Legal | Privacy record

Privacy policy

How Sessional Limited (company number 17159781) collects, uses, and protects your personal data.

1. Who we are

Sessional Limited (company number 17159781, ICO registration reference ZC167783) ("Sessional", "we", "us") is the data controller for personal data processed through sessional.co.uk and email.sessional.co.uk. We provide workflow software for UK locum healthcare professionals.

Data protection contact: [email protected]

2. What data we collect

We collect the following categories of personal data:

Account information

  • First name, last name, and email address
  • Phone number (optional)
  • Professional registration number (optional)
  • Profile photo (optional)
  • Password (stored as a one-way cryptographic hash. We cannot read your password.)

Professional information

  • Employment type and pension scheme
  • Primary specialty and professional biography
  • Postcode for location-based search. When you use address lookup or autocomplete, we may send postcode and free-text address search strings to Ideal Postcodes so we can return UK address matches.
  • National Insurance number and pension reference number (used for NHS pension form generation, stored encrypted at rest)

Workflow data

  • Booking records (dates, times, rates, organisation details, payment terms, cancellation terms)
  • Invoice data (amounts, payment status, organisation references, delivery tracking)
  • Billing details (bank name, sort code, account number, UTR, company registration, stored encrypted at rest)
  • Expense records (category, amount, mileage, dates, receipt uploads)
  • Professional documents (DBS, indemnity certificates, training records, stored encrypted in transit)
  • Booking requests from organisations
  • Availability calendar entries
  • NHS pension form calculations and submission records
  • Notification preferences
  • Support tickets and correspondence (every tier; Pro is routed first)

Technical and security data

  • Authentication session records (login times, last activity)
  • Audit logs of account actions (for security and compliance)
  • Email delivery status (sent, delivered, bounced, via Postmark)
  • API keys and usage logs (Pro tier)

3. How we use your data

PurposeLawful basis
Providing the Sessional service (bookings, invoicing, pension forms, expenses)Contract performance
Account creation, authentication, and email verificationContract performance
Processing payments and managing subscriptions via StripeContract performance
Sending transactional emails (booking confirmations, password resets, verification, invoice delivery to organisations)Contract performance
Storing uploaded documents and receipts securelyContract performance
Displaying your public profile to organisations in the locum directoryContract performance (you control visibility)
Providing API access for automation (Pro tier)Contract performance
Processing support ticketsContract performance
Security monitoring, fraud prevention, and audit loggingLegitimate interests
Product updates and new feature announcementsConsent (you can unsubscribe at any time)
Keeping what you typed into the free invoice template, so we can help if you get in touch and understand which professions use the toolLegitimate interests

When you use the free invoice template, we keep the details you typed, except your bank details and your own address, which we never store, for 180 days, so we can help if you get in touch and understand which professions use the tool; where you have agreed to hear from us we may also use them to tell you about Sessional. Your name, email address, phone number and registration number are encrypted at rest, and the technical data described in section 10 is kept with them. After 180 days the whole record is deleted.

4. Who we share your data with

We share your data only with the following third-party processors, and only to the extent necessary to provide the service:

ProviderPurposeWhere it processes dataData shared
StripePayment processing and subscription managementUnited StatesEmail, name, payment method details
PostmarkTransactional email delivery (outbound) and inbound mail handling for support@/billing@/contact@/security@/hello@ aliases routed via the inbound subdomain (email.sessional.co.uk)United StatesEmail address, name, message bodies sent to the listed aliases
CloudflareCDN, WAF, DNS, Tunnel, and file storage (R2)United Kingdom region (R2), global edge network (CDN, WAF)Profile photos, invoice PDFs, receipts, professional documents, uploaded documents and CVs, and the nightly encrypted database backup
Anthropic (Claude API)The Plus AI assistant, and helping our staff draft replies to messages you send usUnited StatesThe question you submit to the assistant, message bodies sent to the listed aliases or exchanged with us in a conversation, and, where the sender holds a Sessional account, a summary of that account (see section 14)
OVHcloud (AI Endpoints)CV profile summaries, the reflection assistant and its identifier check, suggested learning needs, the session reflection prompts, transcribing voice notes, reading course certificates and receipts, some staff draft-reply generation, an automated content-safety filter, the feedback comment check and the feedback themes panel, the covering-note draft, and behind-the-scenes similarity search over our own help and product contentFranceThe CV text you submit, reflection text and the notes or answers you give the assistant, a summary of your own sessions and saved reflections when you ask for learning needs, a summary of your own sessions alone for the session reflection prompts, voice recordings you choose to transcribe (never stored by us), certificate and receipt images, message bodies where a member of staff uses AI to draft a reply, message content passed to the safety filter, feedback comments for the identifier check and the themes panel, and the covering-note facts described in section 14
postcodes.ioPostcode geocoding for location searchUnited KingdomPostcode only (no name or account details)
Ideal Postcodes (api.ideal-postcodes.co.uk)UK address lookup / autocompleteUnited Kingdompostcode and free-text address search strings
NHS Digital ODS (directory.spineservices.nhs.uk)organisation lookupUnited Kingdomorganisation search terms and postcode (no personal data)
CQC (api.service.cqc.org.uk)organisation lookupUnited Kingdomorganisation search terms and postcode (no personal data)
Xero (if connected by user)Accounting sync (Pro)Australia and New ZealandInvoices, expenses, contacts (only when user initiates connection)

We do not sell your data. We do not share it with advertisers, and we do not share it with anyone outside the processors listed above, except where you ask us to: sending an invoice or a booking confirmation to an organisation, or creating a document link, sends what you chose to the person you chose.

If you connect a third-party accounting integration (e.g. Xero), your invoice, expense, and contact data will be shared with that provider under their own privacy policy. You can disconnect at any time from your integrations page.

5. International data transfers

Your data is stored and processed in the United Kingdom: our application servers and database run on OVHcloud in London, and uploaded files are stored with Cloudflare R2 in the UK region. Some providers process data outside the UK. OVHcloud’s AI models run in France, covered by the UK’s adequacy regulations for the EU. Xero’s New Zealand entities are covered by the UK’s adequacy regulations for New Zealand. For providers in the United States (Stripe, Postmark, Anthropic, and Cloudflare’s own operations) we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses in our contract with them. The sub-processor table in section 4 names each provider, where it processes data, and what it receives.

We assess each processor to ensure your data receives equivalent protection to UK GDPR standards.

6. How long we keep your data

Data typeRetention periodReason
Account and profile dataUntil you delete your account + 30 days30-day grace period allows account recovery
Invoices and financial recordsDuration of account + 30 daysDeleted with account. HMRC record-keeping is the locum's own responsibility.
NHS pension form recordsDuration of account + 30 daysDeleted with account. Locums should retain their own copies.
Uploaded documents and receiptsDuration of account + 30 daysDeleted with account. Download copies before requesting deletion.
API keysA revoked key is disabled at once and deleted with your accountSecurity audit trail
Support ticketsDuration of account + 30 daysSupport history
Feedback respondents’ names and email addressesLife of the feedback round + 90 daysThird-party contact details held only to ask and to remind once. See section 15. The responses themselves stay with the professional’s record.
Audit logsKept while your account exists; on erasure the personal identifiers are removed and the de-identified trail is keptSecurity and compliance
Details typed into the free invoice template180 daysSee section 3. Bank details and your own address are never stored.
Authentication sessions30 days from last activitySession management

When you request account deletion, we remove all your personal data within 30 days, including invoices, bookings, expenses, and pension records. We recommend you export your data before requesting deletion.

7. Your rights

Under UK GDPR, you have the right to:

  • Access: request a copy of all personal data we hold about you
  • Rectification: correct any inaccurate data (you can do this directly in your profile settings)
  • Erasure: request deletion of your account and personal data
  • Portability: export your data in a machine-readable format
  • Restriction: ask us to limit how we use your data while a question about its accuracy or our basis for using it is settled
  • Object: object to processing based on legitimate interests
  • Withdraw consent: unsubscribe from marketing communications at any time
  • Complain to us: you can complain to us first, at the address in section 17; we will acknowledge within a month and tell you the outcome

What you must provide: your name, email address and profession are needed to open an account, because we cannot provide the service without them. Everything else is optional, and each feature explains what happens without it.

You can exercise your right to access and portability directly from your dashboard using the data export feature. For other requests, contact [email protected]. We will respond without undue delay and within one month.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

8. Data security

  • Passwords are securely hashed with per-user salts. We never store or have access to your password in plain text.
  • Sensitive personal data (bank details, registration numbers, pension references) is encrypted at rest using industry-standard encryption.
  • All connections are encrypted in transit using TLS (HTTPS) with strict transport security enforced.
  • Session management uses cryptographically secure tokens with appropriate browser security protections.
  • Uploaded documents and receipts are stored securely with no public access. Files are only accessible through authenticated requests.
  • Payment data is handled entirely by Stripe, a PCI DSS Level 1 certified payment processor. We never see or store card numbers.
  • Access to production systems is restricted to authorised personnel and subject to audit logging.
  • We implement standard web application security protections including cross-site scripting prevention, cross-site request forgery protection, and rate limiting.

9. Cookies

We use only strictly necessary cookies. We do not use tracking or advertising cookies. We load no analytics or advertising scripts. The visitor counting described in section 10 is our own first-party code, served from sessional.co.uk, and it sets no cookie. See our cookie policy for the full list of cookies and of what we store on your device.

10. Server-side visit logging

To count visitors accurately and detect abuse, we record each visit to our website with a daily-rotating SHA-256 hash of your IP address combined with your User-Agent string, the page URL, country and city derived from Cloudflare network-edge headers, the type of device used, and, if you are signed in, your account ID. We also record any UTM campaign parameters and click identifiers present in the inbound URL, and the page that referred you (if any).

If you create an account, we link the visits you made earlier that same day to your new account, so that we can tell which page brought you to us. This uses the same daily-rotating hash described above and reaches no further back than it: visits from previous days cannot be connected to you, because the hash has already changed.

We do not store raw IP addresses, do not set tracking cookies, load no analytics or advertising scripts, and do not share this data with any third party. The daily hash rotation means we cannot link visits across days back to an individual.

Records are retained for 90 days and then automatically deleted. The lawful basis is our legitimate interest in measuring website use, sizing infrastructure, and detecting abuse (UK GDPR Article 6(1)(f)). You can object to this processing at any time by contacting us at the address below; we will exclude your IP from future records on request.

11. Useful emails (opt-in only)

Our free invoice template includes an optional tickbox that asks if you would like occasional, genuinely useful emails from Sessional: tax-deadline reminders, GMC/NMC revalidation reminders, locum rate updates, occasional Sessional product updates, and the odd question about what we should build next. The box is unticked by default and you can use the tool without opting in.

When you tick the box we record: your email address, the tool you opted in from, the date and time, and a hashed copy of your IP and User-Agent (kept for audit so we can prove later that the consent came from a real session). We do not share this information with any third party, and we never sell your data. Each message contains a one-click unsubscribe link that works without logging in.

The lawful basis for sending these emails is your consent (UK GDPR Article 6(1)(a)) and PECR Regulation 22. You can withdraw consent at any time by clicking unsubscribe or emailing us. Withdrawal does not affect the lawfulness of processing before withdrawal.

12. Age restriction

Sessional is designed for qualified healthcare professionals. You must be at least 18 years old to create an account.

13. Changes to this policy

We may update this policy to reflect changes in our processing activities or legal requirements. We will notify you of material changes by email or through a notice in the application. The date at the bottom of this page shows when it was last updated.

14. AI assistant, reflections, voice notes, CV summaries, drafting replies, document sharing, and messaging

How we use AI, and what we never do with it

Sessional uses AI in a few places: the Plus assistant, the reflection assistant and voice notes on the Reflections page, suggested learning needs and the session reflection prompts, reading course certificates and receipts, the CV profile-summary tool, helping our staff draft replies to messages you send us, an automated content-safety filter on inbound messages, the identifier check and the themes panel on feedback rounds, drafting the covering note that goes with a feedback invitation, and behind-the-scenes similarity search over our own help and product content. In each case the relevant text, image, or audio is sent to an AI sub-processor only to generate a result. Neither provider uses data submitted through its API to train models, and we do not use your data to train any model. Data belonging to one person is never mixed with another person’s: the assistant and the CV tool only ever see your own data, and a draft reply only ever sees your message and your account.

When you use the reflection identifier check or the standard suggestion on the Reflections page, the text of that reflection is sent to OVHcloud AI Endpoints in the EU only when you press the button, and only after Sessional’s built-in check has found no NHS number, date of birth, or named person in it. The result is a list of findings or suggestions, the provider does not use it to train models, and nothing is written into your reflection for you.

The reflection assistant, voice notes, and certificates

The reflection assistant works only from material you give it. When you press the button that sends them, the rough notes you typed, the answers you gave to its questions, and the draft it composes are processed by OVHcloud AI Endpoints in the European Union. The same deterministic identifier check described above runs first, on every note, answer, and transcript, and blocks NHS numbers, dates of birth, and named people before anything is sent. Nothing is sent while you are typing, and nothing is sent to Anthropic: if the EU provider is unavailable, the feature returns an error rather than routing your reflection anywhere else.

A voice note is recorded in your browser and stays on your device until you press Transcribe. The audio is then sent to OVHcloud AI Endpoints in the EU for transcription only. Sessional never stores the audio, the provider does not retain it beyond what it needs for billing, and neither of us uses it to train any model. What comes back is a transcript, shown to you for checking, and it is kept only inside a record you choose to save. If you close the recorder or do not press Transcribe, the recording is discarded and never leaves the device.

A course certificate you upload to the CPD evidence store is read by the same EU provider so the title, provider, date, and hours can be offered to you as editable fields. The file itself is stored in the UK with your other uploads, and the values are not treated as yours until you confirm them. A certificate you forward to our receipts address is read in exactly the same way, by the same provider, as part of the receipts pipeline: what the read decides is whether the file is a certificate or a receipt, and therefore whether it is stored as CPD evidence or offered to you as a draft expense. You can move it either way afterwards.

When you ask for suggested learning needs, we send that provider a summary of your own record and nothing else: the names of the organisations you worked at, the type of setting each one is, the dates and start times of those sessions, how many days passed between them, how many sessions you worked at one organisation, and the titles and “what changes” lines of your last ten saved reflections. The suggestions come back to your screen, are never written into your record, and are not stored by us or by the provider. Nothing else about you is sent, and no other person’s data is ever in the request.

The “Start from a session” cards on the Reflections page send the same provider the same facts about your sessions, and only those: the names of the organisations you worked at, the type of setting each one is, the dates and start times of those sessions, how many days passed between them, and how many sessions you worked at one organisation. No reflection text goes with them, because the cards are written from your session log alone. The questions come back to your screen, nothing is written into your record, and none of it is used to train any model. The one difference from the learning needs above is that we do keep the questions: they are stored on your own profile and reused for a day, so that returning to the page shows you the same cards instead of asking the provider again, and the next set replaces them. A session whose organisation name looks like it holds someone’s details is left out of the cards altogether, and no other person’s data is ever in the request.

The monthly cycle reminder uses no AI at all. If you leave it switched on, it is written by Sessional from your own record: the counts on your meters, the days left in your cycle, and up to three recent sessions named by organisation and date. No AI provider sees it. It is delivered by Postmark like every other email we send, and you can switch it off under Notification preferences at any time.

We use two AI providers. The Plus assistant runs on Anthropic (the Claude API), which is US-based and processes data under UK-approved transfer mechanisms. The CV summary tool, the content-safety filter, similarity search, and some staff draft-reply generation run on OVHcloud AI Endpoints, which processes the text in the European Union (France) under the UK-EU adequacy decision. A member of staff drafting a reply may choose either provider.

Feedback rounds

Feedback themes. Once a round has at least three checked comments, the professional can ask for a reading aid: the checked comments are sent together to the OVHcloud model in France, which returns three to five themes. The output is checked for names before it is shown, is labelled as an aid rather than evidence, and only the themes are stored; no comment is altered.

Covering notes. When a professional invites colleagues, they can ask for a draft covering note; the model receives the professional’s own name and profession, the organisation’s name, the dates worked and how the questionnaire is described, never a respondent’s details. Nothing about the draft is stored.

AI assistant (Plus)

If you use the optional AI assistant, the text of your question, your recent chat turns, and a summary of your own Sessional data (your profession, plan, logged session count, your annualised earnings and tax-reserve estimates, and an operational snapshot such as outstanding invoices and upcoming sessions) are sent to Anthropic to generate a reply. The assistant provides general information, not regulated financial, tax, clinical, or regulatory advice.

CV profile summary

If you use the CV summary tool, the text of the CV you upload or paste is sent to OVHcloud AI Endpoints (in the EU) to draft a profile summary, which you review and edit before it is saved. It is not used to train any model. If you upload your CV as a file, a copy is saved to your own document store so you can reuse it; you can delete it there at any time. We do not retain the extracted CV text after the draft is generated.

Drafting replies to messages you send us

When you write to us, by emailing one of our support aliases (support@, billing@, contact@, security@, or hello@ at email.sessional.co.uk) or through a conversation in the app, a member of our staff may use AI to draft a reply. If they do, the text of your message and of the earlier messages in that conversation is sent to our AI provider (Anthropic or OVHcloud, at the drafter's choice), and the message may also be passed to our OVHcloud content-safety filter.

This applies whether or not you hold a Sessional account. If you write to us and have no account, the content of your message is still sent to our AI provider (Anthropic or OVHcloud) when a member of staff drafts a reply, and nothing else about you is sent because we hold nothing else.

Where you do hold an account, two further things are sent: up to the last eight messages you have exchanged with us across all your conversations, and a summary of your account so the reply is accurate. That summary is: your name and email address; your profession and regulator; your employment type; your plan, subscription status, and any trial or complimentary access; how long ago you signed up; whether your public profile is published; counts of your sessions, invoices sent, expenses, and documents (including how many documents expire in the next 30 days); your total earnings across paid invoices; the date of your last logged session; which Sessional features you have used; and the date, organisation name, city, and billing mode of your five most recent sessions. For nurses and midwives it also includes your NMC revalidation entry counts. It does not include your password, payment details, registration number, document contents, or invoice PDFs.

A draft is only ever a draft. A member of staff reads it, edits it, and decides whether to send it. Nothing is sent to you automatically, and the AI takes no action on your account.

Compliance document sharing (Plus)

When you create a compliance link, the documents you choose are made available to whoever holds the link (typically an organisation) through a time-limited, revocable URL, with no Sessional account required on their side. You decide what to include and can revoke the link at any time. We store metadata about the link (the documents included, its expiry, and view counts). We do not verify or validate the documents themselves; that is for you and the organisation.

Booking messages

Messages you exchange with an organisation on a booking are stored so the conversation history is available to you, and may be delivered to the organisation by email. We retain message content for the life of the booking record.

15. If you have been asked to give feedback about a professional

This section is for you if a healthcare professional has asked you for feedback through Sessional, as a colleague, as someone who booked or supervised them, or as a patient who saw them. You do not have a Sessional account and you are not our customer. You are a third party whose details a professional gave us so that we could ask you one set of questions on their behalf, and this section says what happens to those details.

Who holds your data, and why

Sessional Limited is the controller of the feedback round: the professional cannot see your individual answers, cannot edit them and cannot delete them, so it would be wrong to call them the controller of something they have no control over. That separation is the point of the feature. Regulators including the General Medical Council expect feedback used for revalidation to be collected and collated independently of the person being described, and Sessional is that independent collator. We are not affiliated with, endorsed by, or acting for any regulator.

Our lawful basis is legitimate interests: the professional’s interest in meeting a condition of staying registered, and ours in providing the service they use to do it. We have balanced that against your interests, which is why the round asks a small number of fixed questions, once, with a refusal link in the message itself.

What we collect about you

  • If you were emailed: your name and email address, given to us by the professional from their own records of the work, along with the role they say you had (colleague, manager, administrator or other) and the organisation the invitation relates to.
  • If you scanned a card or followed a short link: nothing that identifies you. A patient card carries no name and asks for none. We do not know who you are and we do not try to find out.
  • Your answers: the options you chose, and any comment you wrote.
  • Technical data needed to stop abuse of a public link, described in section 10 above.

Your name and email address, where we hold them, are encrypted at rest. Your answers are stored separately from them.

What the professional sees

Your scores are combined with everyone else’s. Anything you write is shown to the professional as a separate comment, without your name, the date or your role, in an order unrelated to when it arrived, and only once at least three people have left comments. Two automated checks remove names before anyone sees a comment. Your contact details are deleted 90 days after the round closes; your answers stay in the professional’s record as part of their appraisal evidence.

In more detail: totals, and only once at least five people have answered. Below that number the professional is told only that fewer than five responses have arrived, and nothing more precise: no exact count, no averages, no comments, no partial results, and no error or refusal message anywhere in the product that carries the number instead. Closing the round does not change that. The exact figure is withheld deliberately, because a number that moved by one after a single invitation went out would say what that one person did. At five and above they see, for each question, how many people answered and the average or proportion, and they see the written comments in an order unrelated to when they arrived, with no date, no role and no organisation attached, and only once at least three of them have been checked and can be shown together. There is no screen, export, download, report or programming interface anywhere in Sessional that shows one person’s answers, or that joins a comment back to the invitation it came from.

They are not shown whether you answered. A professional can see that they invited you, when the invitation was sent, and whether it bounced back. No interface, export, PDF, notification or log tells them that you responded, declined, or did nothing, and there is no setting that changes this. Reminders go to everyone who has not answered in a single action, and the professional is told only that the reminder has been sent: not a list, and not a count either, because on a round with one invitation still outstanding the difference between nobody and one person is your answer. Declines are not reported to them at all, not even as a number: a count that rose the morning after three invitations went out would be a fact about one of those three.

The counts and the report are recalculated once a day, over the responses received before midnight London time, so that a figure cannot move in step with a message the professional has just sent you.

We record a one-way fingerprint of the network and browser each response came from (a keyed cryptographic hash over the address and the browser’s user agent). We do not store your IP address against your response, and the fingerprint cannot be turned back into one. It is used only to count, on the report, how many responses arrived from a network or device the professional has also used. Those responses are kept and included in the figures: an organisation shares one network and one browser build, so a match there is at least as likely to be a colleague as the professional, and discarding a colleague’s honest answer on that basis would be worse than reporting the number and letting an appraiser weigh it.

One thing is excluded rather than counted. If a questionnaire is submitted while the professional’s own Sessional account is signed in on that browser, the response is left out of every figure in the report and the exclusion is counted and shown. The page reads its own session cookie if one happens to be present and looks at nothing else about you. The professional sees these as counts and never learns which response was involved.

Two automated checks run on your comment before anyone sees it: a rules-based check, and a language model in France that is asked only to name identifiers. Neither rewrites or scores what you wrote. The rules-based check runs as the comment is stored and replaces details that would identify a person: a name with a title in front of it, an NHS number, a date of birth, a phone number or an email address. The model then reads it on the hour and names any remaining personal names, such as a colleague named without a title, and those are replaced too, by ordinary code. A comment that has not been through both checks is not shown to anybody, so comments appear the morning after they are checked rather than being published unchecked if the second check is unavailable. A comment the second check cannot read at all stays held indefinitely, and the professional is told how many comments are being held, never which or by whom. Nothing is used to train any model. Please do not put your own name, a patient’s name, or anyone else’s in the comment box.

Once at least three comments have been checked, the professional can ask for a reading aid that lists three to five themes across the checked comments. It is produced by the same model in France, is checked for names before it is shown, and is labelled as an aid rather than as evidence. Only the themes are stored, no comment is altered, and your own comment is still shown separately in the way described above.

When the professional exports the report, or closes the round, Sessional records an unchangeable copy of the figures with a short code printed on the document. Anyone the professional gives that code to can open a public page showing what Sessional recorded for that version: the professional’s name and profession, the round, the window, the counts and the per-question averages. It never shows a comment, and it never shows anything about an individual respondent. It exists so that an appraiser can check the document they were handed against what Sessional actually recorded.

Who else can see your answers, and what the page loads

Our own staff cannot read your responses. No administrative screen lists or exports them, and the feedback pages and routes are blocked in assisted-support sessions, the mode in which a member of our staff views a customer’s account with that customer’s permission in order to help them. Support can see that a round exists and what its counts are. Our audit records log that a round was sent, reminded, closed, revoked or exported, with identifiers and counts, and never with the text of anything you wrote.

The page you answer on sets no cookies, loads nothing from any third party and carries no analytics. It is marked so that search engines do not index it and sends no referrer information onward, so following the link does not disclose to anyone else that you were asked. Nothing about your visit is shared with an advertising network, because none is present.

Your data is held in the United Kingdom: our servers and database run in the UK and your files are stored with Cloudflare in the UK region. The database connection is encrypted. Two things leave the UK: emails are delivered by Postmark in the United States, and the automated check for names in feedback comments runs on a model hosted in France by OVHcloud. Nothing is stored by either beyond what that step needs. Reports are generated at the moment they are requested and are not filed in any storage service afterwards.

How to decline

Every invitation and reminder email carries a decline link. It opens a page with a button, and the refusal is only recorded when you press that button. The second step is there on purpose: many mail systems and security filters open every link in a message automatically, and a decline that happened on the link alone could be triggered on your behalf by software, without your knowledge. Once you press it we stop asking. That refusal is permanent and applies across the whole of Sessional, not just to the round you were sent: no professional using Sessional can invite that address again, whoever they are. We keep a one-way cryptographic fingerprint of the address so that we can honour it without keeping the address itself. There is deliberately no self-serve way to undo a decline, because a link that reverses a refusal is a link that can be clicked by the wrong person. If you declined by mistake, write to us at the address in section 17 and we will remove the entry.

You can also simply not respond. Nothing happens if you ignore the invitation, beyond a single reminder.

How long we keep it, and what we never do with it

Your name and email address are deleted 90 days after the round closes or is withdrawn, whichever comes first, and a round closes automatically 60 days after it opens. Your answers stay, because they are part of the professional’s record and are by then no longer connected to any contact detail we hold. A decline fingerprint is kept indefinitely, because it exists to keep a promise not to contact you. If you reply to the invitation email, that reply is a support conversation rather than part of the round: it reaches our support desk, it is never shown to the professional, and it is kept with our other support correspondence rather than deleted on the 90-day timetable above.

We never market to you. Your address is used to send the invitation, at most one reminder, and nothing else. It is not added to any mailing list, is not used to suggest you create an account, is not sold, and is not shared with anyone beyond the email provider named in section 4 that delivers the message. It is not shown in full to the professional who gave it to us: their screen masks it.

You have the rights set out in section 7 over the data we hold about you, including asking for a copy of it or asking us to delete it. Where your feedback was given anonymously through a card, we may not be able to identify your response in order to act on such a request, because we hold nothing that connects it to you.

16. Organisation contacts

When a professional records an organisation’s contact and sends an invoice, chase or booking confirmation through Sessional, we process the contact’s name and email on the professional’s behalf and under their instructions, as their processor: we send the message, hold the thread so a reply reaches them, and delete the data when the professional deletes the record or erases their account. The professional is responsible for having a proper basis to use those details.

If you have received a message from Sessional on a professional’s behalf and want to know what we hold, write to the address in section 17 and we will tell you and pass your request to the professional.

17. Contact

For any questions about this policy or how we handle your data:

Sessional Limited, registered in England and Wales, company number 17159781.
Registered office: 128 City Road, London, EC1V 2NX.
Email: [email protected]

Last updated: 8 September 2026