Privacy Policy

Effective date: May 7th, 2025

Sessions, Inc (“Sessions,” “us”, “we”, or “our”) operates the www.sessionshealth.com website (hereinafter referred to as the “Service”). This page informs you of our policies regarding the collection, use and disclosure of personal data when you use our Service and the choices you have associated with that data (“Privacy Policy” or “Policy”).

We use your data to provide and improve the Service. By using the Service and accepting our Terms and Conditions, you agree to the collection and use of information in accordance with this Policy. Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions,accessible from www.sessionshealth.com or app.sessionshealth.com.

Definitions.

Service. Service is the app.sessionshealth.com website operated by Sessions, Inc.

Personal Data. Personal Data means data about a living individual who can be individually identified from those data (or from those and other information either in our possession or likely to come into our possession).

Usage Data. Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Cookies. Cookies are small files stored on your device (computer or mobile device).

Types of Data Collected.

Personal Data

While using our Service, we may ask you to provide us with certain individually identifiable information that can be used to contact or individually identify you (“Personal Data”).

Category Examples Collected Disclosed
Identifiers. A real name, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name. YES YES – Service providers as needed for services used.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). A name, signature, telephone number, credit card number, debit card number, or any other financial information. YES YES – Payment processor to collect payment for services.
Protected classification characteristics. Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). NO NO
Commercial information. Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. NO NO
Sensitive Personal Data Precise geolocation, Social Security number, driver’s license, state identification card, passport number, financial account, racial or ethnic origin, religious/philosophical beliefs, or union membership, genetic data and processing of biometric information, health and sexual orientation. NO NO
Biometric Information. Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. NO NO
Internet or other similar network activity. Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. NO NO
Geolocation data. Physical location or movements. NO NO
Sensory data. Audio, electronic, visual, thermal, olfactory, or similar information. NO NO
Professional or employment-related information. Current or past job history or performance evaluations. NO NO
Non-public education information. Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. NO NO
Inferences drawn from other Personal Data. Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. NO NO

We may obtain the Personal Data listed above from the following categories of sources:

  • Directly from you. For example, when you:
    • register yourself with the website or to use the Service;
    • use our Services;
    • review or comment on one of our services;
    • otherwise communicate with us, such as contacting us for more information.
  • Newsletters. We may also use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send.
  • Indirectly from you. For example, through information we collect from you in the course of providing our Service to you.

Usage Data

We may also collect information on how the Service is accessed and used (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

Cookies

We use Cookies to help support certain parts of our Service. You can read more about it at our Cookie Policy.

Aggregated and De-Identified Data

We may also collect, use and disclose aggregated and de-identified data such as statistical or demographic data for internal purposes. Aggregated and de-Identified data could be derived from your Personal Data but is not considered Personal Data under applicable law as this data will not directly or indirectly reveal your identity. However, if we combine or connect aggregated or de-identified data with your Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this Policy.

Free-Text Boxes

The information that you provide in each case will vary. In some cases, you may be able to provide Personal Data via email or free text boxes, such as contacting Sessions to request further information. When providing your Personal Data, please provide only relevant information and do not provide unnecessary sensitive information, such as Social Security numbers, credit card information or other sensitive personal data, unless required for our services or support.

Credentials; Other Sources. We may ask you to create a username and password that should only be known to you. When you provide this information to us, you are no longer anonymous. Additionally, we may receive information about you from other sources and add it to the information you have provided to us.

Recording Use of the Website. We partner with trusted third-party vendors to analyze performance and traffic of our Website. This may include things like buttons you click, mouse movements and other behavior on the Website, date and time of access, pages visited, web beacons, and cookie or pixel tag information.

Use of Data:

Sessions, Inc uses the collected data for various purposes:

  • security, credit or fraud prevention purposes;
  • providing you with effective customer service;
  • providing you with a personalized experience when you use the website or Service;
  • developing new products and services;
  • contacting you with special offers and other information we believe will be of interest to you (in accordance with any privacy preferences you have expressed to us);
  • contacting you with information and notices related to your use of the website or our Service;
  • inviting you to participate in surveys and providing feedback to us (in accordance with any privacy preferences you have expressed to us); better understanding your needs and interests;
  • improving the content, functionality and usability of the Website;
  • improving our products and services;
  • improving our marketing and promotional efforts; and
  • any other purpose identified at the point of data collection, in an applicable privacy notice, in a click-through agreement or in any other agreement between you and us.
  • Duration. The length of time Sessions intends to retain Personal Data, including sensitive personal information, if any, is for as long as reasonably necessary to carry out Sessions intended business purpose for such information

Disclosure of Data. We do not sell or lease your Personal Data to any third party. We may disclose your Personal Data under the following circumstances.

Business Transaction

If Sessions, Inc is involved in a merger, acquisition or asset sale, your Personal Data may be transferred.

Disclosure for Law Enforcement

Under certain circumstances, Sessions, Inc may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Legal Requirements

Sessions, Inc may disclose your Personal Data in the good faith belief that such action is necessary to:

  • To comply with a legal obligation
  • To protect and defend the rights or property of Sessions, Inc
  • To prevent or investigate possible wrongdoing in connection with the Service
  • To protect the personal safety of users of the Service, Session employees or the public
  • To protect Sessions against legal liability

Security of Data

The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we have stringent data security policies and use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

Service Providers.

We may employ third party companies and individuals to facilitate our Service (“Service Providers”), provide the Service on our behalf, perform Service-related services or assist us in analyzing how our Service is used.

These third parties have access to your Personal Data only to perform these tasks on our behalf and are contractually obligated not to disclose or use it for any other purpose. For those service providers that process Protected Health Information on behalf of Session, a business associate agreement (“BAA”) is also in place.

Currently, our service providers include:

  • Healthcare Blocks: This is our partner for hosting our primary web and database services. Healthcare Blocks helps us with meeting applicable HIPAA requirements in our existing infrastructure with server monitoring and security. Healthcare Blocks is hosted on Amazon Web Services. All of the main web traffic is encrypted end-to-end and monitored in real-time. All access to the application servers is behind a VPN. Healthcare Blocks helps us maintain database backups, access audits, and various tools to maintain data privacy and security. BAA: Yes
  • Google Cloud: This is our partner for hosting our HIPAA-compliant telehealth services. Google helps us monitor and secure our telehealth infrastructure. We do not record any video of telehealth sessions. Audio may be relayed to handle speech-to-text recognition for audio features such as closed captioning, but is never persisted or stored. BAA: Yes
  • Datadog: This is our partner for application-level monitoring and security. No client PHI will ever reach Datadog. We use Datadog for monitoring web application performance, along with temporary log storage and a web application firewall for specific application-level threat detection and management. BAA: Yes
  • HelpScout: this is our partner for all customer support-related activities. All emails you send to support@sessionshealth.com are relayed through HelpScout and are triaged amongst the team. We also use HelpScout for our support documentation. BAA: Yes
  • Claim.MD: This is our primary electronic clearinghouse. For you to submit claims electronically, receive remittances, or check eligibility, we may need to send and receive protected information. These are optional services. BAA: Yes
  • Twilio: This is our SMS text and Voice appointment reminder partner. BAA: Yes
  • Mailgun: This is our email delivery partner. BAA: Yes
  • OpenAI: This is an artificial intelligence research organization that’s used to provide AI related services to customers that opt-in to those services. BAA: Yes
  • Stripe: This is one of our credit card processors. If you setup an account with Stripe and establish a connection between Stripe and Sessions Health, we need to share limited information about you and your clients for you to administer those transactions through Sessions Health. We do not share any protected health information. BAA: No, Per Health and Human Services (“HHS”) guidance payment processors/financial institutions are compliant with the HIPAA Privacy Rule.
  • Payabli: This is one of our credit card processors. If you set up an account with Payabli and establish a connection between Payabli and Sessions Health, we need to share limited information about you and your clients for you to administer those transactions through Sessions Health. We do not share any protected health information. BAA: Per Health and Human Services (“HHS”) guidance payment processors/financial institutions are compliant with the HIPAA Privacy Rule.

Third-Party Services or Websites.

Our Service may contain links to third party websites or services that are not owned or controlled by Sessions, Inc.

Sessions has no control over, and assumes no responsibility or liability for the content, privacy policies, or practices of any third-party websites or third-party services. We do not warrant the offerings of any of these entities/individuals or their websites.

You acknowledge and agree that Sessions shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any such third-party content, goods or services available on or through any such third- party web sites or services.

We strongly advise you to read the applicable terms and conditions and privacy policies of any third-party websites or services that you visit.

Information of Minors

We do not knowingly collect or use information from individuals under the age of eighteen (18) without parental or guardian consent. We do not target the website Service to minors, and would not expect them to be engaging with the website or our Service. We encourage parents and guardians to provide adequate protection measures to prevent minors from providing information unwillingly on the internet. If we are aware of any Personal Data that we have collected about minors under the age of eighteen (18), we will take steps to securely remove it from our systems.

Your Rights Under State Law

California.

  • Shine the Light law. Pursuant to California Civil Code Section 1798.83, we will not disclose or share your Personal Data with third parties for the purposes of third-party marketing to you without your prior consent.
  • Do Not Track Signals. Other than as disclosed in this Policy, the Website does not operate any differently when it receives Do Not Track signals from your internet web browser.
  • WE DO NOT SELL OR SHARE YOUR PERSONAL INFORMATION. If we ever decide to “sell” or “share” Personal Data, as those terms are defined under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, we will update you via this Policy and include a link entitled “Do Not Sell or Share My Personal Data,” to provide you with an opportunity to opt out of the selling or sharing of your Personal Data.

Your Consumer Rights.

Some state laws in the United States provide consumers with additional rights with respect to their Personal Data (also known as “personal information”), as those terms are defined under those applicable state laws. Such state laws may include, but are not limited to, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Florida Digital Bill of Rights, the Oregon Consumer Privacy Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, and the Virginia Consumer Data Protection Act (collectively, the “U.S. State Privacy Laws”). Any Personal Data we collect is collected for the commercial purpose of effectively providing our services to you, as well as enabling you to learn more about, and benefit from, our services. If you reside in a state that provides additional rights with respect to your Personal Data, you may exercise each of your rights as identified below, subject to our verification of your identity.

  • Access. You have the right to request that we disclose certain information to you about our collection, use and disclosure of your Personal Data over the past twelve (12) months.
  • Correction. You can correct what personal data our Website database currently contains by contacting us to request that we correct or rectify any personal data that you have provided to us.
  • Limit Use and Disclosure of Sensitive Personal Data. If we collect any sensitive personal information, you have the right to request that we limit the use of the sensitive personal information to that use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services.
  • Portability. Upon request and when possible, we can provide you with copies of your Personal Data. When such a request cannot be honored, we will advise you accordingly. You can then choose to exercise any other rights under this Policy.
  • Deletion. You have the right to request that we delete any of your Personal Data, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your Personal Data from our records, unless an exception applies. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Opt-out of Processing. You have the right to request that we do not sell your Personal Data, use your Personal Data for Targeted Advertising, or use your Personal Data for profiling. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Non-Discrimination. If a consumer exercises his or her rights under applicable U.S. State Privacy Laws, we shall not discriminate against that data subject by denying our goods or services, charging different prices or rates to similarly situated consumers, providing a different level or quality of our goods or services, or taking any other adverse action.
  • Exercising your rights. If you are a consumer that has rights under applicable U.S. State Privacy Laws who chooses to exercise the rights listed above, you can:
    Submit a request via email at contact@sessionshealth.com

Only you, or someone legally authorized to act on your behalf, may make a request related to your Personal Data. If an authorized agent makes a request on your behalf, we may require proof that you gave the agent permission to submit the request.

Responding to Your Request. Upon receiving your request, we will confirm receipt of your request by sending you an email confirming receipt. To help protect your privacy and maintain security, we may take steps to verify your identity before granting you access to the Personal Data. In some instances, such as a request to delete personal information, we may first separately confirm that you would like for us to in fact delete your personal information before acting on your request.

We will respond to your request within forty-five (45) days. If we require more time, we will inform you of the reason and extension period in writing.

In some cases our ability to uphold these rights for you may depend upon our obligations to process Personal Data for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.

LOCATION OF OUR WEBSITE AND SERVICES

Unless specifically stated in writing, we do not warrant or represent that this Policy or the website’s use of your Personal Data complies with the laws of every jurisdiction. Furthermore, to provide you with our services, we may store, process, and transmit information in the United States and other locations around the world, including countries that may not have the same privacy and security laws as yours. Regardless of the country in which such information is stored, we will process your Personal Data in accordance with this Policy.

FOR USERS OUTSIDE THE UNITED STATES

Under the (i) General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, or “GDPR”), (ii) Data Protection Act 2018, (iii) the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland (i.e., “UK GDPR”) as provided in the Data Protection Act 2018, and (iv) any other applicable data protection legislation of any country or other jurisdiction (collectively “International Data Protection Laws”) individuals have specific rights with respect to their Personal Data, or “personal data” as defined under the International Data Protection Laws. For the purposes of this Policy, Sessions operates as a data controller. Any personal data we collect from you is processed in the United States and under the terms of this Policy.

Any personal data we collect from you is processed in the legitimate interest of our business and providing our services to you as the lawful means of such processing. You may always withdraw your consent to our use of your personal data as described below. We will only retain your personal data for the time necessary to provide you the information and services to which you have consented, to comply with the law and in accordance with your rights below.

The Data Controller is:
NAME: Sessions, Inc.
ADDRESS: 3948 Market St #24702, Minneapolis, MN 55424
EMAIL ADDRESS: contact@sessionshealth.com

You can exercise any of the following rights, subject to verification of your identity, by notifying us as described below:

  • Access. You may request a copy of the personal data our Website databases currently contain.
  • Automated Processing and Decision-Making. You may request that we stop using your personal data for automated processing, such as profiling. When contacting Sessions, please explain how you wish us to restrict automated processing of your personal data. When such restrictions are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent to the processing of your personal data.
  • Correction or Rectification. You can correct what personal data our Website database currently contains by accessing your account directly, or by emailing us (as provided below) to request that we correct or rectify any personal data that you have provided to us. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause information to be incorrect. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Restrict Processing. When applicable, you may restrict the processing of your personal data by submitting a request via email (to the email provided below). In your email, please explain how you wish us to restrict processing of your personal data. When such restrictions are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent to the processing of your personal data. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Object to Processing. When applicable, you have the right to object to the processing of your personal data by submitting a request via email to (to the email provided below). When such objections are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent to the processing of your personal data. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Portability. Upon request and when possible, we can provide you with copies of your personal data. When such a request cannot be honored, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent. Where applicable, we will ensure such changes are shared with any trusted third parties.
  • Withdraw Consent. At any time, you may withdraw your consent to our processing of your personal data through this Website by notifying us via email (to the email provided below). Using the same email address associated with your Website account, simply type the words “WITHDRAW CONSENT” in the subject line of your email. Upon receipt of such a withdrawal of consent, we will confirm receipt and proceed to stop processing your personal data. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Erasure. If you should wish to cease use of our Website and have your personal data deleted from our Website, then you may submit a request by emailing us at the email provided below. Upon receipt of such a request for erasure, we will confirm receipt and will confirm once your personal data has been deleted. Where applicable, we will ensure such changes are shared with trusted third parties.

Exercising your rights. If you are a data subject that has rights under the International Data Protection Laws, who chooses to exercise the rights listed above, you can submit a request via email at contact@sessionshealth.com.

Submit Complaints or Questions. If you wish to raise a complaint on how we have handled your personal data, you can contact us as described below. If you reside in a European Union member state or the United Kingdom, you may also lodge a complaint with the supervisory authority in your country.

Changes to This Privacy Policy.

We may update our Privacy Policy from time to time, which you may find on our website at www.sessionshealth.com. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us:

If you have any questions about this Privacy Policy, please contact us at contact@sessionshealth.com.