HIPAA-Aligned · DPDP Compliant
TheraTreat Data Security Policy
How we keep your personal, health, and payment data safe — in plain language, with the exact safeguards we run behind the scenes.
AES-256 at Rest
Best-practice encryption
Data encrypted at rest and via TLS 1.3 in transit.
RBAC + Verification
Least privilege
Role-based access; phone/OTP-verified professional accounts.
DPDP Aligned
Consent & rights
Consent, purpose limitation, access/erase rights.
ISO 27001 Infra
Hardened hosting
Audited environments with monitoring and alerts.
1. Strong Encryption Standards
Protecting PHI and payments end-to-end
- All sensitive data (health records, therapy notes, payment info) is encrypted using AES-256.
- Data is encrypted in transit via HTTPS/TLS 1.3 and at rest in secure storage.
- Payment transactions are processed by PCI-DSS compliant gateways (e.g., Razorpay).
2. Compliance with DPDP Act, 2023
Lawful basis, consent, and user rights
- We process personal data only for clear, lawful purposes related to therapy and operations.
- Consent is obtained before collecting personal or health information.
- You may access, correct, update, or request deletion of your data.
- A Data Protection Officer (DPO) oversees compliance and responds to requests.
3. Role-Based Access Controls
Least-privilege access with identity assurance
- Only authorised personnel (therapists, clinics, and you) can access relevant data.
- Phone/OTP verification is required to register a therapist or clinic account; role-based access, session controls, and activity logging are enforced.
- Periodic access reviews keep privileges current and minimal.
4. Secure Infrastructure
Hardened cloud, monitoring, and testing
- Hosted on ISO 27001 certified providers with regular vulnerability scans.
- Firewalls, intrusion detection, and real-time monitoring safeguard systems.
- Regular security audits and penetration testing ensure ongoing protection.
5. Data Retention & Deletion
Retention limits and deletion requests
- Health and therapy data is stored only for required durations and service continuity.
- You may request deletion of your account and personal information, subject to applicable legal, clinical, financial and regulatory retention requirements. Approved deletion requests are processed through our deletion workflow.
6. Breach Notification
Transparent, timely communication
In the unlikely event of a data breach:
- Users will be informed promptly.
- Corrective measures will be taken immediately.
- Authorities will be notified as required by the DPDP Act.
7. Your Responsibilities
Simple steps to keep your account safe
- Use strong passwords and don't share your credentials.
- Log out after using shared devices.
- Report suspicious activity immediately at security@theratreat.in.
8. Contact Our Data Protection Officer
Reach out for privacy or security concerns
For details on personal data handling, see our Privacy Policy. For platform-wide policies (accessibility, cancellation, etc.), visit Policies.
Operated by TheraTreat Health Private Limited · Last updated 28 February 2026