SessioSessio

Data Processing Agreement

Effective date: 22 July 2026 · Last updated: 28 July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Sessio ApS ("Sessio," "we," "us," the "Processor") and the organisation — a publisher, label, school, or association — that subscribes to or is granted access to the Sessio Publisher Portal (the "Customer," "you," the "Controller"). It governs Sessio's processing of personal data on the Customer's behalf under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applicable Danish data-protection law.

On the subject of Customer personal data that Sessio processes on the Customer's documented instructions, this DPA prevails over any conflicting term in our Terms of Service or Privacy Policy. Terms not defined here have the meaning given to them in the GDPR.

1. Parties and roles

This DPA applies where Sessio processes personal data on behalf of the Customer in connection with the Sessio Publisher Portal.

  • The Customer is the Controller. It determines the purposes and means of processing the personal data of its roster and staff, and is responsible for having a lawful basis for that personal data being in Sessio.
  • Sessio is the Processor. It processes that personal data only on behalf of, and on the documented instructions of, the Customer, as described in this DPA.
  • Where a sub-processor processes personal data on Sessio's behalf, Sessio remains responsible to the Customer for that sub-processor's performance (Section 6).

Where Sessio acts as an independent controller, that processing is governed by our Privacy Policy, not by this DPA. This applies, for example, to the Customer's billing and account-administration contacts, to securing and improving the Platform, and to the Customer's own use of the marketing website. It also applies to the hunt and enrichment services - the royalty hunts and profile hunts (whether started by the member or run at the Customer's request on the member's behalf), the roster sweep, the organisation-identity dossier, and the co-signer ranking. For those services Sessio determines the purposes and means of the processing and acts as controller; they are not performed on the Customer's instructions, and Section 1A states what the Customer may and must do with the results it can see. This DPA covers only processing where Sessio acts as a processor for the Customer.

Contact for data-protection matters: [email protected]. Sessio ApS, CVR 45830012, Burmeistersgade 2, 1. th, 1429 København K, Denmark.

1A. Hunt Services - Sessio as controller; the Customer as recipient

"Hunt Services" means the following services, together with the corresponding member-initiated (self-run) versions of them, in each case as described in this Section 1A:

  • (a) Organisation-run royalty hunts. At the request of the Customer's administrator, and only for a roster member who holds a current member-approved grant at the required tier, Sessio searches external sources - collecting-society unclaimed-works and works-register data obtained on documented, licensed access routes; licensed commercial data feeds; and public music-credit and catalogue databases - for royalties, registrations and rights-data gaps that may belong to that member. Where the Customer prepares claims, the full finding and every claim draft are written into the member's own Sessio account as ready-to-send claims. Where the Customer runs a gap scan only, the result is a summary in the Portal and no finding or claim draft is created for the member. Only the member can send a claim; Sessio provides no mechanism by which the Customer can file or send a claim as the member.
  • (b) The roster sweep. Sessio's own scheduled watch that periodically re-checks roster members holding a current qualifying grant for new gaps, on Sessio's initiative and schedule, without any act by the Customer. Members who have objected, and members at the view-only tier, are excluded.
  • (c) The on-behalf profile hunt. At the request of the Customer's administrator, only at the full-representation tier, Sessio compiles a dossier of the member's public professional footprint for review. Approved fields can be applied to the member's Sessio profile. Dossier output passes a deterministic content filter that enforces a professional-data schema; an application is refused in full if the filter flags any content.
  • (d) The organisation-identity dossier. At the request of the Customer's administrator, Sessio compiles a dossier about the Customer itself from the Customer's own public website and other public sources about the Customer: organisation facts (description, city, links, logo candidates), the Customer's public professional footprint including writer names credited in those sources, and an indication of whether such names match existing Sessio accounts. Applying the dossier writes organisation facts only; it never edits any person's profile.
  • (e) Co-signer ranking. Sessio's internal ranking, where enabled, of registered Sessio users as candidates for a specific detected missing-contributor gap on a work, so that a person can be asked to confirm or reject. Ranking output is never delivered to the Customer.

"Hunt Output" means any result of a Hunt Service that the Customer's staff can view in the Publisher Portal, including gap summaries, counts, dossiers and match indications.

1A.1 Roles

For the Hunt Services, Sessio is an independent controller under its Privacy Policy. The Hunt Services are not performed on the Customer's documented instructions, and Sections 2 to 11 of this DPA do not apply to them; for those services Sessio's obligations - including on sub-processors, international transfers and retention - are owed as controller under the Privacy Policy and the GDPR rather than to the Customer under this DPA. A request by the Customer's administrator to run a hunt triggers the service; it is not an instruction that makes Sessio the Customer's processor (GDPR Article 28(10)).

1A.2 What the Customer can see

Hunt Output is deliberately limited. For royalty hunts, the Customer sees summaries: society, country, work or recording title, artist name, confidence, method and claim state. On the roster sweep, the Customer receives counts only, without per-member detail, until the member concerned has been notified of the processing. On the roster money map, the Customer sees, per member: their name, their grant tier, whether a scan has run, counts of provable and potential registrations, and the societies involved. In Hunt Output the Customer never receives rights-identifier values (IPI, IPN, ISNI, ISWC, ISRC), never a claim draft, never the member's claim correspondence, and never the claim contact route. (Rights identifiers a member has chosen to share are separately visible to a Customer holding a full-representation grant, outside the Hunt Services.) The Portal provides no export, bulk-download or file facility for Hunt Output. Sessio may further limit, suspend or withdraw Hunt Output at any time where a member exercises a right or Sessio's own assessment requires it; the member's own account is unaffected.

1A.3 Notice to the member is Sessio's duty

As controller, Sessio is responsible for informing the member about the Hunt Services under Articles 13 and 14. Before the Customer receives the first Hunt Output of an organisation-requested hunt concerning a member, Sessio notifies that member, and the notice names the Customer as the organisation on whose initiative the hunt runs; Sessio does not run an organisation-requested hunt for a member who has not been notified. The Customer remains responsible under Articles 13 and 14 for its own further use of Hunt Output (Section 1A.5(d)).

1A.4 The member's controls

The member can object to organisation-context hunts at any time; an objection stops future hunts about that member, stops further results reaching the Customer, and removes the organisation-visible sweep alerts about that member, in every organisation. An objection does not by itself undo a disclosure already made; the Customer's duties in Section 1A.5(e) apply to anything it already holds. Sessio will not invoke compelling legitimate grounds to override such an objection. The member can also lower or remove the Customer's grant at any time, and can see a history in their own account of the organisation-run hunts and profile applications concerning them. The Customer must not pressure a member to withdraw an objection, to restore a grant, or to hand over hunt results the design withholds from the Customer.

1A.5 The Customer's obligations

From the first moment the Customer can view a Hunt Output, and for as long as it retains any copy or note of it, the Customer must:

  • (a) Purpose limitation. Use Hunt Output only for roster administration in the interest of the member concerned - for example, to talk to the member about a possible unclaimed royalty - and use the organisation-identity dossier only to establish its own Sessio presence and to propose roster invitations to writers with whom it has a genuine existing relationship. The Customer must not use Hunt Output for prospecting or scouting unrelated to its own roster, for surveillance, for evaluating or profiling a member beyond the stated purpose, or for any purpose incompatible with the purpose for which Sessio disclosed it.
  • (b) No adverse use. Never use the existence or content of a Hunt Output against the member - including in negotiations over terms, in recoupment or settlement discussions, or in any decision adverse to the member.
  • (c) No onward disclosure. Not disclose Hunt Output outside the Customer's organisation, and not to any staff without a need to know, unless the Customer has its own lawful basis and has satisfied its own controller duties for that disclosure. Names of third parties (for example co-writers, or writers who are not Sessio users) appearing in Hunt Output receive the same protection as the member's data.
  • (d) Own controller duties for own use. Where the Customer takes Hunt Output into its own records, systems or decisions, it does so as a separate controller: it is responsible for its own lawful basis, its own Article 13/14 information to the member and to any third party concerned, its own records, and its own retention and security for those copies.
  • (e) Propagation. On notice from Sessio that a member or a third party has exercised a right of rectification, erasure, restriction or objection: correct, delete, restrict or cease using the Customer's own copies of the affected Hunt Output accordingly, without undue delay and at the latest within 30 days.
  • (f) Accuracy caution. Treat every match as indicative, not verified. In particular, an indication that a writer name matches a Sessio account is an exact-name match only; it does not establish that the account belongs to the Customer's writer, and the Customer must confirm identity with the person concerned before acting on it.
  • (g) No circumvention. Not scrape, systematically copy out, reconstruct or aggregate Hunt Output to rebuild what the design withholds (including bulk collection of per-member details or third-party names), and not attempt to obtain withheld fields by other means.
  • (h) Rights requests. Forward any data-subject request it receives concerning the Hunt Services to [email protected] without undue delay. The Customer answers requests concerning its own copies and its own use.

1A.6 Rights routing

A member (or any person named in Hunt Output) can exercise their rights for everything held in Sessio directly against Sessio at [email protected], and does not need to go through the Customer. The Customer is the right addressee only for its own copies and its own use.

1A.7 Breach

If the Customer becomes aware that Hunt Output in its possession has been accessed unlawfully, disclosed or lost, it informs Sessio at [email protected] without undue delay, and in any event within 24 hours. Sessio informs the Customer within the same period of any breach affecting Hunt Output it has disclosed to the Customer. The parties cooperate in good faith on any resulting Article 33/34 obligations, each for its own systems.

1A.8 Role review

This allocation reflects the parties' current functional assessment. The purpose limitation in Section 1A.5(a) is a restriction Sessio imposes on the Customer as recipient; it is not an agreement that the Customer determines the purposes or means of the Hunt Services. If it is later established - by the parties, by competent supervisory guidance, or by a court - that the Customer and Sessio act as joint controllers for any Hunt Service, the parties will without undue delay record a transparent arrangement under Article 26 reflecting their respective responsibilities, and will make its essence available to the members concerned. Until then, the obligations of this Section 1A apply in full from the moment the Customer can view a result.

1A.9 Suspension and consequences

If the Customer materially breaches this Section 1A, Sessio may suspend the Customer's access to Hunt Output while the breach continues. On termination of the Customer's use of the Publisher Portal, the Customer's access to Hunt Output ends; copies the Customer has taken remain subject to this Section 1A, and the member's own account and findings are unaffected.

1A.10 Notices

Notices under this Section 1A are given to the Customer's administrator contact on record in the Publisher Portal and to any data-protection contact the Customer has notified in writing to [email protected], and are deemed received on the next business day.

2. Subject-matter and duration

The subject-matter of the processing is the provision of the Sessio Publisher Portal and related services to the Customer, including hosting the Customer's roster records and giving the Customer's authorised staff a live view of their roster's sessions, songs, splits, availability, and related activity. The subject-matter of this DPA does not include the Hunt Services (Section 1A), for which Sessio acts as controller.

This DPA takes effect when the Customer first accesses the Publisher Portal and continues for as long as Sessio processes personal data on the Customer's behalf. On termination, Sessio returns or deletes the personal data as set out in Section 9.

3. Nature and purpose of processing

Sessio processes the Customer's personal data only to provide and support the Publisher Portal and the features the Customer chooses to use, including:

  • Storing and displaying roster profiles and career data to the Customer's authorised staff.
  • Showing the Customer's roster's sessions, songs, credits, and split information, and the history of who did what.
  • Displaying roster availability and, where a workspace calendar is connected, syncing Sessio sessions with that calendar (see the Privacy Policy, Section 3.4).
  • Enabling messaging and collaboration between the Customer's staff and connected creators.
  • Providing the in-portal AI assistant ("Ask Sessio"), which answers questions over the Customer's own workspace data.
  • Producing analytics and reporting for the Customer about its own roster and activity.
  • Operating, securing, backing up, and supporting the service, and providing customer support the Customer asks us for.

Sessio does not use the personal data it processes on the Customer's behalf for its own purposes, does not sell it, and does not use it for advertising or for training AI models. The hunt and enrichment services - royalty hunts, profile hunts, the roster sweep, the organisation-identity dossier and the co-signer ranking - are not among the processor services listed above and are not processing on the Customer's behalf; they are governed by Section 1A and Sessio's Privacy Policy.

4. Categories of data subjects and personal data

4.1 Categories of data subjects

  • The Customer's roster — the songwriters, artists, producers, and other creators the Customer manages or represents.
  • The Customer's own staff and administrators who use the Publisher Portal.
  • Other Sessio users who connect to, collaborate with, or appear in sessions with the Customer's roster.

4.2 Categories of personal data

  • Identity and contact data — names, email addresses, country, and (optionally) city.
  • Profile and career data — biographical text, professions, instruments, genres, experience level, credits, representation, and profile photos.
  • Rights identifiers — where provided, industry identifiers associated with a creator or work, such as IPI/IPN numbers, ISWC and ISRC codes, and collecting-society or CMO membership references.
  • Session and collaboration data — session titles, dates, locations, participant lists, roles, and split/credit allocations.
  • Calendar and availability data — busy/free status and Sessio session events for roster members whose calendars are connected.
  • Messages — direct and session group-chat messages exchanged in the course of collaboration.
  • Usage and technical metadata — identifiers, log data, and activity records generated as the service is used.

The Publisher Portal is not intended for special categories of personal data (GDPR Art. 9) or data relating to criminal convictions (Art. 10). The Customer must not upload or instruct Sessio to process such data through free-text fields or otherwise.

Hunt Output viewed by the Customer can contain personal data originating outside the Customer's records, including data about people who are not Sessio users (for example a name from a collecting society's unclaimed list, or a writer named on the Customer's own website). Such people are not thereby a category of data subjects processed under this DPA (Section 4.1): their data is disclosed to the Customer as a recipient under Section 1A, not processed on the Customer's instructions, and carries the obligations in Section 1A.5.

5. Processor obligations

Sessio, acting as Processor, undertakes to (GDPR Art. 28(3)):

  • Process the personal data only on the Customer's documented instructions — including this DPA and the Customer's use and configuration of the Publisher Portal — unless required to do otherwise by EU or Member-State law, in which case Sessio will inform the Customer before processing, unless that law prohibits it.
  • Inform the Customer without undue delay if, in Sessio's opinion, an instruction infringes the GDPR or other data-protection law.
  • Ensure that persons authorised to process the personal data are bound by an appropriate duty of confidentiality.
  • Implement and maintain appropriate technical and organisational security measures under GDPR Art. 32 (Section 5.1).
  • Respect the conditions in Section 6 for engaging sub-processors.
  • Assist the Customer as set out in Sections 7 and 8.
  • Return or delete the personal data on termination as set out in Section 9, and make available the information needed to demonstrate compliance and to allow for audits (Section 10).

5.1 Security of processing (Art. 32)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Sessio applies appropriate technical and organisational measures, including:

  • Encryption in transit (HTTPS / TLS) for all connections to the Platform, and encryption at rest on the infrastructure of our hosting providers.
  • Encryption of particularly sensitive tokens at rest — for example, connected-calendar refresh tokens are encrypted with AES-256-GCM.
  • Role-based access controls, so access to production systems and Customer data is limited to authorised staff who need it for their role.
  • Passwords stored only as salted hashes, never in plaintext.
  • Backups for service continuity, and a process for applying security patches and updates.
  • Measures to help ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems, and to restore availability after an incident.

6. Sub-processors

The Customer gives Sessio a general authorisation to engage sub-processors to help provide the Publisher Portal. Each sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in this DPA, and Sessio remains fully liable to the Customer for their performance.

Sessio's current sub-processors, aligned with the Privacy Policy (Section 6), include:

  • Marketing site + web hosting — Vercel Inc. (US company; EU regions used; Standard Contractual Clauses).
  • Backend application hosting — Fly.io Inc. (US company; EU regions used; Standard Contractual Clauses).
  • Relational database (accounts, sessions, messages) — Neon Inc. (US company; EU region used; Standard Contractual Clauses).
  • File storage (profile photos, session cover images, uploads) — Cloudflare, Inc. (US company; EU regions used; Standard Contractual Clauses).
  • Push notifications + mobile app build pipeline — Expo (650 Industries, Inc.) (US; Standard Contractual Clauses).
  • Transactional email (invitations, reminders, notifications) — Postmark, a service of ActiveCampaign LLC (US; Standard Contractual Clauses).
  • Waitlist + marketing newsletter delivery — EmailOctopus Ltd (UK / EEA; UK adequacy decision).
  • AI assistant (Ask Sessio) — Anthropic, PBC (US company; provider of the Claude models; Standard Contractual Clauses). Receives the prompt and the workspace context needed to answer; inputs and outputs sent through the API are not used to train Anthropic's models.
  • Billing and subscription payments — Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (US company; Standard Contractual Clauses). Handles checkout, card processing, and recurring billing; Sessio does not store full card numbers.
  • Google Calendar integration — Google Ireland Limited / Google LLC (EU / US company; Standard Contractual Clauses), where the Customer connects a workspace calendar. Google acts as the provider of the connected calendar account rather than solely on Sessio's instructions (see the Privacy Policy, Section 6).

A current list of sub-processors is available on request at [email protected]. Sessio will give the Customer prior notice by email of any intended addition or replacement of a sub-processor, giving the Customer a reasonable opportunity to object on reasonable data-protection grounds. If the Customer objects and the parties cannot resolve the concern, the Customer may terminate the affected service.

7. Assistance with data-subject rights and DPIAs

Taking into account the nature of the processing, Sessio assists the Customer by appropriate technical and organisational measures, insofar as possible, so the Customer can respond to requests from data subjects exercising their GDPR rights — access, rectification, erasure, restriction, portability, and objection (Art. 28(3)(e)).

If Sessio receives a request from a data subject that relates to personal data Sessio processes on the Customer's behalf, Sessio will not respond directly (except to confirm the request should be directed to the Customer) and will forward the request to the Customer without undue delay.

Sessio also assists the Customer, taking into account the information available to Sessio, with the Customer's obligations on security of processing, personal-data-breach notification, data-protection impact assessments (DPIAs), and prior consultation with a supervisory authority (Art. 28(3)(f); Art. 32–36).

8. Personal-data-breach notification

Sessio notifies the Customer without undue delay after becoming aware of a personal-data breach affecting personal data processed on the Customer's behalf. The notification will, to the extent known and where relevant, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects.

Sessio's notification to the Customer is not an acknowledgement of fault or liability. Any notification of the breach to a supervisory authority or to affected data subjects, where required under Art. 33–34, remains the Customer's responsibility as Controller, with Sessio's reasonable assistance.

9. Return and deletion on termination

On termination of the Customer's use of the Publisher Portal, and at the Customer's choice, Sessio deletes or returns the personal data it processes on the Customer's behalf and deletes existing copies, unless EU or Member-State law requires further storage.

  • The Customer may export its data before or during the wind-down period; contact [email protected].
  • Personal data is deleted or irreversibly anonymised in line with the retention schedule in the Privacy Policy (Section 8), typically within 30 days of the end of the wind-down period.
  • Backups are overwritten or expire on their normal cycle.
  • Where a roster member is also an independent Sessio user, that individual's own account and personal data remain governed by the Privacy Policy and are not deleted by the Customer's termination.
  • Hunt Output ceases to be visible to the Customer on termination. Findings and claim drafts belonging to a member's own account are the member's, are governed by the Privacy Policy, and are not deleted by the Customer's termination.

10. Audit rights

Sessio makes available to the Customer the information reasonably necessary to demonstrate compliance with GDPR Art. 28 and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates (Art. 28(3)(h)).

  • Sessio may satisfy audit requests, in the first instance, by providing its security documentation and answering the Customer's reasonable written questions.
  • On-site inspections are on reasonable prior notice, during business hours, no more than once a year (unless required by a supervisory authority or following a breach), and conducted so as not to disrupt Sessio's operations or the confidentiality of other customers' data.
  • Each party bears its own costs, subject to any different allocation agreed in writing.

11. International data transfers

Where possible, Sessio uses European data-centre regions so that the Customer's personal data is held within the EEA at rest. Backend hosting, database, and file storage are configured for EU regions.

Where a sub-processor is established outside the EEA, or personal data is otherwise transferred outside the EEA, Sessio relies on an appropriate transfer mechanism under GDPR Chapter V — in particular the European Commission's Standard Contractual Clauses (SCCs), supplemented by additional safeguards where needed. For EmailOctopus (UK), Sessio relies on the UK adequacy decision. Sessio will not transfer the Customer's personal data outside the EEA without a valid transfer mechanism in place.

The sub-processors, the regions they use, and the applicable transfer mechanism are set out in Section 6 above and available on request at [email protected].

12. General

This DPA is governed by Danish law, aligned with the governing-law and jurisdiction terms of the Terms of Service. If any provision is found unenforceable, the remainder stays in effect.

This DPA becomes binding on the Customer and Sessio only once agreed and, where applicable, countersigned. To request the current, countersigned version for your organisation, or to raise any data-protection question, contact [email protected].

13. Contact

For data-processing and privacy matters: