TheraTreat Logo

HIPAA-Aligned · DPDP Compliant

TheraTreat Data Security Policy

How we keep your personal, health, and payment data safe — in plain language, with the exact safeguards we run behind the scenes.

AES-256 at Rest

Best-practice encryption

Data encrypted at rest and via TLS 1.3 in transit.

RBAC + MFA

Least privilege

Role-based access; MFA for therapists and clinics.

DPDP Aligned

Consent & rights

Consent, purpose limitation, access/erase rights.

ISO 27001 Infra

Hardened hosting

Audited environments with monitoring and alerts.

1. Strong Encryption Standards

Protecting PHI and payments end-to-end

  • All sensitive data (health records, therapy notes, payment info) is encrypted using AES-256.
  • Data is encrypted in transit via HTTPS/TLS 1.3 and at rest in secure storage.
  • Payment transactions are processed by PCI-DSS compliant gateways (e.g., Razorpay).

2. Compliance with DPDP Act, 2023

Lawful basis, consent, and user rights

  • We process personal data only for clear, lawful purposes related to therapy and operations.
  • Consent is obtained before collecting personal or health information.
  • You may access, correct, update, or request deletion of your data.
  • A Data Protection Officer (DPO) oversees compliance and responds to requests.

3. Role-Based Access Controls

Least-privilege access with identity assurance

  • Only authorised personnel (therapists, clinics, and you) can access relevant data.
  • MFA is required for therapists and clinics; session controls and activity logging enforced.
  • Periodic access reviews keep privileges current and minimal.

4. Secure Infrastructure

Hardened cloud, monitoring, and testing

  • Hosted on ISO 27001 certified providers with regular vulnerability scans.
  • Firewalls, intrusion detection, and real-time monitoring safeguard systems.
  • Regular security audits and penetration testing ensure ongoing protection.

5. Data Retention & Deletion

Retention limits and verifiable deletion

  • Health and therapy data is stored only for required durations and service continuity.
  • You may request deletion at any time, subject to legal requirements.
  • Deleted data is irreversibly removed from live and backup systems per schedule.

6. Breach Notification

Transparent, timely communication

In the unlikely event of a data breach:

  • Users will be informed promptly.
  • Corrective measures will be taken immediately.
  • Authorities will be notified as required by the DPDP Act.

7. Your Responsibilities

Simple steps to keep your account safe

  • Use strong passwords and don't share your credentials.
  • Log out after using shared devices.
  • Report suspicious activity immediately at security@theratreat.com.

8. Contact Our Data Protection Officer

Reach out for privacy or security concerns

For details on personal data handling, see our Privacy Policy. For platform-wide policies (accessibility, cancellation, etc.), visit Policies.

Last updated Apr 25, 2026