Privacy Policy
1. Who we are, and our role
Therapist & Co. (“the platform”, “we”) provides practice-management software to mental-health practitioners and practices in India. Two roles matter for your data:
- Each practice (or solo practitioner) is the Data Fiduciary for its own patients’ clinical records under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the DPDP Rules, 2025. The practice decides the purpose and means of processing its patients’ data.
- The platform is a Data Processor acting on each practice’s documented instructions for that same clinical data. For your own account identity (below), the platform is the Data Fiduciary.
This separation is real in how the product is built: clinical data is siloed per practice, and no practice can see another practice’s records.
2. Information we process
Account identity (travels with you)
- Name, email address, phone number, password (stored only as a secure hash), and multi-factor-authentication enrolment.
- Optional profile photo.
Clinical and practice data (held on behalf of a practice)
- Session records, appointment history, clinical notes and assessments, consent records, and mood or wellbeing check-ins you choose to share.
- Billing and payment metadata (amounts, currency, status, invoices, credits, refunds). We do not store full card numbers; card and UPI details are handled by the payment gateway.
Operational data
- Security and audit logs (who did what, and when), correlation identifiers for error tracing, and IP address on security-relevant events (for example, sign-in and failed sign-in).
We do not operate a private journaling feature; no free-text personal journal is collected or stored by the platform.
3. How we use your data, and our lawful basis
- To provide the service a practice has engaged us to run: scheduling, billing, clinical record-keeping, notifications, and reporting.
- To keep the service secure (authentication, MFA, audit logging, fraud and abuse prevention).
- To meet legal, regulatory, and record-retention obligations.
Processing rests on the consent you or the practice provide under the DPDP Act, and on the legitimate provision of a service you have asked for. You can withdraw consent at any time (see “Your rights”), subject to the record-retention obligations below.
4. Where your data lives, and who processes it
We use a small set of trusted infrastructure providers acting as sub-processors on our instructions:
- Database, authentication and file storage: our cloud database provider.
- Application hosting: our cloud hosting provider (Mumbai region).
- Transactional email: our email delivery provider.
- Payments: the payment gateway(s) a practice has connected.
- Bot and fraud detection: Cloudflare Turnstile.
A current, named sub-processor list will be published here before launch.
5. How we protect it
- Row-level security and strict tenant isolation on every table, so data access is scoped to the practice it belongs to.
- Encryption of sensitive stored secrets (such as connected payment-gateway credentials) and encryption in transit.
- Multi-factor authentication for staff accounts, and an append-only audit trail of sensitive actions.
6. How long we keep it
For clinical records, retention is set by your practice, not by us. Every practice, whether an organisation or a solo practitioner, is the Data Fiduciary for its own patients’ records and is the party the law holds responsible for deciding how long they are kept. The correct period depends on the practitioner’s profession, their regulator, and the jurisdiction they practise in. That is not something a software provider can determine on a practice’s behalf, and we do not pretend otherwise.
What that means in practice:
- Your practice sets the retention period for each category of record, in its practice settings. Every category arrives with a researched default, so a practice is never asked to start from a blank field. We store records for as long as you instruct.
- We enforce a legal minimum. Each category carries a floor drawn from the applicable statutory duty. A period may be set longer than its floor, never shorter, so a setting can never place a practice below its own legal obligation.
- We never destroy clinical records on a timer. Nothing is deleted automatically because a period has elapsed. We report what has become eligible for disposal, and the decision to destroy anything is always taken by a person at the practice.
- A record under legal hold is never destroyed while the hold stands, whatever period is configured. Medico-legal matters, complaints and investigations are held until resolved.
- Financial and tax records follow their own, longer clock, set by tax and company law. They are never removed as a side effect of deleting a clinical record.
- A practitioner’s clinical notes about clients are the practice’s records, not the practitioner’s, and follow the practice’s clinical-record periods. Their authorship of a record is preserved for as long as the record itself is kept, because a clinical record that cannot be attributed to its author has no evidential value. Their personal and account information is separate from that authorship and is anonymised once no record we still hold depends on it.
- Data we hold as controller in our own right, such as your account, billing and subscription records and our security audit trail, is kept for the periods our own legal, tax and accounting obligations require.
Downloading a copy of your data is not the same as deletion: where a retention obligation applies, it overrides an erasure request for the duration of that obligation. Where we are able to erase data, we give you at least 48 hours’ notice before doing so.
7. When a practice closes
Closing a practice does not delete its records. They remain subject to the same retention obligations that applied before closure, and those obligations continue to rest with the practice. Before a closure is confirmed, the practice must export its records and confirm it has done so. We keep a permanent record of that confirmation, showing who gave it, when, and exactly what the export contained.
The closure is then finalised after a 30-day countdown. Where a solo practitioner closes, the platform continues to act as retention custodian for the clinical records for the remaining required period. Records are not deleted on a short grace period.
8. Your rights
Under the DPDP Act and applicable clinical-records law, you may:
- Request access to, and a copy of, the personal data held about you.
- Request correction of inaccurate or incomplete data.
- Request erasure, subject to the retention obligations above.
- Nominate another person to exercise your rights.
- Withdraw consent, and raise a grievance.
Because each practice is the Data Fiduciary for its own patients’ clinical records, requests about that data are directed to the practice, which must designate a grievance officer and run a grievance-redressal mechanism. You can also raise a data-rights request from within your account. For account-identity data held by the platform, contact us using the details below.
We (or the practice, for its own patients’ records) respond to a request for access to or erasure of your data within 90 days. A request specifically for access to clinical records is met within 2 weeks, in line with the Mental Healthcare Act, 2017.
9. Children and minors
Where a patient is a minor, processing relies on verifiable consent from a parent or lawful guardian, as required by the DPDP Act and the DPDP Rules, 2025. A practice is responsible for obtaining that consent for its patients.
10. Changes, and how to reach us
We will post any material change to this policy on this page with a revised “last updated” date. For privacy questions about platform-held data, or to reach the platform’s Data Protection contact, email privacy@therapistandco.com. For questions about your clinical records at a specific practice, contact that practice’s grievance officer.