Privacy Policy
Effective 7 June 2026 · Last reviewed 7 September 2026
Who we are
TheraFlow is operated by Taksh Innovation Lab LLP ("TheraFlow", "we", "us"), a limited liability partnership registered in Bangalore, India. We provide practice management software to therapy centres.
For most personal data we handle, the therapy centre that uses TheraFlow is the data fiduciary (DPDP Act 2023) and TheraFlow is the data processor acting on their instructions.
What data we collect
From therapy centre staff (admins, therapists, receptionists)
- Name, work email, phone number
- Role and the centre you belong to
- Authentication identifiers (Clerk-issued session tokens)
- Usage logs, IP address, browser/device information for security and debugging
From patients and their guardians (entered by the centre)
- Names, dates of birth, contact details, addresses
- Diagnosis, therapy goals, session notes, attendance records
- Optional: medical history, Aadhaar / ABHA ID, photos, intake documents — only when the centre chooses to enter them
- Billing and payment records (invoices, package balances)
From website visitors
- Page views, referrer, basic device info via standard analytics
- Anything you submit through contact or sign-up forms
WhatsApp and Meta Platform Data
A centre can connect its own WhatsApp Business Account to TheraFlow so that appointment confirmations, reminders, receipts and package alerts go out from the centre's own number. TheraFlow is a Meta Tech Provider and uses the official WhatsApp Business Platform (Cloud API) for this. See theraflow.in/whatsapp for how it works.
What we receive from Meta
When a centre connects its WhatsApp Business Account, TheraFlow receives from Meta:
- The WhatsApp Business Account ID
- The business phone number ID
- The business portfolio ID
- Message template metadata (template names, categories and approval status)
- Message delivery status (sent, delivered, read, failed)
If your centre keeps the WhatsApp Business app on the same number, Meta also sends TheraFlow copies of the messages your staff send from that app, your contact-list changes and, only if you opt in inside the app, past chats, so that the app and the API stay in step. TheraFlow acknowledges these and does not store them, and never requests past chats.
What we use it for
Solely to send transactional messages on that centre's behalf and to show delivery status inside TheraFlow. We send utility messages only — confirmations, reminders, cancellations, receipts and balance alerts. We do not send marketing or promotional messages on a centre's behalf.
What we never do with it
- We do not sell this data
- We do not share it with third parties
- We do not combine it across centres — each centre's connection is isolated
- We do not use it for advertising or for training AI models
Access tokens
The access token Meta issues for a centre's connection is stored encrypted and is deleted when the centre disconnects WhatsApp from TheraFlow settings.
How long we keep it
Platform Data is retained only while the centre's WhatsApp connection is active, plus the backup-retention window described under "How long we keep it" below.
Requesting deletion
Disconnecting WhatsApp from TheraFlow settings deletes the access token immediately. To have the remaining Platform Data removed ahead of the normal retention window, write to founders@theraflow.in — the same route as any other deletion request under "How long we keep it".
Why we collect it
- To operate and provide the TheraFlow service
- To authenticate users and prevent abuse
- To respond to support requests
- To send service-related communications (billing, security, product updates you have opted into)
- To improve TheraFlow (in aggregate, never by inspecting individual patient records)
- To meet legal and regulatory obligations
How long we keep it
While your centre is an active TheraFlow customer, we retain your data as long as is needed to provide the service. On cancellation, you have 60 days to export everything you need. After that, your tenant is irreversibly deleted from primary storage and removed from backups within a further 60 days.
Centres can request earlier deletion of any individual patient record from inside the app or by writing to founders@theraflow.in.
Who else processes it
We use a small set of sub-processors to operate the service — cloud hosting, authentication, payments, AI features. The full current list is at theraflow.in/sub-processors. We notify customers before adding any new sub-processor that touches patient data.
We never sell personal data. We never share it for advertising. AI providers we use (Anthropic, Google) do not train on our API calls.
How we protect it
Encryption at rest (AES-256) and in transit (TLS 1.3); per-tenant data isolation; role-based access control with MFA available on every account; audit log of every data access; rate limiting and account lockout on the login flow. Full detail at theraflow.in/security.
If we ever discover a security incident affecting your data, we notify the affected centre and India's Data Protection Board within 72 hours, with the facts as we know them.
Your rights under DPDP Act 2023
Where TheraFlow is the data fiduciary for your data (for example, data you provide directly to us — not through your therapy centre), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request erasure of data we no longer need
- Withdraw consent for processing where we relied on it
- Nominate another individual to exercise these rights if you cannot
- Raise a grievance with our Grievance Officer (see contact below)
Where the data was entered into TheraFlow by a therapy centre, please contact the centre first — they are the data fiduciary. We will assist them with any request.
Children's data
Most patients in TheraFlow are children. Centres collect this data with the consent of a parent or guardian. We do not process children's data for advertising, profiling, or any purpose other than running the centre's clinical operations, as the law requires.
Cookies and tracking
The TheraFlow website uses minimal first-party cookies for authentication and basic analytics. We do not use third-party advertising cookies.
Changes to this policy
We will update this page if our practices change. Material changes will be notified by email to centre admins at least 30 days before they take effect.
Contact us
Data Protection contact / Grievance Officer: founders@theraflow.in
Mailing address: Taksh Innovation Lab LLP, Bangalore, India.
This policy is intended to be plain English and may be updated to reflect feedback from customers and counsel.