Privacy Notice
How Therasize collects, uses and protects your personal data, the legal bases we rely on, and the rights you have.
Version 2.1 · Last updated 30 July 2026
This Privacy Notice describes our policies and procedures on the collection, use and disclosure of personal data, and informs you about your privacy rights and how the law protects your rights and freedoms. It covers your use of our app and any communication with us, including data you provide when you sign up and use our services.
Who we are and how to contact us
Therasize Limited is a company registered in England and Wales (no. 14110293), registered office Soho Works, 180 Strand, London, United Kingdom, WC2R 1EA.
If you would like to contact us about anything in this Privacy Notice, if you have questions about how we use your information, or if you would like to exercise any of your data subject rights, please contact us at contact@therasize.com.
The types of personal data we collect
Personal data means any information about an individual from which that person can be identified. We may collect, use, store and transfer different kinds of personal data about you, grouped as follows:
- Identity Data
- For practitioners: first name, last name, email address, a system-generated account identifier, and role or organisation membership. For clients: an email address and a system-generated account identifier only. We do not collect clients’ names, and we do not collect date of birth, gender, title or marital status for any user.
- Contact Data
- Email address, and, where a user chooses to set it up, a telephone number used for multi-factor authentication. We do not collect postal, billing or delivery addresses; payment details are handled by our payment provider, and the service does not involve physical deliveries.
- Transaction Data
- Details about payments to and from you, and other details of products and services you have purchased from us.
- Technical Data
- Internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website.
- Profile Data
- Your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
- Usage Data
- Information about how you interact with and use our website, products and services.
- Marketing and Communications Data
- Your preferences in receiving marketing from us and our third parties, and your communication preferences.
- Health Data
- Any data about your health that you share with us when you express interest in, sign up for, or use our services.
We also collect, use and share anonymised aggregated data such as statistical or demographic data, which is not personal data as it does not directly or indirectly reveal your identity. For example, we may use this anonymised data to help build evidence to justify formal clinical trials and feasibility studies in a clinical setting, for internal research and product development (including product development involving machine learning and large-scale data analysis), or for future publications.
1. How is your personal data collected?
Your interactions with us
You may give us your personal data when you use the Therasize web app or contact us. This includes personal data, and special category health-related data, that you provide when you:
- create an account to use the Therasize web app, as a practitioner or as a client;
- sign in and use the web app, for example completing worksheets and assessments, messaging your therapist, uploading files, and managing sessions;
- are invited or connected by your therapist or organisation to access the service;
- subscribe to our newsletter or ask us to send you marketing;
- opt in to be contacted about a research project, where this is offered; or
- give us feedback or contact us by email or otherwise.
Automated technologies or interactions
As you use the app, we automatically collect certain Technical Data about your device, browser and how you use the service. On the web app we use only essential cookies and similar technologies needed for authentication and security; we do not use tracking or advertising cookies. Our marketing website uses privacy-focused, cookie-less analytics. See our Cookies Policy.
Third parties
- Your therapist, or the organisation providing your care, who may invite or connect you to the service;
- our payment provider (Stripe), which confirms subscription and payment information for paying customers;
- calendar providers (Google or Microsoft), where a practitioner chooses to connect their calendar for scheduling.
2. How we use your personal data
2.1 Legal basis
The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following:
- Performance of a contract
- Where we need to perform the contract we are about to enter into, or have entered into, with you.
- Legitimate interests
- Where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and to give you a secure customer experience. We consider and balance any potential impact on you and your rights before we process your personal data on this basis, and we do not rely on it where our interests are overridden by the impact on you.
- Legal obligation
- Where it is necessary for compliance with a legal obligation we are subject to. We will identify the relevant obligation when we rely on this basis.
- Consent
- Only where we have obtained your active agreement to use your personal data for a specified purpose.
2.2 Purposes for which we will use your personal data
| Purpose / use | Type of data | Legal basis |
|---|---|---|
| To register you as a new user | Identity, Contact | Performance of a contract with you |
| To take and identify payments and any refunds, and to record what you have purchased | Transaction | Performance of a contract with you |
| To provide and deliver the service to you, including recording your worksheets, assessments, symptoms and progress, and providing relevant educational and supportive materials | Identity, Contact, Profile, Health | Where your care is provided through a practitioner or organisation, that practitioner or organisation is the controller and determines the lawful basis and the special category (Article 9) condition for your health-related data; Therasize processes it on their documented instruction as a processor. Where you use Therasize directly without a practitioner, we rely on the performance of our contract with you and your explicit consent for the processing of health-related data. |
| To manage our relationship with you, including notifying you about changes to our terms or this Privacy Notice, and dealing with your requests, complaints and queries | Identity, Contact, Profile, Marketing and Communications | Performance of a contract with you; compliance with a legal obligation; our legitimate interests (keeping our records updated and managing our relationship with you) |
| To enable you to take part in a survey or research project, where you choose to | Identity, Contact, Profile, Usage | Our legitimate interests (understanding how the service is used and improving it); consent, and, where any health-related data is involved, your explicit consent |
| To administer and protect our business and this web app, including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data | Identity, Contact, Technical | Our legitimate interests (running our business, providing IT services, network security, preventing fraud, and in the context of a business reorganisation); compliance with a legal obligation |
| To use analytics to improve our website and service and to understand how they are used | Technical, Usage | Our legitimate interests (keeping our website and service relevant and developing our business). Our website analytics is cookie-less. |
| To send you marketing communications where you have asked us to | Identity, Contact, Usage, Profile, Marketing and Communications | Consent, having obtained your prior consent to receiving direct marketing communications |
2.2.1 Therasize as a data processor
Therasize acts as a data processor when it processes care content on behalf of the practitioners and organisations that use the platform to deliver a service — such as a private therapy practice, clinic, charity, employer or NHS service. We process this data only on the controller’s documented instructions, and the controller determines the lawful basis.
Depending on the organisation, a controller commonly relies on Article 6(1)(b) (contract), 6(1)(e) (public task, for public bodies) or 6(1)(f) (legitimate interests), and for health data Article 9(2)(h) (provision of health or social care) or 9(2)(a) (explicit consent).
Because we are the processor for this data, it is the controller, not Therasize, who is responsible for matters such as the national data opt-out and, in the first instance, your rights in relation to that data. You can read more about the national data opt-out at nhs.uk/your-nhs-data-matters.
2.3 Direct marketing
We may contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You can opt out of any or all of these communications by following the unsubscribe link in any email we send, or by contacting us at contact@therasize.com.
2.4 Third-party marketing
We will get your express consent before we share your personal data with any third party for their own direct marketing purposes.
2.5 Opting out of marketing
You can ask us to stop sending you marketing communications at any time. If you opt out, you will still receive service-related communications that are essential for administrative or customer service purposes.
2.6 Cookies
For more information about the cookies we use and how to change your cookie preferences, please see our Cookies Policy.
3. Disclosures of your personal data
We may share your personal data where necessary with external third parties who provide services to us, such as cloud service providers and technology services, or clinical research organisations. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We have Data Processing Agreements in place with these providers, we do not allow them to use your personal data for their own purposes, and we only permit them to process it for specified purposes and in accordance with our instructions.
3.1 Business transactions
If we are involved in a merger, acquisition or asset sale, your personal data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different privacy notice.
3.2 Law enforcement
Under certain circumstances we may be required to disclose your personal data if required to do so by law, or in response to valid requests by public authorities such as a court or a government agency.
3.3 Other legal requirements
We may disclose your personal data in the good faith belief that such action is necessary to:
- comply with a legal obligation;
- protect and defend our rights or property;
- prevent or investigate possible wrongdoing in connection with the service;
- protect the personal safety of users of the service or the public; or
- protect against legal liability.
4. International transfers
We may transfer your personal data to service providers that carry out certain functions on our behalf. This may involve transferring personal data outside the UK or EEA to countries whose laws do not provide the same level of data protection as UK or EU law.
Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection by making sure one of the following safeguards is in place:
- we only transfer your personal data to countries deemed by the UK or the EU to provide an adequate level of protection; or
- we use specific standard contractual terms approved for use in the UK and/or EEA, or another transfer mechanism approved by the relevant regulator, which give the transferred personal data the same protection as it has in the UK or EEA.
To obtain a copy of these contractual safeguards, please contact us at contact@therasize.com.
5. Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We also limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
6. Data retention
6.1 How long will you use my personal data for?
Your information is securely stored. Therasize Limited will retain your personal data only for as long as is necessary for the purposes set out in this Privacy Notice.
We will retain and use your personal data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies. We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except where it is used to strengthen the security or improve the functionality of our service, or where we are legally obliged to retain it for longer.
To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes by other means, and the applicable legal, regulatory, tax and accounting requirements.
In some circumstances we will anonymise your personal data, so that it can no longer be associated with you, for research or statistical purposes. We may use that anonymised information indefinitely without further notice to you.
6.2 When a connection with your practitioner ends
Either you or your practitioner can end your connection at any time. When that happens, their access to your worksheets, assessments, uploaded documents and other shared content stops immediately.
This is because your practitioner, not Therasize, is the controller of your clinical record. Practitioners are required by their professional body and by law to keep clinical records for a number of years, and ending your connection with them does not remove that duty. Once they have downloaded that copy it is held by them, under their own retention rules, and you should contact them directly about it.
Notes your practitioner writes about your sessions, and their case formulation, are their own professional record throughout. They are not included in the copy you can download yourself.
You can download your own copy of your record at any time from your profile, whether or not you are connected to a practitioner.
7. Protecting your sensitive data
We follow the information security values of confidentiality (keeping your information private), integrity (ensuring the completeness, consistency and accuracy of data over its lifecycle) and availability (ensuring the right information is available to the right person at the right time).
7.1 People
- Training. Everyone who works with personal data completes data protection and security awareness training when they join, keeps it current, and understands their responsibilities for keeping data secure.
- Minimised access. Access to personal data, including health-related data, is strictly limited and granted on a need-to-know basis. It is scoped to the relationship between a practitioner and the specific people they support, and enforced on our servers. Our own team does not routinely access client health content, and does so only where strictly necessary to operate or support the service, under confidentiality obligations.
- Security support. We are supported by an external assurance partner on our information governance, are appointing an independent Data Protection Officer, and are working towards Cyber Essentials.
7.2 Cyber resiliency, business continuity and disaster recovery
- We run on secure, managed infrastructure from Google Cloud and Vercel, which is kept patched and up to date by the providers.
- The web application itself stores no personal data. Data is held in our Firebase (Cloud Firestore) database, encrypted at rest with AES-256 and in transit with TLS, and access is controlled by authenticated, server-side security rules. Code is type-checked and reviewed before release.
- For resilience, data is held across multiple availability zones and regions within the UK and EU, and the database has point-in-time recovery (a 7-day window) and weekly scheduled backups retained for 98 days.
- We are establishing annual independent security testing, including a penetration test, to provide ongoing assurance.
7.3 Technology
We follow Secure by Design principles, including:
- an architecture built on established, industry-standard managed cloud platforms (Google Cloud / Firebase and Vercel);
- role- and relationship-based access controls, enforced on the server rather than only in the application;
- server-side authentication and authorisation on all authenticated interfaces, so access to data is restricted to authorised users and limited to what each role needs;
- authentication handled by Firebase Authentication, which securely salts and hashes credentials using industry-standard algorithms — we never store raw passwords. A minimum password length of 12 characters is enforced, multi-factor authentication is available, and a hardware security key is required for administrative access;
- encryption in transit using TLS across all connections between users, applications and our cloud services, and at rest using AES-256 provided by the underlying cloud platforms;
- all production data held within the UK and EU (Cloud Firestore EU multi-region, Cloud Storage EU multi-region, Cloud Functions europe-west1, and web functions in London, Dublin and Stockholm);
- secrets managed through the platform’s secret store, separated by environment, with keys not held in code;
- regular dependency and package audits, with findings remediated or formally risk-accepted;
- logical separation of production and development environments, including isolated databases; and
- code review, type-checked code before release, and validation of security rules.
We are further strengthening this with formal static and dynamic application security testing and an independent penetration test, which are planned rather than yet in place.
8. Your legal rights
You have a number of rights under data protection laws in relation to your personal data. You have the right to:
- Request access to your personal data (commonly known as a subject access request). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- Request correction of the personal data we hold about you. This enables you to have incomplete or inaccurate data corrected, though we may need to verify the accuracy of the new data you provide.
- Request erasure of your personal data in certain circumstances, where there is no good reason for us continuing to process it, where you have successfully objected to processing, where we may have processed your information unlawfully, or where we are required to erase it to comply with local law. We may not always be able to comply for specific legal reasons, which will be notified to you at the time of your request. One such reason applies whenever you have worked with a practitioner through Therasize: they retain their own clinical record of your care, and for 30 days after a connection ends they can still download the record as it stood on that day. See section 6.2.
- Object to processing where we are relying on a legitimate interest (or those of a third party). In some cases we may demonstrate compelling legitimate grounds that override your right to object. You also have an absolute right to object at any time to processing for direct marketing purposes.
- Request the transfer of your personal data to you or to a third party, in a structured, commonly used, machine-readable format. You can exercise this yourself at any time from your profile. The download is a single archive containing your record as structured JSON and as spreadsheet files, a readable copy you can open in any browser or print, and the original documents on your record. This right only applies to automated information which you initially provided consent for us to use, or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are relying on consent. This will not affect the lawfulness of any processing carried out before you withdraw. If you withdraw your consent, we may not be able to provide certain products or services, and we will tell you if that is the case at the time.
- Request restriction of processing where you want us to establish the data’s accuracy; where our use is unlawful but you do not want it erased; where you need us to hold it to establish, exercise or defend legal claims; or where you have objected and we need to verify whether we have overriding legitimate grounds.
If you wish to exercise any of the rights set out above, please contact us at contact@therasize.com.
8.1 No fee usually required
You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive — or we could refuse to comply with your request in those circumstances.
8.2 What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data, or to exercise any of your other rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you for further information to speed up our response.
8.3 Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it could take longer if your request is particularly complex or you have made a number of requests. In that case we will notify you and keep you updated.
9. Contact details
If you have any questions about this Privacy Notice or about the use of your personal data, or you want to exercise your privacy rights, please contact us at contact@therasize.com.
10. Complaints
You have the right to make a complaint to us if you believe that our processing of your personal data infringes any part of the UK GDPR. You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues, at ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
11. Changes to this Privacy Notice
We keep our Privacy Notice under regular review. The version number and date at the top of this page show when it was last updated.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
12. Third-party links
This website may include links to third-party websites, plug-ins and applications. Clicking those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
13. Payments
We may provide paid products or services within the service. In that case we use third-party payment processors. We will not store or collect your payment card details — that information is provided directly to our third-party payment processors, whose use of your personal information is governed by their own privacy notice.
14. National Data Opt-Out (UK)
The national data opt-out is an NHS policy that applies to health and adult social care organisations in England when they use confidential patient information for research and planning purposes beyond an individual’s direct care.
Therasize Limited is a private technology provider, and where it processes health-related data it does so as a processor to support the direct care delivered by practitioners and organisations. We do not use or share personal data for the research or planning purposes to which the national data opt-out applies, and we review our processing at least annually to confirm this remains the case.
Where Therasize is deployed within an NHS setting, the NHS organisation, as the controller, is responsible for applying the national data opt-out. You can find out more at nhs.uk/your-nhs-data-matters.
15. Children’s privacy
Our service is intended for use by adults, and we do not market the service to children. You must be 18 or over to create your own account directly with us.
Some practitioners and organisations that use Therasize provide therapy to children and young people. Where that is the case, the practitioner or organisation is the data controller and is responsible for the lawful basis for using the platform with a young person, for obtaining any necessary consent from a parent or guardian, for considering the young person’s capacity, and for their safeguarding obligations. Therasize processes that information on the controller’s instructions as a processor. Because we identify clients by email address only and do not collect names or dates of birth, we do not generally hold information that reveals a client’s age.
If you are a parent or guardian and believe your child has provided personal data to us directly, rather than through a practitioner, please contact us and we will take steps to delete it.