Version 1 · Effective 2026-08-15
This document is a draft and has not yet been reviewed by legal counsel. It is not yet in effect.
Sub-processors
Effective date: August 15, 2026 · Version: 1
Coachstra uses the following sub-processors to provide the Service. Each is bound by a data processing agreement with Coachstra imposing obligations no less protective than our own Data Processing Agreement.
We will give at least 30 days' notice before adding or replacing a sub-processor, and provide a genuine opportunity to object on reasonable data protection grounds. To be notified of changes, [PENDING: link a change-notification subscription mechanism once built].
| Vendor | Purpose | Location | Transfer mechanism |
| ----------------------- | -------------------------------------------------------------- | ---------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Supabase | Database, authentication, file storage | EU (Frankfurt region) / US-headquartered | SCCs + published Transfer Impact Assessment |
| Vercel | Application hosting | US | EU-US Data Privacy Framework + SCCs |
| OpenAI | Session transcription (Whisper) and AI note generation (GPT-4) | US | SCCs (confirmed — OpenAI's own Data Processing Addendum is SCC-based). DPF certification could not be independently confirmed from a primary source in this review — do not cite DPF for OpenAI until a signed copy of OpenAI's DPA on file confirms it. |
| Stripe | Payment processing | US / IE | EU-US Data Privacy Framework + SCCs. Stripe is also an independent controller for payment and anti-fraud data it collects directly. |
| Daily.co | In-app video sessions | US | EU-US Data Privacy Framework + SCCs (Daily is DPF-certified per its own GDPR compliance page, and maintains a Data Processing Addendum covering GDPR transfer terms). |
| Recall.ai | Desktop system-audio session capture | US | SCCs (EU SCCs and UK SCCs), per Recall.ai's own Data Processing Agreement — no DPF certification found. |
| SignWell / Dropbox Sign | Contract e-signature | US | Split finding — vendor choice not yet finalized (see security.md). Dropbox Sign confirms SCCs (Processor-to-Processor Model Clauses) in its own DPA. SignWell's public privacy policy names no SCC/DPF mechanism at all, instead citing a contract-necessity/consent basis — flagged as a real open question for the lawyer brief, not a research gap. |
| Resend | Transactional email delivery | US | EU-US Data Privacy Framework + SCCs (EU SCCs and UK SCCs), per Resend's own Data Processing Addendum. |
| Twilio / Meta Cloud API | WhatsApp messaging | US | Twilio: EU-US Data Privacy Framework + SCCs (2021 EU SCCs), per Twilio's own Data Protection Addendum. Meta Cloud API (the untaken alternative per CLAUDE.md) has not been separately verified — re-run this check if that path is chosen instead. |
| Google (Gmail API) | Coach-authorized email sync | US | Google is DPF-certified and separately offers SCCs at the vendor level. Whether this coach-authorized OAuth integration makes Coachstra a sub-processor of Google (vs. a direct coach-to-Google relationship outside Coachstra's own DPA) is a legal judgment call, not a factual lookup — routed to the lawyer brief, question 11. |
| Microsoft (Graph API) | Coach-authorized email sync | US | Microsoft is DPF-certified and separately offers SCCs (EU Model Clauses) at the vendor level. Same sub-processor-classification question as Google above — routed to the lawyer brief, question 11. |
We do not rely on Data Privacy Framework certification alone for any vendor. Given the ongoing legal challenge to the EU-US DPF as of mid-2026 (see our Data Processing Agreement, Section 11), Standard Contractual Clauses are the primary safeguard we rely on, with DPF treated as an additional, not sole, layer where a vendor holds it.
This document is a draft. The remaining open items above (OpenAI's DPF status, the SignWell/Dropbox Sign choice, Meta Cloud API's mechanism if chosen over Twilio, and the Google/Microsoft OAuth sub-processor classification) must be resolved before this page is published as a binding, final sub-processor list — see Issue #35's lawyer brief.