Version 5 · Effective 2026-08-15

This document is a draft and has not yet been reviewed by legal counsel. It is not yet in effect.

Sub-processors

Version: 5 · Last revised: August 15, 2026 · not yet in effect — see the notice above

Coachstra uses the following sub-processors to provide the Service. Each is bound by a data processing agreement with Coachstra imposing obligations no less protective than our own Data Processing Agreement.

We will give at least 30 days' notice before adding or replacing a sub-processor, and provide a genuine opportunity to object on reasonable data protection grounds. Notice is sent by email to the address on your Coachstra account — there is nothing to subscribe to, and no way to miss it by not having opted in. If you would like notice sent to a different address, such as a privacy or compliance mailbox, email info@coachstra.com and we will record it.

VendorPurposeLocationTransfer mechanism
SupabaseDatabase, authentication, file storageEU (Ireland, eu-west-1) / US-headquarteredSCCs + published Transfer Impact Assessment. Production data is stored in Ireland; the separate development environment runs in Frankfurt and holds no production Customer Data.
VercelApplication hosting and request processingUS (us-east-1, Virginia) — moving to EUEU-US Data Privacy Framework + SCCs. Note that Customer Data is stored in the EU but currently processed on US infrastructure while serving requests; we are moving processing into the EU so both sit in the same region. See Technical and Organisational Measures, "Data locations".
OpenAISession transcription (Whisper), AI note generation, and briefings prepared from a client's written intake answers (currently gpt-4o, configurable and subject to change as OpenAI's offerings improve)USSCCs, via OpenAI's own Data Processing Addendum (SCC-based), accepted and on file for the Coachstra organization.
StripePayment processingUS / IEEU-US Data Privacy Framework + SCCs. Stripe is also an independent controller for payment and anti-fraud data it collects directly.
Daily.coIn-app video sessionsUSEU-US Data Privacy Framework + SCCs (Daily is DPF-certified per its own GDPR compliance page, and maintains a Data Processing Addendum covering GDPR transfer terms).
SignWellContract e-signatureUSSignWell's public privacy policy names no SCC/DPF transfer mechanism, citing a contract-necessity/consent basis instead — an open question for legal review, not yet resolved.
ResendTransactional email deliveryUSEU-US Data Privacy Framework + SCCs (EU SCCs and UK SCCs), per Resend's own Data Processing Addendum.
Google (Gmail API)Coach-authorized email syncUSGoogle is DPF-certified and separately offers SCCs at the vendor level. Whether this coach-authorized OAuth integration makes Coachstra a sub-processor of Google, versus a direct coach-to-Google relationship outside this DPA, is an open legal question currently under review with our counsel.
ZoomCoach-authorized meeting creation for booked sessionsUSZoom is DPF-certified and separately offers SCCs in its own Global Data Processing Addendum. Only meeting metadata (ID, topic, start time, join URL) and the connected account's email are exchanged — no recordings, transcripts, chat, or meeting content. The same sub-processor-classification question as the Google and Microsoft rows applies here.
Google (Calendar / Meet)Coach-authorized calendar sync and Meet link creationUSSame vendor mechanism as the Gmail row above (DPF + SCCs at vendor level). Meet links are created through the Calendar API's conferencing data; no separate Meet content is accessed.
Microsoft (Graph — Teams & Calendar)Coach-authorized Teams meeting creation and Outlook calendar sync for booked sessionsUSMicrosoft is DPF-certified and separately offers SCCs (EU Model Clauses) at the vendor level. Only meeting metadata, the join link, and calendar event titles/times are exchanged — no meeting content, recordings, or email. The same sub-processor-classification question as the Google rows applies here.

We do not rely on Data Privacy Framework certification alone for any vendor. Standard Contractual Clauses are our primary safeguard for every transfer outside the EEA, with DPF certification treated as an additional layer where a vendor holds it — not a substitute for SCCs.


This document is a draft. The remaining open item above — whether coach- authorized OAuth integrations (Google, Microsoft) make Coachstra a sub-processor of those vendors — must be resolved before this page is published as a binding, final sub-processor list. WhatsApp/Twilio/Meta are not listed here because no WhatsApp integration exists in the product today (cut from MVP scope per D-024, 2026-07-30) — add this row back if and when that integration is actually built, not before.