Customer uses the Service, some data (for example wellness questionnaire answers or injury notes) may be health data under Art. 9 GDPR. Safeguards: encryption at rest and in transit, access restricted to the Customer's organisation and to two named Relay administrators, and push notifications that carry no content.
- Frequency: Continuous, for the term of the Service.
Annex 2: Technical and Organisational Measures
- Hosting: Google Cloud, Frankfurt, Germany (europe-west3).
- Encryption: Data encrypted at rest; all connections encrypted in transit with TLS.
- Access control: Production access limited to two named administrators with enforced 2-step verification; least privilege; read-only roles for diagnostics; access reviewed periodically.
- Separation: Database row-level security separates each customer's data.
- Availability: Daily backups kept for 7 days with point-in-time recovery; backup restoration tested at least annually; documented disaster recovery plan.
- Logging and monitoring: Infrastructure audit logs and alerting on errors and availability.
- Vulnerability management: Automated dependency vulnerability alerts with defined remediation timelines.
- Change management: All changes tracked in version control with automated checks before deployment.
- People: Confidentiality obligations, security awareness training and acknowledged security policies for everyone with access.
- Incident response: Documented incident response process, including breach notification under section 10.