This Data Processing Agreement ("DPA") is entered into between Theralyft ("Processor") and each therapist or organisation using the Platform ("Controller"). It forms part of the Terms of Service. By accepting the Terms of Service, you also agree to this DPA.
Controller — the therapist or organisation that determines the purposes and means of processing client personal data.
Processor — Theralyft, which processes personal data on behalf of the Controller.
Data Subject — clients and other individuals whose personal data is processed through the Platform.
Personal Data — any information relating to an identified or identifiable natural person.
Health Data — personal data relating to an individual's physical or mental health.
Applicable Law — GDPR (EU), UK GDPR, HIPAA (US), Australian Privacy Act 1988, and Zambia Data Protection Act 2021, as applicable.
Theralyft processes client personal data — including health and session data — on behalf of therapists solely to provide the services described in the Terms of Service: session scheduling, secure messaging, video sessions, and payment facilitation. Theralyft does not use this data for its own commercial purposes.
Theralyft agrees to:
The therapist or organisation agrees to:
Theralyft uses the following sub-processors. By accepting this DPA, the Controller provides general authorisation for their use:
| Sub-Processor | Role | Location |
|---|---|---|
| Supabase Inc. | Database, auth, file storage | US / EU |
| Stripe Inc. | Payment processing | US |
| Resend Inc. | Transactional email | US |
| Stream Inc. | Messaging and video | US |
We will notify Controllers of any intended addition or replacement of sub-processors with at least 14 days' notice, giving Controllers the opportunity to object.
Where personal data is transferred outside the EEA, UK, Australia, or Zambia to the sub-processors above, Theralyft relies on Standard Contractual Clauses (for EU/UK transfers) and equivalent contractual safeguards for other jurisdictions. Theralyft will provide evidence of such safeguards upon request.
In the event of a personal data breach involving Controller data, Theralyft will notify the Controller within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed to address the breach.
Upon termination of the Controller's account, Theralyft will delete personal data processed on the Controller's behalf within 30 days, except where retention is required by law. Controllers may request a data export before account closure.
DPA enquiries: privacy@theralyft.com