
Security & Compliance
Your clients’ privacy, protected
Therapy records are special category data under UK GDPR. Here is how Therasee keeps them safe, and how it helps you meet your own obligations as a practitioner.
- AES-256 encryptionNotes, forms and files are encrypted and stored in UK data centres.
- Two-factor sign-inAdd a code from an authenticator app every time you sign in.
- Privacy modeHide client details on screen in one click, for calls or shared rooms.
- Payments by StripeCard details go straight to Stripe, certified to PCI DSS Level 1.
- GDPR compliantA Data Processing Agreement comes with every account.
- ICO registeredWith the Information Commissioner’s Office, ref. ZB610705.
In detail
Where your data lives
Everything you and your clients add to Therasee is stored in the UK.
- Hosted in UK data centres on Microsoft Azure and Google Cloud.
- Encrypted at rest with AES-256, and in transit with TLS.
- Notes, forms, files and messages are held in the same protected environment.
Signing in
Only the right people get into your practice.
- Two-factor sign-in with an authenticator app, with recovery codes if you lose your phone.
- Repeated sign-in attempts are slowed down and blocked.
- Each person on your team has their own account. Nobody shares a login.
Inside your practice
You decide who sees what.
- Give each team member access area by area: clients, notes, billing, settings and more.
- Privacy mode hides client names and details on screen in one click, for calls or shared rooms.
- Choose which parts of the client portal each client can use.
Payments
Card details never touch Therasee.
- Online payments are handled by Stripe, certified to PCI DSS Level 1.
- Card numbers go straight to Stripe and are never stored by Therasee.
AI features
Speech to text and the form assistant use Google's enterprise AI.
- Your data is not used to train AI models.
- Requests are not logged by the AI provider.
Backups and recovery
Your records are protected against loss.
- Encrypted backups are taken automatically every day and kept for 35 days.
- Backups are stored in the UK, with the same encryption as your live data.
- Restoring from backup is tested regularly.
Testing and monitoring
Security is checked, not assumed.
- Independent penetration testing at least once a year.
- Regular internal security reviews and continuous monitoring of our systems.
- Security updates are applied promptly across the platform.
Clinical will safeguards
If you name executors, they only ever see what you allow.
- Executors confirm their identity with a one-time code to their mobile.
- They can only reach the areas you choose in your clinical will.
- Everything they open or change is recorded in a log.
Your obligations, covered
You are the data controller for your clients’ records. Therasee acts as your data processor, and the paperwork is in place from day one.
- Data Processing AgreementIncluded with every account.
- Privacy PolicyHow we handle personal data.
- Terms of ServiceThe agreement between us.
Registered with the Information Commissioner’s Office, reference ZB610705.
A question about security?
If your practice, service or supervisor needs more detail, our team is happy to help.