Back to Sessionkeep

Data Processing Agreement

Article 28 terms between you as controller and WORKSJO LTD as processor. This agreement takes effect automatically when you open an account and forms part of the Terms of Service.

Last updated August 4, 2026

1. Parties and roles

1. Parties and roles

This agreement is between you, the account holder ('Controller'), and WORKSJO LTD ('Processor'). It applies to personal data that the Processor processes on the Controller's behalf through Sessionkeep. No signature is needed: it binds both parties from the moment the account is created.

For the Controller's own account and billing data, the Processor acts as a controller in its own right; that processing is governed by the Privacy Policy, not by this agreement.

2. Subject matter, duration, nature and purpose

2. Subject matter, duration, nature and purpose

  • Subject matter: the provision of clinical documentation and practice management software.
  • Duration: for as long as the account is open, plus the deletion period in section 11.
  • Nature: storage, organisation, retrieval, generation of drafts by automated means, transmission, and erasure.
  • Purpose: enabling the Controller to document and manage their own clinical practice.

3. Types of personal data and categories of data subjects

3. Types of personal data and categories of data subjects

Data subjects

  • The Controller's clients, and where relevant their emergency contacts or guardians.
  • People whom the Controller mentions in a record in the course of clinical work.

Types of data

  • Identifiers chosen by the Controller: pseudonyms, contact names, email addresses and phone numbers.
  • Special category data under Article 9: data concerning health, including session notes, transcripts, uploaded documents, assessment scores and messages.
  • Appointment data: dates, times, attendance and booking requests.
  • Consent records and signed forms, including signature images.

4. Controller instructions

4. Controller instructions

The Processor will process personal data only on the Controller's documented instructions. The actions the Controller takes in the product, together with this agreement and the Terms of Service, constitute those instructions.

The Processor will inform the Controller if, in its opinion, an instruction infringes data protection law, and may suspend the instruction until it is resolved. Where law requires the Processor to process data otherwise, it will inform the Controller before processing unless that law forbids it.

5. Confidentiality

5. Confidentiality

Access to personal data is limited to personnel who need it to operate or support the service. Those people are bound by written confidentiality obligations that survive the end of their engagement, and their access is logged.

6. Security measures (Annex II)

6. Security measures (Annex II)

The Processor implements appropriate technical and organisational measures under Article 32, including:

  • Encryption of data in transit (TLS) and at rest.
  • Row level security on every table, so tenant isolation is enforced by the database rather than by application code alone.
  • Two factor authentication with recovery codes, plus device and session management for account holders.
  • Least privilege access to production systems, with audit logging of administrative access.
  • Segregation of clinical data from telemetry: no clinical content in emails, error reports or analytics, and no session replay.
  • Automated daily backups with a rolling expiry, and documented restore procedures.
  • Vulnerability management through maintained dependencies and monitored builds.

7. Sub-processors (Annex III)

7. Sub-processors (Annex III)

The Controller gives general written authorisation for the Processor to engage sub-processors. The current list, with purpose, location and transfer basis, is published on the sub-processors page and forms part of this agreement.

The Processor will notify account holders by email before a new sub-processor begins processing, giving the Controller a reasonable period to object on legitimate data protection grounds. If the objection cannot be resolved, the Controller may terminate the subscription and export the data before the change takes effect. Each sub-processor is bound by written terms imposing obligations no less protective than these, and the Processor remains fully liable for their performance.

8. International transfers

8. International transfers

Clinical records are stored in the European Union. Where a sub-processor processes personal data outside the EEA or the United Kingdom, the transfer is made under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum where applicable, supported by a transfer risk assessment.

9. Assistance with data subject rights

9. Assistance with data subject rights

The service gives the Controller direct means to satisfy data subject requests: access and portability through export, rectification and erasure through the interface, and restriction through archiving. Where the Controller cannot fulfil a request with those tools, the Processor will provide reasonable assistance taking into account the nature of the processing.

If a data subject contacts the Processor directly, the Processor will not respond on the merits and will refer them to the Controller, informing the Controller where appropriate.

10. Personal data breaches

10. Personal data breaches

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, the measures taken and a point of contact, to the extent known, and will be supplemented as the investigation progresses.

The Processor will assist the Controller in meeting its own obligations under Articles 33 and 34, including any duty to notify a supervisory authority or affected individuals. Deciding whether to notify remains the Controller's decision.

11. Deletion and return

11. Deletion and return

  • The Controller may export all data at any time from the application in a portable format.
  • On termination, or on the Controller's instruction, the Processor deletes the Controller's data from live systems.
  • Residual copies in encrypted backups are deleted as the backup cycle turns, within 35 days, and remain subject to this agreement until they are gone.
  • The Processor may retain data where law requires it, and will process it only for that purpose.

12. Audits and information

12. Audits and information

The Processor will make available the information necessary to demonstrate compliance with Article 28, and will contribute to audits conducted by the Controller or an auditor it mandates. In the first instance the Processor may satisfy an audit request by providing documentation of its measures and sub-processors. Where an on site audit is genuinely necessary, the parties will agree scope and timing in advance, it will take place no more than once a year unless a breach has occurred, and it must not compromise the confidentiality of other customers' data.

13. Data protection impact assessments

13. Data protection impact assessments

Taking into account the nature of the processing and the information available to it, the Processor will provide reasonable assistance with data protection impact assessments and prior consultation under Articles 35 and 36.

14. Liability and precedence

14. Liability and precedence

The liability provisions of the Terms of Service apply to this agreement. In the event of a conflict between this agreement and the Terms of Service in relation to the processing of personal data, this agreement prevails. Where Standard Contractual Clauses apply and conflict with this agreement, those clauses prevail.

Questions about this agreement: privacy@sessionkeep.app