Back to home
§Index

Privacy Policy

Theramate is designed by and for mental health professionals. Privacy is not a feature: it is the foundation of our platform.

Last updated: 20 September 2026
§ 01

Data Collected

  • Account data Email, name, billing information
  • Clinical data Session notes, reports, patient questionnaires
  • Technical data Login logs, device used (for support)
§ 03

Encryption

Core guarantee

All clinical and personal data is encrypted with AES-256-GCM at rest, with a key specific to each practitioner, and exchanges are encrypted in transit (TLS). Keys are managed server-side in a secure environment, with restricted access, logging, and internal controls. Audio submitted for transcription is encrypted with your key as soon as it is taken in charge, then deleted once integrated into the record. Our operational commitment is not to view clinical content; any technical intervention is limited, authorized, logged, and not used to read records, except under a valid legal obligation.

§ 04

Hosting

Core guarantee

Your data is hosted on Google Cloud infrastructure located in the European Union: database replicated in Belgium and the Netherlands (eur3 multi-region), server processing in Frankfurt (europe-west3), files in the EU multi-region. HDS v2.0 certified infrastructure. Technical subprocessors are contractually governed. Theramate application data remains in the European Union.

§ 05

Subprocessors

To operate Theramate, we rely on technical subprocessors governed by contract. This list is reflected in our contractual documentation and may evolve in accordance with the DPA and applicable Terms.

  • Google Cloud (European Union) Primary hosting, database, serverless functions, authentication, and technical infrastructure. EU regions used include Belgium and Germany depending on the services.
  • Scaleway (France) Transactional email and hosting of the video consultation server. Datacenters in Paris, France.
  • OpenAI Notes, transcripts and clinical context needed to generate summaries, documents and responses through the OpenAI APIs. No content retention by the provider (Zero Data Retention, ZDR) and no training on your data. Processing is governed by a DPA and the applicable contractual agreements.
  • Soniox Session audio sent to the European (EU) endpoint of the Soniox APIs for transcription. No content retention by the provider (Zero Data Retention, ZDR) and no training on your data. Processing is governed by a DPA and the applicable contractual agreements.
  • Google Technical service provider and, depending on enabled features, provider for selected AI processing. No training on your data.
  • Stripe (Ireland) Subscription management, payments, billing, and, where applicable, patient payments through Stripe Connect.
§ 06

Artificial Intelligence

  • No training Your data is never used to train or improve AI models
  • Controlled APIs AI processing goes through contractually governed providers. Data necessary for a request is not retained API-side.
  • Assistance, not automated decision-making AI suggestions are drafting, summarization, or organization aids. No clinical or therapeutic decision is made solely by AI: you remain responsible for reviewing, editing, accepting, or rejecting proposed content.
  • Transparency You know when AI is used, for what purpose, and you remain in control of clinical use of the results
§ 07

Your Rights (GDPR)

  • Access View all your data at any time
  • Rectification Correct your personal information
  • Portability Export your data in standard format (Word, PDF, Markdown)
  • Deletion Request complete and irreversible deletion of your data
§ 08

Retention

Your data is retained for the duration of your subscription. After termination you keep twelve (12) months of read and export access before permanent deletion, and you may request immediate deletion at any time.

§ 09

Data Sharing

We never sell your data and do not use it for advertising. It may be processed by the technical subprocessors listed above, strictly to provide Theramate, or disclosed where a valid legal obligation requires it. Your professional and clinical content remains under your control.

§ 10

Google Calendar Integration

Core guarantee
  • Data Accessed Theramate accesses your Google Calendar events (title, time, location) and your Google email address for account verification. No other Google data is accessed.
  • Data Usage Google Calendar data is used exclusively to synchronize your appointments between Theramate and Google Calendar. Events are synchronized bidirectionally over a 90-day window. No clinical data (session notes, diagnoses, patient history) is ever sent to Google Calendar.
  • Data Sharing Your Google data is not shared with any third party. It remains strictly between Theramate and your Google account. Theramate does not use Google data for advertising purposes.
  • Data Storage & Protection Google authentication tokens are encrypted with AES-256 and stored exclusively server-side in a secure environment. No tokens are ever stored on your device. Synchronized appointment titles are configurable (generic, initials, or first name only) to protect your patients' privacy.
  • Data Retention & Deletion You can disconnect Google Calendar at any time from Theramate settings. Disconnection immediately revokes access, deletes all encrypted tokens from our servers, and stops all synchronization. Events already in your Google Calendar are not deleted.
§ 11

Google API Services Compliance

Theramate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Theramate only uses Google data to provide the calendar synchronization functionality. The data is not used for advertising, is not sold to third parties, and is not used to train artificial intelligence models.

§DPO Contact

For any questions regarding your personal data:

privacy@theramate.pro

Playfield SRL · Company no. 0833.702.033 · Chemin de Toune 4, 1325 Chaumont-Gistoux, Belgium