This addendum forms part of the agreement between Another Session ("Processor") and the customer ("Controller") whenever the Controller stores personal data about their own clients in the Service. It applies automatically to every paid and free account.
1. Roles
The Controller decides what client information to record (for example, a client's name, contact details, session notes and payment status). The Processor stores and processes that information solely on the Controller's documented instructions, which are the configuration and use of the Service.
2. Subject matter and duration
The Processor processes personal data for as long as the Controller's account is active, plus the deletion period set out in the Privacy Policy.
3. Nature and purpose of processing
Hosting, storage, organisation, retrieval, backup and deletion of the Controller's client records, session notes, packages and payment tracking, in order to provide the Service.
4. Categories of data subjects and data
- Data subjects: the Controller's clients (and, where relevant, parents or guardians of junior clients).
- Data categories: name, contact details, session history, coaching notes, payment status, package balances, and any other information the Controller chooses to record.
The Service is not designed to store special category data (such as health or biometric data). Controllers should avoid recording such data unless they have an appropriate lawful basis.
5. Processor obligations
- Process personal data only on the Controller's instructions.
- Ensure people authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures, including encryption in transit and at rest, role-based access controls and row-level security.
- Assist the Controller with data subject rights requests, security incidents, data protection impact assessments and consultations with supervisory authorities.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting their data.
- On termination, delete or return personal data, except where retention is required by law.
6. Sub-processors
The Controller authorises the following sub-processors, listed in the Privacy Policy: Lovable Cloud (Supabase) for hosting and database, and Resend for transactional email. We will give the Controller reasonable prior notice of any new sub-processor and a chance to object.
7. International transfers
Where personal data is transferred outside the UK or EEA, the Processor uses appropriate safeguards such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
8. Audits
The Processor will make available, on reasonable written request, summary information about its security and compliance practices to help the Controller meet its audit obligations under Article 28 GDPR.
9. Liability
Liability under this addendum is governed by the limitations set out in the Terms of Service.
10. Contact
For data protection matters, email hello@anothersession.app.