Security & Privacy
This page is maintained by PurposeCoach® (c/o WBC Wellbeing Business Community GmbH) to answer common questions about security, privacy, and data handling on purposecoach.ch. It is owner-maintained content, not an independent certification.
Controller & Scope
The controller for this website and the practices described here is PurposeCoach® c/o WBC Wellbeing Business Community GmbH, Seftigenstrasse 302, 3084 Wabern, Switzerland. The contents of this page refer to purposecoach.ch and the directly connected booking, lead, and customer flows. They do not replace our legally binding privacy notice.
What data we collect
We collect the data you actively submit (e.g. name, email, phone, and message in forms, bookings, the Kompass funnel, or testimonials) as well as technical logs required for operations, security, and abuse prevention. Details and legal bases are in our privacy notice.
Security controls
- TLS/HTTPS encryption for all traffic between browser and backend.
- Database with Row Level Security (RLS) enabled by default — tables are not reachable without an explicit policy.
- Role-based access control (RBAC) using a dedicated user_roles table; admin areas are protected server-side.
- Rate limiting and honeypot fields on public forms to mitigate bots and abuse.
- Have-I-Been-Pwned password check on sign-up and password change.
- Edge functions encapsulate sensitive operations; service keys stay server-side.
Hosting & subprocessors
The site runs on Lovable Cloud (Supabase infrastructure). For specific features we use specialised providers, e.g. for transactional email, appointment booking, course payments, and web analytics. The current list of providers, purposes, and data categories is maintained in our privacy notice.
Retention & deletion
Personal data is retained only as long as needed for its purpose (e.g. inquiry, coaching engagement, statutory retention). On request we will inform, correct, or delete your data within the limits set by applicable law.
Your rights (FADP / GDPR)
You have the right to access, rectification, erasure, restriction of processing, and data portability. Please send requests to info@purposecoach.ch.
Security & vulnerability reports
Please report security concerns or potential vulnerabilities confidentially to info@purposecoach.ch with the subject “Security”. We acknowledge receipt and investigate promptly.
Note
This page describes currently enabled, app-visible controls. It is not a certification, audit result, or attestation under SOC 2, ISO 27001, HIPAA, or PCI. Binding statements are in our privacy notice and imprint.
