Session — booking platform (bookasession.org)
Version 1.5 · 1 October 2026
This Data Processing Agreement ("DPA") is entered into between:
together the "Parties".
This DPA supplements and forms part of the Session Terms of Service (the "Agreement"). Where this DPA conflicts with the Agreement in relation to the Processing of Personal Data, this DPA prevails.
| Data | Controller | Processor |
|---|---|---|
| Your customers' personal data (bookings, contact details, waivers, marketing consent, membership records) | You | Session |
| Your own account and staff-user data, billing data, and platform usage/telemetry | Session | — |
You determine the purposes and means of Processing your customers' Personal Data. Session Processes that data only to provide the Platform to you.
Where Session Processes data as a Controller in its own right (your account, billing, and platform telemetry), that Processing is governed by the Session Privacy Policy, not by this DPA.
"Data Protection Law" means the UK General Data Protection Regulation, the Data Protection Act 2018, and — where applicable to a Party — Regulation (EU) 2016/679 ("EU GDPR"), each as amended.
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Data Protection Law.
"Sub-processor" means any third party engaged by Session to Process Personal Data on your behalf.
(UK GDPR Article 28(3))
Subject matter. Provision of the Session booking platform: session scheduling and capacity management, taking and managing bookings, payment initiation, digital waivers, memberships and credits, customer records, recording where bookings come from, and transactional and marketing email.
Duration. The term of the Agreement, plus the retention and deletion periods in Section 10.
Nature and purpose. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to Sub-processors, restriction, erasure and destruction, in each case solely to provide the Platform and as further instructed by you.
Types of Personal Data and categories of Data Subject. See Annex 1.
3.1 Session Processes Personal Data only on your documented instructions, including as to international transfers, unless required to do otherwise by law. Where such a legal requirement applies, Session will inform you before Processing unless the law prohibits it.
3.2 Your instructions are: (a) the Agreement and this DPA; (b) your configuration and use of the Platform through the admin interface and API; and (c) any further written instructions agreed by the Parties.
3.3 Session will inform you if, in its opinion, an instruction infringes Data Protection Law. Session may suspend the affected Processing until the instruction is amended or confirmed.
3.4 Session does not sell Personal Data, and does not use your customers' Personal Data to train machine-learning models or for its own marketing.
Session ensures that persons authorised to Process Personal Data are subject to an appropriate duty of confidentiality, are informed of the confidential nature of the data, and access it only where necessary to perform their role.
(UK GDPR Articles 28(3)(c) and 32)
Session implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Current measures are described in Annex 2. Session may update these measures provided the level of security is not materially reduced.
Continuity of the service, including key-personnel cover, is addressed in Section 13.
(UK GDPR Article 28(2) and 28(4))
6.1 You give general written authorisation for Session to engage Sub-processors. The current list is at Annex 3.
6.2 Session will give you at least 30 days' notice by email before adding or replacing a Sub-processor.
6.3 You may object to a proposed Sub-processor on reasonable data-protection grounds within that notice period. The Parties will work in good faith to resolve the objection. If it cannot be resolved, you may terminate the affected Services without penalty and receive a pro-rata refund of any prepaid fees.
6.4 Session imposes on each Sub-processor data-protection obligations no less protective than those in this DPA, and remains fully liable to you for each Sub-processor's performance.
6.5 AI applications you connect. If you connect an AI application (for example Claude) to the Platform, you instruct Session to give that application the data it requests through the connection, under your own account with its provider. That provider is not a Session Sub-processor: it acts on your instructions under your terms with it, and you can revoke the connection at any time in Settings.
(UK GDPR Article 28(3)(e))
7.1 The Platform provides self-service tools that let you respond to most requests yourself, including data export and access to a customer's full record. See Annex 4.
7.2 Where a request cannot be satisfied through those tools, Session will provide reasonable assistance, at no charge for a reasonable volume of requests, to help you respond within the statutory deadline.
7.3 If a Data Subject contacts Session directly about data Session Processes on your behalf, Session will not respond substantively (other than to acknowledge and redirect) and will notify you promptly.
(UK GDPR Article 28(3)(f), Articles 32–36)
8.1 Breach notification. Session will notify you without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Personal Data Processed on your behalf. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point.
8.2 Session will not notify a Supervisory Authority or Data Subjects on your behalf unless you instruct it to, or Session is legally required to do so.
8.3 Session will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the nature of Processing and the information available to Session.
(UK GDPR Article 28(3)(h))
9.1 Session will make available all information reasonably necessary to demonstrate compliance with Article 28 and this DPA.
9.2 You may audit Session's compliance no more than once in any 12-month period (and additionally after a Personal Data Breach affecting your data), on at least 30 days' written notice, during business hours, subject to reasonable confidentiality undertakings and without unreasonable disruption to Session's operations.
9.3 Session may satisfy an audit request by providing written responses to a reasonable questionnaire, or third-party certifications or reports where available.
(UK GDPR Article 28(3)(g))
10.1 During the term. You may export your data at any time using the export tools in Annex 4.
10.2 On termination. At your choice, Session will return or delete Personal Data Processed on your behalf. You may export your data at any time during the term and for 30 days after termination. After that period Session will delete the data within a further 60 days, except as set out in 10.3.
10.3 Retention required by law. Session retains booking and payment records where required for tax, accounting or the establishment or defence of legal claims — currently up to 7 years, in line with UK tax law. Data retained on this basis is retained only for that purpose and remains subject to the security and confidentiality obligations of this DPA.
10.4 Service wind-down. If Session ceases to provide the Platform, Session will give you at least 90 days' notice and will make a complete export of your data available throughout that period.
10.5 Backups are cycled on a rolling basis and are overwritten in the ordinary course. Deletion from live systems takes effect immediately; deletion from backups takes effect as those backups expire, within 30 days.
11.1 Personal Data is stored at rest in the European Economic Area (Republic of Ireland). See Annex 3 for the location of each Sub-processor.
11.2 Some Sub-processors are established in the United States. Where Personal Data is transferred outside the UK/EEA, Session ensures an appropriate safeguard is in place under Article 46 — the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, and where applicable the Sub-processor's certification under the UK–US and EU–US Data Privacy Framework.
11.3 Session will provide copies of the relevant transfer mechanisms on request.
12.1 Each Party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
12.2 Notices. Notices under this DPA — sub-processor objections, audit requests, data-subject requests escalated to Session, and breach notifications — are given by email. Notices to Session go to wil@bookasession.org; notices to you go to the administrator email address on your account, and to your Also-send-to address where one is set.
12.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, unless the Agreement provides otherwise.
12.4 If any provision is held invalid, the remainder continues in force.
(UK GDPR Article 32(1)(b) and (c))
13.1 Continuity of the service. The Platform runs on managed third-party infrastructure and operates without routine manual intervention. Bookings, payments, transactional email and scheduled jobs continue to run in the ordinary course without action by Session personnel.
13.2 Key personnel. Session is operated by a sole trader. A second individual holds full access to the source code and to each platform account on which the Platform depends, and is able to operate and maintain the Platform if the principal is unavailable for an extended period.
13.3 Source code and data. The source code is held in a private version-controlled repository with its full history. Database backups are taken as described in Annex 2 and include an independent off-platform copy held with a provider other than the primary database host, so that the failure of a single provider does not put your data beyond recovery.
13.4 Funds. Session does not hold your funds. Payments are processed through your own Stripe account under Stripe Connect. Your payment history, payouts, disputes and recurring payment arrangements remain under your control independently of Session and of this DPA.
13.5 Wind-down. If Session ceases to provide the Platform, Section 10.4 applies.
| Category | Fields |
|---|---|
| Identity and contact | Name, email address, telephone number |
| Booking records | Sessions booked, dates and times, number of spaces, attendance and check-in status, notes added by your staff, booking reference |
| Booking source | Where a booking came from: the advertising click identifier on the link the customer followed (Google gclid, wbraid or gbraid; Meta fbclid), the campaign tags on that link (utm_source, utm_medium, utm_campaign and utm_content), the domain of the referring website (never its full address), and whether the booking started on your booking page or on the timetable embedded on your own website. Recorded when the customer arrives, without cookies or any other storage on their device. Session does not send it to Google, Meta or any other advertising platform; it is included in your full data export (Settings → Data). On erasure the click identifier and referring domain are removed and the campaign tags are kept |
| Payment records | Amount, currency, payment status, refunds, payment method type, Stripe identifiers. No card numbers — card data is captured by Stripe and never reaches Session's systems |
| Waivers | The waiver text agreed, signer name and email, signature, timestamp and version |
| Membership and credits | Tier, status, period dates, session allowances, bundle and gift-voucher balances |
| Marketing | The lawful basis on which each person is on the mailing list, and the record for it: where they opted in, the consent status and audit trail (source, timestamp, wording shown); where you rely on the soft opt-in, the notice shown and the request in which it was shown (wording, timestamp, IP address, device). Also mailing-list membership, email delivery, open and click events |
| Account and technical | Authentication identifiers, roles and permissions, IP address, device and browser data, audit-log entries |
| Optional demographic survey | Where you enable the community survey: birth year, gender, ethnicity, postcode, work and housing situation, whether the person lives locally |
The optional demographic survey collects ethnicity, which is special category data under Article 9. It is off by default and collected only if you switch it on. If you enable it, you are responsible for identifying an Article 9 condition and providing the relevant privacy information to your customers. Session Processes it only as storage and retrieval, and it appears only in your own exports and reports.
Continuous, for the term of the Agreement.
Access control. Role-based access (admin, staff, superadmin) with least-privilege permission sets. Staff accounts can be scoped to named locations. Authentication and session management are provided by Clerk. Administrative access to production infrastructure is limited to named personnel with multi-factor authentication.
Tenant isolation. All records are scoped to an organisation identifier. Database row-level security is enabled, and application-layer authorisation checks organisation ownership on every read and write of tenant data.
Encryption. TLS 1.2+ in transit for all connections. Encryption at rest for the database, object storage and backups.
Payment data. Card details are collected directly by Stripe (PCI-DSS Level 1). Session stores only payment metadata and Stripe identifiers.
Backups and resilience. Daily automated database backups with 7-day point-in-time restore, plus an independent weekly off-platform backup with 14-day retention. Backup integrity is checked automatically and a failed or empty backup fails the job.
Logging and monitoring. An administrative activity log records privileged actions against bookings, customers and configuration. Automated nightly reconciliation checks payment records against Stripe and alerts on divergence.
Secure development. Version-controlled source, peer or automated code review before release, migrations applied under change control, and secrets held in the deployment platform's encrypted environment store rather than in source.
Personnel. Personnel with access to Personal Data are bound by confidentiality obligations.
Business continuity. The Platform operates without routine manual intervention, and a second individual holds full access to the source code and to each underlying platform account so that the service can be operated and maintained if the principal is unavailable. See Section 13.
Sub-processor management. Written data processing terms with each Sub-processor and an appropriate Article 46 transfer mechanism where the Sub-processor is outside the UK/EEA.
Current as at 19 August 2026.
| Sub-processor | Service | Entity / location | Data location |
|---|---|---|---|
| Supabase | Database, storage and back-end infrastructure | Supabase Inc., USA | AWS eu-west-1 — Republic of Ireland (EEA) |
| Vercel | Application hosting and content delivery | Vercel Inc., USA | Primary compute in Dublin, Republic of Ireland (EEA); global edge network for static content |
| Stripe | Payment processing and subscription billing | Stripe Payments Europe Ltd., Republic of Ireland | EEA / Stripe global infrastructure |
| Clerk | Authentication and user identity | Clerk Inc., USA | United States |
| Resend | Transactional email delivery | Resend Inc., USA | United States |
| Amazon Web Services | Marketing email delivery (SES) | Amazon Web Services, Inc. | eu-west-2 — London, United Kingdom |
| bunny.net | Image and asset content delivery | BunnyWay d.o.o., Slovenia (EU) | London, United Kingdom |
| Featurebase | In-app support chat and feedback | CORDNET OÜ (registry code 14748498), Kaluri tee 4-32, Haabneeme alevik, Viimsi vald, Harju maakond 74001, Estonia (EEA) | Estonia (EEA) |
| Address autocomplete during account setup (administrator entry only) | Google Ireland Ltd. / Google LLC | EEA / United States |
Where a Sub-processor is outside the UK/EEA, transfers are made under the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, and, where applicable, that Sub-processor's Data Privacy Framework certification.
| Right | How to satisfy it |
|---|---|
| Access / portability (Art. 15, 20) | Customers → Export produces a CSV of customer records including contact details, visit and spend history, membership, marketing consent and any survey answers. Reports → Export produces the bookings ledger and session attendance. Search a single customer first to scope the export to them. |
| Rectification (Art. 16) | Edit the customer record directly in Customers. |
| Erasure (Art. 17) | Contact Session and we will action erasure or anonymisation within the statutory deadline. Where the customer has booking history, records required for tax and accounting are anonymised rather than deleted and retained under Section 10.3. |
| Restriction / objection (Art. 18, 21) | Every person on a mailing list carries a per-organisation record of why they are on it — a consent audit trail where they opted in, or the notice they were shown where you rely on the soft opt-in. Marketing stops on request from the customer's account page, from the unsubscribe link in any marketing email, or by you in Customers, and an objection binds whichever basis applied. |
| Withdrawing consent (Art. 7(3)) | Self-service from the customer's account page or any marketing email footer. The same two controls stop marketing sent under the soft opt-in, where there is no consent to withdraw and the right engaged is the objection above. |
Processor — Wil Grace, sole trader, trading as Session
Name: ............................ Title: ............................
Signature: ............................ Date: ............................
Controller
Name: ............................ Title: ............................
Signature: ............................ Date: ............................