Privacy policy
Propela Therapy processes two very different kinds of personal data: data about practices and their staff (where we are the controller) and client/patient data inside a practice's account (where the practice is the controller and we are a processor under Art. 28 GDPR). This policy covers both.
Data we process as controller
- Account data: name, email, practice name, role, language preferences
- Billing data: subscription tier (payments are handled by Stripe)
- Usage events: feature usage and diagnostics, never clinical content
- Contact-form messages
Data we process as processor
Everything a practice stores about its clients — contact details, appointments, session recordings, transcripts, notes, treatment plans, questionnaire answers, messages, and documents. We process this data exclusively on the practice's instructions, under a Data Processing Agreement available to every customer.
Where data lives
Production data is stored in the EU (Frankfurt) with our hosting and database sub-processors. Session recordings and secure messages are encrypted at rest with keys we manage separately from the database. AI processing (transcription and note drafting) is performed by our AI sub-processors under agreements that prohibit training on your data.
Your rights
Practice owners can export or erase any client's data (or the entire practice) from the app at any time. Individuals can direct access, rectification, and erasure requests to their practice — or to us at privacy@propela.com and we will assist the practice in responding within the GDPR's timelines.
Retention
Account data is kept while the subscription is active and deleted within 30 days of account deletion. Client data is retained according to the practice's own clinical retention obligations and removed immediately when the practice erases it.
Contact
Propela · privacy@propela.com. You may also lodge a complaint with your supervisory authority (in the Netherlands: Autoriteit Persoonsgegevens).






