Sub-processors

Sub-processors — Sessy.app

Last updated: 11 September 2026

This page is part of the Processor addendum and supplements section 8 of the Privacy Statement. It lists types of processors, then the named providers Sessy actually uses.

Sessy wears two hats:

When Sessy’s role Whose data
Gyms using the Platform (including Sessy AI in platform mode) Processor for the gym Member and gym data
Website visitors, Provider billing, Sessy’s own accounts Controller Visitor and customer-contact data

Type 1 — Cloud hosting and application infrastructure

Provider Purpose Location Documents
Google Cloud / Firebase Hosting, database, authentication, push, file storage, App Check EU (primary) Google Cloud, Firebase

Not used to train AI models.


Type 2 — Payments

Provider Purpose Location Documents
Stripe Sessy license billing, optional AI credit checkout, Provider collection of member payments May include non-EEA Stripe DPA

Sessy does not store full card numbers.


Type 3 — Customer support (website)

Provider Purpose Location Documents
Chatwoot (self-hosted by Sessy) Support chat on sessy.app EU Chatwoot privacy

Messages you type in the website chat are stored on Sessy’s EU Chatwoot server. This chat does not access gym member databases. It is separate from in-app Sessy AI.


Type 4 — AI inference (in-app Sessy AI, platform mode only)

Used only when a gym uses the in-app assistant without BYOK.

Provider Type Purpose Location Documents
Opper AI gateway Routes prompts and tool results to the configured model EU (AWS Stockholm) Opper DPA, Opper sub-processors, Opper security
Microsoft Azure (via Opper, family azure) Model provider Generates the assistant reply EU Listed on Opper’s sub-processor page

What is sent: staff chat messages, recent conversation context, and gym data the tools return (schedule, members, notes, etc., limited by that employee’s role).

Training: Sessy does not train models on this data. Opper states it does not train on customer data. For the default Azure route, Opper states the content is not used to train the model. Azure may retain content for up to 30 days for abuse monitoring.

Opper’s own vendors (for example AWS in Sweden, error logging in the EU) are Opper sub-processors, not separate Sessy contracts. See Opper’s list.

Default production model: azure/gpt-5.6-luna (EU Azure). Sessy does not send platform-mode traffic to non-EU model providers unless this page is updated first.


Not Sessy sub-processors (Provider’s choice)

These are listed so gyms and members are not left guessing. They are not processors Sessy selects for all customers.

BYOK (own Opper key). The gym chooses the Opper account, model and region. Sessy still transmits the request as processor, on the gym’s instruction. The gym must have its own DPA with Opper.

MCP (external AI tools). If a gym creates an agent token and connects Claude, ChatGPT, Cursor or another MCP client, that AI vendor is the gym’s processor, not Sessy’s. Data location, training and retention follow that vendor’s terms. Prefer Limited — no member data tokens when member data is not needed. See Connect AI agent.


Type 5 — Analytics and security (website)

Provider Purpose Location Documents
Google Analytics Website usage Configured for EU Google Analytics
Google reCAPTCHA Abuse prevention on forms Google infrastructure Google privacy

Changes

Material changes to this list are published here. Providers may object within 30 days as described in the Processor addendum.

Questions: contact@sessy.app