Privacy Statement

PRIVACY STATEMENT SESSY.APP

Located at 3e Poellaan 40, 2161 DN Lisse, the Netherlands Registered with the Chamber of Commerce under number 75498707

Last modification on: 11 September 2026

This Privacy Statement has been translated from the original Dutch version. In case of any discrepencies between the translated and the Dutch version, the Dutch version takes precedence. Click here for the Dutch version.

Sessy (hereinafter: “us”, “we” or “our”) offers an online Platform, via which Platform Users can 1) use the Services of Sessy and 2) Users can offer services to other Users and enter into agreements with each other. In these cases, the Personal Data you provide will be processed by us.

This privacy statement contains information about our policy regarding the processing (collection, storage, use, sharing and disclosure) of your Personal Data by Sessy, for example when you visit our Website, use our App or Platform, contact us through the form on our Website, register for our newsletter, create an account, use our Services or purchase services from a Provider on the Platform and enter into an agreement with the Provider, and the choices you have with regard to the processing of that data by Sessy.

We use your Personal Data to communicate with you, to perform the agreement we have entered into with you, and to provide and improve our Services. When you use our Services, you agree to the processing of your Personal Data in accordance with this policy.

1. DEFINITIONS

In this Privacy Statement, the following terms are capitalized and used with the following meaning:

  • Sessy: the owner of the Platform.

  • User: the person who uses the Sessy Platform.

  • Member / Members: the person who purchases services from the Provider via the Platform and enters into an Agreement with the Provider via the Platform.

  • Provider: the natural or legal person who offers services via the Platform and in that context enters into Agreements with one or more Members via the Platform.

  • Subscription: the agreement between a Provider and a Member on the basis of which the Member has the right to use the services of the Provider and to register for Sessions of the Provider.

  • Platform: the online platform of Sessy, consisting of the Website, the Sessy web application for Providers and Members, and the Sessy app that (among other things) enables Users to enter into Agreements with each other.

  • Sessy Web Application: online application (available at https://my.sessy.app) intended for Providers and Members in which the Provider can define what kind of Subscriptions they want to offer, what type of Sessions, etc. In addition, Providers can set the payment options for their Members in the Sessy Web Application, perform the membership administration, collect payments, schedule Sessions and communicate with their Members. Previously referred to as the Backend Application.

  • Sessy App: the native app, which can be downloaded on a mobile device, which enables the User to enter into one or more Subscriptions with Providers, register for Sessions, make payments to Providers and maintain personal account details.

  • Services: all services offered by Sessy, including but not limited to making the Platform available, including the associated functionalities and the mediation activities that Sessy performs.

  • Website: the website of Sessy, which can be reached via: https://www.sessy.app, as well as the support site (https://sessy.app/en/docs) and the Sessy web application (https://my.sessy.app).

  • Usage data: automatically collected data generated by the use of our Website, for example: the duration of the visit to a page on our website.

  • Data controller- the natural or legal person who (alone, jointly or jointly with other persons) determines the purposes for which and the manner in which Personal Data are or will be processed. In the context of this Privacy Statement, we are a Controller of your Personal Data.

  • Data processors: the natural or legal person who processes the Personal Data on behalf of Sessy. We may use the services of various Data Processors to process your data.

  • Data Subject: The Data Subject is any living individual who purchases Services from us and who is the subject of the Personal Data processed by us.

  • Personal data: all information about an identified or identifiable natural person. This means that information is either directly about someone or can be traced back to this person.

2. DATA COLLECTION AND USE

We collect different types of data for different purposes to perform our Services, as well as to provide our Services to you and to improve our Services.

Personal data

When you use our Platform, we may ask you to provide us with certain personally identifiable information that can be used to operate the Services, contact you, or identify you. This personally identifiable information may include, but is not limited to, the information below. A distinction is made here between Website visitors, (employees of) Providers and Members/Users.

Website visitor
Personal data Purposes for processing
IP address The IP address is stored by means of a cookie to provide chat functionality on the website for providing support to (potential) customers.
First and last name
Email
Telephone
Processing the contact form on the Platform and communication with the visitor of the Website.
(employees of) Provider
Personal data Purposes for processing
First and last name
Address
E-mail
Phone
Date of birth
Name and contact details of company contacts are kept for customer identification, support, use of the Platform, communication purposes and informing about developments on the Platform (such as new functionality).
Payment information The payment information is captured in Stripe and used to charge the monthly license fee.
Sessy does not have access to this information

Members / Users
Personal data Purposes for processing
First and last name Address
Email
Telephone
Date of birth
Name and contact details are kept so that the Providers on the Platform can communicate with their Members, provide their services and personalize services to their Members (exact service depends on the company) and collect payments.
Bank account If the company uses direct debit via its own company account: the IBAN bank account of Members is collected by the Platform in order to generate a payment file with which the Provider can import direct debits into their banking environment.
Payment data If the Provider uses Stripe to collect payments from their Members: Payment data is stored in Stripe. Sessy and the Provider do not have access to this data
Purchases Purchases (subscriptions and other purchases) are tracked on the Platform, including the payment status so that payments can be collected.
Session history The session history is kept on the Platform so that Sessy and Providers can offer a personalized service to their Users and Members (for example, based on the session types visited). In addition, the information is used to improve the service.
Personal Notes Personal notes and attachments may be added by the Provider to Members to provide a personal/individual service (tracking progress, injuries, etc.).
Device tokens Unique code for each device on which the Sessy App is used by Members/Users. The device token is used by Sessy and Providers on the Platform to send notifications (general and personal messages) to their Users and Members.

Sessy AI (in-app assistant)

Admin and Employee users of a Provider may use Sessy AI inside the Sessy app. This processing is done on behalf of the Provider (the gym is controller; Sessy is processor). Members do not chat with the assistant; staff do, and staff questions may retrieve Member data.

Depending on the Provider’s configuration:

  • Platform mode (default): Sessy sends the request to Opper (EU AI gateway) and then to Microsoft Azure in the EU (default model). See the Sub-processors list.
  • BYOK: the Provider’s own Opper account and chosen model. Sessy still transmits the request, but the Provider chooses region and vendor terms.
  • MCP (external tools): if the Provider creates an agent token, gym data may be sent to an AI vendor the Provider selects (Claude, ChatGPT, Cursor, etc.). That vendor is not a Sessy sub-processor.
Personal data Purposes for processing
Staff chat messages and recent conversation context To answer questions and prepare actions the staff user can review and confirm.
Gym data returned by AI tools Depending on role and question: schedule, member names, bookings, notes, programming, or other data that employee may already see in Sessy.
AI usage counters To apply query, credit and write limits.

Legal basis (when Sessy is controller): not applicable to Member data in Sessy AI — Sessy acts as processor. The Provider must have a basis to use Member data in the assistant (typically performance of the membership contract and/or legitimate interest). If notes contain health data (for example injuries), the Provider also needs an article 9 GDPR basis before staff use AI tools that can read those notes.

Training: Sessy does not use gym or Member data to train AI models. On the default Azure route, Opper states that Opper does not train on customer data and that Azure does not use this API content to train the model. Azure may retain content up to 30 days for abuse monitoring. Other models (BYOK or MCP) can differ — that is the Provider’s choice.

Location (platform mode): Opper is hosted in the EU; the default model provider is Azure in the EU. Sessy does not route platform-mode gym data to non-EU model providers unless the Sub-processors list is updated first.

Retention: The app may keep conversation history on the staff device until cleared. Sessy does not keep full prompt/response logs for billing beyond what is needed to run the service (usage counters). Sessy does not use AI conversations for marketing.

The written processing terms for Providers are the Processor addendum.

Sessy as Data Processor

Personal data of the Members of the Provider are processed by Sessy in the context of the Subscription that Members have purchased from the Provider. In this context, Sessy only processes the Personal Data of Members for the benefit of and on behalf of the Provider. With regard to that processing Sessy is therefore a Data Processor and not the Controller. The written terms for that processing are the Processor addendum. Sessy is only Controller with regard to the Personal Data of Members insofar as Sessy uses this Personal Data for its own purposes.

Usage data

We may collect data that your browser sends when you use our Platform. This Usage Data may include information such as your device’s Internet Protocol (IP) address, browser type, browser version, the pages you have visited on our Platform, the time and date of your visit, the time spent on those pages, the unique device identifier and other diagnostic data. When you use our Platform with a mobile device, this Usage Data may also include information such as the type of mobile device you use, the unique ID of your mobile device, the IP address of your mobile device, the operating system of your mobile device, the mobile internet browser that you use, the unique device identifier and other diagnostic data.

We use the Usage Data for a variety of purposes:

  • to collect analytics or valuable data that we can apply to improve the Platform and Services
  • to detect, prevent and treat technical problems

Newsletter

Similar to the information that we have indirectly collected about you, we may use the Personal Data you provide to us for sending our own newsletter or other marketing purposes, for example an email with offers that are related to the Services you have previously used, purchased from us or services from Providers that you may be interested in. For this we use your e-mail address and your first and last name. You can indicate at any time that you no longer wish to receive newsletters from us. To do so, please follow the unsubscribe instructions included in every email you receive from us.

If you are from the European Economic Area (EEA), the legal basis for the collection and use of the Personal Data described in this Privacy Statement depends on the Personal Data we collect and the specific context in which we collect it.

We may use your Personal Data because:

  • You use our Platform or our Services
  • You have given us permission to do so
  • The processing is in our legitimate interest and is not overridden by your rights
  • In compliance with the law

4. DATA STORAGE AND RETENTION

We primarily process and store Personal Data on infrastructure located in the European Union. Some sub-processors may process data outside the European Economic Area (EEA) where necessary for their service (for example payment processing), in which case we rely on appropriate safeguards such as Standard Contractual Clauses or the sub-processor’s DPA. Our Sub-processors list describes processor categories and typical locations.

For Sessy AI in platform mode, Sessy configures EU-hosted inference routes by default. Providers who enable BYOK choose their own model and region in Opper.

We only retain your Personal Data for as long as this is necessary for the purposes stated in this Privacy Statement. We retain and use your Personal Data to the extent necessary to comply with our legal obligations (e.g. if we are required to retain your data in compliance with applicable law), resolve disputes, and enforce our legal obligations or policies.

We also store your Usage Data for internal analytical purposes. Usage data is anonymized as much as reasonably possible, unless we are legally obliged not to store this data anonymously.

All Personal Data will be deleted by us when it is no longer necessary for the purposes for which we process the Personal Data, unless we are obliged to keep (part of) your Personal Data for longer on the basis of a legal obligation. Personal data is removed manually by us.

5. DATA DISCLOSURE

Business transaction

If Sessy.app is involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will notify you before your Personal Data is transferred and becomes the subject of a different Privacy Statement.

Disclosure for Law Enforcement Purposes

In certain circumstances, we may be required to disclose your Personal Data if required to do so by law or at the request of government authorities (e.g. a court or government agency).

We may disclose your Personal Data in the good faith belief that such action is necessary to:

  • To comply with a legal obligation
  • To protect and defend the rights and property of Sessy
  • To prevent or investigate possible wrongdoing in connection with the use of our Platform and the provision of Services
  • To protect the personal safety of Users of the Platform or the public
  • As protection against legal liability

6. DATA SECURITY

The security of your Personal Data is important to us. However, please note that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

7. YOUR DATA PROTECTION RIGHTS UNDER THE GENERAL PERSONAL DATA REGULATIONENS (GDPR)

If you are a resident of the European Economic Area (EEA), you have certain data protection rights. We strive to take reasonable steps to allow you to correct, amend, delete or limit the use of your Personal Data.

If you want to know which Personal Data we process about you and if you want certain Personal Data to be removed from our systems, you can contact us.

In any case, you have the following legal data protection rights:

  • The right to access, update or delete the Personal Data that we process about you. Where possible, you can access and update your Personal Data or request its deletion directly in your account settings. If you are unable to perform these actions yourself, you can contact us for assistance.
  • The right to correction. You have the right to have your information corrected if that information is inaccurate or incomplete.
  • The right to object. You have the right to object to the processing of your Personal Data.
  • The right to restriction. You have the right to request that we restrict the processing of your Personal Data.
  • The right to data portability. You have the right to receive a copy of the information we process from you in a structured, machine-readable and commonly used format.
  • The right to withdraw your consent. You also have the right to withdraw your consent at any time where we process your Personal Data based on your consent.

Please note that we may ask you to verify your identity before responding to such requests.

You have the right to submit a complaint to the Dutch Data Protection Authority regarding our collection and use of your Personal Data. For more information, please contact the Dutch Data Protection Authority.

8. SHARING OF PERSONAL DATA

Brokerage activities

Our Services include facilitating the conclusion of agreements between Users (Provider and Member). In this context, we may share your Personal Data with a Provider. This includes your first and last name, e-mail address, address, telephone number and IP address. The Provider processes the Personal Data he/she has received from us for his/her own purposes. The Provider is therefore itself the controller with regard to your Personal Data that the Provider receives from us.

In addition, in the context of our business activities, we share your Personal Data with external companies and persons to provide our Services, to (be able to) perform work in the context of our Services, to simplify our Services, to (be able to) process your Personal Data, or to help us analyze how our Services and Platform are used or could be improved.

We have concluded processing agreements with processors that process Personal Data on our behalf. Those processors may only use the data to perform their task for us.

We group processors by type: (1) cloud hosting and storage, (2) payments, (3) customer support, (4) AI inference for in-app Sessy AI, (5) analytics and security. Named providers, locations and DPA links: Sub-processors.

Processor addendum (Providers): If you are a Provider, Sessy processes Member Personal Data on your behalf under the Processor addendum. That addendum is the article 28 GDPR contract. You do not need to request a separate copy.

Processor Type Purpose
Google Cloud Hosting & storage Platform hosting in the EU (GCP, Firebase, Workspace, Analytics, reCAPTCHA as used on our sites). Google Cloud, Firebase
Stripe Payments License fees, optional AI credits, and Provider payment collection. May process outside the EEA. Stripe DPA
Chatwoot Support Website support chat, self-hosted by Sessy in the EU. No gym member database access. Chatwoot privacy
Opper + Microsoft Azure (EU) AI (platform mode) In-app Sessy AI only. Prompts and tool results go to Opper’s EU gateway, then Azure in the EU. Sessy does not train on this data. Azure may retain content up to 30 days for abuse monitoring. Opper DPA, Opper sub-processors
BYOK and MCP AI vendors are chosen by the Provider and are not listed as Sessy processors. See the Sub-processors page.

We do not sell your Personal Data to other parties.

Social media

On our Platform we may show messages and/or links to social media channels. The terms and conditions of the relevant social media platform apply to the use of social media.

On our Platform you may find hyperlinks to third party websites. We bear no responsibility with regard to the way in which these third parties handle your data. Read the privacy statement, if available, of the website you visit.

10. CHANGES TO THIS PRIVACY POLICY

We may update our Privacy Statement at any time. We will notify you of any changes by publishing the new Privacy Statement on our Platform.

11. CONTACT US

If you have any questions about this Privacy Statement or wish to exercise your rights, you can contact us via the website (contact form) or via email: contact@sessy.app.