TheraTreat Data Security Policy
Your trust is our highest priority. We protect your personal, health, and financial data with state‑of‑the‑art security measures aligned with the Digital Personal Data Protection Act, 2023 (DPDP) and HIPAA safeguards.
AES‑256 at Rest
Best‑practice encryption
RBAC + MFA
Least privilege
DPDP Aligned
Consent & rights
ISO 27001 Infra
Hardened hosting
1. Strong Encryption Standards
Protecting PHI and payments end‑to‑end
- All sensitive data (health records, therapy notes, payment info) is encrypted using AES‑256.
- Data is encrypted in transit via HTTPS/TLS 1.3 and at rest in secure storage.
- Payment transactions are processed by PCI‑DSS compliant gateways (e.g., Razorpay).
2. Compliance with DPDP Act, 2023
Lawful basis, consent, and user rights
- We process personal data only for clear, lawful purposes related to therapy and operations.
- Consent is obtained before collecting personal or health information.
- You may access, correct, update, or request deletion of your data.
- A Data Protection Officer (DPO) oversees compliance and responds to requests.
3. Role‑Based Access Controls
Least‑privilege access with identity assurance
- Only authorised personnel (therapists, clinics, and you) can access relevant data.
- MFA is required for therapists and clinics; session controls and activity logging enforced.
- Periodic access reviews keep privileges current and minimal.
4. Secure Infrastructure
Hardened cloud, monitoring, and testing
- Hosted on ISO 27001 certified providers with regular vulnerability scans.
- Firewalls, intrusion detection, and real‑time monitoring safeguard systems.
- Regular security audits and penetration testing ensure ongoing protection.
5. Data Retention & Deletion
Retention limits and verifiable deletion
- Health and therapy data is stored only for required durations and service continuity.
- You may request deletion at any time, subject to legal requirements.
- Deleted data is irreversibly removed from live and backup systems per schedule.
6. Breach Notification
Transparent, timely communication
In the unlikely event of a data breach:
- Users will be informed promptly.
- Corrective measures will be taken immediately.
- Authorities will be notified as required by the DPDP Act.
7. Your Responsibilities
Simple steps to keep your account safe
- Use strong passwords and don’t share your credentials.
- Log out after using shared devices.
- Report suspicious activity immediately at security@theratreat.com.
8. Contact Our Data Protection Officer
Reach out for privacy or security concerns
For details on personal data handling, see our Privacy Policy. For platform‑wide policies (accessibility, cancellation, etc.), visit Policies.