Skip to main content

Ethics · Safety · Governance

Compliance at TheraTreat

Patient safety, clinician standards, and careful data handling — the ground rules we won't cut corners on.

DPDP Principles

Consent & rights

Lawful processing, purpose limitation, deletion on request.

Therapist Verification

Before listing

Identity (PAN) and bank-account checks, and a review of licence or registration documents.

Security Controls

Defence in depth

Encryption, role-based access, audit logs, monitoring.

Accountability

Every complaint tracked

Each grievance gets a reference number; we aim to respond within 15 working days.

DPDP & Privacy

Digital Personal Data Protection Act, 2023 alignment

  • Consent-based processing with clear lawful purposes.
  • Purpose limitation, minimisation, and retention periods set out in the Privacy Policy.
  • Your rights: access, correction, erasure and grievance redressal — and you can nominate someone to exercise them for you.
  • A Data Protection Officer for requests and oversight.

See our Privacy Policy and Data Security Policy for implementation details.

Clinical Standards

Therapist verification and practice quality

  • Before a therapist is listed: an identity check (PAN), a check of the bank account they are paid into, and a review of the licence or registration documents they upload.
  • We do not run criminal background checks, and we don't claim to.
  • AI drafts of session notes are proposals until the therapist reviews, edits and signs them; supervised notes can be co-signed.
  • Clear escalation paths for complaints and grievances: Report an Issue, the grievance form, and disputes@theratreat.in.

Operational Compliance

Controls across people, process, and technology

  • Role-based access, phone verification for therapist and clinic sign-ups, and a second sign-in step for our admin team.
  • Service providers receive personal data only for the purposes set out in the Privacy Policy.
  • If a breach affects your data, we tell you and notify the Data Protection Board of India as the law requires.

Technical controls are summarised in the Data Security Policy.

Monitoring & Accountability

Seeing problems early, and owning them

  • Errors and unusual activity are monitored and alert our team.
  • Data exports and refunds are recorded in audit logs.
  • Every grievance gets a reference number and stays open until it is resolved.

Contact & References

Where to learn more and who to reach

For compliance queries or reports, please contact our DPO at dpo@theratreat.in.

Related: Privacy Policy · Data Security Policy · Accessibility · Refund & Cancellation

Operated by TheraTreat Health Private Limited · Last updated 2 October 2026