← Session
Data Processing Agreement
Data Processing Agreement.
Session Care Ltd · registered in England and Wales, company number 14261673
Version 1.0 · issued 18 August 2026 · effective 18 August 2026
This is the agreement your legal team asked for. It is drafted to be signed as it stands. It forms part of the licence between your organisation and Session Care Ltd, and it governs wherever anything else we have written disagrees with it.
01Parties, and how this fits together
This Data Processing Agreement (DPA) is between:
| The Customer | The organisation named in the Licence, acting as
Controller. |
| The Processor | Session Care Ltd, registered in
England and Wales under number 14261673, registered office Flat 6, 102 Newent Close, London SE15 6ED, acting as
Processor. |
It is incorporated into the licence, order form or subscription agreement between the parties
(the Licence). It takes effect on the date of the Licence and lasts as long as we
process Customer Personal Data.
Order of precedence. Where there is a conflict, this DPA prevails over the
Licence on data protection matters, and both prevail over any published notice, security overview
or web page.
Definitions. "UK GDPR", "EU GDPR", "controller", "processor", "sub-processor",
"personal data", "processing", "data subject" and "personal data breach" carry the meanings given
in the UK GDPR and the Data Protection Act 2018. Data Protection Law means the UK
GDPR, the DPA 2018, the Privacy and Electronic Communications Regulations 2003 and, where it
applies to the Customer, the EU GDPR. Customer Personal Data means personal data
we process on the Customer's behalf under the Licence.
02Who is controller of what, and why the split matters
Mara has an unusual and deliberate architecture: the Customer buys the programme but
cannot see what any individual says inside it. That drives the roles.
| Data | Role |
| Enrolment and account administration data — who has a seat, team, status |
Customer is Controller. We are Processor. |
| Engagement and aggregate cohort reporting delivered to the Customer |
Customer is Controller. We are Processor. |
| The content of an individual's coaching and practice sessions, their scores, delivery
signals and recordings |
We are Controller in our own right, under our published Privacy Notice. The
Customer has no access to it, gives us no instructions on it and cannot obtain it under this DPA.
We answer to the individual for it. |
| Our billing, accounting and business records | We are Controller. |
The Customer acknowledges that it is not the controller of individual session content, cannot
require its disclosure, and will not seek it. This is a condition of the Licence. It is also the
reason members use the product honestly, which is the reason it works.
03Our obligations as Processor
We will:
- Process only on documented instructions. The Licence and this DPA are the
Customer's complete instructions. We will process on other instructions only if agreed in writing.
If the law requires us to process otherwise we will tell the Customer first, unless that law
forbids it.
- Tell the Customer if an instruction is unlawful in our opinion, and we may
suspend it until resolved.
- Keep it confidential. Everyone we authorise to process Customer Personal Data
is bound by a duty of confidentiality that survives the end of their engagement, and is granted
access only where they need it.
- Secure it using the measures in Annex 2, appropriate to the risk under Article
32.
- Manage sub-processors as set out in section 04.
- Assist with data subject rights as set out in section 05.
- Assist with Articles 32 to 36 — security, breach notification, data protection
impact assessments and prior consultation — taking account of what we know and what the Customer
does not.
- Notify a personal data breach as set out in section 06.
- Delete or return Customer Personal Data at the end of the Licence, as set out
in section 08.
- Make available the information needed to demonstrate compliance, and submit to
audits as set out in section 09.
04Sub-processors
The Customer gives general written authorisation for us to appoint the sub-processors listed in
Annex 3.
- Every sub-processor is engaged under a written contract imposing data protection obligations
no less protective than those in this DPA.
- Every sub-processor is contractually prohibited from using Customer Personal Data to train
models or for any purpose other than providing its service to us.
- We remain fully liable to the Customer for a sub-processor's performance.
- Change notice. We will give the Customer at least 30 days'
written notice before adding or replacing a sub-processor. The Customer may reasonably object on
data protection grounds within that period. If we cannot resolve the objection, the Customer may
terminate the affected part of the Licence without penalty and receive a pro-rata refund of
prepaid fees.
To receive change notices, send a monitored address to
privacy@thesessionlab.com.
05Data subject rights
Taking account of the nature of the processing, we will assist the Customer by appropriate
technical and organisational measures, so far as possible, in responding to requests under Chapter
III of the UK GDPR.
- Where we receive a request that relates to data we process for the Customer, we will not
respond to it ourselves. We will tell the Customer without undue delay, and no later than
5 working days, and follow the Customer's instructions.
- Where a request relates to session content for which we are the controller, we handle it
ourselves under our Privacy Notice, and we will tell the requester which of us holds what.
- Self-service is built in: a member can export or delete their own recordings and shred an Off
the Record conversation without asking anybody.
- Assistance under this section is provided at no charge, unless a request is manifestly
unfounded, excessive or repetitive, in which case we may charge a reasonable fee agreed in
advance.
06Personal data breach
- We will notify the Customer without undue delay and in any event within 72 hours
of becoming aware of a personal data breach affecting Customer Personal Data.
- The notification will describe the nature of the breach, the categories and approximate number
of data subjects and records affected, the likely consequences, the measures taken or proposed, and
a point of contact. Where we cannot provide all of it at once, we will provide it in phases without
further undue delay.
- We will co-operate with the Customer and take reasonable steps to contain, investigate and
remediate.
- We will not notify a supervisory authority or any data subject on the Customer's behalf, or
make any public statement identifying the Customer, without the Customer's prior written agreement,
unless the law requires it of us directly.
Report a suspected breach or vulnerability to
security@thesessionlab.com.
07International transfers
Customer Personal Data is stored in the United Kingdom (Supabase, London) and
the application processing it runs in the European Union (Render, Frankfurt). Some
sub-processors in Annex 3 process personal data outside the UK and the EEA.
- Where a transfer is made to a country without UK adequacy regulations, it is made under the
UK International Data Transfer Addendum to the EU Standard Contractual Clauses,
or the Addendum and the Clauses as applicable to the Customer,
together with a documented transfer risk assessment and supplementary measures where the assessment
calls for them.
- The parties agree that, to the extent the EU SCCs apply, Module Two (controller to processor)
is incorporated by reference: Annex 1 of this DPA populates the SCC Annex I, Annex 2 populates
Annex II, and Annex 3 lists the authorised sub-processors. The governing law and forum are those of
England and Wales, or of the relevant EU Member State where the EU SCCs apply directly.
- Where a Customer requires that inference and hosting remain within the UK or the EEA, that is
available as a configured deployment and is recorded as a binding term in the Licence. It is not
the default, and we will not describe it as though it were.
08Deletion and return
- On termination or expiry of the Licence, and at the Customer's election, we will delete or
return Customer Personal Data within 30 days, and delete existing copies unless
the law requires us to keep them.
- The Customer may request an export in a structured, commonly used, machine-readable format
during the Licence and for 30 days after it ends.
- Backups are deleted on their ordinary rotation cycle, which does not exceed
35 days. Personal data in a backup is not restored to live systems after a
deletion request.
- We may retain aggregated, anonymised data that cannot be attributed to an individual, and
records we are required by law to keep.
- Individual session content, for which we are controller, is deleted on the timetable in the
Privacy Notice and on a member's own request, whether or not the Licence has ended.
09Audit
- We will make available to the Customer the information necessary to demonstrate compliance with
Article 28, including a completed security questionnaire, our current measures, and any assurance
reports we hold.
- The Customer may audit once in any 12-month period, on 30 days' written notice, during business
hours, without unreasonably disrupting our operations, and under confidentiality. A further audit
may be conducted following a personal data breach affecting the Customer, or where a supervisory
authority requires it.
- Audits may be conducted by the Customer or by an independent auditor who is not our competitor
and who signs confidentiality undertakings.
- Each party bears its own audit costs, except that the Customer bears our reasonable costs for
any audit beyond the first in a 12-month period.
10Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability
in the Licence, except that nothing limits liability that cannot lawfully be limited, or either
party's liability to a data subject under Article 82.
Where both parties are responsible for damage caused by processing, liability is apportioned
according to each party's responsibility for the event.
11Annex 1 · Description of the processing
| Subject matter | Provision of the Mara AI performance coaching
platform to the Customer's personnel. |
| Duration | The term of the Licence, plus the deletion period in
section 08. |
| Nature and purpose | Hosting, storage, authentication, generation of
coaching responses, transcription, production of scores and summaries, aggregate reporting, and
transactional email, in order to deliver a communication and performance coaching programme. |
| Categories of data subject | The Customer's employees, contractors
and personnel enrolled on the programme, and their administrators. Incidentally, third parties
present in a meeting where a member has enabled Meeting Observer, whose speech is transcribed
only where the member shares a live meeting source. |
| Categories of personal data | Identity and contact data (name, work
email); employment data (job title, team, organisation); authentication data; profile and
diagnostic responses; session content (text of coaching conversations, journal entries); derived
delivery signals (pace, pitch, pause, energy, posture, gaze, stillness) and scores; saved
recordings where a member chooses to keep one; usage and progress records; technical and log data
(IP address, device, timestamps). |
| Special category data | Not requested and not required. A member may
volunteer health-related information in the course of a coaching conversation. Where they do, it is
processed on their explicit consent under Article 9(2)(a), is not disclosed to the Customer, and is
excluded from all reporting. Delivery signals are not biometric data within Article
9, because they are not processed for the purpose of uniquely identifying a natural person; there is
no facial recognition, voiceprint or identity matching in the platform. |
| Criminal offence data | None. |
| Frequency | Continuous, for the term. |
| Retention | As set out in section 08 and in the Privacy Notice. |
12Annex 2 · Technical and organisational measures
Stated as implemented on the date of this DPA. Section 12.10 lists what is not in place,
because a measures schedule that only lists strengths is not a measures schedule.
12.1 Encryption
- TLS for all traffic, with HTTP Strict Transport Security enforced.
- Encryption at rest at the database and object storage layer, managed by our database provider.
- An additional application layer of AES-256-GCM on a narrow category of safety-flagged content,
using a key held in the server environment and never exposed to the browser.
12.2 Access control
- Every request authenticated against a signed session token.
- Role-based authorisation, with administrative functions restricted to defined administrator
roles and the highest privileges held narrowly.
- The durable session cookie is HttpOnly, Secure and SameSite=Lax, so page scripts cannot read
it.
- Service credentials held server side only.
- Least privilege applied to personnel access, reviewed on joining and leaving.
12.3 Separation and confidentiality of members
- Organisations are isolated from one another.
- Individual session content, scores and signals are architecturally unavailable to the
Customer's administrators.
- Aggregate reporting is suppressed below a configurable minimum cohort size, set to no fewer
than five, so that an individual cannot be inferred from a group figure.
12.4 Retention enforcement
- Session records and saved practice recordings carry a ninety-day expiry stamped at creation.
- A scheduled sweep deletes expired records and the stored media behind them, and strips
identifiers and scores from historical usage events.
- Meeting recordings are never received by us. The Meeting Observer extension writes them to the
member's own machine and no server route accepts one, so there is no meeting recording in our
estate to retain, secure or breach.
12.5 Data minimisation by design
- Camera and microphone are read and analysed in the member's own browser. Raw video and audio
are not uploaded for analysis.
- A recording is stored only where the member chooses to keep a take.
- Off the Record conversations are not recorded, not transcribed and not retained on our servers.
12.6 Application security
- Content Security Policy, X-Content-Type-Options and a strict Referrer-Policy set on all
responses.
- Rate limiting on authentication, chat and application endpoints.
- Signed, expiring links for stored files.
- Dependencies from managed registries, with security updates applied on a routine cycle.
12.7 Logging and accountability
- Administrative actions on member records written to an audit log.
- Application and access logs retained for 12 months.
- Acceptance of this DPA and per-member consent recorded with a versioned, timestamped record.
12.8 Resilience
- Automated daily backups by our managed database provider, encrypted and held within the same
regional boundary as the primary data.
- Managed platform hosting with provider-level redundancy.
- Backup restoration tested periodically.
12.9 People and governance
- Confidentiality obligations on everyone with access, surviving the end of engagement.
- Written contracts with every sub-processor, prohibiting model training on customer data.
- A named individual accountable for data protection.
- Breach response process with a 72-hour notification commitment.
12.10 What is not in place
- No SOC 2, ISO 27001 or equivalent certification. We hold none, and we are not
mid-audit for one. We will say so on any questionnaire.
- No single sign-on, SCIM provisioning or multi-factor authentication. Not built.
On the roadmap. A Customer requiring SSO before deployment should treat it as a gating requirement
rather than a commitment.
- No penetration test by an independent third party has been commissioned to
date.
- No 24/7 security operations coverage. We are a small team and respond within
business hours, with an out-of-hours escalation route for confirmed incidents.
These are stated because a Customer's risk assessment is worth more than our marketing, and
because every one of them would be found in diligence anyway.
13Annex 3 · Authorised sub-processors
Current as at the date of this DPA. Changes are notified under section 04.
| Sub-processor | Purpose | Data | Location | Transfer basis |
| Anthropic PBC | Generation of coaching responses and session analysis |
Session text | United States | UK Addendum + EU SCCs |
| OpenAI, L.L.C. | Speech to text, including meeting audio where a member shares a
live source in Meeting Observer |
Audio, then text | United States | UK Addendum + EU SCCs |
| Google LLC | Browser built in speech recognition, used to transcribe the member's
own voice in Meeting Observer | Member speech audio | United States |
UK Addendum + EU SCCs |
| Supabase, Inc. | Database, authentication, object storage |
Account and session data | Data in United Kingdom (London); vendor support access from
the United States | UK Addendum + EU SCCs |
| Render Services, Inc. | Application and worker hosting |
Requests in transit and in memory | European Union (Frankfurt); vendor in the United
States | UK Addendum + EU SCCs |
| Stripe, Inc. / Stripe Payments Europe Ltd | Subscription and payment processing |
Billing and contact details | Ireland and United States |
UK Addendum + EU SCCs |
| Sendinblue SAS (Brevo) | Transactional and programme email |
Name and email | France | Adequacy (EEA) |
| Zoom Communications, Inc. | Meeting capture for Meeting Observer, only where a member
enables it | Meeting audio | United States | UK Addendum + EU SCCs |
| Amazon Web Services EMEA SARL | Model inference via AWS Bedrock, where the
Licence specifies EU-resident inference | Session text |
European Union (Frankfurt) | Adequacy (EEA) |
Where a Licence specifies EU-resident inference through AWS Bedrock, Anthropic PBC is not a
sub-processor for that deployment. Where it does not, AWS is not. The Licence states which applies,
and it is one or the other, not both at once.
14Signature
This DPA is agreed by the parties on the date of the Licence. Where a signed counterpart is
required, we will provide one on request to
privacy@thesessionlab.com, executed on behalf of Session Care Ltd.
| For the Customer | For Session Care Ltd |
Name Position Date Signature | Name Position Date Signature |