Mara is used for conversations people would not have anywhere else. This notice sets out exactly what is collected, what is never collected, who it reaches and what you can make us do about it. It describes the platform as it works today, not as we would like it to work.
Session Care Ltd is a company registered in England and Wales under number 14261673, with its registered office at Flat 6, 102 Newent Close, London SE15 6ED. We trade as Session and as The Session Lab, and we operate Mara, an AI performance coaching platform. We are registered with the Information Commissioner's Office under ZC224491.
Which data protection role we hold depends on how you reached Mara, and the split is deliberate rather than convenient:
| Situation | Our role |
|---|---|
| You bought Mara yourself | Controller. We decide what is processed and why, and this notice is the whole story. |
| Your employer bought Mara and enrolled you | Processor for the data your employer instructs us on: that you have an account, that you are using it, and the aggregate cohort reporting they receive. Your employer is the controller for that, and their own privacy notice applies to it. |
| The content of your coaching sessions, in either case | Controller. Your employer cannot see this data, cannot ask us for it, and cannot instruct us on it. An organisation cannot be the controller of something it has no access to and no say over, so we hold that role and answer to you for it. |
| Our own billing, accounting and business records | Controller. |
The people who bought Mara for you see whether you turned up and how the group is moving. They never see what you said, what you scored, or what you worked on. That is a property of how the system is built and of the contract we sign with them, not a setting somebody could change on a bad day.
For anything in this notice, write to privacy@thesessionlab.com. We have not appointed a statutory Data Protection Officer, as we are not required to; privacy questions reach a named person on our side and are answered by them.
| What we do | Lawful basis |
|---|---|
| Run your account and deliver the coaching you signed up for | Contract (Article 6(1)(b)), or our legitimate interests in performing a contract with your employer where they enrolled you |
| Generate coaching responses, scores and summaries from your session | Contract (Article 6(1)(b)) — this is the service |
| Save a practice recording to your library | Consent (Article 6(1)(a)), given by choosing to keep the take. Withdrawn by deleting it. |
| Capture a real meeting through Meeting Observer | Consent (Article 6(1)(a)) from you, and see section 06 on everybody else in the room |
| Send you programme and member emails | Legitimate interests (Article 6(1)(f)) where you are a member, or consent where you are not. Unsubscribe in any message. |
| Aggregate, minimum-cohort reporting to an organisation that bought seats | Legitimate interests (Article 6(1)(f)) of that organisation in knowing whether the programme is working, balanced by the rule that no individual is identifiable in it |
| Keep the service secure, investigate abuse, keep audit records | Legitimate interests (Article 6(1)(f)) |
| Improve Mara's coaching quality | Legitimate interests (Article 6(1)(f)), using aggregated and de-identified material. Never by handing your sessions to anybody to train a model on. |
| Keep accounting and tax records | Legal obligation (Article 6(1)(c)) |
Where we rely on legitimate interests we have weighed them against your rights and concluded they do not override yours. You can ask us for that assessment, and you can object under section 09.
Two things need saying plainly, because a coaching product that reads a camera invites the wrong assumption about both.
We do not seek information about your health, and Mara is designed to coach performance rather than to treat anything. Mara is not therapy, is not a clinical service, and does not diagnose.
People under pressure sometimes volunteer things anyway — a panic response, a medication, a diagnosis. Where you choose to put that into a coaching session, we process it on the basis of your explicit consent (Article 9(2)(a)), given by choosing to share it, and we use it only to coach you in that session. It is never surfaced to your employer, never used in reporting, and you can withdraw that consent and have it deleted at any time by writing to privacy@thesessionlab.com. If you would rather it never touched our systems at all, use Off the Record, which is not retained.
Mara measures how you are delivering: pace, pitch, pause, energy, posture, gaze, stillness. Under UK and EU GDPR, data derived from a face or a voice becomes special category biometric data only when it is processed for the purpose of uniquely identifying a person. Mara does not do that. There is no facial recognition, no voiceprint, no identity matching, and no attempt to recognise you from your face or voice. The signals exist to coach the person already logged in, and they are measured on that person's own device.
Saving a practice take records only you, in your own browser, at your choice.
Meeting Observer is different, and there are two ways to use it. They do different things with other people's voices, so we describe them separately rather than averaging them into a comfortable sentence.
You are the person who owes those participants that duty; we cannot discharge it for you, and we will not pretend otherwise. Mara produces coaching about your contribution only: other participants are never scored, never profiled and never reported on.
We use a small number of providers to run the service. Each receives only what it needs, each is under a written contract that forbids using our customers' data to train its models, and the dated, authoritative version of this list lives in the Data Processing Agreement.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Anthropic PBC | Generates Mara's coaching responses and session analysis | Session text | United States |
| OpenAI | Converts speech to text, including meeting audio where you share a live source in Meeting Observer | Audio, then text | United States |
| Your browser's built in speech recognition, used to transcribe your own voice in Meeting Observer | Your speech audio | United States | |
| Supabase | Database, authentication and file storage | Account and session data | United Kingdom (London), vendor in the United States |
| Render | Application hosting | Requests in transit and in memory | European Union (Frankfurt) |
| Stripe | Subscriptions and payments | Billing and contact details | Ireland and United States |
| Brevo | Transactional and programme email | Name and email | France |
| Zoom | Meeting capture for Meeting Observer, only if you turn it on | Meeting audio | United States |
We will also disclose personal data where the law requires it, to our professional advisers under duties of confidence, and to a buyer if the business is ever sold — in which case you would be told before anything moved.
We publish changes to this list before they take effect, and organisation customers get thirty days' written notice and a right to object under the DPA.
Your database records and files are held in the United Kingdom, in the London region, by Supabase. The application itself runs in the European Union, in the Frankfurt region, on Render.
Some of the providers above are outside the UK and the EEA. Those transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the Addendum and the Clauses as applicable, together with a transfer risk assessment. Coaching text reaching Anthropic for generation, and audio reaching OpenAI for transcription, are transfers of that kind.
Whether the model that generates Mara's coaching runs through AWS Bedrock in Frankfurt or directly with Anthropic in the United States is a deployment setting, and it changes the answer above. We state the position that is live on the date on this page and we will not describe a configuration we have not switched on. Organisation customers who need EU or UK-only inference should ask for it, and the answer goes into their Data Processing Agreement as a binding term rather than a sentence on a website.
| What | How long, in reality |
|---|---|
| Coaching and Practise session records | Stamped with a ninety-day expiry when written. After that date Mara no longer returns the record, and a scheduled sweep deletes it. You can delete anything sooner by asking. |
| Meeting Observer recordings | We do not hold any. The extension writes the recording to your own computer and there is no route on our servers that accepts one. Deleting it is yours to do. |
| Historical usage events | Kept for product analytics, but stripped of the identifiers and the scores after ninety days, so what remains cannot be traced back to a person. |
| Working transcripts | Held for the session and to produce the summary and the scores. What we are trying to keep is the point of learning, not the conversation. |
| Off the Record | Not kept on our servers at all. Shredding is immediate and permanent. |
| Saved recordings | Kept until you delete them. Access is through expiring signed links. Delete removes the file from storage. |
| Account and profile | While your account is open. Deleted or anonymised within thirty days of closure, offboarding or a valid erasure request. |
| Billing and accounting records | Six years after the end of the relevant accounting period, because HMRC requires it. |
| Security and audit logs | Twelve months. |
| Marketing contacts | Until you unsubscribe, then a suppression record so we do not contact you again. |
Under the UK GDPR you can ask us to:
Some of these you can do yourself and immediately: delete any recording from your library, shred any Off the Record conversation, unsubscribe from any email. For the rest, write to privacy@thesessionlab.com. We answer within one month, free of charge. We may need to confirm who you are first.
If your employer enrolled you, direct requests about your enrolment and engagement data to them as controller; send anything about your coaching content to us. If you ask the wrong one of us, we will point you at the right one rather than leaving you to work it out.
If we get it wrong, complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or on 0303 123 1113. We would rather you came to us first, but that is your right, not our permission.
Mara is built on large language models. Three limits matter, and we hold ourselves to all three.
Mara can be wrong. It is a coach, not an oracle, and it is not a substitute for professional medical, psychological, legal or financial advice.
Overstating security is worse than having less of it, so this section says what is actually in place and stops there. Organisation customers get the full technical and organisational measures schedule in the DPA.
What we do not yet have. Single sign-on through your own identity provider, SCIM provisioning and multi-factor authentication are not built. They are on the roadmap and we will not claim them before they exist. We hold no SOC 2 or ISO 27001 certification. We are glad to complete your security questionnaire and to say no to the questions where the answer is no.
If you believe you have found a vulnerability, write to security@thesessionlab.com. We will not take legal action against anyone who reports one in good faith, gives us a reasonable chance to fix it, and does not access or alter data that is not theirs.
If a breach puts your rights at risk we will tell the ICO within 72 hours of becoming aware, and tell you without undue delay where the risk to you is high.
Mara is built for working adults and is not offered to anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will delete it.
We version this notice and date it. Where a change materially affects you we will tell you by email or in the product before it takes effect, rather than editing the page and hoping.
| Version | Date | Change |
|---|---|---|
| 1.0 | 18 August 2026 | First issue under Session Care Ltd. Replaces the earlier notice published under a trading name, and corrects the sub-processor, residency, retention and security descriptions to match the platform as built. |
Questions: privacy@thesessionlab.com. Anything else: hello@thesessionlab.com.