HIPAA-aligned · DPDP-aligned
TheraTreat Data Security Policy
How we keep your personal, health, and payment data safe — in plain language.
256-bit encryption
In transit and at rest
Everything travels over HTTPS; the most sensitive fields are encrypted again where they are stored, with AES-256.
Role-based access
Least privilege
Each person sees what their role needs; our admin team signs in with a second step.
DPDP-aligned
Consent & rights
Clear purposes, consent where it is needed, and your rights to access, correct and erase.
Monitored
Watched and logged
Errors and unusual activity alert our team; data exports and refunds are audit-logged.
1. Strong Encryption Standards
Protecting health data and payments in transit and at rest
- Data travels between your device and TheraTreat over encrypted HTTPS connections, and online sessions are encrypted in transit.
- The most sensitive fields — clinical notes, TheraSelf health answers, AI conversations, and PAN, bank and UPI details — are encrypted again where they are stored, one by one, with AES-256 and keys held in a managed key service.
- Card payments are handled by our payment gateway, which is certified to the PCI-DSS standard. We never see or store your full card number.
2. The DPDP Act, 2023
Lawful purposes, consent, and your rights
- We process personal data for the purposes we tell you about — your care, bookings and running the service — with your consent or where the law otherwise allows.
- You can access, correct, download or delete your data, and raise a grievance, from your dashboard or by writing to us.
- Our Data Protection Officer handles privacy requests and oversight.
3. Role-Based Access Controls
Least-privilege access with identity assurance
- Access is role-based: you, your therapist, clinic staff and our team each see only what their role needs.
- Therapist and clinic accounts verify a phone number with a one-time code when they register, and our admin team signs in with a second step.
- Data exports and refunds are recorded in an audit log.
4. Secure Infrastructure
Established hosting and monitoring
- TheraTreat runs on established cloud providers. Where your data is stored and processed, including outside India, is set out in the Privacy Policy.
- Errors and unusual activity are monitored and alert our team.
- Encryption keys are held in a managed key service, separate from the data they protect.
5. Data Retention & Deletion
Retention limits and deletion requests
- We keep data only as long as we need it for your care, the service, or the law. The Privacy Policy sets out the main retention periods.
- You can ask to delete your account from the Privacy tab in your dashboard. We carry out the request after a 30-day grace period, during which you can cancel it: your personal data is then erased or anonymised. Records the law requires us to keep — such as payment and invoice records — are kept for as long as it requires.
6. Breach Notification
Transparent, timely communication
If a breach affects your personal data:
- We act at once to contain it and put it right.
- We tell you what happened and what it means for you.
- We notify the Data Protection Board of India as the DPDP Act requires.
7. Your Responsibilities
Simple steps to keep your account safe
- Use strong passwords and don't share your credentials.
- Log out after using shared devices.
- Report suspicious activity immediately at security@theratreat.in.
8. Contact Our Data Protection Officer
Reach out for privacy or security concerns
For details on personal data handling, see our Privacy Policy. For platform-wide policies (accessibility, cancellation, etc.), visit Policies.
Operated by TheraTreat Health Private Limited · Last updated 2 October 2026