Version 3 · Effective 2026-08-15

This document is a draft and has not yet been reviewed by legal counsel. It is not yet in effect.

Technical & Organisational Measures

Version: 3 · Last revised: August 15, 2026 · not yet in effect — see the notice above

This document expands on the summary in our Data Processing Agreement's Annex 2, for use in customer security/procurement review. Where this document and the DPA's Annex 2 conflict, the DPA's Annex 2 controls contractually — this is the more detailed, non-contractual companion.

Organisational measures

Technical measures

Data locations

Storage. Customer Data is stored in the European Union. The production database and file storage run in eu-west-1 (Ireland); the separate development environment runs in eu-central-1 (Frankfurt) and holds no production Customer Data.

Processing. Application servers currently run in the United States (us-east-1, Virginia). Customer Data is therefore stored in the EU but read and processed on US infrastructure in the course of serving requests. This transfer is covered by the safeguards described in our Sub-processors notice and our Data Processing Agreement. We consider this a gap rather than a design choice, and are moving application processing into the EU (Ireland) so that storage and processing sit in the same region. This section will be updated when that move completes.

Backup and disaster recovery

The database and the stored files are covered differently. We state both separately rather than describing them together.

Database. Coachstra relies on the managed backup facilities of its database platform rather than operating its own schedule.

Stored files. Session recordings, signed contracts, receipts, uploaded session documents and profile images are held as objects in the platform's file storage, and database backups do not cover them. The platform provides no backup and no versioning for stored objects at any service tier, and deleting an object is immediate and irreversible. One consequence is worth stating plainly because it works in your favour: when a stored file is deleted, that deletion is final — no copy survives in a backup.

We have not yet set or tested a recovery time objective or recovery point objective, and do not claim one. Both will be stated here once they are defined and a restore has been rehearsed.

Sub-processor oversight

Each sub-processor we rely on is required to accept obligations no less protective than our own Data Processing Agreement with you. A signed data processing agreement confirming this is currently on file for OpenAI; for the remaining sub-processors listed in Sub-processors, this is our contracting standard rather than a confirmed, on-file fact for every vendor.

Testing and review

Coachstra does not currently run penetration testing, and has no established security-review cadence. Code changes are reviewed before merge and automated tests run in continuous integration, but neither is a substitute for independent security testing and we do not present them as one. Any testing cadence will be described here only once it actually exists.


This document must not claim measures that are not actually in place — every PENDING marker above reflects something to confirm against reality, not fill in with a plausible-sounding guess.