What we do with personal data, in two distinct roles: as the controller of your account, and as the processor of your clients' records.
1. Two roles, kept separate
1. Two roles, kept separate
Sessionkeep handles two very different kinds of data, and the law treats them differently. Reading this policy is much easier once the distinction is clear.
- Your account data. Your name, email, practice settings, billing and support history. Here we are the data controller and this policy is our notice to you.
- Your clients' records. Everything you enter about the people you see: sessions, notes, documents, assessments, messages. Here you are the data controller and we act only as your processor, under the Data Processing Agreement. We do not decide what goes in, why, or for how long.
Clinical records are special category data under Article 9 of the UK GDPR and the EU GDPR. We treat them accordingly: they stay in the European Union, they are isolated per practice at the database level, and they never appear in our emails, our error monitoring or any analytics.
2. Who we are
2. Who we are
WORKSJO LTD, registered in England and Wales under number 15824979, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, registered with the UK Information Commissioner's Office under ZB810612. Sessionkeep is our trading name. For anything in this policy, write to privacy@sessionkeep.app
3. Data we hold as controller
3. Data we hold as controller
You give us
- Account details: name or practice name, email address, password hash or federated sign in identity, two factor settings and recovery code hashes.
- Practice settings: time zone, email preferences, booking configuration, client portal preferences.
- Billing details: subscription status, plan and invoice history. Card data goes to Stripe and never reaches us.
- Anything you send us: support messages and in app feedback.
We collect automatically
- Sign in events, device and session records so you can review and revoke your own sessions.
- Audit events recording which actions happened in your practice. These contain identifiers and action names, never clinical content.
- Technical logs and error reports. Client identifiers, portal links, request bodies and local variables are stripped before an error report leaves the application.
We do not use
- Advertising, marketing or behavioural analytics cookies. We run no third party analytics on the application.
- Any profiling or automated decision making that produces legal or similarly significant effects on you.
4. Why we may use it, and on what basis
4. Why we may use it, and on what basis
- To provide the service you subscribed to, and to bill you. Basis: performance of a contract.
- To keep accounts secure, prevent abuse and investigate incidents. Basis: legitimate interests.
- To send service messages you have configured, such as your own agenda email. Basis: performance of a contract.
- To answer support requests and act on feedback. Basis: legitimate interests, and performance of a contract.
- To meet accounting, tax and other legal obligations. Basis: legal obligation.
- To send occasional product announcements to account holders. Basis: legitimate interests, and you can opt out at any time.
5. Client records: what we do on your behalf
5. Client records: what we do on your behalf
We process your clients' data only on your documented instructions, which are the actions you take in the product. Concretely, that means:
- Storing records, documents and audio you upload in an EU database and EU object storage.
- Sending material to our AI provider as context when you use an AI feature, to produce your draft or answer. It is not used to train models.
- Sending names, dates and times, never clinical content, by email when you enable reminders, agenda or portal notifications.
- Relaying video and audio for online sessions. Sessions are not recorded by the video provider.
- Producing your export when you ask for one, and deleting records when you delete them.
Nobody at our company reads your clinical records as a matter of course. Access to production data is restricted, requires a specific operational reason such as a support request you raised or a fault we must fix, and is logged.
6. AI processing, stated plainly
6. AI processing, stated plainly
- We use large language models to draft notes, summarise, extract candidate facts, transcribe audio and answer questions about a record.
- Data submitted through the API is used to produce your output only. It is not used to train the provider's models, and we ask for zero retention where the provider offers it.
- AI output is a draft. It is never written into the record without your explicit approval.
- Every clinical claim in AI output carries a reference back to the source material.
- Semantic search uses numerical embeddings of your records, stored in the same EU database as the records themselves.
7. Who else is involved
7. Who else is involved
We rely on a small number of vetted providers. Each is listed on our sub-processors page with its purpose, its processing location and the legal basis for any transfer outside the EEA. The database that holds clinical records is in the European Union and does not leave it.
We do not sell personal data, and we do not share it with anyone for their own purposes. We may disclose data where the law compels us to; where we are permitted to tell you, we will.
8. How long we keep things
8. How long we keep things
- Client records: for as long as you keep them. You decide, and your professional retention obligations apply, not ours.
- Account data: for as long as your account is open, then up to 90 days after closure, except where we must keep records longer for accounting or legal reasons.
- Billing records: seven years, as UK tax law requires.
- Audit events: up to 24 months.
- Error reports: up to 90 days.
- Encrypted backups: they expire on a rolling cycle, and deleted data disappears from them as that cycle turns.
9. How we protect it
9. How we protect it
- Data is encrypted in transit and at rest.
- Every table enforces row level security, so a query can only ever return rows belonging to your practice. Isolation is enforced by the database, not only by application code.
- Two factor authentication with recovery codes, plus device and session management you control.
- Least privilege access to production, with logging.
- Deliberate omissions that matter: no session replay, no analytics on the app, no clinical content in email, no client data in error reports.
10. Your rights
10. Your rights
If you hold a Sessionkeep account, you have the following rights over your account data under the UK and EU GDPR. Write to privacy@sessionkeep.app and we will respond within one month.
- Access a copy of your data, and export your records at any time from the app.
- Correct data that is wrong, and complete data that is incomplete.
- Erase data, subject to obligations that require us to keep some of it.
- Restrict or object to processing based on legitimate interests.
- Receive your data in a portable format.
- Withdraw consent where processing rests on consent, without affecting what happened before.
- Complain to a supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority where you live or work.
If you are a client of a therapist who uses Sessionkeep, your therapist is the data controller. Please address requests about your records to them. If you contact us directly, we will refer you to them and, where appropriate, tell them you got in touch.
11. Turkey: KVKK notice
11. Turkey: KVKK notice
For data subjects in Turkey, this section serves as the disclosure notice required by Article 10 of Law No. 6698 on the Protection of Personal Data. The data controller is WORKSJO LTD, at the address above. Health data is special category data under Article 6 of the Law and is processed only within the limits set out here.
- Purposes: providing the subscription service, securing accounts, billing and meeting legal obligations, as described in section 4.
- Method and legal ground of collection: collected electronically through the application, on the grounds that processing is necessary for the performance of a contract and for our legitimate interests, and, for health data, on the basis of explicit consent obtained by the therapist as controller.
- Transfers abroad: our providers are listed on the sub-processors page. Transfers outside Turkey rest on your explicit consent to this policy and, where applicable, on the safeguards described there.
- Your rights under Article 11: to learn whether your data is processed, to request information and correction, to request erasure, to object to results produced solely by automated analysis, and to claim compensation for damage. Requests go to privacy@sessionkeep.app and can also be raised with the Personal Data Protection Authority.
12. Cookies
12. Cookies
We use only what the service needs to work: a session cookie to keep you signed in, a language preference cookie, and a portal session cookie when a client verifies their identity. We set no advertising or analytics cookies, so there is no consent banner to click through.
13. Children
13. Children
Sessionkeep accounts are for professionals and are not offered to children. Therapists may of course keep records about young clients; where they do, the therapist is the controller and is responsible for the lawful basis, including any parental consent their jurisdiction requires.
14. Changes
14. Changes
We will post any change here and update the date at the top. If a change materially affects your rights, we will email account holders at least 30 days before it takes effect.
15. Contact
15. Contact
WORKSJO LTD, registered in England and Wales under number 15824979, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, registered with the UK Information Commissioner's Office under ZB810612. Sessionkeep is our trading name. For anything in this policy, write to privacy@sessionkeep.app