Related documents: Data Processing Addendum · Privacy Policy · Sub-processors · AI FAQs · Data subject access request.
The General Data Protection Regulation (GDPR) is the European Union’s data-protection law. It has been in force since 25 May 2018. It replaced Directive 95/46/EC and sets rules for how organizations collect, use, store, and delete personal data of people in the EEA. The UK GDPR applies similar rules in the United Kingdom.
California’s Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and comparable state privacy laws give residents similar rights over personal information.
The data-protection principles include:
GDPR and similar laws set requirements for how companies protect personal data, with meaningful enforcement. Sessionboard treats data privacy as a core obligation and maintains security and privacy practices described in our Information Security & Compliance page, including SOC 2 Type II certification.
We offer a Data Processing Addendum (DPA) for customers who process personal data subject to GDPR or similar laws. The DPA sets contractual terms that meet those requirements and reflect our privacy and security commitments. A prior version (July 6, 2023) is archived here.
A core privacy group of leaders across Sessionboard, headed by our Data Protection Officer, owns GDPR and related privacy requirements from marketing through engineering. That group maintains awareness training so personnel stay current on the regulations that apply to their work.
Our Cookie Policy describes what is set when you visit our site and how it is used, and the steps you can take to control cookies in your browser.
We have inventoried where Sessionboard collects and processes customer data — from cookies to support conversations — and validated the legal basis and safeguards for that processing. Our Privacy Policy describes what we collect, why, and how consent is managed.
Vendors that process personal data are reviewed for privacy and security before we contract with them, and at least annually after that. We put data-processing terms in place with vendors that process personal data on our behalf. The current list is at List of Sub-processors.
Our Terms of Service and Privacy Policy describe what personal data we collect and process, why, how we use it, who we share it with, and how long we store it.
We help customers meet data-subject rights requirements. Personal data on the platform is processed with DPA-covered vendors. Event admins can search, update, export, and delete end-user records in the product. For requests we must handle ourselves, use the data subject access request form or email privacy@sessionboard.com. Support can also help at support@sessionboard.com.
A data protection impact assessment (DPIA) process is required for certain GDPR processing. Sessionboard’s engineering team reviews security and privacy impact when tooling or implementation changes how personal data is handled. If a risk is identified, product and engineering work to mitigate it before the change ships.
We maintain a breach management and communication plan. It covers escalation and, where required, notification to customers and data subjects under GDPR and other applicable law. See also the incident-management section of our security page.
AI-powered features are described in the Sessionboard AI FAQs, including how we handle EU data, Standard Contractual Clauses, and opt-out.
Questions: support@sessionboard.com or privacy@sessionboard.com.
Last Modified: September 8, 2026