Help

Data protection & GDPR

Answer a compliance question in one go - where your customer data is hosted, how to get a Data Processing Agreement, and how to handle an access or deletion request without losing your books.

5 min read

Under UK GDPR you are the data controller for your customers' personal data, and Session is your processor - we only handle it to run your booking page for you. That split is what most of your compliance paperwork hangs off, and this page has the facts you'll be asked for.

The Customers page in the Session admin, showing the customer list with the export control
Customers is where you'll answer most data requests - search, export, edit, or erase from one place.

Get a Data Processing Agreement

Article 28 requires a written contract between you and any processor handling personal data on your behalf. Ours is at bookasession.org/dpa - read it, and email us if you need a countersigned copy for your files. If your insurer or local authority has their own template, send it over and we'll work from that instead.

The agreement covers the sub-processor list, the security measures, breach notification, how we help with data-subject requests, and what happens to your data if you leave or if Session winds down.

Where your data is hosted

  1. 1

    Stored in the Republic of Ireland (EEA), on AWS via Supabase.

  2. 2

    Runs in Dublin, Republic of Ireland.

  3. 3

    Handled by Stripe Payments Europe, an Irish entity. Card numbers never reach Session - Stripe captures them directly, so your booking system is out of scope for card data.

  4. 4

    Marketing email is sent through AWS in London. Transactional email (confirmations, reminders) goes through Resend in the US.

A few sub-processors are US-based - Clerk for logins, Resend for transactional email, and Vercel as the hosting company, though the compute runs in Dublin. Those transfers are covered by the UK International Data Transfer Agreement. Annex 3 of the DPA lists every sub-processor with its location, and we'll give you 30 days' notice before that list changes.

Answer a subject access request

Someone asking for a copy of their data is an Article 15 request, and you have one month to respond.

  1. 1

    Go to Customers and search for their name or email.

  2. 2

    Use Export with the search still applied. The CSV scopes to the matching customers, so you get one row for that person - contact details, visit and spend history, membership, marketing consent, and any survey answers.

  3. 3

    Reports → Export gives you the bookings ledger for a date range. See CSV exports.

Tip

Send them the CSV as-is. You're not obliged to reformat it, only to provide the data in a commonly used, machine-readable format - which a CSV is.

Handle a deletion request

Someone asking to be deleted is an Article 17 request. On the customer's record in Customers, open them and choose Erase personal data.

What happens next depends on whether they've ever booked:

  • They've never booked. The record is removed entirely. Nothing is kept.
  • They've booked before. Their name, email, phone and any survey answers are removed, their sign-in is closed, and they come off every mailing list. The booking and payment rows stay as anonymous entries, and their signed waiver keeps the fact and version they agreed to without the signature or name.
Note

Keeping the anonymised booking rows is deliberate, and it's what the law expects. HMRC requires you to keep transaction records for six years, and a signed waiver is the evidence that defends a liability claim. Article 17(3) allows you to retain data on those grounds. Your revenue reports and year-end figures are unaffected by an erasure.

Erasure can't be undone, so make sure the request is genuine and from the person themselves before you action it.

Consent is recorded per organisation with a full audit trail - what wording was shown, where it was given, and when. Customers can withdraw it themselves from their account page or the unsubscribe link in any marketing email, and you can see and change it on their record in Customers. See email marketing.

Transactional emails - booking confirmations, reminders, cancellations - are sent regardless of marketing consent, because they're about a booking the customer made rather than promotion.

Special category data

The optional community survey asks for demographic details including ethnicity, which is special category data under Article 9 and needs a stronger legal basis than ordinary personal data.

It's off unless you switch it on. If you do turn it on, you're responsible for identifying an Article 9 condition and telling your customers what you're collecting and why. Nothing else in Session collects special category data.

Common questions

  1. Do I need to register with the ICO? Almost certainly yes - most UK businesses processing customer data do, and it costs £40-£60 a year. Check the ICO's self-assessment.

  2. Am I the controller or the processor? You're the controller for your customers' data. Session is your processor. Anyone your customers deal with through you - a payment provider, an insurer - may be a controller in their own right.

  3. Do I need my own privacy policy? Yes. Session's privacy policy covers what we do as your processor, but your customers are contracting with you, so they need a notice from you about what you collect and why.

  4. Can I get my data out if I leave? Yes. The CSV exports above work at any time, and the DPA commits us to keeping your data available for export for 30 days after you stop using Session, and to giving 90 days' notice if Session were ever wound down.

  5. What happens if there's a data breach? We'll tell you without undue delay and within 48 hours, with what happened and what's affected. Reporting to the ICO is the controller's call, which means it's yours - we won't do it on your behalf unless you ask.

  6. A customer says delete everything, but they owe me money. Erasure doesn't cancel a debt or an unfinished dispute. Article 17(3) lets you retain what you need to establish or defend a legal claim. Settle the matter first, then erase.