Version 1 · Effective 2026-08-15
This document is a draft and has not yet been reviewed by legal counsel. It is not yet in effect.
Data Processing Agreement
Effective date: August 15, 2026 · Version: 1
This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Controller") and Ladoos Consultancy BV ("Processor," "Coachstra") for use of the Service, and is automatically accepted alongside our Terms of Service at signup — no separate signature is required for this DPA to take effect, consistent with GDPR Article 28(9)'s permission for electronic form. If your organization requires a counter-signed copy for internal record-keeping, contact us and we will provide one.
1. Subject matter, duration, and nature of processing
Coachstra processes personal data on your behalf for the duration of your subscription, for the purpose of providing the practice-management Service described in the Terms of Service: storing and displaying client records, facilitating scheduling, recording and transcribing sessions where you have enabled it, generating AI-assisted notes and summaries, and related features you activate.
2. Categories of data and data subjects
Data: client contact and profile information, intake-form responses, session recordings and transcripts, AI-generated notes and summaries, contract and e-signature records, message content synced from connected email/WhatsApp accounts.
Data subjects: your clients, and where relevant, other participants in group or team coaching sessions.
3. Controller's instructions
Coachstra will process personal data only on your documented instructions, including with regard to transfers to a third country, unless required to do otherwise by EU or Member State law — in which case we will inform you of that legal requirement before processing, unless the law prohibits this. Using the Service's features as designed (recording, transcription, AI notes, etc.) constitutes your instruction to process accordingly.
We do not use Customer Data — your client data, recordings, transcripts, or AI outputs — for any purpose beyond providing the Service to you, including model training, cross-customer benchmarking, or product research on real content. Doing so would make us a controller of that data under GDPR Article 28(10), which we commit not to become.
4. Confidentiality
Coachstra ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security measures
Coachstra implements the technical and organisational measures described in Annex 2 (Technical and Organisational Measures), designed to ensure a level of security appropriate to the risk, including encryption in transit and at rest, access controls scoped per coach/practice, and audit logging of access to session content.
6. Sub-processors
Coachstra has your general authorization to engage the sub-processors listed at /subprocessors. We will give notice of any intended addition or replacement at least 30 days before it takes effect and will provide a genuine opportunity to object on reasonable data protection grounds. We remain fully liable to you for each sub-processor's performance of its data protection obligations, and impose data protection terms on each sub-processor no less protective than those in this DPA.
7. Assistance with data subject rights and security obligations
Taking into account the nature of processing, Coachstra will assist you, by appropriate technical and organisational measures, in fulfilling your obligation to respond to data subject rights requests (access, rectification, erasure, restriction, portability). We will also assist you in ensuring compliance with your obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessment, prior consultation), taking into account the information available to us. If a data subject contacts Coachstra directly, we will not act on the request ourselves — we will inform the requester that you are their controller and forward the request to you without undue delay.
8. Breach notification
Coachstra will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, providing the information reasonably available to us to help you meet your own 72-hour notification obligation to your supervisory authority.
9. Deletion or return of data
On termination of the Service, Coachstra will, at your choice, delete or return all Customer Data, and delete existing copies, within a reasonable period (subject to any legal obligation requiring continued storage), as described further in our Privacy Policy's retention section.
10. Audits and information
Coachstra will make available to you all information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice and confidentiality.
11. International transfers
Where Customer Data is transferred outside the EEA — including to sub-processors located in the United States — Coachstra relies on the EU Standard Contractual Clauses (Module 3: processor to processor) as the transfer mechanism, supplemented where relevant by additional safeguards described in our sub-processor list. We do not rely solely on Data Privacy Framework certification given its ongoing legal challenge as of mid-2026.
Annex 1: Description of Processing
See Section 2 above (categories of data and data subjects) and the sub-processor list for the vendors involved in each processing activity.
Annex 2: Technical and Organisational Measures
- Encryption in transit (TLS) for all connections; encryption at rest for stored data via our infrastructure provider.
- Row-level access controls scoping every coach's data to that coach's own practice; a separate, more restrictive access tier for sponsor/aggregate reporting roles that cannot reach individual session content.
- Consent gates enforced server-side before any recording or AI processing begins.
- Access logging for recordings, transcripts, and session notes.
- [PENDING: confirm and list backup frequency, incident-response point of contact, and any relevant certifications once available.]
Annex 3: Sub-processors
See /subprocessors for the current, authoritative list.
This document is a draft pending review by a Belgian privacy lawyer, including specific confirmation of the processor-vs-joint-controller question for the AI processing pipeline (see Issue #35's lawyer brief). It is not yet in effect and must not be relied upon as binding until that review is complete.