About this statement

This statement explains how the Coaching Effectiveness Index (CEI) handles personal information. It is written for the organisations that use CEI — and for their privacy, risk, and procurement teams — who need to understand exactly how participant data is collected, stored, and protected.

CEI is a coaching-measurement service. It is operated by authorised CEI personnel. Client organisations and their coaches do not log in to the platform. Participants complete short surveys via a secure link, and CEI produces the resulting reports. Because CEI does not connect to client systems, requires no logins from client staff, and collects only a small amount of non-sensitive personal information, its data-protection footprint is deliberately small — which we treat as a reason to hold a high standard, not a lower one.

Current as of 24 June 2026. CEI is in a pilot phase, and these practices will be reviewed and strengthened as the platform matures.

At a glance
  • Australian data residency. All personal data is stored in Australia.
  • Certified platform. Hosted on Supabase, a third-party platform that is ISO 27001 and SOC 2 certified.
  • Encrypted. Information is encrypted in transit and at rest.
  • Minimal collection. Only what is needed to measure coaching impact; no sensitive personal information.
  • Identity separated from responses. Names and emails are held apart from survey answers.
  • Restricted access. Limited to a small number of authorised CEI personnel.
  • Privacy Act aligned. Handled under the Australian Privacy Principles (Privacy Act 1988 (Cth)).
  • Never sold. Never used for performance management or coach ranking.
Personal information we collect

CEI collects only what is needed to measure coaching impact and deliver the resulting reports:

CategoryWhat it includes
Engagement detailsCoachee, Leader, and Coach name and email address; organisation; leadership level; coaching provider.
Survey responsesRating-scale answers, selected coaching focus areas, and free-text reflections from the Coachee and Leader at set points in the engagement.

CEI does not collect sensitive information as defined by the Privacy Act (such as health, racial or ethnic origin, religious, or political information). Email addresses are used only to deliver surveys and reports.

How we use it

CEI data is used exclusively to produce coaching-effectiveness reporting: an individual report for the Coachee, and aggregated, de-identified insights for the organisation. With the organisation’s agreement, de-identified data contributes to industry benchmarking.

CEI data is never used for performance management, never used to rank or compare individual coaches or coachees, and is never sold.

Who can access the data

Visibility is deliberately controlled to protect the coaching relationship while still giving organisations meaningful insight.

DataWho can see it
Individual Coachee responsesThe Coachee and their Coach only.
Coachee focus areasShared with the Leader so they can contribute ahead of the Opening Alignment Session.
Individual Leader responsesShared with the Coachee and Coach after the Closing Reflection Session.
The organisationAggregated, de-identified data only — and only once 5 or more Coaching Programs are complete.
Where data is stored

All personal data is stored and processed in Australia, in the Sydney region of Supabase — a third-party platform that is independently certified to ISO 27001 and SOC 2. Choosing an Australian region means participant data does not leave the country at rest.

Security controls
Encryption

Data is encrypted in transit (TLS) and at rest on the hosting platform.

Access control

Access is limited to a small number of authorised CEI personnel, protected by multi-factor authentication. There is no public sign-up and no client logins.

Identity separation

Identifying details (names, emails) are held in a separate record from survey responses, which are keyed by a non-identifying engagement reference.

Locked-down survey access

The public survey link can only submit answers. It cannot read identifying information — participant names and emails are not exposed through it.

Sub-processors

CEI relies on a small number of trusted service providers:

ProviderRoleNotes
SupabaseDatabase & storage of all personal dataAustralian (Sydney) region; ISO 27001 and SOC 2 certified.
NetlifyHosting of the survey pages & submission notificationsThe survey pages hold no personal data at rest; all stored data sits in Supabase (Australia).

As CEI moves from pilot to its long-term build, all processing is being consolidated onto Australian-resident infrastructure.

Data retention & deletion

Personal data is retained for the duration of the coaching engagement and the associated reporting. After that, identifying information is deleted or the data is de-identified for benchmarking. Detailed retention schedules are being formalised as part of CEI’s ongoing privacy program and are available to client organisations on request.

Independence & confidentiality

CEI is operated as an independent measurement service. The platform is administered only by a small number of authorised CEI personnel, who are bound to treat all participant data as strictly confidential. Individual results are never shared with an organisation or across coaching providers — organisations receive only de-identified, aggregated reporting, protecting the confidentiality of every participant and the neutrality of the measure.

Your rights

In line with the Australian Privacy Principles, individuals may request access to the personal information CEI holds about them and ask for corrections. Requests can be made using the contact below.

Data breach response

If a data breach occurs that is likely to result in serious harm, CEI will respond in line with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) — containing and assessing the incident and notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

Certifications & roadmap

CEI is hosted on a platform (Supabase) that is independently certified to ISO 27001 and SOC 2. CEI also applies its own controls — Australian data residency, encryption, restricted access, and separation of identifying data from responses — modelled on recognised standards including ISO 27001. We are happy to walk client risk teams through our current posture and roadmap.

Contact

For any data protection or privacy enquiry — including access and correction requests — contact cei (at) coachingindex.com.au.

← Back to About CEI