sessions.imAll legal documentsHelp centre
published

Data processing addendum

The DPA terms for customer-controlled personal data processed by sessions.im on behalf of UK accounting firms.

Effective date
2026-07-10
Owner
legal

Processing instructions

sessions.im processes customer personal data only to provide the service, follow documented customer instructions, and meet legal obligations.

Security measures

Controls include MFA for sensitive administration, permission-checked artifact access, short-lived links, audit logs, EU storage, and provider adapter boundaries.

Subprocessors

Approved subprocessors are listed on the subprocessors page. Material changes are published before use where commercially reasonable.

Return and deletion

On termination, customer data is returned or deleted according to the contract, retention policy, legal hold, and audit obligations.