Mnemia
Sign InTry Mnemia

Data Processing Agreement

Last updated: 23 August 2026

This Data Processing Agreement (“DPA”) forms part of the Mnemia coach agreement. It is between the practice or independent coach identified as the controller in the account (“Controller”) and the Mnemia operator identified in the Impressum(“Processor”). The person accepting it confirms that they are authorised to bind the Controller.

It applies when Mnemia processes client personal data on the Controller's behalf. It is intended to satisfy Article 9 of the Swiss Federal Act on Data Protection (FADP) and, where applicable, Article 28 GDPR. A client is a data subject and is never asked to accept this DPA.

1. Scope, roles, and instructions

The Controller decides why and how its client data is processed. Mnemia processes that data only on the Controller's documented instructions, including the coach agreement, this DPA, enabled product settings, and lawful support requests. Mnemia may process data where required by applicable law; where permitted, it will tell the Controller before doing so.

Mnemia is separately a controller for its own account administration, security, billing, legal-compliance, and business-contact data, as described in the Privacy Notice.

2. Controller obligations

The Controller will:

  • give lawful, fair, and transparent instructions and establish every required legal basis, including any separate condition for sensitive or special-category data;
  • provide its clients with the information required by law and honour access, correction, objection, withdrawal, export, restriction, and erasure rights where applicable;
  • use the product permission controls faithfully without treating them as a substitute for any professional, contractual, secrecy, or jurisdiction-specific obligation; and
  • keep account access secure and use Mnemia only for supported adult, one-to-one, non-clinical coaching unless a different service has been expressly agreed in writing.

3. Confidentiality and personnel

Mnemia ensures that people authorised to process Controller data are subject to an appropriate duty of confidentiality, receive access only where necessary, and process the data only for the agreed service. Mnemia does not use Controller data to train public or shared AI models.

4. Security

Mnemia applies technical and organisational measures appropriate to the risks, including transport encryption; field encryption for stored session content; role-based access and database row-level controls; separation of coach and client views; protected secrets; security logging; human review before client-facing AI material is shared; and minimisation and deletion controls for source material. Original uploaded and recorded media bytes are processed transiently and are not intentionally retained as product records.

The measures may evolve as technology and risk change, provided the overall protection is not materially reduced. Further security information reasonably needed for a Controller's assessment is available on request, subject to confidentiality and system security.

5. Sub-processors

The Controller gives general written authorisation for the providers on the current Sub-processorslist. Mnemia places data-protection obligations on each sub-processor that are appropriate to the service it performs and remains responsible to the Controller for that sub-processor's performance to the extent required by law.

Mnemia will give reasonable advance notice of a material addition or replacement. The Controller may object on documented, reasonable data-protection grounds. The parties will try to resolve the concern in good faith; if they cannot, the Controller may stop the affected processing or terminate the affected service.

6. International access and transfers

The primary database is in Switzerland. Sensitive application processing is configured for Switzerland and supported EU regions as described on the Sub-processors page. If personal data is transferred to a country without an applicable adequacy decision, Mnemia will use a lawful transfer mechanism and any supplementary safeguards reasonably required, including recognised standard contractual clauses where appropriate.

7. Assistance

Taking account of the nature of the processing and the information available to it, Mnemia will reasonably assist the Controller with data-subject requests, security obligations, personal-data breach duties, data-protection impact assessments, and prior consultation. If Mnemia receives a request concerning Controller data directly, it will direct the person to the Controller unless authorised or legally required to respond itself.

8. Personal-data breaches

Mnemia will notify the Controller without undue delay after becoming aware of a confirmed personal-data breach affecting Controller data. As information becomes available, the notice will describe the known nature and likely consequences, affected data or people, measures taken or proposed, and a contact point. Notification does not itself acknowledge fault or liability.

9. Return, deletion, and retention

During the service, the Controller may use available export and deletion tools or request assistance. At the end of the service, Mnemia will delete or return Controller data at the Controller's choice, then delete remaining copies within the documented backup cycle, unless applicable law requires continued retention. Mnemia may retain content-free evidence of legal and permission events where necessary for accountability or legal claims.

Temporary transcripts or extracted text used to verify an AI result are subject to the source-retention schedule in the Privacy Notice. Coach-authored records remain subject to the Controller's chosen lawful retention and deletion instructions.

10. Information and audits

Mnemia will make available information reasonably necessary to demonstrate compliance with this DPA and permit a proportionate audit no more than once per year, unless a breach, regulator, or credible compliance concern reasonably requires more. The Controller will first use available reports and remote evidence, protect confidential information, avoid disruption, and bear its own audit costs. Mnemia will promptly tell the Controller if, in its opinion, an instruction infringes applicable data-protection law and may pause that instruction while the parties resolve it.

11. Duration, priority, and law

This DPA begins when an authorised person accepts it for the Controller and lasts while Mnemia processes Controller data. If it conflicts with the general Terms on protection of Controller data, this DPA controls. Swiss law and the forum stated in the Terms apply, without displacing mandatory data-protection rights.

Annex 1: Processing details

  • Subject matter and purpose: secure client and relationship management; manual coaching records; and, only when enabled, transcription, analysis, recaps, continuity, homework, and coach reflection.
  • Duration: for the account or relationship term, plus documented source, deletion, backup, and lawful-retention periods.
  • Operations: collection, receipt, organisation, storage, encryption, retrieval, consultation, transmission to authorised sub-processors, analysis, display, export, restriction, and deletion.
  • Data subjects: coaches, prospective and active clients, portal users, and people lawfully mentioned in coaching records.
  • Data: identity and contact data, relationship metadata, manual notes, recordings and uploaded material processed transiently, transcripts and extracted text, approved outputs, permissions and notices, and limited security and audit metadata.
  • Sensitive data: coaching material may reveal health, intimate-sphere, religious, political, philosophical, trade-union, biometric, sexual-life, or other sensitive or special-category information. Mnemia does not require these details and the Controller must minimise them.

Annex 2: Current safeguards

  • Swiss primary data storage and configured Switzerland/EU application processing.
  • AES-256-GCM field encryption for stored session content, with separated key derivation.
  • Authentication, least-privilege roles, row-level security, and client-view restrictions.
  • Permission gates before AI processing and recording-run gates before microphone use.
  • Transient handling of original media, source-retention limits, and deletion evidence.
  • Change-controlled policy versions and append-only legal and permission evidence.
  • Security testing, dependency review, logging, backups, and incident response procedures.

Contact

DPA and audit questions can be sent to privacy@mnemia.ch.

Review version 2026-08-23-review-v1. This is the complete production review agreement. A material amendment after counsel review will receive a new version and fresh acceptance where required.

Mnemia

Continuity in your practice.

Product
How it worksPricingChangelogTry Mnemia
Company
AboutFAQContactSign in
Legal
Privacy NoticeTerms of ServiceData Processing AgreementSub-processorsLegal notice
© 2026 Mnemia
ENFRDE
Designed and built by 0xCreativeMind