Processor addendum — Sessy.app
Last updated: 11 September 2026
Parties: the Provider (controller) and Sessy (processor).
This addendum supplements article 6.6 of the Terms of Use and applies to all Providers using the Platform. The Dutch version prevails.
This page is the written article 28 GDPR processing agreement. You do not need to request a separate copy.
1. Roles
- The Provider is controller for personal data of Members, staff and others that the Provider stores in Sessy.
- Sessy is processor for that data insofar as Sessy processes it to provide the Platform.
- Sessy is controller for its own purposes (license billing, Provider accounts, website visitors, support chat on sessy.app). Those processing operations are covered by the Privacy Statement, not this addendum.
2. Subject matter
|
|
| Subject |
Hosting and delivery of the Sessy platform (membership admin, schedule, payments, communication, and optionally Sessy AI). |
| Duration |
For as long as the Provider uses the Platform, plus any retention required by law. |
| Nature |
Storage, access, transmission, alteration and deletion on the Provider’s instructions, including sharing with sub-processors. |
| Purpose |
Only to perform the services the Provider enables in Sessy. |
| Data subjects |
Members, Provider staff/contacts, and other people whose data the Provider enters in Sessy. |
| Data |
Identity and contact details, subscriptions, bookings, payment status, session history, notes/attachments, device tokens, and — if the Provider uses Sessy AI or MCP — chat messages and tool results. |
Notes may include special-category data (for example health data about injuries). Sessy processes that only if the Provider stores it or retrieves it via AI/MCP. The Provider is responsible for a valid legal basis, including GDPR article 9 where applicable.
3. Instructions
- Sessy processes personal data only on the Provider’s documented instructions: use of the Platform, the Terms, this addendum, and reasonable written instructions.
- Sessy AI (platform mode) is an instruction to process relevant gym data (depending on role and question) via Sessy’s AI sub-processors, solely to answer or prepare a change.
- BYOK: enabling the Provider’s own Opper key is an instruction to send the same in-app requests via the Provider’s Opper account. The Provider chooses model and region and must have an appropriate relationship (including a DPA) with Opper.
- MCP: creating an agent token is an instruction to give API access to the external AI tool the Provider chooses. That tool is not a Sessy sub-processor. The Provider is responsible for that vendor (DPA, transfers, training, location).
4. Confidentiality and security
Sessy ensures persons with access are under confidentiality, and applies appropriate technical and organisational measures (GDPR article 32), including access control, encryption in transit, and EU hosting for core Platform data.
5. Sub-processors
- The Provider gives general written authorisation for Sessy to engage sub-processors.
- The current list, by type of processing, is at Sub-processors. That page forms part of this addendum.
- For Sessy AI in platform mode, the relevant sub-processors are Opper (AI gateway, EU) and Sessy’s chosen EU model provider (default: Microsoft Azure in the EU, via Opper). Opper may use its own sub-processors as listed in the Opper sub-processor list.
- Sessy imposes data-processing terms on sub-processors that are no less protective than this addendum.
- When Sessy adds or replaces a sub-processor, it updates the list. The Provider may object within 30 days of publication on objective data-protection grounds. Absent timely objection, the change is accepted. If an objection is justified, the Provider may disable the relevant feature (for example Sessy AI) or terminate the agreement.
6. Transfers outside the EEA
Core Platform data is processed primarily in the EU. Some sub-processors (in particular Stripe for payments) may process data outside the EEA. Sessy relies on a valid transfer mechanism (such as Standard Contractual Clauses) in that sub-processor’s DPA.
Sessy AI in platform mode is configured for an EU route (Opper in the EU + Azure in the EU). BYOK and MCP may leave the EU if the Provider configures them that way; that is the Provider’s choice and responsibility.
7. Training
Sessy does not use Provider or Member data to train AI models. On the default platform route, Opper states that Opper itself does not train and that the Azure route is not used to train the model. Model providers may retain requests briefly for abuse monitoring (for Azure: up to 30 days according to Opper). Other models the Provider chooses via BYOK or MCP may have different terms.
8. Data-subject rights, incidents, audits
- Sessy assists the Provider with data-subject requests insofar as the Platform features or reasonable cooperation allow. Requests Sessy receives directly about a gym’s member data are forwarded to that Provider.
- Sessy notifies the Provider without undue delay of a personal-data breach affecting processing under this addendum, with information the Provider needs for GDPR articles 33/34.
- On request, Sessy makes available the information needed to demonstrate article 28 compliance. Audits are at most once per year, after reasonable notice, at the Provider’s cost, without disproportionate disruption or access to other customers’ data.
9. End of processing
After the Provider stops using the Platform, Sessy deletes or returns the Provider’s personal data unless law requires retention. Export through Platform features counts as return.
10. Liability and law
Liability follows the Terms of Use. Dutch law; courts as in the Terms of Use.
Contact: contact@sessy.app