HIPAA-Aligned · DPDP Compliant
TheraTreat Data Security Policy
How we keep your personal, health, and payment data safe — in plain language, with the exact safeguards we run behind the scenes.
AES-256 at Rest
Best-practice encryption
Data encrypted at rest and via TLS 1.3 in transit.
RBAC + MFA
Least privilege
Role-based access; MFA for therapists and clinics.
DPDP Aligned
Consent & rights
Consent, purpose limitation, access/erase rights.
ISO 27001 Infra
Hardened hosting
Audited environments with monitoring and alerts.
1. Strong Encryption Standards
Protecting PHI and payments end-to-end
- All sensitive data (health records, therapy notes, payment info) is encrypted using AES-256.
- Data is encrypted in transit via HTTPS/TLS 1.3 and at rest in secure storage.
- Payment transactions are processed by PCI-DSS compliant gateways (e.g., Razorpay).
2. Compliance with DPDP Act, 2023
Lawful basis, consent, and user rights
- We process personal data only for clear, lawful purposes related to therapy and operations.
- Consent is obtained before collecting personal or health information.
- You may access, correct, update, or request deletion of your data.
- A Data Protection Officer (DPO) oversees compliance and responds to requests.
3. Role-Based Access Controls
Least-privilege access with identity assurance
- Only authorised personnel (therapists, clinics, and you) can access relevant data.
- MFA is required for therapists and clinics; session controls and activity logging enforced.
- Periodic access reviews keep privileges current and minimal.
4. Secure Infrastructure
Hardened cloud, monitoring, and testing
- Hosted on ISO 27001 certified providers with regular vulnerability scans.
- Firewalls, intrusion detection, and real-time monitoring safeguard systems.
- Regular security audits and penetration testing ensure ongoing protection.
5. Data Retention & Deletion
Retention limits and verifiable deletion
- Health and therapy data is stored only for required durations and service continuity.
- You may request deletion at any time, subject to legal requirements.
- Deleted data is irreversibly removed from live and backup systems per schedule.
6. Breach Notification
Transparent, timely communication
In the unlikely event of a data breach:
- Users will be informed promptly.
- Corrective measures will be taken immediately.
- Authorities will be notified as required by the DPDP Act.
7. Your Responsibilities
Simple steps to keep your account safe
- Use strong passwords and don't share your credentials.
- Log out after using shared devices.
- Report suspicious activity immediately at security@theratreat.com.
8. Contact Our Data Protection Officer
Reach out for privacy or security concerns
For details on personal data handling, see our Privacy Policy. For platform-wide policies (accessibility, cancellation, etc.), visit Policies.
Last updated Apr 25, 2026