DPA

Peak Data Processing Addendum

How Peak processes personal data on behalf of its customers. The DPA forms part of the Peak B2B Terms of Service and of every Order Form that incorporates it.

Last updated: October 2, 2026

1. Scope

This Data Processing Addendum (DPA) forms part of the agreement between Peak Motion Labs GmbH, Hildburghäuser Straße 5, 52146 Würselen, Germany, registered with the commercial register of the Amtsgericht Aachen under HRB 30103 (Peak, Processor), and the customer identified in the applicable Order Form or account registration (Customer, Controller). It is accepted together with the Peak B2B Terms of Service or by signature of an Order Form that incorporates it.

This DPA applies where Peak processes personal data on behalf of Customer in connection with the Peak software platform and related services (Services).

This DPA does not govern processing for which Peak independently determines the purposes and means, including Peak's own account administration, billing, legal compliance, fraud prevention, service security and technical service data, and Peak's independent collection and curation of publicly available competition information. Such processing is governed by applicable data protection law and Peak's privacy information.

2. Roles

Customer determines the purposes and means of processing Customer Personal Data and acts as controller, business or equivalent responsible organization under applicable data protection laws. Peak processes Customer Personal Data only on behalf of Customer and acts as processor, service provider or equivalent service provider role.

3. Customer Instructions

Peak will process Customer Personal Data only on documented instructions from Customer, including the agreement, order form, product configuration, user actions and written support instructions, unless required by law.

Peak will not process Customer Personal Data for advertising, customer benchmarking or the training of machine-learning models unless the parties expressly agree in writing. Peak may create and use aggregated or anonymized information only where neither Customer nor any individual is reasonably identifiable, and Peak will not attempt to re-identify such information.

If Peak believes an instruction infringes applicable data protection laws, Peak will notify Customer where legally permitted.

4. Customer Responsibilities

Customer is responsible for:

  • having a valid legal basis for collecting, using and sharing Customer Personal Data;
  • providing required notices to data subjects;
  • obtaining required consents or permissions, including parental or guardian consent where required for minors;
  • ensuring that the platform is used for sports, team, training and organization workflows and that roles, access rights and configurable fields are appropriate and lawful;
  • responding to data-subject requests and giving Peak accurate and lawful instructions.

Body weight, body measurements, customer-configured tracking metrics, check-ins, wellbeing entries and performance-testing data are not prohibited by this DPA. Customer must determine whether such data constitutes health information, special-category data or otherwise sensitive data in its context and, if so, apply the required legal basis, notices, access controls and safeguards.

The Services must not be used for medical diagnosis, injury or treatment records, medication data, rehabilitation records or other regulated medical information, and Customer must not enter genetic data, biometric identification data, government identifiers or payment card data into the Services, unless the parties expressly agree in writing and implement appropriate additional safeguards.

5. Peak Obligations

Peak will:

  • ensure that persons authorized to process Customer Personal Data are bound by confidentiality;
  • implement appropriate technical and organizational measures as described in Schedule 2;
  • assist Customer reasonably with data subject requests, security incidents, deletion, data protection impact assessments, prior consultation requests where applicable and other compliance obligations, taking into account the nature of the processing;
  • make available information reasonably necessary to demonstrate compliance with this DPA;
  • delete or return Customer Personal Data after termination as described in Section 10.

6. Subprocessors

Customer gives Peak general authorization to use subprocessors necessary to provide the services. Current subprocessors are listed in Schedule 3. Peak will impose data protection obligations on subprocessors that are materially equivalent to this DPA and remains responsible for the performance of those obligations by subprocessors to the extent required by applicable law.

Peak may update subprocessors from time to time. Peak will notify Customer of material new subprocessors by email at least 10 days before the new subprocessor is authorized where reasonably practicable. Customer may object on reasonable data protection grounds within 7 days after notice. If the parties cannot resolve the objection, Customer may terminate the affected services.

If a subprocessor must be replaced urgently for security, continuity or legal reasons, Peak may do so immediately and will notify Customer as soon as reasonably possible.

7. International Transfers

Peak is established in Germany and its primary production backend is configured in the European Union, currently EU West (Ireland). Some subprocessors may process data in other countries. Where applicable data protection laws require a transfer mechanism, the parties will rely on an applicable adequacy decision, standard contractual clauses, data processing addendum, data privacy framework certification or other lawful transfer mechanism, and Customer authorizes Peak to enter into such terms with subprocessors on Customer's behalf where necessary.

Where Peak makes Customer Personal Data available to or returns it to Customer outside the European Economic Area, the transfer is subject to Chapter V of the GDPR and no adequacy decision or other lawful mechanism covers it, Schedule 4 applies.

8. Security Incidents

Peak will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 48 hours of becoming aware. Information may be provided in phases as it becomes available.

The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of affected data subjects and records, the likely consequences, and the measures taken or proposed. Peak will provide reasonable ongoing information and cooperation so Customer can meet its legal obligations, including any obligation to notify supervisory authorities or data subjects. Peak's notification is not an admission of fault or liability.

9. Data Subject Requests

Peak will reasonably assist Customer with requests from data subjects to access, correct, delete, export or restrict processing of Customer Personal Data. Where possible, Customer should use the product functionality to handle requests directly.

If Peak receives a request directly from a data subject concerning Customer Personal Data, Peak will redirect the requester to Customer or notify Customer, and will not respond substantively unless Customer authorizes it or the law requires it.

The parties will agree in advance on reasonable costs for assistance that is unusually burdensome or goes beyond Peak's legal obligations.

10. Deletion and Return

On request before deletion, Peak will provide one reasonable export of available Customer Personal Data in a commonly usable format, such as CSV or JSON. The export may be performed manually.

After termination or expiry of the services, Peak will delete or return active Customer Personal Data within 30 days after Customer request or contract end, unless retention is required by law, security, backup, accounting or dispute-resolution obligations. Backup copies will be deleted or overwritten within 90 days in the ordinary backup lifecycle, unless longer retention is legally required. During any residual retention, Peak will continue to protect the data under this DPA and will not use it for another purpose.

11. Audits and Information

Upon reasonable written request, Peak will provide information reasonably necessary to demonstrate compliance with this DPA, including relevant information about subprocessors, security measures and deletion.

Where required by applicable data protection law, Customer (or an independent auditor mandated by Customer and bound by confidentiality) may audit Peak's compliance with this DPA, including inspections. Audits are limited to once per calendar year (unless required by a supervisory authority or following a personal data breach), require at least 30 days' prior written notice, take place during normal business hours, must not unreasonably disrupt Peak's operations, and are at Customer's cost. Peak may satisfy an audit request first by providing existing audit reports, certifications or documentation.

12. Liability

Liability under this DPA is subject to the limitations and exclusions in the main agreement, unless applicable law requires otherwise.

Schedule 1: Processing Details

ItemDescription
Subject matterProvision, operation, maintenance, security and support of the Peak software platform.
DurationFor the term of the applicable Order Form or online subscription and the deletion/backup period after termination.
PurposeSports team, coach and athlete organization, including account access, team management, calendar and scheduling, training and program organization, competition workflows, athlete tracking, statistics, notifications, communications, support and service security.
Data subjectsCustomer staff, administrators, coaches and other personnel; invited users; athletes, including minor athletes where Customer adds them; parents or guardians where Customer provides their information; and users who contact support.
Categories of personal dataIdentity and contact data (name, email address, optional profile image, account identifiers); organization, team, site, role, membership and assignment data; athlete profile data (age category, gender, discipline, group, customer-provided external sport identifiers); calendar, attendance, session, training plan, exercise, assignment, notes and communication data; competition, event, result and performance statistics; customer-configured tracking, check-in and performance-testing data (which may include body weight or wellbeing entries); notification preferences, device push tokens and delivery records; support requests and uploaded content; and technical logs and usage/security data processed on behalf of Customer.
Excluded unless expressly agreedMedical diagnosis, injury or treatment records, medication and rehabilitation data, regulated medical information, genetic data, biometric identification data, government identifiers, payment card data and other sensitive data not required for the agreed service.

Schedule 2: Technical and Organizational Measures

Access control: unique administrative accounts, role-based access where available, least-privilege internal access, and MFA for administrative provider accounts where supported.

Tenant and authorization controls: backend authorization checks with organization, role, capability and athlete-assignment scoping designed to prevent unauthorized cross-customer and cross-role access.

Confidentiality: personnel and contractor confidentiality obligations.

Encryption: HTTPS/TLS for data in transit and provider-managed encryption at rest where supported by the relevant infrastructure provider.

Hosting and infrastructure: managed cloud and SaaS infrastructure providers under their published security, privacy and DPA terms.

Availability: operational monitoring, provider backup or restore capabilities, and incident response processes.

Logging and security: technical logs for operation, troubleshooting, abuse prevention and security investigation, with support access limited to what is necessary.

Vendor management: use of subprocessors with published data protection terms, DPAs or equivalent contractual protections.

Schedule 3: Subprocessors

SubprocessorPurposeNotes
Convex, Inc.Backend, database, authentication, file storage and application infrastructurePeak production deployment configured in Europe (EU West, Ireland). DPA: convex.dev/legal/dpa
Vercel Inc.Web hosting, deployment, content delivery, web infrastructure and analytics where enabledDPA: vercel.com/legal/dpa
Plus Five Five, Inc. (Resend)Transactional email sending (invitations and service notifications, including recipient address, message content and delivery metadata)DPA: resend.com/legal/dpa
650 Industries, Inc. (Expo)Mobile application build and delivery services and mediation of mobile push notifications where enabled, including device push tokens and notification payloadsLegal terms/DPA available through Expo's published terms.
Hostinger International Ltd.Domain, business email mailbox and related website/email services where support communications contain Customer Personal DataLegal terms/DPA available through Hostinger legal terms and account documentation.

When push notifications are enabled, the device-platform or browser push service of the user's device or browser (for example Apple Push Notification service, Google/Firebase Cloud Messaging or Mozilla's push service) may also receive a device token and notification payload under the relevant platform terms.

Payment processing for Peak's own billing (Stripe) is not sub-processing of Customer Personal Data and is described in Peak's Privacy Policy.

Schedule 4: International Transfer Clauses

This Schedule applies only where Peak, acting as processor in the European Economic Area, makes Customer Personal Data available to or returns it to Customer acting as controller outside the European Economic Area, the transfer is subject to Chapter V of the GDPR, and no adequacy decision or other lawful transfer mechanism covers the transfer.

In that case, the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Four (processor to controller), are incorporated into this DPA as set out in full in the Annex to this Schedule 4 (official text: eur-lex.europa.eu/eli/dec_impl/2021/914/oj) with the following selections: Clause 7 (docking clause) is not used; the optional independent dispute-resolution language in Clause 11 is not used; for Clause 17, the clauses are governed by the law of Germany; for Clause 18, the parties choose the courts of Germany.

Peak is the data exporter (processor) and Customer is the data importer (controller). Annex I of the clauses is completed by the parties' details in the applicable Order Form or account registration and the processing description in Schedule 1 of this DPA, as set out in the Annex to this Schedule 4; Schedule 2 describes Peak's technical and organizational measures. Acceptance of the Peak B2B Terms of Service, or acceptance or signature of the applicable Order Form, constitutes signature of the clauses by both parties. If the clauses conflict with this DPA or the agreement, the clauses prevail to the extent of the conflict.

Annex to Schedule 4: Standard Contractual Clauses, Module Four (Transfer processor to controller)

This Annex contains the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Four (processor to controller), as used by the parties, including the selected options and the completed Appendix. It forms an integral part of Schedule 4 of this DPA. Acceptance of the Peak B2B Terms of Service, or acceptance or signature of the applicable Order Form, constitutes signature of these Clauses by both Parties.

Selections made by the Parties: Module Four applies. Clause 7 (docking clause) is not used. The optional independent dispute-resolution paragraph in Clause 11(a) is not used. Clause 17: the law of Germany. Clause 18: the courts of Germany. Text applicable only to Modules One, Two or Three is omitted; bracketed module-conditional inserts for other modules are omitted.

SECTION I

Clause 1 — Purpose and scope

(a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country.

(b) The Parties:

(i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter 'entity/ies') transferring the personal data, as listed in Annex I.A (hereinafter each 'data exporter'), and

(ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each 'data importer')

have agreed to these standard contractual clauses (hereinafter: 'Clauses').

(c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.

(d) The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses.

Clause 2 — Effect and invariability of the Clauses

(a) These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects.

(b) These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.

Clause 3 — Third-party beneficiaries

(a) Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions:

(i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;

(ii) Clause 8 – Module One: Clause 8.5(e) and Clause 8.9(b); Module Two: Clause 8.1(b), 8.9(a), (c), (d) and (e); Module Three: Clause 8.1(a), (c) and (d) and Clause 8.9(a), (c), (d), (e), (f) and (g); Module Four: Clause 8.1(b) and Clause 8.3(b);

(iii) Clause 9 – Module Two: Clause 9(a), (c), (d) and (e); Module Three: Clause 9(a), (c), (d) and (e);

(iv) Clause 12 – Module One: Clause 12(a) and (d); Modules Two and Three: Clause 12(a), (d) and (f);

(v) Clause 13;

(vi) Clause 15.1(c), (d) and (e);

(vii) Clause 16(e);

(viii) Clause 18 – Modules One, Two and Three: Clause 18(a) and (b); Module Four: Clause 18.

(b) Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.

Clause 4 — Interpretation

(a) Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.

(b) These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.

(c) These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679.

Clause 5 — Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

Clause 6 — Description of the transfer(s)

The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.

Clause 7 — Optional: Docking clause

Not used.

SECTION II – OBLIGATIONS OF THE PARTIES

Clause 8 — Data protection safeguards

The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses.

MODULE FOUR: Transfer processor to controller

8.1 Instructions

(a) The data exporter shall process the personal data only on documented instructions from the data importer acting as its controller.

(b) The data exporter shall immediately inform the data importer if it is unable to follow those instructions, including if such instructions infringe Regulation (EU) 2016/679 or other Union or Member State data protection law.

(c) The data importer shall refrain from any action that would prevent the data exporter from fulfilling its obligations under Regulation (EU) 2016/679, including in the context of sub-processing or as regards cooperation with competent supervisory authorities.

(d) After the end of the provision of the processing services, the data exporter shall, at the choice of the data importer, delete all personal data processed on behalf of the data importer and certify to the data importer that it has done so, or return to the data importer all personal data processed on its behalf and delete existing copies.

8.2 Security of processing

(a) The Parties shall implement appropriate technical and organisational measures to ensure the security of the data, including during transmission, and protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access (hereinafter 'personal data breach'). In assessing the appropriate level of security, they shall take due account of the state of the art, the costs of implementation, the nature of the personal data (1), the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subjects, and in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner.

(b) The data exporter shall assist the data importer in ensuring appropriate security of the data in accordance with paragraph (a). In case of a personal data breach concerning the personal data processed by the data exporter under these Clauses, the data exporter shall notify the data importer without undue delay after becoming aware of it and assist the data importer in addressing the breach.

(c) The data exporter shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

8.3 Documentation and compliance

(a) The Parties shall be able to demonstrate compliance with these Clauses.

(b) The data exporter shall make available to the data importer all information necessary to demonstrate compliance with its obligations under these Clauses and allow for and contribute to audits.

(1) This includes whether the transfer and further processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person's sex life or sexual orientation, or data relating to criminal convictions or offences.

Clause 9 — Use of sub-processors

Not applicable to Module Four.

Clause 10 — Data subject rights

MODULE FOUR: Transfer processor to controller

The Parties shall assist each other in responding to enquiries and requests made by data subjects under the local law applicable to the data importer or, for data processing by the data exporter in the EU, under Regulation (EU) 2016/679.

Clause 11 — Redress

(a) The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject.

(The optional independent dispute-resolution paragraph is not used.)

Clause 12 — Liability

MODULE FOUR: Transfer processor to controller

(a) Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses.

(b) Each Party shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages that the Party causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter under Regulation (EU) 2016/679.

(c) Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties.

(d) The Parties agree that if one Party is held liable under paragraph (c), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its/their responsibility for the damage.

(e) The data importer may not invoke the conduct of a processor or sub-processor to avoid its own liability.

Clause 13 — Supervision

Not applicable to Module Four.

SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES

Clause 14 — Local laws and practices affecting compliance with the Clauses

MODULE FOUR: Transfer processor to controller (where the EU processor combines the personal data received from the third country-controller with personal data collected by the processor in the EU)

(a) The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses.

(b) The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular of the following elements:

(i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; intended onward transfers; the type of recipient; the purpose of processing; the categories and format of the transferred personal data; the economic sector in which the transfer occurs; the storage location of the data transferred;

(ii) the laws and practices of the third country of destination – including those requiring the disclosure of data to public authorities or authorising access by such authorities – relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards (2);

(iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination.

(c) The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses.

(d) The Parties agree to document the assessment under paragraph (b) and make it available to the competent supervisory authority on request.

(e) The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under paragraph (a), including following a change in the laws of the third country or a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line with the requirements in paragraph (a).

(f) Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality) to be adopted by the data exporter and/or data importer to address the situation. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses. If the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise. Where the contract is terminated pursuant to this Clause, Clause 16(d) and (e) shall apply.

(2) As regards the impact of such laws and practices on compliance with these Clauses, different elements may be considered as part of an overall assessment. Such elements may include relevant and documented practical experience with prior instances of requests for disclosure from public authorities, or the absence of such requests, covering a sufficiently representative time-frame. This refers in particular to internal records or other documentation, drawn up on a continuous basis in accordance with due diligence and certified at senior management level, provided that this information can be lawfully shared with third parties. Where this practical experience is relied upon to conclude that the data importer will not be prevented from complying with these Clauses, it needs to be supported by other relevant, objective elements, and it is for the Parties to consider carefully whether these elements together carry sufficient weight, in terms of their reliability and representativeness, to support this conclusion. In particular, the Parties have to take into account whether their practical experience is corroborated and not contradicted by publicly available or otherwise accessible, reliable information on the existence or absence of requests within the same sector and/or the application of the law in practice, such as case law and reports by independent oversight bodies.

Clause 15 — Obligations of the data importer in case of access by public authorities

MODULE FOUR: Transfer processor to controller (where the EU processor combines the personal data received from the third country-controller with personal data collected by the processor in the EU)

15.1 Notification

(a) The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if necessary with the help of the data exporter) if it:

(i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response provided; or

(ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination; such notification shall include all information available to the importer.

(b) If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. The data importer agrees to document its best efforts in order to be able to demonstrate them on request of the data exporter.

(c) Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received (in particular, number of requests, type of data requested, requesting authority/ies, whether requests have been challenged and the outcome of such challenges, etc.).

(d) The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request.

(e) Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.

15.2 Review of legality and data minimisation

(a) The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested until required to do so under the applicable procedural rules. These requirements are without prejudice to the obligations of the data importer under Clause 14(e).

(b) The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible under the laws of the country of destination, make the documentation available to the data exporter. It shall also make it available to the competent supervisory authority on request.

(c) The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.

SECTION IV – FINAL PROVISIONS

Clause 16 — Non-compliance with the Clauses and termination

(a) The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason.

(b) In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. This is without prejudice to Clause 14(f).

(c) The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where:

(i) the data exporter has suspended the transfer of personal data to the data importer pursuant to paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension;

(ii) the data importer is in substantial or persistent breach of these Clauses; or

(iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses.

In these cases, it shall inform the competent supervisory authority of such non-compliance. Where the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise.

(d) Personal data collected by the data exporter in the EU that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall immediately be deleted in its entirety, including any copy thereof. The data importer shall certify the deletion of the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit the return or deletion of the transferred personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process the data to the extent and for as long as required under that local law.

(e) Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred. This is without prejudice to other obligations applying to the processing in question under Regulation (EU) 2016/679.

Clause 17 — Governing law

MODULE FOUR: Transfer processor to controller These Clauses shall be governed by the law of a country allowing for third-party beneficiary rights. The Parties agree that this shall be the law of Germany.

Clause 18 — Choice of forum and jurisdiction

MODULE FOUR: Transfer processor to controller Any dispute arising from these Clauses shall be resolved by the courts of Germany.

APPENDIX

EXPLANATORY NOTE: It must be possible to clearly distinguish the information applicable to each transfer or category of transfers and, in this regard, to determine the respective role(s) of the Parties as data exporter(s) and/or data importer(s). This does not necessarily require completing and signing separate appendices for each transfer/category of transfers and/or contractual relationship, where this transparency can achieved through one appendix. However, where necessary to ensure sufficient clarity, separate appendices should be used.

ANNEX I

A. LIST OF PARTIES

MODULE FOUR: Transfer processor to controller

Data exporter(s):

1. Name: Peak Motion Labs GmbH. Address: Hildburghäuser Straße 5, 52146 Würselen, Germany, registered with the commercial register of the Amtsgericht Aachen under HRB 30103. Contact person's name, position and contact details: Moritz Wesemann, Managing Director, [support@peakmotionlabs.com](mailto:support@peakmotionlabs.com). Activities relevant to the data transferred under these Clauses: Provision, operation, maintenance, security and support of the Peak software platform (PeakDive) as processor on behalf of the data importer, as described in this DPA and the applicable Order Form or account registration. Signature and date: By acceptance of the Peak B2B Terms of Service or by acceptance or signature of the applicable Order Form. Role (controller/processor): Processor

Data importer(s):

1. Name and address: The Customer identified in the applicable Order Form or account registration. Contact person's name, position and contact details: The Customer's account owner, or the contact stated in the applicable Order Form. Activities relevant to the data transferred under these Clauses: Use of the PeakDive platform as controller for sports team, coach and athlete organization, including training planning, calendars, athlete self-documentation, configured check-ins, competition analysis and related workflows, as described in the applicable Order Form or account registration. Signature and date: By acceptance of the Peak B2B Terms of Service or by acceptance or signature of the applicable Order Form. Role (controller/processor): Controller

B. DESCRIPTION OF TRANSFER

MODULE FOUR: Transfer processor to controller

Categories of data subjects whose personal data is transferred: Customer staff, administrators, coaches and other personnel; invited users; athletes, including minor athletes where the data importer adds them; parents or guardians where the data importer provides their information; users who contact support; and, for the public competition-results feature, athletes whose competition results have been made publicly available by the relevant result provider (which may include athletes located in the European Economic Area).

Categories of personal data transferred: Identity and contact data (name, email address, optional profile image, account identifiers); organization, team, site, role, membership and assignment data; athlete profile data (age category, gender, discipline, group, customer-provided external sport identifiers); calendar, attendance, session, training plan, exercise, assignment, notes and communication data; competition, event, result and performance statistics (including publicly available competition results such as athlete name, nation, gender, birth year, competition, event, placement and scores); customer-configured tracking, check-in and performance-testing data (which may include body weight or wellbeing entries); notification preferences, device push tokens and delivery records; support requests and uploaded content; and technical logs and usage/security data processed on behalf of the data importer.

Sensitive data transferred (if applicable) and applied restrictions or safeguards: Customer-configured tracking fields may include body weight and wellbeing entries which, in their context of use, may constitute data concerning health. Applied restrictions and safeguards: strict purpose limitation to the provision of the contracted services; role- and assignment-based access controls (athlete/coach/head-coach scoping); least-privilege internal access; confidentiality obligations; encryption in transit (HTTPS/TLS) and provider-managed encryption at rest; exclusion of medical diagnosis, injury, treatment, medication, rehabilitation, genetic, biometric-identification, government-identifier and payment-card data from the standard service; exclusion of sensitive values from push-notification payloads; and the further measures described in Schedule 2 of this DPA.

The frequency of the transfer: Continuous, for the duration of the applicable Order Form or online subscription, whenever the data importer or its authorized users access the services, receive exports or receive returned data.

Nature of the processing: Hosting, storage, organization, structuring, retrieval, consultation, use, disclosure by transmission to the data importer and its authorized users, export, erasure and related operations necessary to provide, operate, maintain, secure and support the services.

Purpose(s) of the data transfer and further processing: Provision of the Peak software platform and related services to the data importer for sports team, coach and athlete organization, including account access, team management, calendar and scheduling, training and program organization, competition workflows, athlete tracking, statistics, notifications, communications, support and service security, as described in Schedule 1 of this DPA and the applicable Order Form or account registration.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: For the term of the applicable Order Form or online subscription; after termination or expiry, active data is deleted or returned within 30 days after request or contract end, and backup copies are deleted or overwritten within 90 days in the ordinary backup lifecycle, unless longer retention is required by law (see Section 10 of this DPA).

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Not applicable (this Module Four transfer is from the processor/data exporter to the controller/data importer; sub-processing within the EEA is governed by Section 6 and Schedule 3 of this DPA).

C. COMPETENT SUPERVISORY AUTHORITY

Not applicable to Module Four (Clause 13 does not apply).

ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES

Annex II of the standard contractual clauses applies to Modules One, Two and Three and is not required for Module Four. For information, the technical and organisational measures implemented by the data exporter are described in Schedule 2 of this DPA.

ANNEX III — LIST OF SUB-PROCESSORS

Not applicable to Module Four.