Exantur
Menu

Security

Coaching conversations involve a level of personal disclosure that is unusual in professional contexts. People share in coaching sessions things they may not share elsewhere - aspirations that feel too ambitious to state publicly, patterns of behavior they find difficult to acknowledge, fears about their competence or character, and experiences that shape their present. The trust that makes this depth of disclosure possible is not incidental to the coaching relationship - it is its foundation. The software that coaches use to document, track, and support those relationships is part of the professional environment in which that trust must be maintained.

All data stored and processed through Exantur is held in the European Union. The platform operates in compliance with the General Data Protection Regulation (GDPR). Access controls are enforced at the database layer through row-level security - a user cannot access data they do not have explicit permission to see, regardless of how that access is attempted. Coach-private notes are never accessible to coachees. Organization data is isolated at the organization level. Multi-factor authentication is available for all users and required by default for platform administrators. No user data is sold, used for advertising purposes, or shared with third parties except as strictly required to provide the service. All data is encrypted in transit (TLS) and at rest.

EU data residency

GDPR-compliant

Row-level security

Your data rights

Individual coachees can request a full export of their personal data or submit a request for permanent deletion of their account and all associated data at any time. The platform includes GDPR-compliant deletion flows for both individual coachees and entire organizations, with a grace period that allows for error correction before permanent deletion occurs. Data processing agreements are available to organizations that require them as part of their own compliance obligations, and can be downloaded directly from our DPA page.

Sub-processors

Exantur relies on a small number of carefully chosen sub-processors to deliver the service. Each is bound by a data processing agreement and processes only the data needed for its function.

Supabase
Database, authentication, file storage and serverless functions (EU region).
Cloudflare
Hosting, content delivery, bot protection and privacy-friendly analytics.
Stripe
Payment processing for subscriptions and coach-to-client invoicing.
Amazon Web Services (SES)
Transactional and notification email delivery.
Anthropic
AI-assisted features (Claude), via a server-side proxy.
Google
Calendar synchronisation when a coach connects Google Calendar.
Microsoft
Calendar synchronisation when a coach connects Outlook / Microsoft 365.

International data transfers

Your data is stored in the European Union. Where a sub-processor may process limited personal data outside the European Economic Area, that transfer is governed by the European Commission’s Standard Contractual Clauses and, where the provider participates, the EU–US Data Privacy Framework, the safeguards required under the GDPR following the Schrems II ruling.

Data breach notification

If a personal data breach occurs, we notify affected organizations without undue delay after becoming aware of it, so controllers can meet their GDPR obligation to inform the supervisory authority within 72 hours. Where a breach is likely to result in a high risk to individuals, affected users are informed without undue delay.

Request a demo

See the actual application in a live demo. No sales pressure, no obligation.