Version 5 · Effective 2026-08-15
This document is a draft and has not yet been reviewed by legal counsel. It is not yet in effect.
Sub-processors
Version: 5 · Last revised: August 15, 2026 · not yet in effect — see the notice above
Coachstra uses the following sub-processors to provide the Service. Each is bound by a data processing agreement with Coachstra imposing obligations no less protective than our own Data Processing Agreement.
We will give at least 30 days' notice before adding or replacing a
sub-processor, and provide a genuine opportunity to object on reasonable
data protection grounds. Notice is sent by email to the address on your
Coachstra account — there is nothing to subscribe to, and no way to miss
it by not having opted in. If you would like notice sent to a different
address, such as a privacy or compliance mailbox, email
info@coachstra.com and we will record it.
| Vendor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database, authentication, file storage | EU (Ireland, eu-west-1) / US-headquartered | SCCs + published Transfer Impact Assessment. Production data is stored in Ireland; the separate development environment runs in Frankfurt and holds no production Customer Data. |
| Vercel | Application hosting and request processing | US (us-east-1, Virginia) — moving to EU | EU-US Data Privacy Framework + SCCs. Note that Customer Data is stored in the EU but currently processed on US infrastructure while serving requests; we are moving processing into the EU so both sit in the same region. See Technical and Organisational Measures, "Data locations". |
| OpenAI | Session transcription (Whisper), AI note generation, and briefings prepared from a client's written intake answers (currently gpt-4o, configurable and subject to change as OpenAI's offerings improve) | US | SCCs, via OpenAI's own Data Processing Addendum (SCC-based), accepted and on file for the Coachstra organization. |
| Stripe | Payment processing | US / IE | EU-US Data Privacy Framework + SCCs. Stripe is also an independent controller for payment and anti-fraud data it collects directly. |
| Daily.co | In-app video sessions | US | EU-US Data Privacy Framework + SCCs (Daily is DPF-certified per its own GDPR compliance page, and maintains a Data Processing Addendum covering GDPR transfer terms). |
| SignWell | Contract e-signature | US | SignWell's public privacy policy names no SCC/DPF transfer mechanism, citing a contract-necessity/consent basis instead — an open question for legal review, not yet resolved. |
| Resend | Transactional email delivery | US | EU-US Data Privacy Framework + SCCs (EU SCCs and UK SCCs), per Resend's own Data Processing Addendum. |
| Google (Gmail API) | Coach-authorized email sync | US | Google is DPF-certified and separately offers SCCs at the vendor level. Whether this coach-authorized OAuth integration makes Coachstra a sub-processor of Google, versus a direct coach-to-Google relationship outside this DPA, is an open legal question currently under review with our counsel. |
| Zoom | Coach-authorized meeting creation for booked sessions | US | Zoom is DPF-certified and separately offers SCCs in its own Global Data Processing Addendum. Only meeting metadata (ID, topic, start time, join URL) and the connected account's email are exchanged — no recordings, transcripts, chat, or meeting content. The same sub-processor-classification question as the Google and Microsoft rows applies here. |
| Google (Calendar / Meet) | Coach-authorized calendar sync and Meet link creation | US | Same vendor mechanism as the Gmail row above (DPF + SCCs at vendor level). Meet links are created through the Calendar API's conferencing data; no separate Meet content is accessed. |
| Microsoft (Graph — Teams & Calendar) | Coach-authorized Teams meeting creation and Outlook calendar sync for booked sessions | US | Microsoft is DPF-certified and separately offers SCCs (EU Model Clauses) at the vendor level. Only meeting metadata, the join link, and calendar event titles/times are exchanged — no meeting content, recordings, or email. The same sub-processor-classification question as the Google rows applies here. |
We do not rely on Data Privacy Framework certification alone for any vendor. Standard Contractual Clauses are our primary safeguard for every transfer outside the EEA, with DPF certification treated as an additional layer where a vendor holds it — not a substitute for SCCs.
This document is a draft. The remaining open item above — whether coach- authorized OAuth integrations (Google, Microsoft) make Coachstra a sub-processor of those vendors — must be resolved before this page is published as a binding, final sub-processor list. WhatsApp/Twilio/Meta are not listed here because no WhatsApp integration exists in the product today (cut from MVP scope per D-024, 2026-07-30) — add this row back if and when that integration is actually built, not before.