1. Data controller
HappySession is responsible for the processing of personal data collected through the platform.
2. Data collected
- Account data (email address, user identifier) managed via AWS Cognito.
- Technical data (IP address, browser type, connection information).
- Anonymised usage data for service improvement purposes.
- Payment data processed exclusively by secure third-party providers (e.g. Stripe).
- Passwords are processed and stored by AWS Cognito; HappySession does not have access to them.
- Authentication tokens may be used to maintain the session and secure access.
- The content of exchanges with the conversational coach (messages sent and associated profile) is transmitted to a third-party artificial intelligence provider in order to generate a response.
3. Purposes of processing
Data is used to provide the service, improve user experience, ensure security and comply with legal obligations.
4. Legal basis
- Performance of the service at the user’s request.
- User consent where required.
- Legitimate interest related to platform improvement and security.
- Legal and regulatory obligations.
5. Data retention
Data is retained only for the period necessary for the purposes for which it was collected, or in accordance with legal obligations.
When a safety profile is created or changed, HappySession retains timestamped evidence of the warning accepted, a snapshot of the profile and the version of the safety configuration applied. The associated email address is encrypted and pseudonymised in a separate restricted-access archive. After account deletion, this evidence is retained for five years for the establishment, exercise or defence of legal claims and is then deleted, unless an ongoing dispute requires its retention.
6. User rights
In accordance with the GDPR, users have the right to access, rectify, erase, restrict, object to and port their data.
These rights can be exercised via the contact given in section 8. Users also have the right to lodge a complaint with the French data protection authority (CNIL - www.cnil.fr), the competent supervisory authority in France.
7. Security
HappySession implements appropriate technical and organisational measures to protect personal data against unauthorised access.
8. Contact
Any request relating to personal data may be sent to: support happysession.org
9. Processors and transfers
HappySession relies on technical service providers (processors) to deliver the service.
- AWS Cognito: authentication and user account management.
- Stripe: payment processing (HappySession does not receive card details).
- OpenAI: processing of messages exchanged with the conversational coach in order to generate a response.
Depending on provider configuration, some data may be processed outside the European Union with appropriate safeguards (e.g. Standard Contractual Clauses).