Sessionly
  • How it works
  • Features
  • Founder
  • Backed by
  • Waitlist
Join waitlist
Legal

Privacy Policy

Last updated: July 2026

Sessionly Ltd ("Sessionly", "we", "us") operates the Sessionly platform: an iOS app for GP locums, a web portal for GP practices, and an administration dashboard (together, the "Service"). This policy explains what personal data we collect, why, and how we look after it.

Sessionly Ltd is a company registered in England and Wales (company number 17156289) and is registered with the Information Commissioner's Office (ICO), registration number ZC192863.

A note on our pilot: Sessionly is currently operating as a pilot service under active development. Features may change, and we may contact you for feedback as part of the pilot.

Who this policy covers

  • Locum GPs using the Sessionly app
  • Practice staff using the Practice Portal on behalf of a GP practice
  • Visitors to our website (sessionlygp.co.uk)

What we collect

Locum GPs

  • Account and profile information: name, email address, phone number, professional details (including GMC number), location and shift preferences.
  • Compliance documents and verification data: documents you upload for verification, which may include photo ID, right-to-work evidence, proof of address, GMC registration, qualification certificates, enhanced DBS certificate, occupational health and immunisation/vaccination history, indemnity certificate, training certificates and references. Some of this is special category data (health information) and criminal records data (DBS) — see "Sensitive data" below.
  • Pension and payment information: details needed to prepare NHS Pension forms (such as your NHS pension reference and National Insurance number) and, where you use invoicing features, the bank account details you choose to include on invoices to practices.
  • Booking and usage data: shifts you view, apply for, book and complete; messages you send through the platform; and technical data needed to run the app (such as device information and notification tokens).
  • Calendar data: if you enable calendar integration, we check your device calendar to detect clashes. Calendar access is controlled by your device permissions and can be switched off at any time.

Practice users

  • Name, work email address, role, practice details, and the shifts, bookings and messages you manage through the Practice Portal.

How we use your data

  • To run the Service: creating accounts, matching locums to shifts, processing bookings, enabling messaging between locums and practices, and sending service notifications (in-app and by email).
  • To verify locums: reviewing uploaded compliance documents so that practices can rely on verified professionals. Practices see your profile and verification status (for example "DBS verified"); our aim is that practices do not need access to your underlying documents.
  • To automate paperwork: generating NHS Pension forms (Locum A and B) and, where used, invoices/timesheets from your shift data. Invoices you send to a practice include the bank details you have provided for that purpose.
  • AI features: when you use SessionlyAI (our conversational shift search), the text of your query is processed by our AI provider, Anthropic, to return results. We do not use your data to train AI models.
  • To improve the Service: understanding how the platform is used, fixing problems, and developing features. During the pilot we may review usage closely to improve the product.

Legal bases

We rely on: performance of a contract (running your account and bookings), legitimate interests (operating, securing and improving the platform, and enabling practices to engage verified locums), legal obligations (where applicable), and consent where required — including your explicit consent when you upload health-related and DBS documents for verification. You can withdraw consent at any time, though this may mean we cannot verify you for bookings.

Sensitive data

Some verification documents contain special category data (for example immunisation and occupational health information) and criminal records data (your DBS certificate). We process these only for the purpose of verifying your eligibility and suitability to work as a locum GP, with your explicit consent, and we restrict access to them. They are stored securely and are not shared with practices; practices see verification status only.

Who we share data with

  • GP practices: practices you apply to or book with can see your professional profile and verification status. If you send an invoice to a practice, it will include the details you have chosen to include on it.
  • Service providers: we use trusted providers to run the platform, including Supabase (database and file storage), Anthropic (AI query processing), our email/notification provider, and Apple (app distribution and push notifications). These providers process data on our behalf under contract.
  • No advertising or data sales: we do not sell your personal data, and we do not share it with advertisers.
  • Legal: we may disclose data where required by law or to protect the rights and safety of users.

Where your data is stored

Your data is stored securely with our hosting providers. Where data is transferred outside the UK (for example to service providers operating internationally), we ensure appropriate safeguards are in place, such as UK-approved standard contractual clauses.

How long we keep it

We keep your data while your account is active. If you close your account, we delete or anonymise your personal data within a reasonable period, except where we need to retain it to meet legal or regulatory obligations (for example, records relating to completed bookings, invoices or pension forms). You can ask us to delete your data at any time.

Your rights

You have the right to access your data, correct it, delete it, restrict or object to its processing, and receive a copy in a portable format. To exercise any right, email us at the address below. You also have the right to complain to the ICO (ico.org.uk).

Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections, access controls, and role-based permissions across the app, Practice Portal and admin dashboard.

Children

The Service is for healthcare professionals and practice staff and is not intended for anyone under 18.

Changes

We may update this policy as the Service develops (particularly during the pilot). We will post updates on this page and update the date above; for significant changes we will notify you in the app or by email.

Contact

Sessionly Ltd

Email: sessionlygp@outlook.com

Website: sessionlygp.co.uk

Sessionly
  • How it works
  • Features
  • LinkedIn
  • Instagram
  • Contact
  • Privacy
  • Terms
© 2026 Sessionly Ltd · 17156289