Security and TOMs
Public summary of the safeguards used for appointment-management data.
Provider information
- Business name
- Theravo
- Proprietor
- Egidijus Girčys
- Business address
- Mies-van-der-Rohe-Str. 6
14469 Potsdam
Germany - Place of business
- Potsdam, Germany
- Contact
- hello@theravo.de
- Legal email
- legal@theravo.de
Responsibility model
netcup secures the physical data centre, hardware and underlying network infrastructure. Theravo administers the root server and is responsible for operating-system hardening, firewall rules, patching, application and database security, tenant separation, access management, secrets, monitoring, backups and incident response.
Hosting location
Theravo's production root server is hosted by netcup GmbH in Nuremberg, Germany. Production appointment data is intended to remain on infrastructure in Germany or another location expressly documented in the subprocessor list.
Encryption in transit
Connections to Theravo are protected using current TLS configurations. Administrative and service-to-service connections are restricted and encrypted where technically applicable. Unencrypted public access to the application is not permitted.
Protection of stored data
Stored data is protected through operating-system and database permissions, restricted service accounts, secrets management and controlled administrative access. Theravo does not describe the service as end-to-end encrypted. The precise use of volume and backup encryption is documented in the internal TOM record and must correspond to the deployed configuration.
Authentication and access control
Access is limited to authenticated users and authorised service processes. Practice users may access only the functions and data assigned to their practice. Patient portal links and sessions are scoped to the relevant patient and practice. Two-factor authentication is available as an optional practice-account security feature in Security settings. Once enabled, a second factor is required during login. Administrative and infrastructure access requirements are separate.
Administrative access
Production administration is restricted to authorised persons, uses individual accounts or keys, and is separated from ordinary user access. Shared credentials are avoided. Privileged access is granted only where operationally necessary and is revoked when no longer required.
Least privilege
Application components, database users and operational accounts receive only the permissions required for their task. Access to patient data for support or maintenance is exceptional, purpose-bound and limited in time.
Updates and vulnerability management
Theravo maintains the operating system, runtime, application dependencies and containers. Security updates are assessed and applied according to risk. Exposed services and firewall rules are reviewed and unnecessary services are disabled.
Security and audit logs
Security-relevant actions, authentication events and administrative changes are logged to support accountability and incident investigation. Logs are protected against unauthorised access and retained only for a documented period appropriate to their purpose. Theravo uses Sentry for error diagnostics and technical monitoring. Sentry receives the following data: Limited technical personal data, in particular IP addresses and technical error and stack-trace information. Patient names and patient email addresses as application fields, patient request content, messages, appointment content, clinical information, patient-entered health information, patient notes and other patient-content fields are not transmitted to Sentry for error-monitoring purposes.
Backups
Theravo creates daily backups of the data required to operate the service. The backups are intended to support restoration of the service following data loss or technical incidents. Where an external service provider processes personal data on Theravo's behalf for backup purposes, that provider is listed according to its role in the subprocessor information.
Restoration testing
Restoration from a backup has been successfully tested. Restoration procedures are documented and reviewed as part of technical operations.
Incident response
Theravo maintains procedures for detecting, assessing, containing and documenting security incidents. Where Theravo processes data for a practice, the practice is informed without undue delay of a personal-data breach affecting its data so that it can meet its legal obligations.
Support access
Support personnel do not access patient content by default. Access is permitted only where necessary to resolve a documented issue, on the practice's instruction or another valid basis, and is limited to the minimum scope and duration.
Secrets and credentials
Passwords, API credentials and encryption keys are not stored in source code or user-visible logs. Secrets are held in access-restricted configuration and are rotated or revoked when compromise is suspected or access changes.
Separation between practices
Practice data is logically separated by tenant identifiers and application-level authorisation. Queries and background jobs must enforce tenant boundaries. Cross-practice access is not permitted.
Appointment email and data minimisation
Theravo uses dedicated appointment addresses under its control and does not require access to a practice's private mailbox. Email content is processed only to support appointment administration. Patients are asked not to include diagnoses or detailed health information that is unnecessary for arranging an appointment.
Local AI processing
Theravo may use the Gemma 3 language model operated locally on the Theravo-managed root server for the technical classification of incoming messages or appointment requests. Classification is used solely to support organisational workflows. The AI system does not make medical diagnoses, treatment decisions, or decisions about accepting, rejecting or prioritising patients. It does not generate responses to patients or send messages. Message content is not transmitted to Google or another external AI API for this processing and is not used to train a general-purpose model. The function is not used for clinical assessment, treatment recommendations, risk assessment or emergency detection.
Deletion and retention
Application deletion follows documented instructions, verified technical rules and applicable obligations. Expired, rejected and unconfirmed appointment requests are not treated as treatment documentation by default. Existing backup copies are overwritten or deleted in accordance with the applicable backup and deletion cycles unless statutory retention obligations require otherwise. Deleting an active record does not immediately remove it from all backup copies.
Vendor management
Theravo concludes the required data-processing terms with subprocessors, reviews their role and processing location, and maintains the current subprocessor list. Providers are not granted access beyond the service they supply.
Evidence and review of safeguards
This page is a public summary. Theravo maintains an internal TOM register recording the control owner, technical implementation, review interval, evidence and documented deviations. Only controls that are actually implemented may be described as active. Detailed evidence is made available to practices under the Data Processing Agreement and appropriate confidentiality.
No advertising profiling
Patient and appointment data is not sold and is not used for behavioural advertising or advertising profiles. Any public-website analytics must be separately documented and configured in accordance with applicable consent requirements.
Security contact
Security and privacy reports may be sent to privacy@theravo.de.