Trust

Security and privacy at Coaching Loft

Coaching conversations are confidential, and the platform that stores them has to treat them that way.

This page explains how Coaching Loft protects your data, who can see what inside an account, and what your IT and procurement teams can request from us.

How your data is protected

Coaching Loft is based in Dubai. Our servers and offices are located in the United Arab Emirates, and the platform runs on infrastructure from third-party cloud providers that hold SOC 2 Type 2 and ISO 27001 certifications, among others. Those certifications belong to our hosting providers, not to Coaching Loft itself.

  • Encryption: data is encrypted in transit, with HTTPS enforced and current TLS versions required, and data is encrypted at rest. 256-bit encryption is included on every plan.
  • Infrastructure access: multi-factor authentication is required to reach our cloud resources, and firewall rules prevent unauthorized access to services such as SSH, RDP, FTP and databases.
  • Monitoring: security logging, threat detection and alerting run across our cloud infrastructure, and access and configuration changes are tracked.
  • Backups: backups are maintained for critical services to support recovery if a system fails.
  • Incidents: if a security breach materially affects you or your clients, we will notify you as soon as possible and then report the action we took in response.

Access control

Coaching firms and enterprises decide who can sign in and what each person can do once they are in.

  • Single sign-on (SSO): connect Coaching Loft to your organization's identity provider so access follows your IT policies. SSO is a paid add-on for firm and enterprise accounts, priced by the number of coach seats.
  • Two-factor authentication (2FA): each sign-in is confirmed with a six-digit code from an authenticator app such as Google Authenticator or Microsoft Authenticator. Enterprise administrators can require 2FA for their coaches and coachees.
  • Four authorized-user types: Super Admin, Admin, Local Admin and Program Sponsor. A Super Admin always holds every permission. For the other three, a permission matrix sets access feature by feature: on or off, or view, edit, or edit and delete.
  • A clear hierarchy: people can change permissions for, or remove, only the users below their own level, and a Local Admin works only within the organizations they belong to.
  • Exporting data is a permission of its own, and it starts switched off for Admins.

Confidentiality of coaching

The organization that pays for coaching should be able to follow progress without reading the conversations. Coaching Loft is set up that way by default.

  • Coaches decide, session by session, whether to share their notes with the coachee, and can make a shared session private again.
  • Session notes are locked from administrators by default. The permission that lets an Admin, Local Admin or Program Sponsor open session notes (View session log data) is off for the whole account, and no one inside the account can switch it on, including the account owner. It is unlocked only when the account owner asks Coaching Loft to unlock it.
  • By default, Program Sponsors see progress, not session content: only the engagements and coaching packages they are assigned to.
  • Video call recordings are not kept on the platform. When a coach records a session, the file is offered for download at the end of the call, and the platform deletes it once the meeting room is closed.
  • AI note summaries work only from the notes a coach writes. They do not record or transcribe sessions.

Your data, your rights

You own the data you put into Coaching Loft. We do not sell it, we do not give your email address to other parties for marketing, and we do not use your data to serve you ads.

  • Export: take your data out when you need it, as HTML client export files, downloadable reports, CSV exports of session logs, or a raw JSON dump of all account data.
  • Deletion: coaches can delete client data at any time and can request deletion of their account from their account settings. Once the request is verified, the account and its data, including session notes and uploaded files, are permanently deleted.
  • Data processing agreements: available for enterprise clients.
  • GDPR: our GDPR Compliance document sets out the lawful bases we rely on and your rights under the GDPR, including access, correction, erasure, restriction, portability, objection and withdrawal of consent.
  • HIPAA: our HIPAA Compliance page describes our safeguards, and a Business Associate Agreement is available on request.
  • AI features: you can opt out of your data being used for AI-powered analytics and model improvement by emailing [email protected]. Opting out turns off AI Reports and Predictive Analytics, which depend on that data.

White label

Coaching firms and enterprises can present Coaching Loft to their coaches and coachees under their own brand.

  • Your own domain: run the platform on a subdomain you own, such as app.yourcompany.com, verified through DNS records you add.
  • Your branding: your logo and color scheme across the admin, coach and coachee portals, the login page and automated emails, with navigation you configure.
  • A branded login page that you can link from your own website.
  • Your own email sending domain (enterprise accounts): invitations, reminders and other platform emails are sent from your company's verified domain, authenticated through DNS records.

Request our security documentation

For a security or procurement review, request our Security Audit Report. It gives an overview of our security practices, compliance measures and infrastructure protections. It is confidential and provided solely for evaluation purposes.

Use the Request our security documentation button on this page to reach the request form. The report covers:

  • Data protection and encryption standards
  • Access control and authentication methods
  • GDPR and HIPAA compliance rules, checklists and the measures we have taken
  • A cloud compliance report

Questions

What IT and procurement teams ask.

Is Coaching Loft SOC 2 or ISO 27001 certified?

Coaching Loft itself does not have a published SOC 2 report or ISO 27001 certificate. The cloud providers that host the platform hold SOC 2 Type 2 and ISO 27001 certifications, among others. For your review, our Security Audit Report is available on request. It covers our data protection and encryption standards, access control and authentication methods, GDPR and HIPAA measures, and a cloud compliance report.

Where is our data stored?

Our servers and offices are located in the United Arab Emirates, so information you store in Coaching Loft is transferred to and stored in the UAE, on infrastructure from cloud providers that hold SOC 2 Type 2 and ISO 27001 certifications. Coaching Loft is based in Dubai. Some services we rely on to run the platform, such as email delivery, payments, video meetings and calendar sync, process data outside the UAE; they are covered in our Privacy Policy. For transfers of personal data from the European Union, see our GDPR Compliance document.

Is our data encrypted?

Yes. Data is encrypted in transit, with HTTPS enforced and current TLS versions required, and data is encrypted at rest. 256-bit encryption is included on every plan.

Can our administrators or program sponsors read coaching session notes?

Not by default. The permission to open session notes (View session log data) is locked for the whole account, and no one in your account can switch it on, including the account owner. It is unlocked only at the account owner's request to Coaching Loft, and can then be granted role by role. Program Sponsors see the engagements and packages they are assigned to, so they can follow progress without seeing session content.

Do you support single sign-on and two-factor authentication?

Yes. Single sign-on connects Coaching Loft to your organization's identity provider and is a paid add-on for firm and enterprise accounts, priced by the number of coach seats. Two-factor authentication uses an authenticator app such as Google Authenticator or Microsoft Authenticator, and enterprise administrators can require it for their coaches and coachees.

Will you sign a data processing agreement or a business associate agreement?

Data processing agreements are available for enterprise clients. If you handle protected health information, a Business Associate Agreement is available on request, as described on our HIPAA Compliance page. Contact us to start either one.

Need more detail for your review?

Request our security documentation, or book a demo and bring your IT questions.