This statement explains how the Coaching Effectiveness Index (CEI) handles personal information. It is written for the organisations that use CEI — and for their privacy, risk, and procurement teams — who need to understand exactly how participant data is collected, stored, and protected.
CEI is a coaching-measurement service. It is operated by authorised CEI personnel. Client organisations and their coaches do not log in to the platform. Participants complete short surveys via a secure link, and CEI produces the resulting reports. Because CEI does not connect to client systems, requires no logins from client staff, and collects only a small amount of non-sensitive personal information, its data-protection footprint is deliberately small — which we treat as a reason to hold a high standard, not a lower one.
Current as of 24 June 2026. CEI is in a pilot phase, and these practices will be reviewed and strengthened as the platform matures.
CEI collects only what is needed to measure coaching impact and deliver the resulting reports:
| Category | What it includes |
|---|---|
| Engagement details | Coachee, Leader, and Coach name and email address; organisation; leadership level; coaching provider. |
| Survey responses | Rating-scale answers, selected coaching focus areas, and free-text reflections from the Coachee and Leader at set points in the engagement. |
CEI does not collect sensitive information as defined by the Privacy Act (such as health, racial or ethnic origin, religious, or political information). Email addresses are used only to deliver surveys and reports.
CEI data is used exclusively to produce coaching-effectiveness reporting: an individual report for the Coachee, and aggregated, de-identified insights for the organisation. With the organisation’s agreement, de-identified data contributes to industry benchmarking.
CEI data is never used for performance management, never used to rank or compare individual coaches or coachees, and is never sold.
Visibility is deliberately controlled to protect the coaching relationship while still giving organisations meaningful insight.
| Data | Who can see it |
|---|---|
| Individual Coachee responses | The Coachee and their Coach only. |
| Coachee focus areas | Shared with the Leader so they can contribute ahead of the Opening Alignment Session. |
| Individual Leader responses | Shared with the Coachee and Coach after the Closing Reflection Session. |
| The organisation | Aggregated, de-identified data only — and only once 5 or more Coaching Programs are complete. |
All personal data is stored and processed in Australia, in the Sydney region of Supabase — a third-party platform that is independently certified to ISO 27001 and SOC 2. Choosing an Australian region means participant data does not leave the country at rest.
Data is encrypted in transit (TLS) and at rest on the hosting platform.
Access is limited to a small number of authorised CEI personnel, protected by multi-factor authentication. There is no public sign-up and no client logins.
Identifying details (names, emails) are held in a separate record from survey responses, which are keyed by a non-identifying engagement reference.
The public survey link can only submit answers. It cannot read identifying information — participant names and emails are not exposed through it.
CEI relies on a small number of trusted service providers:
| Provider | Role | Notes |
|---|---|---|
| Supabase | Database & storage of all personal data | Australian (Sydney) region; ISO 27001 and SOC 2 certified. |
| Netlify | Hosting of the survey pages & submission notifications | The survey pages hold no personal data at rest; all stored data sits in Supabase (Australia). |
As CEI moves from pilot to its long-term build, all processing is being consolidated onto Australian-resident infrastructure.
Personal data is retained for the duration of the coaching engagement and the associated reporting. After that, identifying information is deleted or the data is de-identified for benchmarking. Detailed retention schedules are being formalised as part of CEI’s ongoing privacy program and are available to client organisations on request.
CEI is operated as an independent measurement service. The platform is administered only by a small number of authorised CEI personnel, who are bound to treat all participant data as strictly confidential. Individual results are never shared with an organisation or across coaching providers — organisations receive only de-identified, aggregated reporting, protecting the confidentiality of every participant and the neutrality of the measure.
In line with the Australian Privacy Principles, individuals may request access to the personal information CEI holds about them and ask for corrections. Requests can be made using the contact below.
If a data breach occurs that is likely to result in serious harm, CEI will respond in line with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) — containing and assessing the incident and notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.
CEI is hosted on a platform (Supabase) that is independently certified to ISO 27001 and SOC 2. CEI also applies its own controls — Australian data residency, encryption, restricted access, and separation of identifying data from responses — modelled on recognised standards including ISO 27001. We are happy to walk client risk teams through our current posture and roadmap.
For any data protection or privacy enquiry — including access and correction requests — contact cei (at) coachingindex.com.au.