Theramate Theramate
Back to home
§For patients

Privacy (Patients)

You use Theramate because your therapist uses it. This page explains, in plain language, how your data is processed, who keeps it, and what your rights are.

Last updated: May 2026
§ 01

Who processes your data

  • Your therapist Your therapist is the data controller under GDPR: they decide what data to collect, for what purpose, and for how long. To exercise your rights, they are your primary point of contact.
  • Theramate (Playfields SPRL) We provide the tools your therapist uses every day (hosting, encryption, management platform). They decide what happens with your data, not us. We process data on your therapist's instructions under a Data Processing Agreement (DPA), and our team does not view clinical content. Necessary technical interventions are governed, logged, and not used to read records.
  • Address Playfields SPRL, Brussels, Belgium
§ 02

Data collected

  • Identity Last name, first name, date of birth, communication language
  • Contact Email and phone number if you or your therapist provided them
  • Appointments Dates, times, brief reasons, attendance
  • Clinical data Session notes, questionnaires, shared documents (only what is relevant to your care)
  • Technical data Connection logs strictly limited to technical support and security
§ 03

Why this data

Your data is used exclusively to provide your therapeutic care: preparing sessions, keeping clinical history, notifying you of appointments, sharing documents (questionnaires, reports, attestations). No other use. No advertising. No resale.

§ 04

Legal bases

Core guarantee

Your therapist, as data controller, determines the legal basis that applies to your care. Depending on the context, processing generally relies on therapeutic care or the care relationship (Article 6 GDPR), combined with Article 9(2)(h) GDPR for health data processed by a professional bound by professional secrecy. Some optional features, such as the patient assistant, audio transcription, or sharing information with a third party, may require specific information and/or your explicit consent where required by law or by your therapist's configuration.

§ 05

Health data

Core guarantee

Your clinical data qualifies as health data under Article 9 GDPR. It benefits from enhanced protection: AES-256 encryption, European hosting, logging, and limited access to systems. PII is encrypted, audio files sent for transcription are encrypted during server processing and deleted after integration, and video is never stored. In normal operation, only your therapist accesses the clinical content useful to your care. The Theramate team does not view your clinical data: this is our internal policy and our commitment to users.

§ 06

Encryption and hosting

Core guarantee
  • Encryption All clinical data and PII are encrypted with AES-256 before storage. Encryption keys are managed server-side in a secure environment, with restricted access and internal controls. This is not end-to-end encryption where only the therapist holds the decryption key; our internal commitment is not to view clinical content.
  • Hosting Google Cloud, European Union regions (Belgium and Germany depending on the services used: europe-west1 / europe-west3). Your data stays in the European Union.
  • Backups Automatic backups, encrypted and geo-redundant within the EU.
§ 07

Subprocessors

To run the platform, we rely on technical subprocessors. All are bound to Theramate by a GDPR-compliant subprocessing agreement.

  • Google Cloud (European Union) Primary hosting, database, serverless functions, authentication. EU regions used include europe-west1 (Belgium) and europe-west3 (Germany), depending on the services.
  • Scaleway (France) Sovereign European cloud used for selected processing and storage. Infrastructure and datacenters entirely located in France.
  • OpenAI Notes, transcripts and clinical context needed to generate summaries, documents and responses through the OpenAI APIs. No content retention by the provider (Zero Data Retention, ZDR) and no training on your data. Processing is governed by a DPA and the applicable contractual agreements.
  • Soniox Session audio sent to the European (EU) endpoint of the Soniox APIs for transcription. No content retention by the provider (Zero Data Retention, ZDR) and no training on your data. Processing is governed by a DPA and the applicable contractual agreements.
  • Google AI provider for selected clinical processing. No training on your data, no API-side storage.
  • Stripe (Ireland) If your therapist bills via Theramate: payment processing and billing data only
§ 08

Artificial intelligence

Core guarantee
  • No training Your data is never used to train AI models.
  • No API-side storage AI APIs process the data necessary for the request without retaining it for their own account.
  • Assistance, not automated decision-making AI may help your therapist draft, summarize, or organize information, including notes related to your care. No clinical, therapeutic, or administrative decision about you is made solely by AI: your therapist remains responsible, reviews, and validates what is used.
  • Specific information and agreement Where certain features involve direct interaction with you or particular sensitive processing (patient assistant, audio transcription, third-party sharing), your therapist must inform you and obtain the required agreement before activation.
§ 09

Emails you may receive

  • Appointment confirmation and reminder Sent by your therapist via Theramate
  • Booking link If your therapist shares a public booking link
  • Shared documents Questionnaires, reports, attestations sent by your therapist
  • Temporary access links To view a shared document without creating an account

No marketing emails. No newsletters. Only what is strictly necessary for your therapeutic care.

§ 10

How long

Retention duration is set by your therapist, in compliance with the legal obligations applicable to their profession. In Belgium, the patient record is generally kept for 30 years after the end of care (Act of 22 August 2002 on patients' rights). After this period, your data is irreversibly deleted.

§ 11

Your GDPR rights

  • Access Request a copy of the data concerning you
  • Rectification Have inaccurate information corrected
  • Erasure Request deletion, subject to legal retention obligations
  • Portability Receive your data in a reusable format
  • Objection and restriction Object to processing or request its restriction

To exercise these rights, contact your therapist (data controller) first. If you cannot reach them, write to privacy@theramate.pro and we will guide you through the process.

§ 12

Minors and legal representatives

If you are a minor or under guardianship, the rights above are exercised by your legal representative, under applicable law. From the age of discernment (typically between 12 and 16, depending on the situation and maturity), the minor may exercise certain rights related to their own health.

§ 13

Complaint to a supervisory authority

You have the right to lodge a complaint with a data protection authority, notably in the EU Member State where you reside or work. In Belgium, the competent authority is the Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be.

§A question

For any request about your data, please contact your therapist first. For technical questions:

privacy@theramate.pro

Playfields SPRL · Brussels, Belgium