EraCoach

Privacy Policy

What we know about you, why we know it, how long we keep it, and what you can require of us.

In force since 29 September 2026·Version 2026-09-29

EraCoach connects professional coaches with people looking for support. That activity means processing personal data, including, at times, sensitive matters raised during coaching. This policy sets out precisely what we do with that data.

Two laws apply at the same time

Because the publisher is established in Quebec and the service is accessible from the European Union, we apply Quebec’s Law 25 and the GDPR. Where the two differ, we follow whichever rule protects you more.

1. Who is responsible for your data

The controller is Agile Smart (a sole proprietorship operated by Koffi Anani Hounnou), 206-25, avenue Vincent-D'Indy, Montréal (Québec) H2V 2S8, Canada, NEQ 2278861648.

The person in charge of the protection of personal information under Law 25, who is also your contact point for any GDPR question, is Koffi Anani Hounnou. You can reach them directly at [email protected].

A useful clarification on roles: when you book a session, the coach is responsible for their own practice and for any notes they keep outside the platform. We are responsible for the platform, the account, the booking and the payment. What your coach keeps on their own systems falls outside this policy: ask them directly.

2. The data we collect

There are three sources: what you give us, what your use of the service produces, and, for coaches only, what we gather from public sources.

2.1 What you give us

CategoryDetail
AccountName, email address, password (never stored in clear text), communication language, profile picture, phone number if you provide one
Coach profile (public)Description, professional title, specialisms, certifications and supporting documents, years of experience, rate and currency, languages spoken, city, links to your networks, photos
BookingTime slots, time zone, session format, message to the coach, cancellation reason where applicable
PaymentAmount, currency, status, transaction identifiers. No card data passes through or is stored on our servers: entry takes place with Stripe
ExchangesMessages sent through the platform’s messaging, reviews you publish, coaches’ replies to reviews
SupportContact requests, support tickets and attachments, reports
ApplicationsCV, cover letter and contact details if you answer a job posting or send a speculative application
SubscriptionsEmail address for the newsletter and job alerts, if you ask for them

What we ask you not to write

Platform messaging exists to organise your sessions. Do not use it to record health information, sexual orientation, political, religious or trade union views, or detailed personal difficulties. The substance of coaching belongs in a session, not in a message thread stored on our servers.

2.2 What your use produces

CategoryDetail
Technical and security logsIP address, user agent, timestamps, sign-ins and sign-in attempts, recognised devices, one-time codes
Activity logSignificant actions taken on the platform (account creation, booking, profile change, administrative action), for traceability and dispute resolution
Relationship historyPast sessions, cancellations, refunds, average ratings
Calendar (coaches, on activation)If you connect Google Calendar or an ICS feed, we read only your busy slots to prevent double bookings. We do not read event titles, attendees or contents
AnalyticsOnly if you consent: see the cookie policy
Email deliveryFor our transactional messages: delivered, opened, bounced, so we can detect invalid addresses

2.3 Coaches: data gathered from public sources

To build the directory, we sometimes identify professional coaches from public sources (professional websites, certification directories, public profiles) and contact them to offer a listing. We may then prepare a profile from that public information.

  • The data involved is strictly professional: name, activity, specialisms, city, professional contact details, information published by the person themselves.
  • A profile prepared this way is never published without the agreement of the person concerned. It stays offline until the coach has validated it.
  • The first message we send states where the information came from and how to request its deletion, in accordance with Article 14 GDPR.
  • Legal basis: our legitimate interest in building a professional directory. You may object at any time, without giving reasons, and deletion is immediate.

2.4 Data coaches record about their clients

A coach may keep, in their area, a record on the people they support. They may also add a person who has no EraCoach account themselves, for example to invite them to book. This section concerns you if you are, or have been, the client of a coach on EraCoach.

Who is responsible

The coach is responsible for this data: the coach decides what to record and why. EraCoach is only their technical provider (processor within the meaning of Article 28 GDPR): we host the data on the coach’s behalf, we do not read it and we do not use it for anything else, whether prospecting, statistics or artificial intelligence training.

DataWho sees itRetention period
Client record: name, email, phone, tagsThe coach only3 years after the last activity between the coach and you
Private session notesThe coach only, never you or another coach3 years after the last activity between the coach and you
Answers to welcome questions written by the coachThe coach only3 years after the last activity between the coach and you
Log of coaching hours (used for the coach’s certifications)The coach onlyThe hours remain; your name and contact details are erased from it 3 years after the session
Enrolment in a programme and prepaid packageThe coach and youSame as bookings and accounting records (see §4)
  • The “last activity” is the coach’s last change to your record or your last session with them. After 3 years, deletion is automatic.
  • Welcome questions are written by the coach, never by EraCoach. They are shown to you after your booking, are all optional, and you may skip them.
  • If the coach added you themselves, the email they send you from EraCoach tells you so and links to this section.
  • To exercise your rights (copy, rectification, deletion), contact the coach, who is responsible for this data. You may also write to us: we forward your request to the coach without delay and help them respond. If the coach closes their account, this data is deleted along with it.
  • Coaches are asked not to record health data, except where it is necessary for the coaching and you have consented.

3. Why we process this data, and on what basis

Every processing operation rests on a specific legal basis. Where the basis is consent, you can withdraw it at any time; where it is legitimate interest, you can object.

PurposeLegal basis (GDPR)What it covers
Create and manage your accountPerformance of the contractSign-up, authentication, profile management, preferences
Connect coach and clientPerformance of the contractSearch, display of public profiles, booking, messaging, calendar
Collect and pay outPerformance of the contractPayment, commission, payout to the coach, refunds, dispute handling
Issue and keep accounting recordsLegal obligationInvoices, tax records (GST/QST)
Verify coachesPerformance of the contract and legitimate interestChecking certifications and experience before a profile goes live
Secure the platformLegitimate interestFraud and abuse detection, security logs, protection against automated attacks
Moderate contentLegitimate interest and legal obligationHandling reports, removing unlawful content, enforcing the community guidelines
Improve the serviceConsentAnalytics: only if you accept
Keep you informedConsentNewsletter and job alerts, with an unsubscribe link in every message
Build the professional directoryLegitimate interestCoach prospecting from public sources (see §2.3)
Answer your requestsPerformance of the contract and legitimate interestSupport, complaints, exercise of your rights

Transactional messages. Messages that are essential to the service (booking confirmation, session reminder, receipt, password reset, notice of a change to the terms) are part of performing the contract. They are not marketing and therefore carry no unsubscribe link: opting out would mean no longer being told about your own appointments.

4. How long we keep it

DataRetentionWhy this period
Account and profileAs long as the account existsYou stay in control
After account deletion7-day cooling-off period, then anonymisationThe delay lets you undo a deletion started by mistake; beyond that, only data subject to a legal obligation remains
Bookings and messages3 years after the last sessionLimitation period applicable in Quebec, in case of a dispute
Invoices and accounting records6 yearsCanadian and Quebec tax obligations
Published reviewsAs long as the coach’s profile is onlineIf you delete your account, the review is detached from your identity rather than deleted, so the coach’s rating is not distorted
Security and audit logs12 monthsInvestigation in the event of an incident
Email delivery log12 monthsDetecting invalid addresses and proving dispatch
Cookie consent proof3 yearsAbility to demonstrate consent (Article 7(1) GDPR)
Data recorded by a coach about their clients (record, notes, answers to welcome questions)3 years after the last activity between the coach and the clientThe coach needs it while supporting the person; beyond that, nothing justifies keeping it (see §2.4)
Coaches contacted with no reply3 years after last contactFrench regulator’s recommendation on business prospecting
Applications2 years after the last exchangeFrench regulator’s recommendation
Newsletter and alertsUntil you unsubscribe, then 3 years of inactivityYou should not remain on a list you have left

These periods are enforced by a daily purge, not case by case.

5. Who can access your data

Internally, access is limited to those who need it for their role. Administrative accounts require two-factor authentication, and every sensitive action is logged.

Other users see your data only to the extent you decided: a coach’s profile is public by the coach’s own choice; a client’s identity is disclosed only to the coach they approached.

We do not sell your data and we do not rent it to anyone. No personal data is passed to data brokers or advertisers.

6. Our processors

We deliberately rely on a small number of providers. Each is bound by a data processing agreement and acts only on our instructions.

ProviderRoleData involvedLocation
Hetzner Online GmbHServer, database and file hostingAll platform dataNuremberg, Germany (EU)
Cloudflare, Inc.Content delivery network, protection against attacksIP address, request headersGlobal network, headquartered in the United States
Stripe, Inc. / Stripe Payments Europe Ltd.Payment, payouts to coaches, coach identity verification (KYC)Identity, contact details, payment data and the coach’s bank detailsIreland and United States
Resend, Inc.Sending transactional email and tracking deliveryEmail address, content of the message sentUnited States
Google Ireland Ltd.Analytics (with consent) and calendar sync (where a coach enables it)Pseudonymous measurement identifier; the coach’s busy calendar slotsIreland and United States
Functional Software, Inc. (Sentry)Application error monitoringTechnical context of the error, IP addressUnited States

The database is self-hosted. It runs on our own servers, with no managed database provider involved. Earlier versions of this page mentioned Vercel and Supabase Inc.: neither plays any part in processing your data.

7. Transfers outside Quebec and the European Union

Primary hosting is in the European Union. Some providers in the table above are nonetheless established in the United States, which amounts to a communication of personal information outside Quebec under Law 25, and a transfer outside the European Union under the GDPR.

  • Legal framework: each transfer relies on the European Commission’s standard contractual clauses and, where the provider participates, on the EU-US Data Privacy Framework.
  • Prior assessment: as required by Article 17 of Law 25, before any transfer we assess whether the information will receive adequate protection, having regard to its sensitivity, the purpose, and the safeguards in place.
  • Minimisation: we send each provider only what it strictly needs. Sentry receives technical context, not the content of your exchanges; Resend receives the email to be sent, not your history.

You can obtain a copy of the safeguards governing these transfers by writing to [email protected].

8. Automated decisions, profiling and artificial intelligence

No decision producing legal effects or significantly affecting you is taken on a solely automated basis. Verifying a coach, suspending an account and handling a dispute are decided by a person.

Search result ranking relies on objective criteria, relevance to your search, specialisms, language, city, average rating, profile completeness. It is not an automated individual decision within the meaning of Article 22 GDPR.

We use artificial intelligence tools to produce editorial content (articles, descriptions). Those tools do not receive your account, booking or message data. Should that change, this policy would be amended before any such use.

9. Minimum age

EraCoach is reserved for people aged 18 or over. We do not knowingly collect data about minors and do not offer them a service.

If you become aware that an account has been created by a minor, report it to [email protected]: the account will be closed and the data deleted without delay.

10. Security

The measures listed below are actually in place. We do not state guarantees here that we could not demonstrate.

  • All communications encrypted in transit (TLS).
  • Passwords stored as irreversible hashes: we cannot read them.
  • Data partitioned at database level: every query is filtered by access policies, including in the event of an application flaw.
  • Two-factor authentication required for administrative accounts.
  • Timestamped audit log of sensitive actions, visible to administration only.
  • Daily encrypted database backup, whose restoration is actually tested every month.
  • No card data on our servers: entry and storage are handled by Stripe, certified PCI-DSS Level 1.
  • Protection against automated attacks and abusive traffic upstream of our servers.

No measure makes a system impregnable. Choose a unique password, do not reuse it elsewhere, and tell us immediately about any suspicious activity on your account.

11. In the event of a confidentiality incident

We maintain a register of confidentiality incidents, as required by Law 25.

  • Where an incident presents a risk of serious injury, we inform the Commission d’accès à l’information du Québec and the individuals concerned promptly.
  • For people located in the European Union, notification to the supervisory authority is made within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.
  • The information provided states the nature of the incident, the data affected, the likely consequences and the steps you can take to protect yourself.

12. Your rights

Access
Confirm that we process your data and receive a copy of it.
Rectification
Have inaccurate or incomplete information corrected.
Erasure
Have your data deleted, except where the law requires us to keep it (accounting) or it remains necessary to establish a legal claim.
Portability
Receive, in a structured, machine-readable format, the computerised data you provided to us. This right is expressly provided by both the GDPR and Law 25.
Restriction
Ask that processing be frozen while a dispute is examined.
Objection
Object to processing based on legitimate interest, and at any time to prospecting.
Withdrawal of consent
Withdraw your agreement at any time, without calling into question what was done beforehand.
De-indexation and cessation of dissemination (Law 25)
Require that dissemination of information about you cease, or that a link giving access to it be de-indexed, where that dissemination causes you serious injury.
Automated decisions
Be told if a decision about you rests solely on automated processing, and obtain human intervention. No such processing is in place today.
Post-mortem instructions
Set instructions on what happens to your data after your death.

How to exercise these rights. Write to [email protected] or use the contact form. We reply within 30 days. If we need to verify your identity, we ask for the minimum necessary: never a copy of an identity document by plain email.

Some of these rights can be exercised straight from your account: change your information, remove your profile from public display, unsubscribe from mailings, and delete your account. Deletion is started from your settings and carried out after 7 days, during which you can change your mind. After that, your profile is anonymised and the data that belongs to you alone (favourites, saved searches, devices, payment methods, calendar connections) is deleted.

If our answer does not satisfy you, you may complain to the Commission d’accès à l’information du Québec or, if you live in the European Union, to your country’s supervisory authority, in France the CNIL, in Spain the AEPD. Complaining to an authority does not deprive you of any judicial remedy.

13. Cookies and trackers

Trackers placed on your device, their lifetime and how to refuse or withdraw your consent are covered by a dedicated document: the cookie policy.

14. Changes to this policy

This policy evolves with the service. Any substantive change (a new purpose, a new recipient, a new transfer outside Quebec or the EU, a change of controller) is notified to you by email at least 30 days before it takes effect, so that you can object or close your account.

Editorial corrections are signalled by updating the effective date and version number at the top of this page.

Privacy Policy | EraCoach