← Back

Data Processing Agreement

Session — booking platform (bookasession.org)

Version 1.0 · 19 August 2026


1. Parties and roles

This Data Processing Agreement ("DPA") is entered into between:

  • Wil Grace, a sole trader of 161 Cathedral Road, Cardiff CF11 9PL, United Kingdom, trading as Session ("Processor", "we", "us"); and
  • the organisation named in the Order Form or account registration ("Controller", "you"),

together the "Parties".

This DPA supplements and forms part of the Session Terms of Service (the "Agreement"). Where this DPA conflicts with the Agreement in relation to the Processing of Personal Data, this DPA prevails.

1.1 Allocation of roles

DataControllerProcessor
Your customers' personal data (bookings, contact details, waivers, marketing consent, membership records)YouSession
Your own account and staff-user data, billing data, and platform usage/telemetrySession

You determine the purposes and means of Processing your customers' Personal Data. Session Processes that data only to provide the Platform to you.

Where Session Processes data as a Controller in its own right (your account, billing, and platform telemetry), that Processing is governed by the Session Privacy Policy, not by this DPA.

1.2 Definitions

"Data Protection Law" means the UK General Data Protection Regulation, the Data Protection Act 2018, and — where applicable to a Party — Regulation (EU) 2016/679 ("EU GDPR"), each as amended.

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Data Protection Law.

"Sub-processor" means any third party engaged by Session to Process Personal Data on your behalf.


2. Subject matter, duration, nature and purpose

(UK GDPR Article 28(3))

Subject matter. Provision of the Session booking platform: session scheduling and capacity management, taking and managing bookings, payment initiation, digital waivers, memberships and credits, customer records, and transactional and marketing email.

Duration. The term of the Agreement, plus the retention and deletion periods in Section 10.

Nature and purpose. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to Sub-processors, restriction, erasure and destruction, in each case solely to provide the Platform and as further instructed by you.

Types of Personal Data and categories of Data Subject. See Annex 1.


3. Processing on documented instructions

3.1 Session Processes Personal Data only on your documented instructions, including as to international transfers, unless required to do otherwise by law. Where such a legal requirement applies, Session will inform you before Processing unless the law prohibits it.

3.2 Your instructions are: (a) the Agreement and this DPA; (b) your configuration and use of the Platform through the admin interface and API; and (c) any further written instructions agreed by the Parties.

3.3 Session will inform you if, in its opinion, an instruction infringes Data Protection Law. Session may suspend the affected Processing until the instruction is amended or confirmed.

3.4 Session does not sell Personal Data, and does not use your customers' Personal Data to train machine-learning models or for its own marketing.


4. Confidentiality

Session ensures that persons authorised to Process Personal Data are subject to an appropriate duty of confidentiality, are informed of the confidential nature of the data, and access it only where necessary to perform their role.


5. Security

(UK GDPR Articles 28(3)(c) and 32)

Session implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Current measures are described in Annex 2. Session may update these measures provided the level of security is not materially reduced.


6. Sub-processors

(UK GDPR Article 28(2) and 28(4))

6.1 You give general written authorisation for Session to engage Sub-processors. The current list is at Annex 3.

6.2 Session will give you at least 30 days' notice by email before adding or replacing a Sub-processor.

6.3 You may object to a proposed Sub-processor on reasonable data-protection grounds within that notice period. The Parties will work in good faith to resolve the objection. If it cannot be resolved, you may terminate the affected Services without penalty and receive a pro-rata refund of any prepaid fees.

6.4 Session imposes on each Sub-processor data-protection obligations no less protective than those in this DPA, and remains fully liable to you for each Sub-processor's performance.


7. Assisting you with Data Subject rights

(UK GDPR Article 28(3)(e))

7.1 The Platform provides self-service tools that let you respond to most requests yourself, including data export and access to a customer's full record. See Annex 4.

7.2 Where a request cannot be satisfied through those tools, Session will provide reasonable assistance, at no charge for a reasonable volume of requests, to help you respond within the statutory deadline.

7.3 If a Data Subject contacts Session directly about data Session Processes on your behalf, Session will not respond substantively (other than to acknowledge and redirect) and will notify you promptly.


8. Assisting you with security, breaches and DPIAs

(UK GDPR Article 28(3)(f), Articles 32–36)

8.1 Breach notification. Session will notify you without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Personal Data Processed on your behalf. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point.

8.2 Session will not notify a Supervisory Authority or Data Subjects on your behalf unless you instruct it to, or Session is legally required to do so.

8.3 Session will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the nature of Processing and the information available to Session.


9. Audit and information rights

(UK GDPR Article 28(3)(h))

9.1 Session will make available all information reasonably necessary to demonstrate compliance with Article 28 and this DPA.

9.2 You may audit Session's compliance no more than once in any 12-month period (and additionally after a Personal Data Breach affecting your data), on at least 30 days' written notice, during business hours, subject to reasonable confidentiality undertakings and without unreasonable disruption to Session's operations.

9.3 Session may satisfy an audit request by providing written responses to a reasonable questionnaire, or third-party certifications or reports where available.


10. Return and deletion of data

(UK GDPR Article 28(3)(g))

10.1 During the term. You may export your data at any time using the export tools in Annex 4.

10.2 On termination. At your choice, Session will return or delete Personal Data Processed on your behalf. You may export your data at any time during the term and for 30 days after termination. After that period Session will delete the data within a further 60 days, except as set out in 10.3.

10.3 Retention required by law. Session retains booking and payment records where required for tax, accounting or the establishment or defence of legal claims — currently up to 7 years, in line with UK tax law. Data retained on this basis is retained only for that purpose and remains subject to the security and confidentiality obligations of this DPA.

10.4 Service wind-down. If Session ceases to provide the Platform, Session will give you at least 90 days' notice and will make a complete export of your data available throughout that period.

10.5 Backups are cycled on a rolling basis and are overwritten in the ordinary course. Deletion from live systems takes effect immediately; deletion from backups takes effect as those backups expire, within 30 days.


11. International transfers

11.1 Personal Data is stored at rest in the European Economic Area (Republic of Ireland). See Annex 3 for the location of each Sub-processor.

11.2 Some Sub-processors are established in the United States. Where Personal Data is transferred outside the UK/EEA, Session ensures an appropriate safeguard is in place under Article 46 — the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, and where applicable the Sub-processor's certification under the UK–US and EU–US Data Privacy Framework.

11.3 Session will provide copies of the relevant transfer mechanisms on request.


12. Liability and general

12.1 Each Party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.

12.2 Notices. Notices under this DPA — sub-processor objections, audit requests, data-subject requests escalated to Session, and breach notifications — are given by email. Notices to Session go to wil@bookasession.org; notices to you go to the administrator email address on your account, and to your Also-send-to address where one is set.

12.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, unless the Agreement provides otherwise.

12.4 If any provision is held invalid, the remainder continues in force.


Annex 1 — Details of Processing

Categories of Data Subject

  • Your customers and prospective customers who book, join a waiting list, hold a membership, buy a bundle or gift voucher, sign a waiver, or subscribe to your mailing list.
  • Guests added to a booking by the booker or by your staff.
  • Your staff and administrators who hold Platform accounts.

Types of Personal Data

CategoryFields
Identity and contactName, email address, telephone number
Booking recordsSessions booked, dates and times, number of spaces, attendance and check-in status, notes added by your staff, booking reference
Payment recordsAmount, currency, payment status, refunds, payment method type, Stripe identifiers. No card numbers — card data is captured by Stripe and never reaches Session's systems
WaiversThe waiver text agreed, signer name and email, signature, timestamp and version
Membership and creditsTier, status, period dates, session allowances, bundle and gift-voucher balances
MarketingConsent status and the consent audit trail (source, timestamp, wording shown), mailing-list membership, email delivery, open and click events
Account and technicalAuthentication identifiers, roles and permissions, IP address, device and browser data, audit-log entries
Optional demographic surveyWhere you enable the community survey: birth year, gender, ethnicity, postcode, work and housing situation, whether the person lives locally

Special category data

The optional demographic survey collects ethnicity, which is special category data under Article 9. It is off by default and collected only if you switch it on. If you enable it, you are responsible for identifying an Article 9 condition and providing the relevant privacy information to your customers. Session Processes it only as storage and retrieval, and it appears only in your own exports and reports.

Frequency and duration

Continuous, for the term of the Agreement.


Annex 2 — Technical and organisational measures

Access control. Role-based access (admin, staff, superadmin) with least-privilege permission sets. Staff accounts can be scoped to named locations. Authentication and session management are provided by Clerk. Administrative access to production infrastructure is limited to named personnel with multi-factor authentication.

Tenant isolation. All records are scoped to an organisation identifier. Database row-level security is enabled, and application-layer authorisation checks organisation ownership on every read and write of tenant data.

Encryption. TLS 1.2+ in transit for all connections. Encryption at rest for the database, object storage and backups.

Payment data. Card details are collected directly by Stripe (PCI-DSS Level 1). Session stores only payment metadata and Stripe identifiers.

Backups and resilience. Daily automated database backups with 7-day point-in-time restore, plus an independent weekly off-platform backup with 14-day retention. Backup integrity is checked automatically and a failed or empty backup fails the job.

Logging and monitoring. An administrative activity log records privileged actions against bookings, customers and configuration. Automated nightly reconciliation checks payment records against Stripe and alerts on divergence.

Secure development. Version-controlled source, peer or automated code review before release, migrations applied under change control, and secrets held in the deployment platform's encrypted environment store rather than in source.

Personnel. Personnel with access to Personal Data are bound by confidentiality obligations.

Sub-processor management. Written data processing terms with each Sub-processor and an appropriate Article 46 transfer mechanism where the Sub-processor is outside the UK/EEA.


Annex 3 — Authorised Sub-processors

Current as at 19 August 2026.

Sub-processorServiceEntity / locationData location
SupabaseDatabase, storage and back-end infrastructureSupabase Inc., USAAWS eu-west-1 — Republic of Ireland (EEA)
VercelApplication hosting and content deliveryVercel Inc., USAPrimary compute in Dublin, Republic of Ireland (EEA); global edge network for static content
StripePayment processing and subscription billingStripe Payments Europe Ltd., Republic of IrelandEEA / Stripe global infrastructure
ClerkAuthentication and user identityClerk Inc., USAUnited States
ResendTransactional email deliveryResend Inc., USAUnited States
Amazon Web ServicesMarketing email delivery (SES)Amazon Web Services, Inc.eu-west-2 — London, United Kingdom
bunny.netImage and asset content deliveryBunnyWay d.o.o., Slovenia (EU)London, United Kingdom
FeaturebaseIn-app support chat and feedbackCORDNET OÜ (registry code 14748498), Kaluri tee 4-32, Haabneeme alevik, Viimsi vald, Harju maakond 74001, Estonia (EEA)Estonia (EEA)
GoogleAddress autocomplete during account setup (administrator entry only)Google Ireland Ltd. / Google LLCEEA / United States

Where a Sub-processor is outside the UK/EEA, transfers are made under the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, and, where applicable, that Sub-processor's Data Privacy Framework certification.


Annex 4 — Data subject request tooling

RightHow to satisfy it
Access / portability (Art. 15, 20)Customers → Export produces a CSV of customer records including contact details, visit and spend history, membership, marketing consent and any survey answers. Reports → Export produces the bookings ledger and session attendance. Search a single customer first to scope the export to them.
Rectification (Art. 16)Edit the customer record directly in Customers.
Erasure (Art. 17)Contact Session and we will action erasure or anonymisation within the statutory deadline. Where the customer has booking history, records required for tax and accounting are anonymised rather than deleted and retained under Section 10.3.
Restriction / objection (Art. 18, 21)Marketing consent is recorded per organisation with a full audit trail and can be withdrawn by the customer from their account page, from the unsubscribe link in any marketing email, or by you in Customers.
Withdrawing consent (Art. 7(3))Self-service from the customer's account page or any marketing email footer.

Signatures

Processor — Wil Grace, sole trader, trading as Session

Name: ............................ Title: ............................

Signature: ............................ Date: ............................

Controller

Name: ............................ Title: ............................

Signature: ............................ Date: ............................