Privacy Policy

Effective Date: April 22, 2026  ·  Version 2.2

Empowered Sessions is operated by Empowered Applications LLC. This policy explains how we collect, use, protect, and handle the data you entrust to us — including sensitive client and student information.

HIPAA & Regulatory Notice

Empowered Sessions stores protected health information (PHI) and personally identifiable information (PII) about the individuals you serve, including educational records, service documentation, and in some cases medical/therapeutic records. Organizations using this platform in connection with covered health services under HIPAA, or student records under FERPA, must ensure their use complies with those regulations. A Business Associate Agreement (BAA) is available upon request — and must be executed before storing PHI in the platform. The AI writing assistance features in this platform are designed as a drafting aid only — they do not transmit student names, dates of birth, diagnoses, or other personally identifiable information to any AI provider. See Section 3 for a full explanation of how data is handled before AI processing occurs. Contact us at legal@empoweredsessions.app.

1. Information We Collect

We collect information in two categories: information about you as a platform user, and information you enter about the individuals you serve (clients, students, participants).

Account & User Information

  • Name and email address (used for authentication and communication)
  • Organization name, role (Admin, Manager, Tutor, Billing, Auditor)
  • Login timestamps and session activity
  • Device and browser type (captured at authentication and consent events for security monitoring and consent audit trail)
  • Preferred interface mode (mobile or desktop) stored as a user preference setting
  • First-login setup completion status
  • Platform type (web browser, iOS, Android, or desktop application via Empowered Sessions desktop app for Windows, Mac, or Linux)

Client & Student Information You Enter

This is data you and your organization submit about the individuals you serve. It may include:

  • Full names, contact information, and identification numbers (e.g., DDD ID, serial codes)
  • Date of birth, age, grade level, and school or program affiliation
  • Agency names, support coordinator names and contact details
  • Funding source information (e.g., DDD, Regional Center, Medicaid, private pay)
  • Service authorization records (SDRs) including authorized hours and date ranges
  • Session attendance records, session notes, and activity logs
  • Service goals and progress data
  • Uploaded documents including IEPs, ISPs, 504 Plans, evaluation reports, and medical records
  • Diagnoses, medications, and medical conditions that may be referenced within uploaded documents (e.g., ISPs, incident reports) — these are stored only as part of the uploaded document content, not as discrete structured database fields
  • Meeting recordings (MP4 video files up to 50GB) and meeting transcripts
  • Screenshots from cognitive training and external activity tracking tools (e.g., BrainHQ, JigsawPlanet)
  • Progress data received from external learning platforms (e.g., Quest of the Mind, BrainHQ)
  • External platform identifiers (IDs used to link students across integrated apps)

Operational & Billing Data

  • Timesheet records and hourly rates (including per-student rate assignments)
  • Invoice history and billing submission records
  • Approval workflow activity and timestamps
  • Quarterly and progress reports
  • AI-generated draft content (goals, progress reports, session summaries) and the underlying inputs

Integration & Technical Data

  • Zoom API credentials (OAuth access tokens and refresh tokens) if Zoom integration is enabled
  • Meeting history and participant attendance records synced from Zoom
  • Stripe customer and subscription identifiers (not credit card numbers)
  • Webhook payloads received from external platforms (progress data, roster updates)

2. How We Protect Your Data

Empowered Sessions is built on enterprise-grade infrastructure with multiple layers of technical and organizational security controls.

Encryption

  • In Transit: All data transmitted between your browser/device and our servers uses TLS 1.2+ (HTTPS). Data is never transmitted unencrypted.
  • At Rest: All data stored in our database and file storage is encrypted at rest using AES-256 encryption, managed by Supabase (built on AWS infrastructure). This includes all database records, uploaded files, recordings, and documents.
  • Storage Buckets: All document and recording storage buckets are private by default. Files are never publicly accessible without explicit, authenticated authorization.

Authentication & Access Control

  • JWT Authentication: Every request to our servers requires a valid, signed JSON Web Token (JWT) issued by Supabase Auth. Tokens expire and are refreshed securely.
  • Row-Level Security (RLS): Every database table enforces row-level security policies at the database engine level. This means that even if a query were constructed incorrectly, the database itself would block access to data belonging to another organization or user. RLS is non-bypassable from the application layer.
  • Role-Based Access: Within each organization, distinct roles govern what data can be seen and modified: Admin, Manager, Tutor, Billing Specialist, and Auditor. Tutors can only access their own assigned students. Managers can view all students within the organization. Admins have full configuration and data access within their own organization only. See the "Platform Administrator Access" section below for information about cross-organization access by Empowered Applications staff.
  • Organization Isolation: Every piece of data — clients, students, sessions, documents, recordings, invoices — is tagged with your organization's unique ID. Database policies enforce that users can only access data within their own organization. Organization names and join codes are visible to authenticated users to support the organization selection and onboarding flow; all substantive client and session data is strictly org-scoped.

Audit Logging

Empowered Sessions maintains audit logs for significant data operations across core tables:

  • Create, update, and delete actions on client, student, session, invoice, billing revenue, document, and recording records are logged
  • Logs capture who performed the action, when, and what changed (before and after state)
  • Recording access is separately logged, including who viewed or downloaded a recording
  • Invoice status changes are tracked with full history
  • Audit log records cannot be modified or deleted through the application layer. Direct database access by Empowered Applications staff is subject to internal access controls.
  • Audit logs are accessible to Admin, Manager, and Auditor roles within your organization

Platform Administrator Access

Transparency Notice: This section describes who at Empowered Applications LLC can access your organization's data, what they can see, why, and what safeguards are in place.

Empowered Applications LLC employs a designated Platform Administrator (internally referred to as "App Developer") who holds an elevated role across all organizations on the platform. This role is necessary for the operation, maintenance, and support of the Empowered Sessions platform.

What the Platform Administrator Can Access

  • All data within every organization, including client and student records, session notes, attendance logs, uploaded documents (IEPs, ISPs, SDRs, medical records), service authorization records, billing data, invoices, timesheets, payroll records, and session recordings (MP4 files).
  • User account information: names, email addresses, assigned roles, login timestamps, and activity logs.
  • Organization settings, membership rosters, subscription status, and integration configurations.
  • Audit logs and system health data across all organizations.

Permitted Purposes (Minimum Necessary Standard)

Under HIPAA's minimum necessary standard (45 CFR § 164.502(b)), Platform Administrator access is limited to the following purposes:

  • Technical support: Diagnosing and resolving issues reported by organizations, including missing data, synchronization failures, permission errors, and upload problems.
  • Platform maintenance: Performing data integrity checks, applying security patches, running database migrations, and ensuring correct operation of all platform features.
  • Compliance and security monitoring: Detecting unauthorized access attempts, investigating security incidents, and monitoring for data anomalies as part of Empowered Sessions's BAA obligations.
  • Onboarding assistance: Helping new organizations configure settings, verify proper setup, and import initial data.

Safeguards

  • The Platform Administrator role is assigned only to authorized Empowered Applications LLC personnel. As of this policy version, one individual holds this role.
  • Platform Administrator access is scoped per organization using the same database-level Row-Level Security (RLS) policies that govern all users. When the administrator accesses an organization, they see only that organization's data. There is no mechanism that allows viewing data from multiple organizations simultaneously.
  • Mandatory justification logging: Every time the Platform Administrator accesses an organization, the platform requires them to: (1) select a reason category (Technical Support, Platform Maintenance, Compliance/Security Monitoring, Onboarding Assistance, Data Integrity Check, or Other); and (2) provide a written justification describing specifically what they need to do and why. The platform enforces a minimum detail requirement (10+ characters). Access to the organization cannot proceed until this justification is submitted. These access justification records are immutable — they cannot be edited or deleted after creation.
  • Organization admin visibility: Your organization's administrators have direct, real-time access to the Platform Administrator Access Log through Organization Settings. Each log entry shows the date, time, reason category, written justification, and session duration. No request to Empowered Applications LLC is needed to view these records.
  • All actions are audit-logged: In addition to the access justification log, every data access, modification, or configuration change performed by the Platform Administrator while inside your organization is recorded in the main audit log with the administrator's user identity, timestamp, affected entity, and the nature of the action.
  • The Platform Administrator is bound by Empowered Applications LLC's internal data handling policies and is subject to the same BAA obligations (breach notification, prohibition on unauthorized use or disclosure, minimum necessary access) as all other platform roles.
  • Platform Administrator access is never used for: marketing, sales, sharing data between organizations, data mining, or any purpose unrelated to platform operation and support.

Your Rights

  • You may request an audit log of all Platform Administrator actions within your organization by contacting security@empoweredsessions.app.
  • You may request that Platform Administrator access to your organization be restricted to emergency-only situations by contacting legal@empoweredsessions.app. Note: this may limit the ability to provide proactive support.
  • If the identity or number of Platform Administrators changes, Empowered Sessions will update the consent version and notify all organizations.

File & Recording Security

  • All uploaded files (PDFs, documents, images, MP4 recordings) are stored in private, encrypted storage buckets. Direct URL access without authentication is not possible.
  • Storage paths are scoped by organization ID — your files are stored under your organization's namespace and cannot be accessed by other organizations.
  • Recording retention policies are configurable per organization (default: 365 days). When auto-deletion is enabled (the default for new organizations), expired recordings are permanently deleted by an automated enforcement job. Organizations may disable auto-deletion, in which case expired recordings are flagged for manual review.
  • MP4 recordings support files up to 50GB. All other documents support up to 50MB.

Infrastructure Security

  • Supabase Platform: Empowered Sessions's database and storage infrastructure is hosted on Supabase, which is built on top of AWS (Amazon Web Services). Supabase is SOC 2 Type 2 compliant and undergoes regular security audits. Data is hosted in the United States.
  • No Direct Database Access: Application users access data only through our authenticated API layer. There is no direct database connection available to end users.
  • Service Role Separation: Backend functions use a privileged service role key that is never exposed to the browser. Frontend clients use a restricted anonymous key whose access is further limited by RLS policies.
  • Google Fonts (Font Delivery): The platform loads the Manrope typeface from Google Fonts CDN (fonts.googleapis.com, fonts.gstatic.com). This results in your browser making a request to Google's servers, which may log your IP address per Google's own privacy policy. No PHI or PII is transmitted in this request. Organizations with strict data minimization requirements should be aware of this font delivery mechanism.

3. AI Writing Assistance

Privacy-First Design: The AI writing tools in Empowered Sessions are designed as a documentation aid for service providers. They help tutors and service providers frame their session notes and progress observations in language that more clearly communicates alignment with each student's individual goals. Personally identifiable information — including student names, dates of birth, diagnoses, and identification numbers — is not transmitted to any AI provider.

Empowered Sessions offers optional AI writing assistance powered by Anthropic's Claude API. These tools are designed to help service providers write clearer, more goal-aligned documentation — not to perform clinical analysis or replace professional judgment. Features include:

  • Progress note drafting: Helps tutors and providers reframe session observations in language that reflects goal progress — improving documentation quality without replacing the provider's professional assessment
  • Goal language suggestions: Generates draft service goal language based on outcomes you describe in your own words
  • Report formatting: Reformats and professionally structures quarterly progress summaries based on narrative text you have already written
  • Transcript analysis: Extracts session themes and goal-relevant observations from meeting transcripts to assist note-writing
  • Activity screenshot analysis: Reads score data from cognitive training app screenshots (BrainHQ, JigsawPlanet) to generate numeric progress entries

What Is — and Is Not — Sent to Anthropic

What is NOT sent to Anthropic

  • Student or client names
  • Dates of birth or ages
  • Social Security Numbers, Medicaid IDs, or DDD IDs
  • Phone numbers, email addresses, or mailing addresses
  • Any direct identifier that could link content to a specific named individual

Before any text is sent, Empowered Sessions automatically scrubs and pseudonymizes these identifiers, replacing names with anonymous placeholders (e.g., CLIENT-A) and removing numeric identifiers.

What may be sent to Anthropic (de-identified)

  • Narrative session descriptions and progress observations (with names removed)
  • Goal descriptions using anonymized references
  • Document text after identifier scrubbing
  • Activity and performance narrative text
  • Screenshot image data from cognitive training apps (which contain scores and performance metrics — if any student names are incidentally visible, the AI model is explicitly instructed to ignore and never output them)

Purpose & Limitations

The AI writing tools are intended solely to help providers communicate more effectively in their documentation. They are not clinical decision-support tools and do not provide medical, therapeutic, or educational recommendations. All AI-generated content is presented as a draft that the provider must review, edit, and take professional responsibility for before use.

Empowered Sessions uses Anthropic's API under its standard commercial terms. API submissions are not used to train Anthropic's models. Anthropic's data handling is governed by their privacy policy and terms of service.

AI is Optional

No AI processing occurs unless a user explicitly initiates it (e.g., clicks a "Draft" or "Polish" action). The platform is fully functional without using any AI features. AI features can be disabled organization-wide by an administrator.

4. HIPAA, FERPA & Regulatory Compliance

Empowered Sessions handles data that may fall under multiple regulatory frameworks depending on how your organization uses the platform.

HIPAA (Health Insurance Portability and Accountability Act)

If your organization uses Empowered Sessions to track, document, or bill for health-related services, and you store Protected Health Information (PHI), HIPAA applies to your use of this platform.

  • A Business Associate Agreement (BAA) is available to organizations that require one. You must execute a BAA before storing PHI. Contact legal@empoweredsessions.app to request a BAA.
  • Empowered Sessions's technical safeguards (encryption, access control, audit logging) are aligned with HIPAA's required Technical Safeguards under 45 CFR § 164.312.
  • Your organization remains the HIPAA Covered Entity and is responsible for workforce training, policies, and breach notification procedures.
  • Minimum Necessary access is enforced through role-based permissions — staff members see only the data required for their job function.
  • AI Writing Assistance & HIPAA: The AI writing assistance tools are designed to operate on de-identified content only. Student names, dates of birth, identification numbers, and other direct identifiers are automatically scrubbed before any content is processed by AI. Narrative content such as session descriptions and goal language — stripped of identifiers — may be processed to assist with documentation drafting. This design ensures the AI tools do not handle PHI as defined under HIPAA. See Section 3 for complete details.
  • Zoom Integration & HIPAA: If Zoom is integrated, meeting data and participant information is synced. Ensure your organization's Zoom account and related data handling comply with HIPAA requirements.
  • Security Incidents: If we become aware of a security incident affecting your data, we will notify you without unreasonable delay and no later than 60 days after discovery, as required to support your breach notification obligations under 45 CFR § 164.410. For breaches affecting fewer than 500 individuals, notification will occur within the timeframe required by applicable law.

FERPA (Family Educational Rights and Privacy Act)

Organizations serving K-12 students and storing educational records must comply with FERPA.

  • Empowered Sessions stores IEPs, 504 Plans, and related educational records only as uploaded by your authorized staff. Access is limited to authenticated members of your organization.
  • Student data is not shared with third parties in identifiable form. When AI writing assistance features are used, content is de-identified before processing — student names and identifiers are removed before any text is sent for AI drafting. See Section 3 for full details.
  • Your organization, as the educational agency, controls and is responsible for educational records stored in the platform.

State Regulations (DDD, Regional Center, Medicaid, etc.)

Many Empowered Sessions users operate under state developmental disabilities programs (e.g., DDD, Regional Center, Medicaid waiver programs). Empowered Sessions's documentation features — service delivery records, approval calendars, billing timesheets — are designed to support your compliance documentation workflows. However, your organization is responsible for ensuring that data entry, authorization tracking, and billing submissions meet your specific state agency's requirements. Empowered Sessions does not verify submissions against any payer's billing rules.

Empowered Sessions is currently piloted with organizations in New Jersey. Organizations in other states should contact us at legal@empoweredsessions.app to confirm the platform meets state-specific requirements before use.

5. Data Sharing & Third Parties

We do not sell, rent, or broker your data. Your data is shared only in these circumstances:

  • Within Your Organization: Data is accessible to authenticated members of your organization according to their assigned role. Admins control who is added to the organization.
  • Platform Administrator (Empowered Applications LLC Staff): A designated Platform Administrator employed by Empowered Applications LLC has access to all organization data for the purposes of technical support, platform maintenance, compliance monitoring, and onboarding assistance. This access is scoped per organization (the administrator sees only one organization's data at a time), is fully audit-logged, and is governed by the same BAA obligations described in Section 4. See Section 2 ("Platform Administrator Access") for complete details on what is accessed, why, and what safeguards are in place.
  • Supabase (Infrastructure Provider): All data is hosted on Supabase's platform, which may process data as a sub-processor. Supabase operates under its own privacy policy and security certifications (SOC 2 Type 2). Data is hosted in the United States.
  • Anthropic / Claude AI (Writing Assistance Only, Optional): The AI writing assistance tools use Anthropic's Claude API. For text-based features (session note drafting, progress report polishing), personally identifiable information — including student names, dates of birth, identification numbers, and contact details — is automatically removed before any content is sent to Anthropic. Only de-identified narrative text (session descriptions, goal language, progress observations) is transmitted, and only when a user explicitly initiates an AI drafting action. For screenshot analysis features (BrainHQ and JigsawPlanet progress parsing), screenshot images are sent to extract numeric performance metrics only — the AI model is explicitly instructed to ignore and never output any personal names or identifiers that may be incidentally visible. Anthropic does not receive PHI or PII as part of this service. API submissions are not used to train Anthropic's models. Anthropic's privacy practices are governed by their own terms of service.
  • Zoom (Meeting Sync, if enabled): If you connect a Zoom account, Empowered Sessions stores Zoom OAuth credentials and uses them to automatically sync meeting history, participant names, and attendance data. Zoom OAuth tokens are stored securely and encrypted. Meeting data from Zoom is governed by both this policy and Zoom's own privacy policy.
  • Stripe (Payment Processing): Subscription and payment information is processed by Stripe, a PCI-compliant payment processor. Empowered Sessions stores Stripe customer IDs and subscription identifiers for account management but does not store credit card numbers or full payment details.
  • External Learning Platforms (Integrations, if enabled): Empowered Sessions can receive and sync student progress data from external educational platforms (e.g., Quest of the Mind, BrainHQ). When these integrations are enabled, student identifiers, performance metrics, and activity data are transmitted between Empowered Sessions and those platforms. Your organization is responsible for ensuring these platforms comply with applicable privacy laws. Empowered Sessions also supports a vendor roster integration that allows authorized external vendors to submit student roster information for matching.
  • External Session Sync (if enabled): Empowered Sessions supports an optional outbound session sync feature that allows organizations to push student session activity data — including student identifiers, activity types, and timestamps — to an external platform configured by your organization's administrator. The external platform receiving this data functions as a sub-processor. Your organization is responsible for ensuring that any external platform you connect to complies with applicable privacy laws and your agreements with that platform. This feature is disabled by default and must be explicitly enabled by an administrator.
  • Read.AI and Other Transcript Sources: If meeting transcripts from third-party recording or transcription services (such as Read.AI) are uploaded into Empowered Sessions, those transcripts are stored and may be processed by AI features. Empowered Sessions does not have a direct integration with Read.AI — transcripts are manually uploaded by your staff.
  • Legal Requirements: We may disclose data if required by law, court order, or government authority, and will notify you where legally permitted to do so.
  • Your Explicit Consent: Any other sharing requires your written authorization.

6. Data Location & Security Incidents

Data Location

Empowered Sessions's database and file storage infrastructure is hosted on Supabase, operating on AWS infrastructure located in the United States. We do not intentionally transfer your data outside the United States. When AI features are used, document content is sent to Anthropic's API, which may process data on servers in the United States or other jurisdictions per Anthropic's infrastructure policies.

Security Incidents & Breach Notification

In the event we discover or are notified of a security incident that affects your organization's data, we will: (1) investigate and contain the incident promptly; (2) notify affected organizations without unreasonable delay and no later than 60 calendar days after discovery, consistent with 45 CFR § 164.410; (3) provide information about the nature of the incident, categories of data involved, and steps taken. If you are subject to HIPAA breach notification obligations (45 CFR §§ 164.400–414), our notification will include the information required to support your own notification obligations to HHS and affected individuals. To report a suspected security incident, contact security@empoweredsessions.app immediately.

7. Data Retention

Recordings

Meeting recordings are subject to a configurable retention period, defaulting to 365 days from the recording date. Organizations can adjust this setting under Organization Settings. When auto-deletion is enabled (the default for new organizations), an automated enforcement job permanently deletes recordings once their retention period expires. Organizations may disable auto-deletion, in which case expired recordings are flagged for manual review but are not automatically removed. Advance notifications are sent as recordings approach expiration.

Client & Session Records

Client records, session documentation, and uploaded documents are retained for as long as your organization account is active. To request deletion of specific records, submit a Data Deletion request through Settings > Data Rights, or contact privacy@empoweredsessions.app. We will respond within 30 days.

Audit Logs

Audit logs are retained while your account is active to support compliance review, dispute resolution, and regulatory requirements. Following account termination, data is retained during the grace period and then scheduled for deletion, except where legal retention requirements apply.

Integration Credentials & Tokens

Zoom OAuth tokens, external platform identifiers, and integration credentials are retained for as long as the integration is active. When you disconnect an integration or terminate your account, these credentials are deleted. Stripe customer and subscription identifiers are retained for as long as your subscription is active for billing and audit purposes.

Account Termination & Data Export

You may submit a data export request at any time through Settings > Data Rights. Upon account termination, a 30-day grace period applies before data deletion is initiated. Data required for legal compliance obligations may be retained beyond that period as required by law. All data requests are fulfilled within 30 days of submission.

8. Your Rights

As an account holder or data subject, you have the right to:

  • Access: Request a copy of the data we hold about you or your organization
  • Correction: Correct inaccurate data directly within the platform or by contacting us
  • Deletion: Request deletion of your account and associated data
  • Portability: Request an export of your data
  • Restriction: Request that we limit processing of your data in certain circumstances
  • Objection: Object to certain uses of your data

To exercise these rights, use the Settings > Data Rights tab within the platform, or contact us at privacy@empoweredsessions.app. We will respond within 30 days.

9. Children's Data

Empowered Sessions requires all account holders and system users to be at least 18 years old. However, the platform is specifically designed to help organizations serve minors (students, participants in developmental disability programs, etc.). Data about minors is entered only by authorized adult service providers within your organization. This data is subject to the same security protections described throughout this policy, plus any additional requirements under FERPA, COPPA, or applicable state law that your organization is responsible for ensuring.

AI Features & Minors' Data: When AI writing assistance features are used in connection with records about minors, the platform automatically removes all direct identifiers — including the minor's name, date of birth, identification numbers, and contact information — before any content is sent to Anthropic's API. Only de-identified narrative content (e.g., anonymized goal descriptions, session observations with names replaced by placeholders) is transmitted. Diagnoses, IEP or ISP content, and educational records are similarly scrubbed of identifiers before AI processing. Your organization remains responsible for ensuring that use of AI features complies with COPPA, FERPA, and any applicable state law governing minors' data. See Section 3 for complete technical details on the de-identification process.

COPPA Notice: Empowered Sessions does not knowingly collect personal information directly from children under 13. All data about minors is collected and entered by authorized adult service providers, not by the minors themselves. If you believe a minor has directly provided personal information through the platform, contact us at privacy@empoweredsessions.app immediately.

10. Cookies & Tracking Technologies

Empowered Sessions uses a minimal set of storage technologies necessary to operate the platform. We do not use third-party advertising trackers, behavioral profiling cookies, or cross-site tracking.

What We Use

  • Authentication Tokens (Essential): Supabase Auth stores a JWT session token in your browser's local storage to maintain your login session. This is required for the platform to function and cannot be disabled.
  • User Preferences (Functional): Local storage may retain your UI preferences (e.g., selected organization, interface mode). These are not transmitted to third parties.
  • Google Fonts (Third-Party): The platform loads the Manrope typeface from Google Fonts CDN. This causes your browser to make a request to Google's servers, which may result in Google logging your IP address per Google's own privacy policy. No PHI or account data is transmitted in this request.

What We Do Not Use

  • No advertising or marketing cookies
  • No behavioral tracking or cross-site tracking pixels
  • No analytics cookies (e.g., Google Analytics, Mixpanel, Hotjar)
  • No social media tracking pixels

Because we do not use non-essential cookies, no cookie consent banner is presented. If this changes in the future, we will update this policy and present appropriate consent mechanisms.

11. Legal Basis for Processing & CCPA Rights

Legal Basis for Processing (GDPR — EEA/UK Users)

If you are located in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases as applicable under the GDPR:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Empowered Sessions platform to your organization under your subscription agreement — including authentication, session tracking, invoicing, and storage of records you enter.
  • Legitimate Interests (Art. 6(1)(f)): Security monitoring, fraud prevention, audit logging, and platform integrity operations that are necessary for the safe operation of the platform and that do not override your fundamental rights.
  • Legal Obligation (Art. 6(1)(c)): Retention of records required by applicable law (e.g., billing records, breach notification obligations).
  • Consent (Art. 6(1)(a)): Optional features such as AI writing assistance are initiated only by explicit user action. Special category data (Art. 9) relating to health or educational records is processed under Art. 9(2)(h) (healthcare/social protection) and/or Art. 9(2)(j) (scientific research/public interest purposes) where applicable, and under your organization's explicit instructions as controller.

Empowered Sessions acts as a Data Processor for the personal data of individuals your organization enters into the platform. Your organization acts as the Data Controller. Empowered Applications LLC acts as Data Controller for account-holder data (name, email, role) used to provide and manage the service. To exercise GDPR rights, contact privacy@empoweredsessions.app.

California Residents — CCPA / CPRA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, and the purposes for which it was collected.
  • Right to Delete: You may request deletion of personal information we hold about you, subject to certain exceptions (e.g., legal obligations, fraud prevention).
  • Right to Correct: You may request correction of inaccurate personal information we hold about you.
  • Right to Opt Out of Sale or Sharing: We do not sell or share your personal information with third parties for cross-context behavioral advertising purposes. No opt-out action is required, but you may confirm this at any time by contacting us.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA rights.

To submit a CCPA request, use Settings > Data Rights within the platform or contact privacy@empoweredsessions.app. We will respond within 45 days as required by the CCPA, with one possible 45-day extension where reasonably necessary.

Data Processing Agreements

Organizations that require a Data Processing Agreement (DPA) — for example, to comply with GDPR Article 28 or CCPA service provider requirements — may request one by contacting legal@empoweredsessions.app. A DPA formalizes the roles of Data Controller (your organization) and Data Processor (Empowered Applications LLC) and specifies the purposes, scope, and security obligations applicable to your data.

12. Contact & Data Protection Officer

Legal & BAA Requests

legal@empoweredsessions.app

Security Concerns & Incidents

security@empoweredsessions.app

Mailing Address

Empowered Applications LLC

Registered in the State of New Jersey

Physical address available upon written request to legal@empoweredsessions.app

This Privacy Policy is effective as of the date listed above and supersedes all prior versions. We will notify you of material changes via email or in-app notification. Continued use of the platform after changes constitutes acceptance. Empowered Sessions is a product of Empowered Applications LLC, a Limited Liability Company registered in the State of New Jersey.