Coachvox and GDPR

How we handle your and your clients’ data

We take GDPR seriously. As a platform that helps coaches run AI chats with their clients, we’re trusted with sensitive information. This page gives a clear, short overview of how we handle that data and what you can expect from us. It’s written for busy coaches; plain English first, legal detail in the linked policies.

Who GDPR applies to

GDPR (and UK GDPR) applies when you’re based in the EU/EEA or UK, or when you target or monitor people there, even if your business is elsewhere.

 

It also applies to us when we offer our service to coaches in the EU/EEA or UK, or when we otherwise handle personal data of people in those regions.

 

In practice, if you or your clients are in a GDPR region, or you actively market to/track people there, GDPR is in scope for you – and for us when we provide the service to you. Further detail on roles appears in the next section and in our policies.

Our roles and responsibilities

Your role
You (the coach or coaching business) run your programme and manage your client relationships.

 

Our role
We provide the platform that powers your AI chats and take appropriate steps to keep it secure and compliant with applicable data protection requirements.

 

Conversation data (what clients and the AI say)
We and you are joint controllers for this data for a few limited, disclosed purposes—like generating aggregate insights about common client challenges and carrying out product quality/safety checks. We don’t use conversation content for unrelated marketing.

 

Account/registration data (sign-ups, workspace setup)
For this data we act as your processor and handle it under your instructions.

 

When Coachvox acts as your processor

This section forms part of our Terms and Conditions and applies when Coachvox processes personal data on your behalf as a processor, including end-user account data.

 

For this processing:

  • Subject matter: providing and operating Coachvox accounts and related platform functionality for your end users.
  • Duration: for as long as we provide the relevant services to you, subject to our data retention and deletion requirements.
  • Nature and purpose: collecting, storing and otherwise processing end-user account data as necessary to provide the Coachvox service on your behalf.
  • Types of personal data: account and registration information such as names, email addresses and related account information.
  • Data subjects: your clients and other end users you authorise to access your AI.
  • Your role: you determine the purposes and means of processing this data and are responsible for your obligations as controller.

 

In accordance with Article 28 of GDPR and UK GDPR, when acting as your processor, Coachvox will:

  • process personal data only on your documented instructions, including in relation to international transfers, unless we are required to process it by law;
  • ensure anyone authorised to access the data is subject to appropriate confidentiality obligations;
  • implement appropriate technical and organisational measures to protect the data;
  • appoint subprocessors as necessary to provide the service under your general authorisation. We will ensure each subprocessor is subject to appropriate data protection obligations. If we intend to add or replace a subprocessor involved in processing personal data on your behalf, we will notify you in advance and give you a reasonable opportunity to object on data protection grounds. Coachvox remains responsible for its subprocessors’ compliance with their applicable data protection obligations;
  • assist you, where reasonably possible, in responding to requests from individuals exercising their data protection rights;
  • assist you with your obligations relating to data security, personal data breaches, data protection impact assessments and regulatory consultation where applicable;
  • at the end of the relevant services, delete or return personal data at your choice in accordance with our applicable retention and deletion procedures, and delete existing copies unless applicable law requires us to retain them;
  • make available the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits or inspections as required by Article 28; and
  • inform you if, in our opinion, an instruction would infringe applicable data protection law.

 

Where this is documented
See our Terms & Conditions, Privacy Policy, and End-user Terms for the full definitions and safeguards.

AI and emerging rules

 

Why this matters

AI regulation in Europe is evolving alongside existing data protection law. Two developments are particularly relevant to the wider AI ecosystem:

 

EU AI Act (2024)
The EU AI Act introduces risk-based rules for developing and using AI systems, including requirements around transparency, oversight and safety. We review our product and practices against the requirements that apply to us.

 

GPAI Code of Practice (2025)
The Code provides guidance for providers of general-purpose AI models on areas including transparency, copyright, safety and security. We take these developing standards into account alongside the requirements that apply directly to Coachvox.

 

What this means for you

We continue to review our product, policies and in-product notices as AI and data protection requirements evolve.

Security, hosting & retention

How we protect data
Encryption in transit and at rest, least-privilege access, logging/monitoring, and regular testing. We design features with privacy and safety in mind.

 

Where data is stored
We mainly store data using Google Cloud (Firebase) in the US. When data moves across regions, we rely on standard contractual safeguards and equivalent protections, consistent with our policies.

 

UK data transfer

Coachvox uses trusted third-party providers to host and process data, primarily in the US. For UK personal data transferred outside the UK, we rely on safeguards recognised under UK data protection law:

 

  • Where a provider is certified under the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge), we rely on that certification.
  • Where a provider isn’t certified, we rely on the UK Addendum to the EU standard contractual clauses, which is included in that provider’s data processing agreement.

 

How long we keep it
We keep data only as long as needed to run the service, ensure safety/reliability, and meet legal requirements. You can request deletion according to our terms.

Talk to us

Got a question we haven’t covered? We’re happy to help.


Email us at hello@coachvox.com or via the support page in Coachvox and we’ll get back to you.

 

Quick links

Terms and Conditions  |  Privacy Policy  |  End User Terms