Security and Data

How My-Therapy-Suite handles your data.

This page is the practical companion to our Privacy Policy and Data Processing Agreement. Those documents are the legal source of truth; this page covers how the platform actually handles your data.

Last updated 11 May 2026. We update this page within 14 days of any material change (new sub-processor, change of hosting region, change to encryption or key management).

Where your data lives

My-Therapy-Suite is hosted in the United Kingdom. The application and the database run on Microsoft Azure in the UK. Session recordings and file uploads are stored on Google Cloud Platform, also in the UK.

This means your client records, notes, and recordings are physically held on servers located in the UK, and the legal regime that applies to them is UK data protection law (UK GDPR and the Data Protection Act 2018), enforced by the Information Commissioner's Office (ICO).

Some of our sub-processors are headquartered outside the UK (for example, Anthropic in the United States). Where personal information is transferred internationally, transfers are governed by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Full details are in our Data Processing Agreement.

How it's encrypted

Your data is encrypted in three different places, with three different keys. That way, a problem with any one of them does not expose the others.

While it travels between your device and the platform

Every connection to and from My-Therapy-Suite is encrypted using TLS, the standard protocol for protecting information sent across the internet. Anyone intercepting traffic on the network sees ciphertext, not the contents of your records.

Once it reaches our database

Sensitive information (client names, contact details, clinical notes, session content) is encrypted by the platform before it is written to the database. Even with direct access to the database, the records would be unreadable without a separate key. That key is stored in a Microsoft-managed key vault, not in the database itself.

Underneath, by Microsoft and Google

On top of our own encryption, Microsoft applies a further layer of encryption to the entire database on disk, using keys managed by Microsoft. Files stored on Google Cloud (such as session recordings) are encrypted in the same way by Google. These layers protect against physical theft of the underlying storage hardware.

Keys and where they live

The encryption key, database credentials, and the API keys we use for third-party services are all stored in a separate Microsoft-managed key vault. They are not written into our source code, our log files, or the machines that run the application.

Microsoft keeps its own independent record of every key access. That record is held outside our environment, so it remains intact even if our own logs are compromised.

Who at My-Therapy-Suite can see your data

Most sensitive information (names, contact details, clinical notes, session content) is encrypted before it reaches the database. Reading it requires the separate key held in the Microsoft-managed key vault.

In normal day-to-day operation, no one at My-Therapy-Suite reads your data. The application uses the key automatically as you, your colleagues, or your clients use the platform. No person is involved in that loop.

Access to the key itself is restricted to a small, identified subset of the technical team. Members of the team working in sales, support, or operations do not have access to the key and therefore cannot read encrypted client content, regardless of their database access.

The only situations where a person on our team would actively use the key to read a specific record are:

  • A legally binding order (for example, a court order or a regulator request).
  • An incident investigation where the only way to identify the cause is to inspect a specific record, and where the affected practice has authorised this in writing.

Each of these is logged by us, and Microsoft independently logs every use of the key in its vault.

What we never do

  • We do not read client records for product analytics, marketing, or product improvement.
  • We do not sell or share data with advertising networks.
  • We do not use your data to train AI models, and our AI providers are contractually prohibited from doing so (see the AI section below).
  • We do not make automated clinical decisions on your behalf.

Sub-processors

We use third-party service providers ("sub-processors") to deliver the platform. They process data only on our instructions, under the contractual obligations set out in our Data Processing Agreement.

ProviderPurposeRegion
Microsoft AzureCloud hosting, database, compute infrastructureUnited Kingdom
Google Cloud PlatformFile storage, including session recordingsUnited Kingdom
AnthropicAI-assisted clinical summarisation, transcription, risk analysis (primary provider)United States
OpenAIAI-assisted clinical summarisation (fallback provider, used only when Anthropic is unavailable)United States
StripePayment processingUnited Kingdom, with EU and US affiliates
CloudflareBot protection (Turnstile) and video session infrastructure (RealtimeKit)Global edge network, with UK ingress
Zoom Video CommunicationsVideo session infrastructureRegion-based routing (typically EU for UK customers)
MailgunTransactional and marketing email delivery (account notifications, appointment reminders, password resets, newsletters)United States
SentryError monitoring and application observabilityUnited States

We update this list within 14 days of any change to our sub-processors.

AI and how we use it

AI features in My-Therapy-Suite are designed so that client data is never used to train AI models, and so that you remain in control of what gets sent.

Providers

  • Anthropic is the primary provider for all AI-assisted features.
  • OpenAI is the fallback provider, used only when Anthropic is temporarily unavailable.

Both providers are accessed through enterprise API contracts. They are contractually prohibited from using the data we send them to train their models, and they are required to delete it after processing each request.

What gets sent to the AI provider

We send only what the feature needs to do its job. For features that work on session content (summarisation, draft notes), this includes the actual clinical text.

FeatureWhat is sent
AI session notesSession transcript or summary text provided by the therapist
AI template builderYour prompt and the existing template structure (no client records)
AI support chatYour support message and platform context (no client records)
Risk signal analysisThe clinical text you flag for analysis

What we do not use AI for

  • We do not run background AI analysis on your records without your action.
  • We do not feed your data into training pipelines, ours or our vendors'.
  • We do not use AI to make automated clinical decisions. AI outputs are drafts for your review; you remain the clinician.

Backups and continuity

Database

The Azure SQL database is backed up automatically with 7-day point-in-time restore. This means we can restore the database to any point in the past 7 days down to the second. Backups are managed by Azure and stored on Azure-managed storage.

File storage

Files uploaded to Google Cloud Storage (session recordings, documents, signed agreements) persist until they are explicitly deleted by the practice or removed as part of the cancellation flow. There is no automated lifecycle deletion.

Disaster recovery

Both Azure SQL and Google Cloud Storage are managed services with high availability and replication built in by the provider. In the event of a regional incident, the platform's recovery depends on Microsoft and Google's published recovery procedures for their respective UK regions.

What we log internally

For security, accountability, and incident investigation, the platform keeps an internal log of significant events. Each entry records what happened, when, and (where relevant) which account or user was involved. Examples include:

  • Logins, two-factor verifications, and failed authentication attempts.
  • Creating, updating, or deleting client records, session notes, and documents.
  • Generating, signing, or revoking client agreements.
  • Invoicing, payment events, and refunds.
  • Use of AI-assisted features, including which feature was used and on which record.
  • Exports of data.

These internal logs are not currently surfaced as a self-service report inside the platform. If you ever need a specific record extracted (for example to support a Subject Access Request your client has made, a complaint, or a regulatory request), contact us and we will produce the relevant entries.

Your rights and your clients' rights

The Privacy Policy sets out the legal detail on rights of access, rectification, erasure, restriction, and portability. The practical version:

  • Export your practice's data: available from the platform at any time, and triggered automatically when a practice cancels its account.
  • Delete a client record: available from the application. Deletion removes the record from the platform.
  • Subject Access Requests from your clients: you remain the controller for client data. We will help you produce the records on request; the response to the client is yours to issue.
  • Retention: records stay on the platform until you delete them, or until the account is cancelled. We are building support to help you apply a retention policy that fits your professional obligations; until it ships, deletion is manual.

Reporting a security issue

Report security issues, or concerns about how data is being handled, to the address below.

Security contact

Email: security@mytherapysuite.com

We aim to acknowledge security reports within one working day.

Changelog

  • 11 May 2026Page first published. Sub-processor list updated to include Mailgun, Sentry, and Cloudflare RealtimeKit.