Skip to main content

HIPAA-aligned · DPDP-aligned

TheraTreat Data Security Policy

How we keep your personal, health, and payment data safe — in plain language.

256-bit encryption

In transit and at rest

Everything travels over HTTPS; the most sensitive fields are encrypted again where they are stored, with AES-256.

Role-based access

Least privilege

Each person sees what their role needs; our admin team signs in with a second step.

DPDP-aligned

Consent & rights

Clear purposes, consent where it is needed, and your rights to access, correct and erase.

Monitored

Watched and logged

Errors and unusual activity alert our team; data exports and refunds are audit-logged.

1. Strong Encryption Standards

Protecting health data and payments in transit and at rest

  • Data travels between your device and TheraTreat over encrypted HTTPS connections, and online sessions are encrypted in transit.
  • The most sensitive fields — clinical notes, TheraSelf health answers, AI conversations, and PAN, bank and UPI details — are encrypted again where they are stored, one by one, with AES-256 and keys held in a managed key service.
  • Card payments are handled by our payment gateway, which is certified to the PCI-DSS standard. We never see or store your full card number.

2. The DPDP Act, 2023

Lawful purposes, consent, and your rights

  • We process personal data for the purposes we tell you about — your care, bookings and running the service — with your consent or where the law otherwise allows.
  • You can access, correct, download or delete your data, and raise a grievance, from your dashboard or by writing to us.
  • Our Data Protection Officer handles privacy requests and oversight.

3. Role-Based Access Controls

Least-privilege access with identity assurance

  • Access is role-based: you, your therapist, clinic staff and our team each see only what their role needs.
  • Therapist and clinic accounts verify a phone number with a one-time code when they register, and our admin team signs in with a second step.
  • Data exports and refunds are recorded in an audit log.

4. Secure Infrastructure

Established hosting and monitoring

  • TheraTreat runs on established cloud providers. Where your data is stored and processed, including outside India, is set out in the Privacy Policy.
  • Errors and unusual activity are monitored and alert our team.
  • Encryption keys are held in a managed key service, separate from the data they protect.

5. Data Retention & Deletion

Retention limits and deletion requests

  • We keep data only as long as we need it for your care, the service, or the law. The Privacy Policy sets out the main retention periods.
  • You can ask to delete your account from the Privacy tab in your dashboard. We carry out the request after a 30-day grace period, during which you can cancel it: your personal data is then erased or anonymised. Records the law requires us to keep — such as payment and invoice records — are kept for as long as it requires.

6. Breach Notification

Transparent, timely communication

If a breach affects your personal data:

  • We act at once to contain it and put it right.
  • We tell you what happened and what it means for you.
  • We notify the Data Protection Board of India as the DPDP Act requires.

7. Your Responsibilities

Simple steps to keep your account safe

  • Use strong passwords and don't share your credentials.
  • Log out after using shared devices.
  • Report suspicious activity immediately at security@theratreat.in.

8. Contact Our Data Protection Officer

Reach out for privacy or security concerns

For details on personal data handling, see our Privacy Policy. For platform-wide policies (accessibility, cancellation, etc.), visit Policies.

Operated by TheraTreat Health Private Limited · Last updated 2 October 2026