The security and data-processing documentation your reviewers ask for, in one place.
FullSession clears enterprise review. Sensitive values are masked, access is role-governed, and data is encrypted. Our DPA covers GDPR Article 28 and CCPA/CPRA requirements.
Security at a glance
A plain-language summary of how FullSession protects customer data across capture, access, infrastructure, operations, resilience, and governance. The published DPA remains the authoritative source.
TLS 1.2+ in transit, encryption at rest, tenant segregation, and managed secrets.
Secure SDLC, dependency and vulnerability scanning, 24×7 monitoring, and an incident-response workflow.
SSO and MFA for admin access, role-based least privilege, and periodic access reviews.
Regular backups, tested restore procedures, and defined recovery-point and recovery-time targets.
Automatic input masking by default, no keystrokes, allow/block rules, and configurable IP collection.
Configurable retention, RBAC and audit logs, plus EU SCCs, the UK Addendum, and Swiss adaptations.
A hardened AWS environment with network segmentation, firewalls, and provider DDoS protection.
ISO and SOC 2 references in the DPA apply to AWS infrastructure, not certifications held by FullSession. Ask sales about BAA, HIPAA, or specific review needs.
The Data Processing Addendum
A plain-language summary of how FullSession protects customer data across capture, access, infrastructure, operations, resilience, and governance. The published DPA remains the authoritative source.
Published DPA text and ordering are preserved from the approved source.
This DPA forms part of the customer agreement between FullSession, Inc. as Processor or Service Provider and the customer as Controller or Business. Defined terms follow the governing agreement.
Customer acts as Controller or Business; FullSession acts as Processor or Service Provider. Processing details are set out in Annex I.
Customer data is processed only on documented lawful instructions or where required by applicable law.
Authorized personnel are bound by appropriate confidentiality obligations.
Technical and organizational safeguards reflect processing risk and the controls summarized in Annex II.
AWS is authorized for hosting and infrastructure. Material changes are notified, and reasonable data-protection objections are supported.
Restricted transfers use EU SCCs Module 2, the UK Addendum, and Swiss adaptations where applicable.
FullSession provides reasonable assistance with requests to exercise data-subject rights.
Customers are notified without undue delay after awareness of a personal-data breach affecting customer data.
Reasonable assistance is available for impact assessments and supervisory-authority consultations.
Compliance information and proportionate audits are available under notice, confidentiality, frequency, and cost controls.
At agreement end, data is returned or deleted at the customer’s choice, subject to legal retention and backup cycles.
Customer data is not sold or shared and is used only within the direct business relationship and permitted service-provider scope.
Agreement liability limits apply. The DPA controls for processing matters; SCCs control if their terms conflict.
Subject matter · FullSession hosted analytics platform
Duration · Subscription term plus return or deletion period
Purpose · Capture and analyze end-user interactions for analytics and support
Data subjects · Customer end users, visitors, and personnel
Data types · Pseudonymous IDs, device/browser data, configurable IPs, usage events, masked inputs, feedback, and support contacts
Special categories · Not intended
Frequency · Continuous during the subscription term
Operations · Collection, storage, structuring, analysis, transmission, and deletion
Organizational · Policies, training, background checks where lawful, vendor management
Logical access · SSO/MFA, unique IDs, access reviews, secure key management
Data protection · TLS 1.2+, encryption at rest, tenant segregation, managed secrets
Development · Secure SDLC, reviews, scanning, vulnerability and change management
Infrastructure · Hardened cloud, segmentation, firewalls, provider DDoS protection
Backups & DR · Regular backups, tested restores, defined RPO/RTO targets
Incident response · Documented plan, 24×7 monitoring, breach workflow
Customer controls · RBAC, retention, allow/block rules, configurable IP collection
Capture scope · Input masking by default, no keystrokes, no uninstrumented third-party capture
EU SCCs · Decision (EU) 2021/914, Module 2; docking enabled
Sub-processors · General written authorization with 30-day objection period
Redress · Clause 11 not used
Governing law and forum · Ireland
SCC annexes · Satisfied by the processing, security, and sub-processor details in this DPA
UK transfers · UK Addendum completes Tables 1–4 from the agreement, order form, and DPA
Switzerland · EU SCCs adapt to Swiss data-protection law and competent authority requirements
See what’s costing you, and prove whats fixing it is worth
Watch the real journey, rank every issue by revenue impact, and validate the result against baseline.



