SECURITY & DATA PROCESSING

The security and data-processing documentation your reviewers ask for, in one place.

FullSession clears enterprise review. Sensitive values are masked, access is role-governed, and data is encrypted. Our DPA covers GDPR Article 28 and CCPA/CPRA requirements.

Security at a glance

A plain-language summary of how FullSession protects customer data across capture, access, infrastructure, operations, resilience, and governance. The published DPA remains the authoritative source.

Encryption

TLS 1.2+ in transit, encryption at rest, tenant segregation, and managed secrets.

Operations

Secure SDLC, dependency and vulnerability scanning, 24×7 monitoring, and an incident-response workflow.

Access

SSO and MFA for admin access, role-based least privilege, and periodic access reviews.

Resilience

Regular backups, tested restore procedures, and defined recovery-point and recovery-time targets.

Capture controls

Automatic input masking by default, no keystrokes, allow/block rules, and configurable IP collection.

Governance

Configurable retention, RBAC and audit logs, plus EU SCCs, the UK Addendum, and Swiss adaptations.

Infrastructure

A hardened AWS environment with network segmentation, firewalls, and provider DDoS protection.

Provider-level certifications

ISO and SOC 2 references in the DPA apply to AWS infrastructure, not certifications held by FullSession. Ask sales about BAA, HIPAA, or specific review needs.

The Data Processing Addendum

A plain-language summary of how FullSession protects customer data across capture, access, infrastructure, operations, resilience, and governance. The published DPA remains the authoritative source.

VERSION
1.0
EFFECTIVE
January 13, 2026
JURISDICTIONS
EU/EEA · UK · Switzerland · US
ENTITY
FullSession, Inc.
CONTACT
privacy@fullsession.io
AUTHORITATIVE SOURCE

Published DPA text and ordering are preserved from the approved source.

FullSession – Data Processing Addendum

This DPA forms part of the customer agreement between FullSession, Inc. as Processor or Service Provider and the customer as Controller or Business. Defined terms follow the governing agreement.

1. Scope & Roles

Customer acts as Controller or Business; FullSession acts as Processor or Service Provider. Processing details are set out in Annex I.

2. Processing on Instructions

Customer data is processed only on documented lawful instructions or where required by applicable law.

3. Confidentiality

Authorized personnel are bound by appropriate confidentiality obligations.

4. Security Measures

Technical and organizational safeguards reflect processing risk and the controls summarized in Annex II.

5. Sub-processors

AWS is authorized for hosting and infrastructure. Material changes are notified, and reasonable data-protection objections are supported.

6. International Transfers; SCCs

Restricted transfers use EU SCCs Module 2, the UK Addendum, and Swiss adaptations where applicable.

7. Data Subject Requests

FullSession provides reasonable assistance with requests to exercise data-subject rights.

8. Breach Notification

Customers are notified without undue delay after awareness of a personal-data breach affecting customer data.

9. Impact Assessments & Consultations

Reasonable assistance is available for impact assessments and supervisory-authority consultations.

10. Audits

Compliance information and proportionate audits are available under notice, confidentiality, frequency, and cost controls.

11. Return or Deletion of Data

At agreement end, data is returned or deleted at the customer’s choice, subject to legal retention and backup cycles.

12. CCPA/CPRA

Customer data is not sold or shared and is used only within the direct business relationship and permitted service-provider scope.

13. Liability & Order of Precedence

Agreement liability limits apply. The DPA controls for processing matters; SCCs control if their terms conflict.

Annex I · Description of Processing

Subject matter · FullSession hosted analytics platform
Duration · Subscription term plus return or deletion period
Purpose · Capture and analyze end-user interactions for analytics and support
Data subjects · Customer end users, visitors, and personnel
Data types · Pseudonymous IDs, device/browser data, configurable IPs, usage events, masked inputs, feedback, and support contacts
Special categories · Not intended
Frequency · Continuous during the subscription term
Operations · Collection, storage, structuring, analysis, transmission, and deletion

Annex II · Security Measures

Organizational · Policies, training, background checks where lawful, vendor management
Logical access · SSO/MFA, unique IDs, access reviews, secure key management
Data protection · TLS 1.2+, encryption at rest, tenant segregation, managed secrets
Development · Secure SDLC, reviews, scanning, vulnerability and change management
Infrastructure · Hardened cloud, segmentation, firewalls, provider DDoS protection
Backups & DR · Regular backups, tested restores, defined RPO/RTO targets
Incident response · Documented plan, 24×7 monitoring, breach workflow
Customer controls · RBAC, retention, allow/block rules, configurable IP collection
Capture scope · Input masking by default, no keystrokes, no uninstrumented third-party capture

Annex III · International Transfers & SCC Details

EU SCCs · Decision (EU) 2021/914, Module 2; docking enabled
Sub-processors · General written authorization with 30-day objection period
Redress · Clause 11 not used
Governing law and forum · Ireland
SCC annexes · Satisfied by the processing, security, and sub-processor details in this DPA
UK transfers · UK Addendum completes Tables 1–4 from the agreement, order form, and DPA
Switzerland · EU SCCs adapt to Swiss data-protection law and competent authority requirements

See what’s costing you, and prove whats fixing it is worth

Watch the real journey, rank every issue by revenue impact, and validate the result against baseline.