← Session
Data Processing Agreement

Data Processing Agreement.

Session Care Ltd · registered in England and Wales, company number 14261673
Version 1.0 · issued 18 August 2026 · effective 18 August 2026

This is the agreement your legal team asked for. It is drafted to be signed as it stands. It forms part of the licence between your organisation and Session Care Ltd, and it governs wherever anything else we have written disagrees with it.

  1. Parties, and how this fits together
  2. Who is controller of what, and why the split matters
  3. Our obligations as Processor
  4. Sub-processors
  5. Data subject rights
  6. Personal data breach
  7. International transfers
  8. Deletion and return
  9. Audit
  10. Liability
  11. Annex 1 · Description of the processing
  12. Annex 2 · Technical and organisational measures
  13. Annex 3 · Authorised sub-processors
  14. Signature

01Parties, and how this fits together

This Data Processing Agreement (DPA) is between:

The CustomerThe organisation named in the Licence, acting as Controller.
The ProcessorSession Care Ltd, registered in England and Wales under number 14261673, registered office Flat 6, 102 Newent Close, London SE15 6ED, acting as Processor.

It is incorporated into the licence, order form or subscription agreement between the parties (the Licence). It takes effect on the date of the Licence and lasts as long as we process Customer Personal Data.

Order of precedence. Where there is a conflict, this DPA prevails over the Licence on data protection matters, and both prevail over any published notice, security overview or web page.

Definitions. "UK GDPR", "EU GDPR", "controller", "processor", "sub-processor", "personal data", "processing", "data subject" and "personal data breach" carry the meanings given in the UK GDPR and the Data Protection Act 2018. Data Protection Law means the UK GDPR, the DPA 2018, the Privacy and Electronic Communications Regulations 2003 and, where it applies to the Customer, the EU GDPR. Customer Personal Data means personal data we process on the Customer's behalf under the Licence.

02Who is controller of what, and why the split matters

Mara has an unusual and deliberate architecture: the Customer buys the programme but cannot see what any individual says inside it. That drives the roles.

DataRole
Enrolment and account administration data — who has a seat, team, status Customer is Controller. We are Processor.
Engagement and aggregate cohort reporting delivered to the Customer Customer is Controller. We are Processor.
The content of an individual's coaching and practice sessions, their scores, delivery signals and recordings We are Controller in our own right, under our published Privacy Notice. The Customer has no access to it, gives us no instructions on it and cannot obtain it under this DPA. We answer to the individual for it.
Our billing, accounting and business recordsWe are Controller.

The Customer acknowledges that it is not the controller of individual session content, cannot require its disclosure, and will not seek it. This is a condition of the Licence. It is also the reason members use the product honestly, which is the reason it works.

03Our obligations as Processor

We will:

  1. Process only on documented instructions. The Licence and this DPA are the Customer's complete instructions. We will process on other instructions only if agreed in writing. If the law requires us to process otherwise we will tell the Customer first, unless that law forbids it.
  2. Tell the Customer if an instruction is unlawful in our opinion, and we may suspend it until resolved.
  3. Keep it confidential. Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality that survives the end of their engagement, and is granted access only where they need it.
  4. Secure it using the measures in Annex 2, appropriate to the risk under Article 32.
  5. Manage sub-processors as set out in section 04.
  6. Assist with data subject rights as set out in section 05.
  7. Assist with Articles 32 to 36 — security, breach notification, data protection impact assessments and prior consultation — taking account of what we know and what the Customer does not.
  8. Notify a personal data breach as set out in section 06.
  9. Delete or return Customer Personal Data at the end of the Licence, as set out in section 08.
  10. Make available the information needed to demonstrate compliance, and submit to audits as set out in section 09.

04Sub-processors

The Customer gives general written authorisation for us to appoint the sub-processors listed in Annex 3.

To receive change notices, send a monitored address to privacy@thesessionlab.com.

05Data subject rights

Taking account of the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, so far as possible, in responding to requests under Chapter III of the UK GDPR.

06Personal data breach

Report a suspected breach or vulnerability to security@thesessionlab.com.

07International transfers

Customer Personal Data is stored in the United Kingdom (Supabase, London) and the application processing it runs in the European Union (Render, Frankfurt). Some sub-processors in Annex 3 process personal data outside the UK and the EEA.

08Deletion and return

09Audit

10Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Licence, except that nothing limits liability that cannot lawfully be limited, or either party's liability to a data subject under Article 82.

Where both parties are responsible for damage caused by processing, liability is apportioned according to each party's responsibility for the event.

11Annex 1 · Description of the processing

Subject matterProvision of the Mara AI performance coaching platform to the Customer's personnel.
DurationThe term of the Licence, plus the deletion period in section 08.
Nature and purposeHosting, storage, authentication, generation of coaching responses, transcription, production of scores and summaries, aggregate reporting, and transactional email, in order to deliver a communication and performance coaching programme.
Categories of data subjectThe Customer's employees, contractors and personnel enrolled on the programme, and their administrators. Incidentally, third parties present in a meeting where a member has enabled Meeting Observer, whose speech is transcribed only where the member shares a live meeting source.
Categories of personal dataIdentity and contact data (name, work email); employment data (job title, team, organisation); authentication data; profile and diagnostic responses; session content (text of coaching conversations, journal entries); derived delivery signals (pace, pitch, pause, energy, posture, gaze, stillness) and scores; saved recordings where a member chooses to keep one; usage and progress records; technical and log data (IP address, device, timestamps).
Special category dataNot requested and not required. A member may volunteer health-related information in the course of a coaching conversation. Where they do, it is processed on their explicit consent under Article 9(2)(a), is not disclosed to the Customer, and is excluded from all reporting. Delivery signals are not biometric data within Article 9, because they are not processed for the purpose of uniquely identifying a natural person; there is no facial recognition, voiceprint or identity matching in the platform.
Criminal offence dataNone.
FrequencyContinuous, for the term.
RetentionAs set out in section 08 and in the Privacy Notice.

12Annex 2 · Technical and organisational measures

Stated as implemented on the date of this DPA. Section 12.10 lists what is not in place, because a measures schedule that only lists strengths is not a measures schedule.

12.1 Encryption

12.2 Access control

12.3 Separation and confidentiality of members

12.4 Retention enforcement

12.5 Data minimisation by design

12.6 Application security

12.7 Logging and accountability

12.8 Resilience

12.9 People and governance

12.10 What is not in place

These are stated because a Customer's risk assessment is worth more than our marketing, and because every one of them would be found in diligence anyway.

13Annex 3 · Authorised sub-processors

Current as at the date of this DPA. Changes are notified under section 04.

Sub-processorPurposeDataLocationTransfer basis
Anthropic PBCGeneration of coaching responses and session analysis Session textUnited StatesUK Addendum + EU SCCs
OpenAI, L.L.C.Speech to text, including meeting audio where a member shares a live source in Meeting Observer Audio, then textUnited StatesUK Addendum + EU SCCs
Google LLCBrowser built in speech recognition, used to transcribe the member's own voice in Meeting ObserverMember speech audioUnited States UK Addendum + EU SCCs
Supabase, Inc.Database, authentication, object storage Account and session dataData in United Kingdom (London); vendor support access from the United StatesUK Addendum + EU SCCs
Render Services, Inc.Application and worker hosting Requests in transit and in memoryEuropean Union (Frankfurt); vendor in the United StatesUK Addendum + EU SCCs
Stripe, Inc. / Stripe Payments Europe LtdSubscription and payment processing Billing and contact detailsIreland and United States UK Addendum + EU SCCs
Sendinblue SAS (Brevo)Transactional and programme email Name and emailFranceAdequacy (EEA)
Zoom Communications, Inc.Meeting capture for Meeting Observer, only where a member enables itMeeting audioUnited StatesUK Addendum + EU SCCs
Amazon Web Services EMEA SARLModel inference via AWS Bedrock, where the Licence specifies EU-resident inferenceSession text European Union (Frankfurt)Adequacy (EEA)

Where a Licence specifies EU-resident inference through AWS Bedrock, Anthropic PBC is not a sub-processor for that deployment. Where it does not, AWS is not. The Licence states which applies, and it is one or the other, not both at once.

14Signature

This DPA is agreed by the parties on the date of the Licence. Where a signed counterpart is required, we will provide one on request to privacy@thesessionlab.com, executed on behalf of Session Care Ltd.

For the CustomerFor Session Care Ltd
Name
Position
Date
Signature
Name
Position
Date
Signature
Session Care Ltd, a company registered in England and Wales under number 14261673.
Registered office: Flat 6, 102 Newent Close, London SE15 6ED. Registered with the Information Commissioner's Office under ZC224491.
Trading as Session, also known as The Session Lab. Mara is the platform; Session is the company and the owner of the methodology.
Privacy privacy@thesessionlab.com · Security security@thesessionlab.com · General hello@thesessionlab.com
© 2026 Session Care Ltd. All rights reserved.