Data processing addendum
The DPA terms for customer-controlled personal data processed by sessions.im on behalf of UK accounting firms.
- Effective date
- 2026-07-10
- Owner
- legal
Processing instructions
sessions.im processes customer personal data only to provide the service, follow documented customer instructions, and meet legal obligations.
Security measures
Controls include MFA for sensitive administration, permission-checked artifact access, short-lived links, audit logs, EU storage, and provider adapter boundaries.
Subprocessors
Approved subprocessors are listed on the subprocessors page. Material changes are published before use where commercially reasonable.
Return and deletion
On termination, customer data is returned or deleted according to the contract, retention policy, legal hold, and audit obligations.