Secure coaching software: privacy and GDPR points to check
What privacy, security and data handling points coaches should check before centralizing clients and sessions in software.
Updated
Short answer: what secure, GDPR-aware coaching software must provide
At a minimum, GDPR-aware coaching software should host your data in the European Union or under equivalent safeguards, encrypt it in transit and at rest, keep it isolated from other users' data, let you export and delete it yourself, and publish a privacy policy that lists its sub-processors.
The tool does not do everything, though: you decide what information you collect about clients and what you do with it. This article offers general good-practice guidance; it is not legal advice for your specific situation.
- EU hosting or equivalent safeguards
- Encryption in transit and at rest
- Strict data isolation between accounts
- Self-service export and deletion
- Published privacy policy and sub-processor list
Who is responsible for what?
For your clients' data, you are generally the controller: you choose to collect a name, a phone number or session notes, and for what purpose. The software vendor then acts as a processor: it handles that data on your behalf and on your instructions, and GDPR (Article 28) requires that relationship to be covered by contractual commitments.
For your own account data (your name, email, subscription), the vendor is the controller. Keeping this distinction in mind tells you what to check with the vendor and what you need to organize yourself.
The data coaches actually need, and what to avoid
Running a coaching practice requires very little: identity and contact details, appointment history, payment status and a few notes that support follow-up. That is the data minimization principle: collect only what genuinely serves the coaching.
Some categories of data get special protection under GDPR (Article 9): health, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation. Fitness, nutrition and wellness coaches run into these quickly. Unless you have a strict need and a clear legal basis, keep them out of your management tools.
- Useful: name, email, phone number
- Useful: session dates, formats and attendance
- Useful: payment status for each session
- Useful: goals and agreed actions
- Avoid: diagnoses, treatments, medical conditions
- Avoid: beliefs, intimate details, screenshots of conversations
Checklist: 10 questions to ask before choosing a tool
The answers should be in the vendor's privacy policy and documentation. If you cannot find them, or they are vague, that is an answer in itself.
- Where is the data hosted?
- Which sub-processors are involved, and for what?
- Is data encrypted in transit and at rest?
- How is my data isolated from other accounts?
- Can I export my data in a readable format?
- Can I delete a client, then my account, without contacting support?
- What happens to the data after account deletion?
- Which data flows to integrations such as calendar or payments?
- How are access and passwords protected?
- Is the client's acceptance of my terms recorded?
Good practices for coaches, step by step
Step 1 — Map your processing: which data, for what purpose, in which tools, for how long. Data protection authorities such as France's CNIL publish simple record templates for small businesses.
Step 2 — Inform your clients: a few clear lines on your booking page or in your terms explaining what you collect and why. Managing appointments generally relies on performing your contract with the client, not on consent.
Step 3 — Set retention periods and stick to them. For prospects, the CNIL uses three years after the last contact as a benchmark; for former clients, set a reasonable, documented period that also reflects your accounting obligations.
Step 4 — Secure your access: a unique password, two-factor authentication on your email, a locked phone, no shared accounts.
Step 5 — Be ready for requests: a client can ask to access or delete their data, and you are generally expected to respond within one month.
Step 6 — Know how to react to an incident: when a data breach poses a risk to people, GDPR requires notifying your data protection authority within 72 hours.
Example: where data goes when a client books
Follow one typical booking to map your data flows. The client enters their name, email and phone number on your booking page and accepts your cancellation policy. That data is stored in your software, which sends a confirmation email through an email delivery provider.
If you sync your calendar, an event is created there: check what it contains, because calendars are often shared with family or colleagues. If the client pays online, their card details are entered on the payment provider's page and never pass through you. This ten-minute exercise covers most of your processing record for bookings.
What Grix actually does
Grix data is hosted in the European Union: database and files with Supabase, and the application served by Vercel from the Paris region. Data is encrypted in transit and at rest, and database row-level security ensures no coach can access another coach's data. Google Calendar access tokens are encrypted (AES-256-GCM); Grix only reads your busy times, never the titles or attendees of your own events, and the events it creates for your sessions are private and contain neither client contact details nor your notes.
From Settings you can export all your data as JSON or CSV and delete your account: deletion is immediate and permanent. A deleted client goes to the trash first, from where you can delete them permanently. The client's acceptance of your cancellation policy is recorded at booking, and sub-processors are listed in the privacy policy. Grix is not designed to host health data, though: what you write in your notes remains your responsibility.
Common mistakes
Most risks do not come from sophisticated attacks but from everyday habits.
- A client spreadsheet shared through a public link
- Health details exchanged over WhatsApp
- Data kept forever “just in case”
- A client list imported into an email marketing tool without a legal basis
- A reused password, or one shared with a relative
- Screenshots of client conversations sitting in your phone's photo gallery
Turn scattered admin into a structured coaching business
Grix brings clients, sessions, bookings and payment tracking into one workflow built for independent coaches.
Start with a structured toolFree · No credit card · No commitment
Frequently asked questions
Is Grix GDPR compliant?
Grix is built with GDPR in mind: data hosted in the EU, encryption, data isolation, self-service export and deletion. Your practice's compliance also depends on how you use it: what you collect, how you inform clients and how long you keep data.
How long should I keep client data?
There is no single answer: set a period tied to the purpose, then delete or anonymize. For prospects, France's CNIL uses three years after the last contact as a benchmark; some accounting records, however, must be kept longer.
Can I export or delete my clients' data?
Check that your tool lets you do it without contacting support. In Grix, a full export is available as JSON or CSV from Settings, and a deleted client goes through the trash before permanent deletion.
Should I store health data in my coaching software?
No, unless there is a clear need and a proper legal basis. Coaching management software should stay operational: record goals and actions, not diagnoses or treatments.
Do I need client consent to store their details?
Usually not: managing appointments generally relies on performing your contract with the client. You do need to inform them clearly about how their data is used. If in doubt, get professional advice.
Is it risky to connect my calendar to coaching software?
Not if permissions are limited. Check what the tool asks for: to prevent double bookings it only needs your busy times and the events it creates itself, not the content of all your appointments.