Ethics · Safety · Governance
Compliance at TheraTreat
Patient safety, clinician standards, and careful data handling — the ground rules we won't cut corners on.
DPDP Principles
Consent & rights
Lawful processing, purpose limitation, deletion on request.
Therapist Verification
Before listing
Identity (PAN) and bank-account checks, and a review of licence or registration documents.
Security Controls
Defence in depth
Encryption, role-based access, audit logs, monitoring.
Accountability
Every complaint tracked
Each grievance gets a reference number; we aim to respond within 15 working days.
DPDP & Privacy
Digital Personal Data Protection Act, 2023 alignment
- Consent-based processing with clear lawful purposes.
- Purpose limitation, minimisation, and retention periods set out in the Privacy Policy.
- Your rights: access, correction, erasure and grievance redressal — and you can nominate someone to exercise them for you.
- A Data Protection Officer for requests and oversight.
See our Privacy Policy and Data Security Policy for implementation details.
Clinical Standards
Therapist verification and practice quality
- Before a therapist is listed: an identity check (PAN), a check of the bank account they are paid into, and a review of the licence or registration documents they upload.
- We do not run criminal background checks, and we don't claim to.
- AI drafts of session notes are proposals until the therapist reviews, edits and signs them; supervised notes can be co-signed.
- Clear escalation paths for complaints and grievances: Report an Issue, the grievance form, and disputes@theratreat.in.
Operational Compliance
Controls across people, process, and technology
- Role-based access, phone verification for therapist and clinic sign-ups, and a second sign-in step for our admin team.
- Service providers receive personal data only for the purposes set out in the Privacy Policy.
- If a breach affects your data, we tell you and notify the Data Protection Board of India as the law requires.
Technical controls are summarised in the Data Security Policy.
Monitoring & Accountability
Seeing problems early, and owning them
- Errors and unusual activity are monitored and alert our team.
- Data exports and refunds are recorded in audit logs.
- Every grievance gets a reference number and stays open until it is resolved.
Contact & References
Where to learn more and who to reach
For compliance queries or reports, please contact our DPO at dpo@theratreat.in.
Related: Privacy Policy · Data Security Policy · Accessibility · Refund & Cancellation
Operated by TheraTreat Health Private Limited · Last updated 2 October 2026