Theralyft

Data Processing Agreement

Last updated: June 25, 2026

This Data Processing Agreement ("DPA") is entered into between Theralyft ("Processor") and each therapist or organisation using the Platform ("Controller"). It forms part of the Terms of Service. By accepting the Terms of Service, you also agree to this DPA.

1. Definitions

Controller — the therapist or organisation that determines the purposes and means of processing client personal data.

Processor — Theralyft, which processes personal data on behalf of the Controller.

Data Subject — clients and other individuals whose personal data is processed through the Platform.

Personal Data — any information relating to an identified or identifiable natural person.

Health Data — personal data relating to an individual's physical or mental health.

Applicable Law — GDPR (EU), UK GDPR, HIPAA (US), Australian Privacy Act 1988, and Zambia Data Protection Act 2021, as applicable.

2. Subject Matter and Scope

Theralyft processes client personal data — including health and session data — on behalf of therapists solely to provide the services described in the Terms of Service: session scheduling, secure messaging, video sessions, and payment facilitation. Theralyft does not use this data for its own commercial purposes.

3. Data Types Processed

  • Client name, email, phone number, and location
  • Therapy request content and session notes
  • In-session chat messages (via Stream Chat)
  • Session scheduling and attendance records
  • Payment transaction references

4. Processor Obligations

Theralyft agrees to:

  • Process personal data only on documented instructions from the Controller (i.e. through use of the Platform)
  • Ensure personnel authorised to process personal data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (encryption at rest and in transit, access controls, audit logging)
  • Not engage sub-processors without the Controller's general authorisation (granted by accepting these Terms; see Section 6 for the sub-processor list)
  • Assist the Controller in responding to Data Subject requests to the extent reasonably possible
  • Notify the Controller within 72 hours of becoming aware of a personal data breach affecting their client data
  • Delete or return personal data upon termination of the Controller's account, subject to legal retention requirements

5. Controller Obligations

The therapist or organisation agrees to:

  • Have a lawful basis for collecting and processing client health data before using the Platform
  • Obtain any consents required by Applicable Law from their clients
  • Maintain their own privacy notice covering the processing described herein
  • Comply with all obligations imposed on data controllers under Applicable Law
  • Promptly notify Theralyft of any Data Subject requests relating to data held on the Platform

6. Sub-Processors

Theralyft uses the following sub-processors. By accepting this DPA, the Controller provides general authorisation for their use:

Sub-ProcessorRoleLocation
Supabase Inc.Database, auth, file storageUS / EU
Stripe Inc.Payment processingUS
Resend Inc.Transactional emailUS
Stream Inc.Messaging and videoUS

We will notify Controllers of any intended addition or replacement of sub-processors with at least 14 days' notice, giving Controllers the opportunity to object.

7. International Transfers

Where personal data is transferred outside the EEA, UK, Australia, or Zambia to the sub-processors above, Theralyft relies on Standard Contractual Clauses (for EU/UK transfers) and equivalent contractual safeguards for other jurisdictions. Theralyft will provide evidence of such safeguards upon request.

8. Security Measures

  • TLS 1.2+ encryption in transit for all data
  • AES-256 encryption at rest (Supabase managed)
  • Row-level security policies restricting data access by user role
  • Access controls and authentication (multi-factor available)
  • Audit logging of data access events
  • Supabase BAA in place for HIPAA compliance

9. Data Breach Notification

In the event of a personal data breach involving Controller data, Theralyft will notify the Controller within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed to address the breach.

10. Termination and Deletion

Upon termination of the Controller's account, Theralyft will delete personal data processed on the Controller's behalf within 30 days, except where retention is required by law. Controllers may request a data export before account closure.

11. Contact

DPA enquiries: privacy@theralyft.com