Privacy Policy

Kerstin Graebner Coaching & Consulting
Am Herrengarten 3
91336 Heroldsbach
Germany
contact@kerstin-graebner.de

Version: August 2026

This is a translation. In case of discrepancies, the German version prevails.

1 Controller

Kerstin Graebner Coaching & Consulting
Am Herrengarten 3
91336 Heroldsbach
Germany
contact@kerstin-graebner.de

Services delivered and invoiced through Parinama Inspired Living Pvt. Ltd. (India) are governed separately under Indian law.

2 Principles

I process personal data in accordance with the GDPR and German data protection law. I collect as little as possible, use it only for the stated purposes, and delete it once it is no longer needed.

Where possible, I choose tools that run locally on my own device or are operated in Europe. Session notes are kept in Obsidian and PDF documents are handled with Stirling PDF. Both are open source applications that work locally only and transmit no data to third parties. Email runs through IONOS in Germany, video sessions through Whereby in Norway, the app I use for handwritten notes comes from MyScript in France, and the client dashboard runs through Softr in France.

Nothing is recorded by default. Coaching sessions are neither recorded nor transcribed unless you give separate, explicit consent. See section 3.7.

3 Processing in detail

3.1 Visiting the website

This website is provided through Squarespace. Technical data is processed when you visit: browser, network and device information, IP address, pages viewed, time spent, clicks and timestamps. Fonts are served by Google Fonts and Adobe Fonts, which may receive technical data including your IP address.

Purpose: providing and securing the website, audience measurement.
Legal basis: Art. 6(1)(f) GDPR, legitimate interest in a functioning website.

3.2 Contact by email

Email is processed through IONOS (Germany). Name, email address and message content are stored.

Purpose: answering your enquiry, preparing a possible engagement.
Legal basis: Art. 6(1)(b) GDPR where a contract is being prepared, otherwise (f).

3.3 Forms

Forms preparing an agreement run on Formly. Name, email address, invoice address, country, language and chosen payment method are processed.

Purpose: preparing and drawing up the coaching or framework agreement.
Legal basis: Art. 6(1)(b) GDPR.

3.4 Booking appointments

Appointments are booked through TidyCal, with Google Calendar and iCloud Calendar connected in the background for availability. Name, email address, chosen session length, date and time are processed.

Purpose: arranging and managing appointments.
Legal basis: Art. 6(1)(b) GDPR.

3.5 Video sessions

Sessions take place on Whereby by default. The provider is based in Norway and therefore within the European Economic Area. That is precisely why I chose it.

If you prefer Google Meet, I will meet you there. In that case the choice originates with you; I do not propose it.

Connection data and the audio and video transmitted during the session are processed. No recording takes place unless you have given explicit consent under section 3.7.

Purpose: delivering the agreed sessions.
Legal basis: Art. 6(1)(b) GDPR.

3.6 Session notes

I take notes during and after sessions. They are written by hand in Nebo Notes and then stored locally on my computer in Obsidian. The notes remain in handwritten form. I do not use automatic text recognition. Obsidian keeps files on the device only. Nothing is transmitted to the provider and nothing is synchronised to a cloud service. The computer is fully encrypted.

Session notes are kept in pseudonymised form. They run under a code and contain no names. The allocation of that code to a person is not stored together with the notes.

My practice administration retains only information without session content: date and duration, methods used, topic categories, and filing and billing details.

I am the only person with access to session content. Should I engage administrative support, this area remains technically out of reach: access would extend to the administrative layer only, never to session notes, recordings or summaries.

Coaching conversations may touch on personal matters that constitute special categories of personal data, such as health, origin, beliefs or relationships. I process such information only on the basis of your explicit consent, given in the framework agreement and revocable at any time.

Alongside data protection law, my handling of records is governed by the Code of Ethics of the International Coaching Federation, to which I am bound as a credentialed coach:

"Maintain, store, and dispose of any records, including electronic files and communications, in a manner that promotes confidentiality, security, and privacy, and complies with applicable laws and agreements." ICF Code of Ethics, Standard 2.4

Source: International Coaching Federation, ICF Code of Ethics, available at https://coachingfederation.org/credentialing/coaching-ethics/icf-code-of-ethics/ (retrieved 4 August 2026).

Purpose: continuity of the work across sessions, preparing follow-up appointments.
Legal basis: Art. 6(1)(b) GDPR, and additionally Art. 9(2)(a) GDPR (explicit consent) for special categories of personal data. The principles of Art. 5 GDPR apply, in particular data minimisation and storage limitation.

3.7 Recording, transcription and AI-assisted summaries

On request I produce written summaries of sessions. This requires several steps, to which you may consent individually and voluntarily:

  1. Recording the session as an audio file via Otter.ai

  2. Automatic conversion of the recording into a transcript, also at Otter.ai

  3. Producing a structured summary from the transcript with the support of Claude (provider: Anthropic), reviewed and edited by me

  4. Storing the finished summary in your client dashboard

The consent form is available in your dashboard. There you can see at any time what has been given, and change or withdraw it without giving reasons and without disadvantage.

Without consent, none of these steps take place.

The ICF Code of Ethics extends professional responsibility explicitly to the technology a coach uses:

"Fulfill my ethical and legal obligations to my coaching client(s), sponsor(s), colleagues, and to the public at large directly and through any technology systems I may utilize (i.e. technology-assisted coaching tools, databases, platforms, software, and artificial intelligence)." ICF Code of Ethics, Standard 2.5

Source: ibid. (retrieved 4 August 2026).

Purpose: producing session summaries.
Legal basis: Art. 6(1)(a) and Art. 9(2)(a) GDPR, consent.

3.8 Client dashboard

The dashboard is provided through Softr (France) and draws on databases in Notion. It holds contact details, agreement data, materials provided, receipts and, where consented, session summaries.

Purpose: providing materials, booking, documents.
Legal basis: Art. 6(1)(b) GDPR.

3.9 Assessments

The Presence-Purpose-Impact assessment runs through Formly and is evaluated in Notion. I additionally use Values Bridge, the Cultural Orientations Framework and, where relevant, VIA Character Strengths. The privacy terms of those providers apply in addition.

Purpose: establishing a starting point and a basis for the work.
Legal basis: Art. 6(1)(b) GDPR.

3.10 Payments and invoices

Payments run through Stripe and PayPal. Invoices and receipts are produced with PopInvoice. Name, invoice address, email address, amount and payment data are processed. The payment data itself is held by the payment providers, not by me.

Purpose: processing payment, invoicing, accounting.
Legal basis: Art. 6(1)(b) GDPR and (c) for statutory retention.

3.11 Accounting and tax advice

I pass only invoicing data to my tax adviser. Content of the work, session notes and assessments are not shared.

Legal basis: Art. 6(1)(c) GDPR.

3.12 Newsletter

The newsletter runs on Substack. Sign-up uses a double opt-in process, recording the times of registration and confirmation and the IP address. Substack measures opens and clicks to gauge the relevance of content. You can unsubscribe at any time via the link in every issue.

Legal basis: Art. 6(1)(a) GDPR, consent.

3.13 Social media

I maintain profiles on Instagram and LinkedIn. Processing on those platforms is governed by their own privacy terms. Messages and comments are retained for communication purposes.

Legal basis: Art. 6(1)(f) GDPR.

4 Practice administration and backups

I use Notion to administer my practice, split into two areas. One holds only what the client dashboard requires: first name, email address, package information, documents and invoices. The second holds my own notes on the working relationship and is not connected to the dashboard.

Session notes are excluded from both. They are held locally only, see section 3.6.

Backups of local data are stored encrypted on a local drive.

5 Recipients and transfers to third countries

I use the following processors: Squarespace, IONOS, Formly, TidyCal, Google, Apple, Whereby, Otter.ai, Anthropic, Softr, Notion, MyScript (Nebo), Stripe, PayPal, PopInvoice, Substack.

Obsidian is deliberately not listed: the application works locally only and transmits no data to the provider.

Providers based in Germany, the EU or the EEA: IONOS (Germany), Whereby (Norway), MyScript (France), Softr (France).

Formly is based in the United Kingdom. Transfers there are covered by an adequacy decision of the European Commission, so no additional safeguards are required.

Some of the remaining providers process data in the United States. Those transfers are covered by data processing agreements with standard contractual clauses, or the providers rely on an adequacy decision of the European Commission.

6 Retention periods

Session notes, agreements and consent records are deleted three years after the engagement ends, all together.

Recordings and transcripts are deleted once the summary has been written, at the latest after fourteen days.

Summaries in your dashboard remain available until the engagement ends. You then have thirty days to save them. After that they are deleted along with the notes.

Invoices and accounting records are kept for eight years, as I am legally required to do.

Enquiries that do not lead to an engagement are deleted after twelve months.

Newsletter data is kept until you unsubscribe.

I will delete session notes earlier at any time on request.

After an engagement ends I retain selected characteristics without personal identifiers, to build a picture over time of who I work with. This is not intended to allow conclusions about individuals.

7 Your rights

You have the right to information, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. Consent already given can be withdrawn at any time with effect for the future.

Please write to contact@kerstin-graebner.de.

You also have the right to complain to a data protection supervisory authority. The competent authority for me is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht).

8 Changes

I update this policy when the services I use or the legal requirements change. The version published on this page applies.

Version: August 2026