Privacy & GDPR

How Reallead handles your data

This page describes honestly and factually which personal data Reallead processes, why, for how long, with which parties, and what rights you have. Privacy is a core value of the platform: your data stays within the platform and is only shared with whoever you give consent for.

Last updated:

Who is responsible?

Reallead is a two-sided marketplace for coaching in the Netherlands/the EU: coaches offer services, seekers find and choose a coach. Reallead is the data controller for the personal data processed via the platform. If you have a privacy question, please get in touch via the address below.

What we do and don't see

Communication between coach and seeker runs through the platform (chat and messages in a private coaching room). We secure that communication with traffic encryption (TLS), strict access control and object-level permissions: only the participants of a match have access to their own coaching room, messages and materials.

We are intentionally transparent about this: "super secure" for us means TLS, access control and platform-mediated communication, but no end-to-end encryption. Technically, the platform can therefore process messages to deliver them. We do not read messages for other purposes, and email notifications never contain the content of a message, only a signal with a secure link.

Which data we process

Accounts & profiles

When you register, we process your email address, username and password (stored encrypted), plus your role (coach or client). We send a verification email and optionally offer two-factor authentication via email. A coach profile contains the data the coach publishes themselves: name, bio, availability, rates and packages, and possibly an external video introduction (a YouTube/Vimeo link; we do not host videos ourselves).

Coaches' certificates

A coach can upload certificates to substantiate qualifications. These files are not publicly downloadable: they are stored outside the public media folder and only served to the owner and to administrators reviewing the profile, via an access-controlled view. Uploads are checked for file type and size.

Self-scans and self-reflection

The platform offers self-scans: self-reflection and intake questionnaires. This may be sensitive information, and we handle it carefully: you give prior consent before completing a self-scan, and coaches never see your individual results. Where a self-scan indicates a health concern, we show a referral safety net to appropriate help. Some self-scans can be completed anonymously without an account; in that case, we do not link any results to a person.

If you complete a self-scan anonymously (without an account), we store your answers for a maximum of 30 days in a temporary session linked to your browser via a cookie, not to your name or an account. After a maximum of 30 days, we automatically delete this data. If you create an account within that period and give your consent, we will place your results in your account.

Coaching rooms, chat and materials

After a match, a private coaching room is created where the coach prepares materials and where you chat and exchange messages securely. Materials are in shielded storage; only the participants of that room have access.

Your consent per channel

You decide yourself, per communication channel (for example chat or email notifications), what you give consent for. We don't work with a single all-or-nothing consent: you choose per channel. By default a channel is closed until you open it (fail-closed).

We keep an activity log that records which actions took place (for example that a message was sent), but not the content of them. This way you can check what happened, without the log itself containing your conversations.

Website statistics

We measure how our website is used with Umami, a privacy-friendly statistics programme that we host ourselves within our own environment. Therefore, no visitor data goes to an external advertising or tracking company. Umami places no cookies and respects your browser's "Do Not Track" setting: if it is enabled, we do not measure your visit.

If you are logged in, we link the pages you visit to your account, so our team can see which pages have been visited most often per user. We use this exclusively internally to understand and improve the platform; this linkage only begins from the moment you are logged in. We only record which pages have been visited, not chat or self-scan content.

The basis for this is our legitimate interest in improving the service. You can object to this linking or request access via the contact address at the bottom of this page; if you delete your account, this link disappears too.

Google Analytics (only with your consent)

Alongside our own cookie-free statistics, we temporarily use Google Analytics to verify our visitor numbers. Google Analytics is off by default: it only loads after you click "Accept" in the cookie banner. Only then does Google place a cookie and process visit data (such as pages viewed and features used, without your name or contact details) via Google Ireland Ltd., possibly on servers outside the EU.

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw or change it at any time via the "Cookie preferences" link at the bottom of every page; if you decline, we only measure anonymously and cookie-free. We have disabled advertising features, personalisation and Google's own-purpose data sharing, and have a data processing agreement with Google. Retention in Google Analytics is limited to 14 months.

Messages, self-scan content and everything within your coaching space are explicitly excluded here: Google Analytics does not measure those.

The guide on our website

On our public pages, there is a "Help with choosing" button at the bottom right. Behind it is a selection menu, not a chatbot or a person: you click on buttons and arrive at the correct page. Nothing from that conversation is saved, and nothing is passed on to another party. While you are completing a self-scan, in your coaching space, in your messages, and on this page, the button does not appear.

If you close the window, your browser remembers this in the session storage under the name "rl-wegwijzer-dismissed". This is a functional preference of yours, it contains no personal data and it disappears as soon as you close the tab.

Only on the employer path can you request contact yourself. If you do so, we ask for your name, organisation and email address, and only after you have ticked the separate consent box do we store that data to follow up on your request. Without that tick box, we send and store nothing.

Newsletter and e-mail measurement

You only receive our newsletter if you have signed up for it yourself, and at the bottom of every newsletter there is an unsubscribe link that works without logging in. Coaches on Reallead can also, exclusively with your separate opt-in per coach, send their own newsletter to their clients; the same applies there: one click and you are unsubscribed.

Whether you open our emails and what you click on, we only measure if you give separate and explicit consent for this (via "Privacy & Permissions" in your account). Without that consent, your emails contain no tracking pixel and no tracking links. You receive exactly the same content, but nothing is measured. By default, this measurement is switched off.

If you do give consent, we only record that an email has been opened or that a link has been clicked, without location or device data, and we store this for a maximum of 90 days. The same consent applies to newsletters your coach sends you via Reallead: these are also not measured without your consent. You can withdraw your consent at any time, and it takes effect immediately for all subsequent emails.

For employers: what you do and don't see

Employer access is activated on this platform, within the hard limits below.

If an employer signs up an employee for coaching, the employee retains full control. The employer only registers an email address; the employee creates an account themselves and gives or refuses consent. An employer can never create an account or consent on behalf of someone else.

An employer can at most request a high-level coaching status (such as "invited" or "training in progress"), and only as long as the employee actively gives consent for it. Withdrawal works immediately. An employer never sees the content: no self-scan results, no chat or email content, no coach's name and no request for help. Every successful status inquiry is visibly logged in the employee's activity log.

Participation in the scheme: what your employer hears from us

If your employer pays for your coaching programme from a purchased scheme, your employer will receive two pieces of information: your name and the date on which that place was assigned to you. They receive nothing more from us, and only someone with a confirmed role as HR Manager or CEO can request that list. What you discuss in coaching remains entirely separate, and the actual start date of your coaching is never included. We do this on the basis of a legitimate interest: your employer needs to be able to check how their budget has been spent. You can object to this via privacy@coachloket.com; if we honour your objection, your entry will disappear from that overview and the rest of your account will remain unchanged.

Employer overview at group level

In addition, an employer can view an overview at group level: numbers of employees per phase (for example, registered or training completed). This only includes employees who themselves gave active consent for status sharing; without that consent, you are not counted anywhere and this is indistinguishable from "not yet started". The overview never contains names, email addresses or content. If your employer views the group overview while your consent is active, you will see an entry for this in your own activity log. Please be aware: in a small team, a group number can in practice be traceable to one person, and withdrawing consent can be visible as a change in a group number.

Group figures on coaching hours

If your employer is paying for your coaching programme through a purchased scheme, you can separately give consent for your coaching hours to count towards a total that your employer sees. This total is a single figure covering all employees who gave this consent: how many coaching hours have been delivered, and across how many programmes they are distributed. Names, session dates, your number of hours, and your number of sessions are never included, and there is no breakdown by department or location. The figures are updated once a month; the reference date is included. This consent is entirely separate from the consent for status sharing: if you gave that previously, it does not count here, and you will only be included once you make this choice yourself and separately. If you withdraw, your hours will no longer count from that moment onwards, nor for the period that has already passed. However, be aware: if few colleagues gave this consent, such a total might, in practice, only concern you, and it could be noticeable if it decreases because you withdraw. We do not hide these figures for small groups. If your employer views the group figures while your consent is active, you will see an entry for it in your own activity log.

What we keep and how you can delete it

We store your data for as long as your account exists and for as long as it is necessary for the service. You can have your account deleted yourself via Account settings → Security → Delete account. You then have a 30-day cooling-off period: your account is immediately locked and no longer visible to others, but nothing has been erased yet. If you retract the request within those 30 days, everything will be exactly as you left it.

After these 30 days, we delete your name, email address and password, your profile and profile picture, your potential coach profile with rates, availability and certificates, your self-scan results, the request for help you wrote during applications, your notification preferences and all your sessions. Files you uploaded yourself are also physically removed from our servers. This cannot be reversed.

We do retain a small portion, as required by law (Art. 17 para. 3 GDPR). These are your invoices and payments (7 years, fiscal retention obligation: your name and address must legally remain on an invoice), proof of your consents (at least 1 year, where we immediately encrypt your email address into an unreadable code) and our administration and impersonation logs (2 years, so that it remains verifiable what our employees have done with accounts). What we retain, we unlink from your account: there is no longer any reference to your person, and it no longer appears in screens that you or other users can see.

Data that is not solely yours is not discarded, but your name is removed from it. Messages you sent remain readable for the person to whom you wrote them, with "Deleted user" as the sender; files you attached are removed. Reviews you wrote remain without your name. Coaching spaces continue to exist as long as the other party is entitled to them: if a coach leaves the platform, their client still has access to the prepared material until the retention period for coaching space material expires. Reason: the right to erasure is not a right to have someone else's data deleted. If you believe a specific message or a review about you should still be removed, please contact us; we will assess that separately.

If you joined Reallead via your employer, we retain the invitation itself as administration for that employer. An invitation that was still open will be completely deleted. For an invitation you had already accepted, we replace your email address with an unreadable code; the organisation, date, and status remain. If your employer provided their own identifier with that invitation (for example, an employee number), we leave that unchanged: that is your employer's data, and your employer is the data controller for it. If you wish to have that removed, please contact your employer.

Cleaning up outstanding invitations sent to your email address is only possible if you have previously confirmed that address. As long as an address has not been confirmed, we have no proof that it belongs to your account, and we leave invitations to that address untouched, so that we never accidentally delete an invitation that was actually meant for someone else. Invitations that you have accepted yourself are always unlinked from your account, regardless of whether the address was confirmed.

Deleted data may still reside in our backups for a short period. We no longer use them for any purpose and do not restore them; they disappear once those backups expire. You can simply sign up again later with the same email address. You will then start with an empty account, your old data will not return.

Reallead automatically cleans up data according to fixed retention periods. Below you will see the period currently applicable per data type.

  • We store business leads for a maximum of 12 months (365 days); after which we automatically delete them.
  • We retain consent registrations (activity and revoked consents) for at least 12 months after revocation, for accountability; after which we delete them.
  • We store inspection and moderation logs for a maximum of 18 months.
  • We store handled reports for a maximum of 6 months; we first soft delete them (recoverable) and then definitively.
  • We retain coaching room material for another 90 days after termination; after which we permanently delete it.
  • The email sending log (which address, which type of message, successful or failed, never the content) is stored for a maximum of 90 days; after that, it is automatically deleted.
  • We store administration audit and impersonation logs for a maximum of 24 months; after which they are irreversibly erased.
  • Anonymous self-scan results are stored for a maximum of 30 days (see "Self-scans and self-reflection" above).
  • We never automatically delete open reports and payment or invoice data.

Your rights

Under the GDPR you have a number of rights. Here's how you exercise them at Reallead:

  • Access: you can see your own account and profile data in your account settings; for a complete overview you can submit a request via the contact address below.
  • Rectification: you adjust your data (name, email address, username, profile) yourself in your account settings and your coach profile.
  • Deletion (right to be forgotten, Art. 17): you have your account deleted yourself via Account settings → Security → Delete account, with a 30-day cooling-off period. Above, under 'What we retain and how you can delete it', it states exactly what we erase, what we are legally required to retain, and for how long.
  • Objection and withdrawal of consent: you withdraw consent per channel via your consent management; that takes effect immediately.
  • Data portability: you download your data yourself via Account settings → My Data. You will receive a ZIP file containing a machine-readable export.json, the files you have uploaded yourself, and a readme with explanations. This can be done once every 24 hours.

One thing is deliberately not included in that export: the text of messages others have written to you. For your own messages, you will receive the full text; for received messages, only the timestamp, whether the sender was a coach or a seeker, and whether an attachment was included. What someone else writes is their personal data, not yours, and a conversation in a coaching space is private. You won't lose anything: you can simply continue to read the conversation in Reallead. If you want to view more than the export provides, you can submit an access request via the contact address at the bottom of this page.

Security

  • Traffic is encrypted with TLS; access is secured with login and optional two-factor authentication.
  • Object-level permissions: only the participants of a match have access to their coaching room, messages and materials.
  • Uploads (such as certificates) are checked for type and size and stored outside the public folder; there are no file names or personal data in URLs.
  • Our technical logs contain no personal data. There is one deliberate exception: for every email we send, we record the address it went to, the type of message, and whether it was successfully sent. This allows us to see if a verification or invitation email has genuinely reached you. We never store the content of the email, only administrators can view this, and after the retention period below, the entry automatically disappears.

Who we share data with (processors)

We engage a limited number of processors. Only what we actually use:

  • Amazon SES (AWS): for sending transactional email (verification, notifications), in the EU region (eu-west-1).
  • DigitalOcean: our hosting provider. The platform runs entirely on a server at DigitalOcean in Amsterdam: the application, the database, and the storage of files that you or your coach uploads, plus the backups thereof.
  • Google (Gemini): solely as an administrative tool for translating public profile and interface texts and generating avatars. No confidential data from the user flow passes through this: no chat content, self-scan results, or data from seekers.
  • Google (sign in with Google): if you choose "Continue with Google", Google acts as the processor for logging in: we receive your email address and name from Google to create or link your account. This link is optional: you can also log in with an email address and password. If you do not use Google, nothing is sent to Google here.
  • Mollie: our payment service provider. If you take out a paid subscription, Mollie B.V. (Amsterdam) processes the payment; for a continuous subscription, Mollie also registers the authorisation for automatic debits. You enter your payment details (e.g. your iDEAL bank or credit card number) in Mollie's secure environment; these details never reach our server. We only receive the payment ID, the amount, the status, and the time of payment from Mollie, and for a continuous subscription, also the customer, authorisation, and subscription number, and the payment method type. If you do not take out a paid subscription, nothing is sent to Mollie.

Payment data

For paid subscriptions, we work with Mollie as a payment service provider (processor). You can pay with iDEAL or credit card. You enter your payment details directly into Mollie's secure environment. Reallead therefore does not see or store any card or account details.

Regarding a payment, Reallead exclusively stores: Mollie's payment ID, the amount, the status (e.g. paid/failed), the time, and for a continuous subscription, Mollie's customer, authorisation, and subscription number, and the payment method type (e.g. "iDEAL"), linked to your account and the chosen subscription. We use this to determine your access to paid features, to link the automatic debit to your account, and for our administration. Mollie's own privacy policy applies to the data Mollie processes.

We store this payment and administration data no longer than necessary, observing statutory (tax) retention periods. With a paid subscription, your first payment authorises automatic debits for each chosen period. This authorisation is held by Mollie; we only store the characteristics needed to link the debit to your account, never your bank account or card number. If you cancel, the debit stops after the current period.

Contact

Questions about privacy or about your data? Get in touch via privacy@coachloket.com.