# Data protection & GDPR

> Answer a compliance question in one go - where your customer data is hosted, how to get a Data Processing Agreement, and how to handle an access or deletion request without losing your books.

Who can do this: admins only.

Under UK GDPR you are the **data controller** for your customers' personal data, and Session is your **processor**.

<Screenshot shot="admin-customers" alt="The Customers page in the Session admin, showing the customer list with the export control" caption="Customers is where you'll answer most data requests - search, export, edit, or erase from one place." mat="cream" />

## Get a Data Processing Agreement

Article 28 requires a written contract with any processor. Ours is at [bookasession.org/dpa](/dpa), covering sub-processors, security, breach notification, data-subject requests and what happens to your data if you leave. Email us for a countersigned copy, or if your insurer or local authority wants their own template.

## Where your data is hosted

- **Your data** (bookings, customers, waivers, consent) is stored in the **Republic of Ireland** (EEA), and the app runs in **Dublin**.
- **Payments** - handled by **Stripe Payments Europe**, an Irish entity. Card numbers never reach Session.
- **Email** - marketing email is sent through AWS in **London**. Transactional email (confirmations, reminders) goes through Resend in the US.

A few sub-processors are US-based - Clerk for logins, Resend for transactional email, and Vercel for hosting. Those transfers are covered by the UK International Data Transfer Agreement. Annex 3 of the [DPA](/dpa) lists every sub-processor with its location, and we'll give you 30 days' notice before that list changes.

## Answer a subject access request

A request for a copy of someone's data is an Article 15 request; you have one month to respond.

<Steps>
  <Step title="Find and export them">
    In **Customers**, search for their name or email, then use **Export** with the search still applied. You get one row for that person - contact details, visit and spend history, membership, marketing consent, and any survey answers.
  </Step>
  <Step title="Add their bookings if they've asked for detail">
    **Reports → Export** gives you the bookings ledger for a date range. See [CSV exports](/docs/csv-exports).
  </Step>
</Steps>

The CSV meets the law's machine-readable format requirement.

## Handle a deletion request

A request to be deleted is an Article 17 request. Open the customer in **Customers** and choose **Erase personal data**.

- **They've never booked, bought or signed anything** (no bookings, memberships, vouchers or waivers). The record is removed entirely. Nothing is kept.
- **They've booked before.** Their name, email, phone and any survey answers are removed, their sign-in is closed, and they come off every mailing list. The booking and payment rows stay as anonymous entries, and their signed waiver keeps the fact and version they agreed to without the signature or name.

<Callout variant="note">
HMRC requires you to keep transaction records for six years, and a signed waiver defends a liability claim; Article 17(3) allows retaining data on those grounds. Erasure doesn't change your reports.
</Callout>

Erasure can't be undone, so check the request comes from the person themselves.

## Marketing consent

Consent is recorded per organisation with a full audit trail - the wording shown, where, and when. Customers can withdraw it from their account page or any marketing email's unsubscribe link, and you can change it on their record in **Customers**. Booking emails (confirmations, reminders) are sent regardless. See [grow your subscriber list](/docs/email-marketing-audience).

## Special category data

The optional **community survey** asks for demographic details including ethnicity, which is special category data under Article 9. It's **off unless you switch it on**. If you turn it on, you're responsible for identifying an Article 9 condition and telling your customers what you're collecting and why. Nothing else in Session collects special category data.

## What the help assistant can see

**Help & support** in the sidebar is given your venue's **settings** so it can answer questions about your setup: the facts already on your public [FAQs page](/docs/faqs-page), plus details like whether Stripe is connected and your region.

It is **not** given your customers, bookings, payments, vouchers or emails, and can't look one up.

Those settings are sent to Anthropic to generate the answer. They contain no customer personal data, so Anthropic isn't on the sub-processor list in Annex 3.

<Callout variant="note">
Your question and the answer are recorded against your organisation to improve the articles. If you'd rather not use it, use **Chat with support** in the same panel.
</Callout>

## AI apps you connect

An AI app an admin [connects](/docs/connect-ai) reads your reports and customer records under your own account with its provider, so it isn't a Session sub-processor (DPA section 6.5).

## Common questions

1. **Do I need to register with the ICO?** Almost certainly - most UK businesses that process customer data must pay an annual data protection fee. Check at [ico.org.uk](https://ico.org.uk).

2. **Do I need my own privacy policy?** Yes. Session's privacy policy covers us as your processor; your customers need a notice from you about what you collect and why.

3. **Can I get my data out if I leave?** Yes. See [exporting all your data](/docs/data-export). The DPA commits us to keeping your data available for export for 30 days after you stop using Session, and to giving 90 days' notice if Session were ever wound down.

4. **What happens if there's a data breach?** We'll tell you without undue delay and within 48 hours, with what happened and what's affected. Reporting to the ICO is your call as controller - we won't do it unless you ask.

5. **A customer says delete everything, but they owe me money.** Erasure doesn't cancel a debt or an unfinished dispute. Article 17(3) lets you retain what you need to establish or defend a legal claim. Settle the matter first, then erase.
