Features How it works Pricing Privacy Log in Schedule a walkthrough
🇬🇧EN
🇩🇪DE 🇬🇧EN 🇵🇱PL
Theravo / Legal / Data Processing Agreement

Data Processing Agreement

Agreement under Article 28 GDPR for processing patient and appointment data on behalf of a practice.

Document version
2026-07-30.4
Effective date
2026-07-30
Last updated
2026-07-30
Language
EN

Provider information

Business name
Theravo
Proprietor
Egidijus Girčys
Business address
Mies-van-der-Rohe-Str. 6
14469 Potsdam
Germany
Place of business
Potsdam, Germany
Contact
hello@theravo.de
Legal email
legal@theravo.de

Purpose of this agreement

This Data Processing Agreement (DPA) forms part of the agreement between the practice or other professional customer (the Controller) and Egidijus Girčys, operating under the business name Theravo (the Processor). It governs personal data that Theravo processes on the Controller's behalf when providing appointment-management services.

Conclusion and evidence

The DPA may be concluded electronically as part of account registration, ordering or an in-account acceptance flow. Where electronic acceptance is used, Theravo records the accepted document version, the customer account, the accepting user, the date and time, and other evidence reasonably required to demonstrate conclusion of the agreement.

Roles of the parties

  • The customer is the Controller and determines the purposes and means of processing patient and practice data.
  • Theravo is the Processor for data processed solely to provide the service on the customer's documented instructions.
  • Theravo remains an independent controller for its own contract administration, billing, security, abuse prevention and legal compliance.

Scope and order of precedence

This DPA applies to processing on behalf of the Controller and takes precedence over conflicting provisions of the general Terms of Service in relation to that processing. The service agreement, the Controller's configuration and documented support instructions constitute processing instructions, provided that they comply with applicable law.

Subject matter and duration

The subject matter is the provision, operation, support and security of Theravo's appointment-management service. Processing begins when the Controller provides or makes personal data available to Theravo and continues for the term of the service agreement, including any limited export, backup-rotation and deletion period after termination.

Documented instructions

  • Theravo processes personal data only on documented instructions from the Controller, including instructions contained in the service agreement, this DPA and the Controller's settings.
  • Theravo may process data without an instruction only where required by Union or Member State law. In that case, Theravo informs the Controller before processing unless the law prohibits that information for important public-interest reasons.
  • Changes that materially extend the processing require a documented instruction or an amendment to the agreement.

Nature and purpose of processing

  • Collecting, recording, organising, structuring, storing, retrieving and displaying appointment data.
  • Receiving and sending appointment-related communications through Theravo-managed addresses.
  • Managing availability, appointment requests, confirmations, cancellations, rescheduling, patient portal access and appointment credit.
  • Locally classifying administrative messages and preparing response drafts using the locally operated Gemma 3 language model.
  • Providing support, security, logging, backup, recovery, export and deletion functions.

Categories of data subjects

  • Patients and prospective patients of the Controller.
  • Therapists, practice owners, employees, contractors and authorised users of the Controller.
  • Persons contacting the practice in relation to an appointment.

Categories of personal data

  • Identity and contact data, such as name, email address and telephone number.
  • Appointment and availability data, appointment type, location or video-session details, booking status and cancellation or rescheduling information.
  • Administrative messages and correspondence relating to appointment management.
  • Patient portal account, authentication and access data.
  • Payment and transaction references where an optional payment function is used.
  • Technical, security and audit data, including identifiers, timestamps, IP addresses and event records.

Special categories of data

Appointment data relating to psychotherapy and free-text messages may reveal health information and can therefore constitute data concerning health under Article 9 GDPR. The Controller must establish a valid Article 9 condition and instruct patients not to submit clinical details that are unnecessary for appointment administration. Theravo does not use the service as an electronic health record and does not require diagnosis or therapy-note data.

Obligations of the Controller

  • The Controller is responsible for the lawfulness, transparency, accuracy and necessity of processing, including the legal bases under Articles 6 and 9 GDPR.
  • The Controller provides data subjects with the required privacy information and handles requests concerning their rights.
  • The Controller configures access rights, retention, appointment forms, message fields and optional functions in accordance with its obligations.
  • The Controller does not instruct Theravo to process unlawful content or more personal data than is necessary for appointment management.
  • The Controller promptly informs Theravo when instructions, authorised users or retention requirements change.

Obligations of Theravo

  • Process data only for the agreed service and on documented instructions.
  • Ensure that persons authorised to process personal data are bound by confidentiality.
  • Implement and maintain appropriate technical and organisational measures under Article 32 GDPR.
  • Assist the Controller with data-subject requests, security obligations, breach assessment, data-protection impact assessments and supervisory-authority consultations, taking account of the nature of processing and the information available to Theravo.
  • Maintain records and provide information reasonably necessary to demonstrate compliance with Article 28 GDPR.
  • Not use Controller data for advertising, sale of data, general-purpose model training or Theravo's own clinical purposes.

Confidentiality

Theravo limits access to persons who require it for operation, maintenance, security or support and ensures that those persons are subject to contractual or statutory confidentiality obligations. Confidentiality continues after their access or engagement ends.

Professional secrecy and section 203 of the German Criminal Code

  • Where the Controller or professionals working for it are subject to criminally protected professional secrecy, the Controller engages Theravo as an external service provider in the professional activity. Natural persons at Theravo who may properly become aware of protected secrets are, where the statutory conditions are met, engaged as other participating persons within the meaning of section 203(3) and (4) of the German Criminal Code.
  • Theravo expressly binds those persons to secrecy before they begin the relevant work. The obligation covers patient secrets and continues after the work, access or contract ends.
  • Access to patient secrets is limited to what is necessary for operation, security, support and the execution of documented instructions. Disclosure to a subprocessor occurs only where necessary for the service and protected by corresponding data-protection and confidentiality obligations.
  • The Controller is responsible for checking the professional-law requirements for engaging Theravo and for satisfying any applicable information, documentation or consent duties under the professional rules that apply to it.
  • Before access is granted, Theravo informs participating persons of the criminal consequences of unauthorised disclosure of protected secrets, in particular under section 203 of the German Criminal Code, and documents the undertaking and instruction. Equivalent duties are required for personnel of relevant subprocessors.

Technical and organisational measures

The applicable measures are described in the Security and TOMs page and in Theravo's internal TOM record. They include the responsibility model for the netcup root server in Nuremberg, transport encryption, access control, least privilege, tenant separation, logging, backup and restoration, incident response, deletion, vendor management and local AI isolation. Theravo may update measures where the overall level of protection is not reduced.

Subprocessors

  • The Controller grants general written authorisation for the subprocessors listed on Theravo's subprocessor page.
  • Theravo imposes data-protection obligations on each subprocessor that provide substantially the same protection as this DPA for the relevant processing.
  • Theravo remains responsible to the Controller for the subprocessor's performance of its data-protection obligations.
  • Theravo gives reasonable prior notice of an intended addition or replacement. The Controller may object within the stated notice period on reasonable data-protection grounds.
  • If the parties cannot resolve a justified objection, Theravo may offer an alternative or either party may terminate the affected service in accordance with the agreement.

General assistance

Taking account of the nature of processing and the information available, Theravo assists the Controller in demonstrating compliance with Articles 32 to 36 GDPR. Additional work outside the normal service scope may be charged at the agreed rate where the need was not caused by Theravo's breach.

Data-subject rights

Theravo forwards requests received directly from a patient concerning Controller data to the relevant practice without responding on the merits unless authorised to do so. Theravo provides available functions or reasonable assistance for access, rectification, restriction, portability and deletion. The Controller remains responsible for deciding and communicating the response.

Security assistance

Theravo provides the Controller with available information about safeguards, relevant incidents, recovery and processing locations that the Controller reasonably needs for its risk assessment and compliance obligations.

Personal-data breaches

Theravo notifies the Controller without undue delay after becoming aware of a personal-data breach affecting data processed on the Controller's behalf. The notification includes the information available to Theravo concerning the nature of the breach, affected data and persons, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases where it is not available at the same time.

DPIA and prior consultation

Theravo provides reasonable information and assistance for a data-protection impact assessment and, where required, prior consultation with a supervisory authority, insofar as the requested assistance relates to Theravo's processing and the information is available to Theravo.

Evidence and audits

  • Theravo provides information reasonably necessary to demonstrate compliance, such as the DPA, TOM summary, subprocessor list and appropriate certificates or test results where available.
  • The Controller may conduct an audit itself or through an independent auditor bound by confidentiality after reasonable notice, normally no more than once per year unless an incident, authority or material compliance concern justifies an additional audit.
  • Audits must avoid disruption and must not expose data, security information or confidential information of other customers.
  • Each party bears its own costs; extraordinary assistance may be charged unless the audit identifies a material breach by Theravo.

Unlawful instructions

Theravo immediately informs the Controller if, in Theravo's opinion, an instruction infringes the GDPR or other applicable data-protection law. Theravo may suspend the affected instruction until it is confirmed, amended or withdrawn, unless law requires otherwise.

Return and deletion after termination

At the Controller's choice and subject to the service's available export functions, Theravo returns or deletes personal data after the end of the services and deletes existing copies, unless Union or Member State law requires storage. Data remaining in protected backups is not used for ordinary processing and must be removed under the applicable, verified backup-deletion process. The Controller must request and complete any export before the applicable deletion point.

International transfers

Theravo does not transfer Controller data to a third country or international organisation unless instructed by the Controller, required by law, or necessary for an expressly documented subprocessor. Any such transfer must comply with Chapter V GDPR and be identified in the subprocessor information.

Data-protection contact

Questions and instructions under this DPA may be sent to privacy@theravo.de.

Legal Notice Privacy policy Terms for practices Information for patients Data Processing Agreement Subprocessors Security © 2026 Theravo