Features How it works Pricing Privacy Log in Schedule a walkthrough
🇬🇧EN
🇩🇪DE 🇬🇧EN 🇵🇱PL
Theravo / Legal / Privacy Policy

Privacy Policy

How Theravo processes practice, patient, appointment and technical data.

Document version
2026-07-30.4
Effective date
2026-07-30
Last updated
2026-07-30
Language
EN

Provider information

Business name
Theravo
Proprietor
Egidijus Girčys
Business address
Mies-van-der-Rohe-Str. 6
14469 Potsdam
Germany
Controller for Theravo's own processing
Egidijus Girčys
Privacy email
privacy@theravo.de

Scope of this policy

This policy explains how Egidijus Girčys, operating under the business name Theravo, processes personal data when people visit the websites https://theravo.de, https://theravo.pl, use a Theravo account, contact Theravo, or use appointment functions provided for a psychotherapy practice.

Who is responsible for which processing?

  • Theravo is the controller for its own website operation, practice-account administration, contracts, billing, support, security, abuse prevention and legal compliance.
  • The psychotherapy practice is normally the controller for patient, prospective-patient, appointment, message and portal data processed for the practice's purposes.
  • For that practice data, Theravo acts as a processor under a Data Processing Agreement and follows the practice's documented instructions.
  • Questions about a practice's patient processing, legal basis, treatment documentation or retention should normally be addressed to that practice first.

Purposes, legal bases and retention criteria

The table distinguishes Theravo's own processing from processing performed on behalf of a practice. For practice-controlled data, the practice determines the applicable legal bases under Articles 6 and 9 GDPR. The entries describe typical purposes and do not replace the practice's own privacy information.

Data category Role Purpose Article 6 GDPR Article 9 GDPR Retention criterion Typical recipients Primary contact
Practice account, contract, contact and billing data Theravo as controller Account provision, contract administration, support, security and invoicing Art. 6(1)(b), (c) and (f), depending on the processing Special-category data is not intended Account term; afterwards statutory retention and limitation periods Theravo, netcup and an active payment provider where applicable Theravo
Website and server log data Theravo as controller Secure delivery, troubleshooting and abuse prevention Art. 6(1)(f); Art. 6(1)(c) where legally required Not intended Purpose-limited retention under verified log-rotation and legal-hold rules Theravo and netcup Theravo
Patient identity, contact, request and appointment data Practice as controller; Theravo as processor Requesting, allocating, confirming, changing and cancelling appointments Determined by the practice, commonly Art. 6(1)(b), (c) or (f) Determined by the practice; where health data is involved, Art. 9(2)(h) or another valid condition may apply Practice instruction, processing purpose, applicable obligations and verified deletion rules; no blanket ten-year period The practice, Theravo and active subprocessors required for the feature The relevant practice
Appointment-related messages and email content Practice as controller; Theravo as processor Administrative communication about appointment requests and changes Determined by the practice May apply if the sender includes health information; determined by the practice Practice instruction, processing purpose and verified message-content deletion rules The practice, Theravo and any active email-transport provider The relevant practice
Patient portal profile, authentication and appointment data Practice as controller; Theravo as processor Secure self-service access to appointments Determined by the practice May apply because the portal relates to psychotherapy appointments Until account deletion or the configured inactive-portal-profile period and the practice’s documented instruction The practice, Theravo and netcup The relevant practice
Administrative message content and generated classification or draft Practice as controller; Theravo as processor Local classification and drafting for appointment administration Same basis as the underlying appointment processing, determined by the practice Same condition as the underlying message where it contains health data No separate training dataset; source content and drafts follow the underlying message-retention criteria and the practice’s instruction Theravo and the relevant practice; no external AI API recipient The relevant practice
Payment status, amount, transaction and billing references Practice and provider roles depend on the payment step Payment processing, reconciliation, fraud prevention and accounting Art. 6(1)(b), (c) and (f), depending on the responsible party Health data is not required for payment Configured period for unsuccessful payments; applicable statutory periods also apply to payment and invoice records Practice, Theravo and the selected payment provider Practice, Theravo or payment provider according to the processing concerned
Authentication, audit and security events Theravo as controller or processor according to the event Security, accountability, support and incident investigation Art. 6(1)(c) and (f), or the practice's underlying basis Not intended; event metadata may refer to an appointment identifier Purpose-limited retention under verified audit-log deletion and legal-hold rules Theravo, the practice where relevant, and netcup Theravo or the relevant practice according to the event

Public website and server logs

When the public website is accessed, the server processes information required to deliver and secure the service, which may include IP address, date and time, requested resource, referrer, user agent and technical error information. Theravo uses this data for secure delivery, troubleshooting and protection against misuse on the basis of legitimate interests, unless another legal basis applies.

Cookies and sessions

Theravo uses cookies or comparable storage that is necessary for authentication, language selection, security and session continuity. Non-essential analytics or marketing technologies are used only where they are separately disclosed and a required consent has been obtained.

Categories of data

  • Practice and user data: name, professional contact details, practice details, account settings, authentication data, subscription and support information.
  • Patient and appointment data: name, contact details, requested or confirmed time, appointment type, location or video-session information, status, cancellations, rescheduling and appointment credit.
  • Communications: administrative messages exchanged for appointment organisation and support.
  • Technical and security data: IP addresses, identifiers, timestamps, authentication events, audit events and diagnostic information.
  • Payment references: payment status, transaction identifiers and limited billing information when an optional payment function is used.

Patient booking and appointment data

A practice determines which information is required to request, confirm, change or cancel an appointment. Theravo processes that information on the practice's behalf to operate the requested workflow. An appointment with a psychotherapist can itself reveal health-related information, even where no diagnosis or therapy note is collected.

Minimisation of health information

Theravo is designed for appointment management and is not an electronic health record. Patients should not enter diagnoses, detailed symptoms, medication information, therapy notes or other health information that is unnecessary for arranging an appointment. Practices should configure forms and free-text fields to collect only what is necessary.

Appointment messages and email

Theravo provides dedicated appointment addresses under its control. Incoming and outgoing messages are assigned to the relevant practice and processed for appointment administration. Theravo does not require access to a practice's private mailbox. Message content may contain special-category data if a sender voluntarily includes health information.

Local AI assistance

Theravo uses the Gemma 3 language model locally on the Theravo-managed root server to classify administrative appointment messages and, where enabled, prepare response drafts. Message content is not transmitted to Google or another external AI API for this purpose and is not used to train a general-purpose model. The function is not intended for diagnosis, treatment recommendations, risk assessment, emergency detection or other clinical decisions.

Transparency for AI-assisted communication

Where a person directly receives an administrative message generated or materially prepared by the local AI function without meaningful human review, Theravo or the practice provides a clear notice that automated assistance was used. The intended standard notice is: “This administrative message was prepared with automated assistance on behalf of the practice.” Practices remain responsible for configuring and supervising automated sending.

No solely automated significant decisions

Theravo does not make solely automated decisions about patients that produce legal effects or similarly significantly affect them. Classification and drafting support appointment administration only. A practice decides whether to accept a patient, offer a therapeutic service or take any clinical action.

Accounts, authentication and access

Theravo processes authentication and access data to create accounts, protect sessions, authorise users and prevent misuse. Practice administrators are responsible for assigning appropriate roles and keeping user access current. Patient portal access is limited to the relevant practice and patient context.

Optional payments

Where a practice enables online payment, payment details are processed by the payment provider identified in the checkout and subprocessor information. Theravo generally receives transaction references, amount, currency and payment status rather than full card data. The payment provider may act as a processor and, for fraud prevention, regulatory or payment-network purposes, as an independent controller.

Appointment credit

Where configured by a practice, Theravo records credit created after a cancellation, including the practice, appointment type, value or entitlement, expiry date and redemption status. The practice determines the cancellation and credit rules and is responsible for informing patients about them.

Retention and deletion

  • Theravo account, contract, billing and support data is retained for the duration of the relationship and afterwards for applicable statutory retention and limitation periods.
  • Patient and appointment data is retained according to the practice’s documented instructions, technically configured deletion rules and applicable obligations. Theravo does not treat every appointment request as treatment documentation and does not apply a blanket ten-year period to every request or message.
  • Retention is determined by the purpose of processing, the practice’s documented instructions, applicable statutory obligations and technically verified deletion rules.
  • Unconfirmed, rejected, expired and abandoned requests are not treated as treatment documentation by default. Their deletion depends on the applicable purpose, instructions, documented holds and verified technical deletion rules.
  • Security, audit and diagnostic logs are retained only as long as necessary for their purpose and applicable obligations. Records may be preserved for a documented investigation or legal hold.
  • Deleted data may remain in protected backups until it is removed through the verified backup-rotation process. It is not used for ordinary processing and must re-enter applicable deletion processes after restoration.

How data is used

Theravo uses personal data only to provide and secure the service, administer accounts and contracts, support users, process appointment workflows on behalf of practices, comply with law and establish or defend legal claims. Patient data is not sold, used for advertising profiles or used to train a general-purpose AI model.

Hosting and storage

Theravo's production service is operated on a Theravo-managed root server hosted by netcup GmbH in Nuremberg, Germany. netcup provides the data-centre and server infrastructure; Theravo manages the operating system, applications, database, access, updates, backups and monitoring. Current safeguards are described on the Security and TOMs page.

Recipients and disclosures

Data is disclosed only to authorised Theravo personnel, the relevant practice and active providers needed to operate a selected feature. The current providers are identified on the subprocessor page. Theravo may also disclose data where required by law or necessary to protect legal claims, security or the rights of affected persons.

Transfers outside the EEA

The primary production server is located in Germany. If an optional provider processes data outside the European Economic Area, Theravo identifies the transfer in the subprocessor information and uses a mechanism permitted by Chapter V GDPR, such as an adequacy decision or standard contractual clauses, together with supplementary measures where required.

Rights of data subjects

Depending on the circumstances, data subjects may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, as well as the right to complain to a supervisory authority. For patient and appointment data controlled by a practice, requests should normally be sent to that practice. Theravo assists the practice as required by the DPA. Requests concerning Theravo's own processing may be sent directly to Theravo.

Supervisory authority

For processing for which Theravo is the controller, complaints may be submitted to the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany. A complaint may also be made to another competent supervisory authority, particularly in the Member State of habitual residence, place of work or the alleged infringement.

Privacy contact

Privacy questions and requests concerning Theravo's own processing may be sent to privacy@theravo.de. For patient data, please identify the relevant practice so the request can be forwarded appropriately.

Legal Notice Privacy policy Terms for practices Information for patients Data Processing Agreement Subprocessors Security © 2026 Theravo