Security and TOMs
Public summary of the safeguards used for appointment-management data.
Provider information
- Business name
- Theravo
- Proprietor
- Egidijus Girčys
- Business address
- Mies-van-der-Rohe-Str. 6
14469 Potsdam
Germany - Place of business
- Potsdam, Germany
- Contact
- hello@theravo.de
- Legal email
- legal@theravo.de
Responsibility model
netcup secures the physical data centre, hardware and underlying network infrastructure. Theravo administers the root server and is responsible for operating-system hardening, firewall rules, patching, application and database security, tenant separation, access management, secrets, monitoring, backups and incident response.
Hosting location
Theravo's production root server is hosted by netcup GmbH in Nuremberg, Germany. Production appointment data is intended to remain on infrastructure in Germany or another location expressly documented in the subprocessor list.
Encryption in transit
Connections to Theravo are protected using current TLS configurations. Administrative and service-to-service connections are restricted and encrypted where technically applicable. Unencrypted public access to the application is not permitted.
Protection of stored data
Stored data is protected through operating-system and database permissions, restricted service accounts, secrets management and controlled administrative access. Theravo does not describe the service as end-to-end encrypted. The precise use of volume and backup encryption is documented in the internal TOM record and must correspond to the deployed configuration.
Authentication and access control
Access is limited to authenticated users and authorised service processes. Practice users may access only the functions and data assigned to their practice. Patient portal links and sessions are scoped to the relevant patient and practice.
Administrative access
Production administration is restricted to authorised persons, uses individual accounts or keys, and is separated from ordinary user access. Shared credentials are avoided. Privileged access is granted only where operationally necessary and is revoked when no longer required.
Least privilege
Application components, database users and operational accounts receive only the permissions required for their task. Access to patient data for support or maintenance is exceptional, purpose-bound and limited in time.
Updates and vulnerability management
Theravo maintains the operating system, runtime, application dependencies and containers. Security updates are assessed and applied according to risk. Exposed services and firewall rules are reviewed and unnecessary services are disabled.
Security and audit logs
Security-relevant actions, authentication events and administrative changes are logged to support accountability and incident investigation. Logs are protected against unauthorised access and retained only for a documented period appropriate to their purpose.
Backups
Theravo is responsible for backups needed to restore the service. Backup frequency, access, location, retention and rotation must be verified and documented before they are described as active controls. Any external backup location must be listed as a subprocessor where it receives personal data.
Restoration testing
Restoration tests must be planned, performed and documented with their scope, date, result and any required corrective actions before restoration testing is described as an active control.
Incident response
Theravo maintains procedures for detecting, assessing, containing and documenting security incidents. Where Theravo processes data for a practice, the practice is informed without undue delay of a personal-data breach affecting its data so that it can meet its legal obligations.
Support access
Support personnel do not access patient content by default. Access is permitted only where necessary to resolve a documented issue, on the practice's instruction or another valid basis, and is limited to the minimum scope and duration.
Secrets and credentials
Passwords, API credentials and encryption keys are not stored in source code or user-visible logs. Secrets are held in access-restricted configuration and are rotated or revoked when compromise is suspected or access changes.
Separation between practices
Practice data is logically separated by tenant identifiers and application-level authorisation. Queries and background jobs must enforce tenant boundaries. Cross-practice access is not permitted.
Appointment email and data minimisation
Theravo uses dedicated appointment addresses under its control and does not require access to a practice's private mailbox. Email content is processed only to support appointment administration. Patients are asked not to include diagnoses or detailed health information that is unnecessary for arranging an appointment.
Local AI processing
The Gemma 3 language model is operated locally on the Theravo-managed root server. Message content is not sent to Google or another external AI API for this processing and is not used to train a general-purpose model. The function is limited to administrative classification and drafting and is not used for diagnosis, treatment, risk assessment, emergency detection or clinical decisions.
Deletion and retention
Application deletion follows documented instructions, verified technical rules and applicable obligations. Expired, rejected and unconfirmed appointment requests are not treated as treatment documentation by default. Backup deletion is described only after the deployed rotation process has been verified.
Vendor management
Theravo concludes the required data-processing terms with subprocessors, reviews their role and processing location, and maintains the current subprocessor list. Providers are not granted access beyond the service they supply.
Evidence and review of safeguards
This page is a public summary. Theravo maintains an internal TOM register recording the control owner, technical implementation, review interval, evidence and documented deviations. Only controls that are actually implemented may be described as active. Detailed evidence is made available to practices under the Data Processing Agreement and appropriate confidentiality.
No advertising profiling
Patient and appointment data is not sold and is not used for behavioural advertising or advertising profiles. Any public-website analytics must be separately documented and configured in accordance with applicable consent requirements.
Security contact
Security and privacy reports may be sent to privacy@theravo.de.