Learn how PR-TOP protects your clients' most sensitive data with industry-leading security measures.
PR-TOP is deployed exclusively within the European Union. All client data — diary entries, session notes, transcripts, and AI summaries — is stored and processed in EU data centers, ensuring full GDPR data residency compliance.
No client data is transferred to servers outside the European Union.
Therapists have full control over who can access their clients' data. Access requires therapist authentication and explicit client consent — both checks run on every request.
You can revoke your API token, remove a client connection, and request complete data deletion at any time. The therapist — not the platform — decides who sees what.
PR-TOP never sells, shares, or provides client data to third parties. AI processing (transcription, summarization) uses API calls where only the minimum necessary data is sent, and no data is retained by AI providers after processing.
We do not use client data for model training, advertising, or any purpose beyond providing the requested PR-TOP features.
Clients own their data. They can export their diary entries and exercise responses at any time, and they can request complete data deletion. Therapists maintain ownership of their own notes and session recordings.
PR-TOP acts as a data processor, not a data controller — the therapist and client remain the decision-makers about how their data is used.