Privacy Policy

Last update: August 14h, 2025

Welcome to Sessionfuel (“Sessionfuel”, “we”, “us”, or “our”). This Policy explains what we collect from Professionals (e.g., therapists, counselors, psychologists, life coaches), website visitors, and business contacts—how we use and share it, and the rights available to you under laws such as the EU GDPR and U.S. HIPAA.

1) Who we are

This Policy applies to processing carried out by Anonyme.IO SAS (Sessionfuel).

Registered office: Anonyme.IO SAS, 6 place Léon Blum, 75011 Paris, France.

Contact: hello@sessionfuel.com

Product: Sessionfuel is a digital platform for mental-health professionals to manage their practice and support patient care.

2) Scope & roles

  • Professionals: For your account, billing, support, security, and usage data, Anonyme.IO acts as controller.

  • Clients/Patients: Clinical data is covered by the Clients/Patients Privacy Policy (https://www.mosaik.care/politique-de-confidentialite) and is processed by us as a processor under GDPR (and as a Business Associate under HIPAA when applicable) on behalf of the Professional (controller/covered entity).

  • Website visitors & business contacts: We act as controller for contact, analytics, and cookie data.

3) Information we collect (Professionals & visitors)

  • Identification & professional data: name, email, phone, password, specialty, license numbers, practice details.

  • Billing & payments: billing address, VAT/Tax IDs, payment details handled via PCI-compliant providers (Paddle, Stripe), invoices and transaction logs.

  • Support & communications: messages you send us; trouble tickets and their resolution metadata.

  • Technical/usage data: IP address, device/browser info, log events, in-app actions for security, performance, and service improvement.

  • Website/cookies: cookies and similar tech for essential functions, preferences, analytics, and (if enabled) marketing—see Section 12.

4) Purposes of processing

We use data to: provide and secure the service; authenticate users and manage roles; maintain audit logs; process payments; deliver support; analyze and improve functionality; comply with legal obligations; and send essential, service-related communications.

5) Legal bases (GDPR)

Depending on context: contract (to deliver the service); legitimate interests (security, quality, anti-abuse); legal obligation (tax/records); consent (where required, e.g., non-essential cookies or optional communications).

For Clients/Patients, the Professional is responsible for establishing a lawful basis under the separate Clients/Patients Privacy Policy.

6) HIPAA & BAA

When a Professional is a HIPAA Covered Entity and uses Sessionfuel to create, receive, maintain, or transmit PHI, we act as a Business Associate and make a Business Associate Agreement (BAA) available when asked (at hello@sessionfuel.com). The BAA sets out permitted uses/disclosures of PHI, safeguards, and breach notification duties.

7) Retention

  • Professional account data: kept for the lifetime of your account, then deleted or archived according to your instructions and applicable law. Identification and professional data are retained for the duration of the contractual relationship, extended by three (3) years for communication and marketing purposes, without prejudice to statutory retention requirements or limitation periods (in particular regarding invoicing and subscription records).

  • Support / communications: retained for the period necessary to manage your requests, and may be further retained for compliance and defense purposes. Users may object to the processing of their personal data for marketing purposes after the end of the contractual relationship by unsubscribing from SessionFuel communications.

  • Website/analytics data: retained for the shortest period aligned with our analytics configuration and legal needs.

  • Clients/Patients: retention governed by the separate Clients/Patients Privacy Policy and the Professional’s legal/ethical obligations. Health data (including medical records) is retained for twenty (20) years from the date of the last entry in the system, in accordance with GDPR and French Public Health Code (Article R1112-7 CSP).

8) Security

We implement administrative, physical, and technical safeguards appropriate to risk, including encryption in transit and at rest, role-based access controls, two-factor authentication, HDS and HIPAA compliant infrastructure, audit logging, backups, confidentiality best practices, and vulnerability management.

9) International transfers

Data is primarily hosted in the EU. Where data is transferred outside the EU (e.g., vetted subprocessors), we implement appropriate safeguards (e.g., Standard Contractual Clauses) to ensure an adequate level of protection.

10) Sharing

We do not sell personal data. We share limited data with:

  • Service providers/subprocessors (hosting, support, analytics, payments, communications) under data-processing terms ;

  • Authorities or third parties where required by law, to protect rights/safety, or in connection with corporate transactions (subject to safeguards).

11) Your rights

EU/UK: You may access, rectify, erase, port, restrict, or object to processing, and withdraw consent for future uses. Contact us at hello@sessionfuel.com. You may lodge a complaint with your supervisory authority (e.g., HHS, CNIL).

HIPAA (US): Individuals generally exercise HIPAA rights via their Professional (covered entity). We support those requests consistent with our BAA.

12) Cookies & tracking

We use:

  • Essential cookies (authentication, security, load balancing),

  • Functional cookies (preferences),

  • Analytics cookies (performance, usability),

  • Marketing cookies (if enabled; for reach measurement and relevance).

Control cookies via our banner and browser settings. Disabling certain cookies may impact functionality. Where required, we obtain consent for non-essential cookies.

13) Breach notification

If a security incident affects personal data (or PHI), we’ll investigate and take remedial action. Where legally required, we will notify the relevant Professional and/or authorities within applicable timelines (e.g., HIPAA’s outer 60-day notice for reportable breaches).

14) Changes to this Policy

We may update this Policy from time to time. The “Last update” date at the top tells you when we last changed it. You are responsible for reviewing this Policy periodically. Your continued use of Sessionfuel after any update constitutes acceptance of the revised Policy.

15) Contact us