GDPR Compliance

Learn how PR-TOP protects your clients' most sensitive data with industry-leading security measures.

Data Minimization

PR-TOP collects only the data strictly necessary for providing the PR-TOP service. We do not collect browsing habits, advertising identifiers, or any data unrelated to the therapist-client workflow.

Analytics are powered by Umami, a privacy-first, cookie-free analytics platform that collects no personal data and is fully GDPR-compliant.

Right to Erasure

Clients and therapists can request complete data deletion at any time. When a deletion request is processed, all associated data — diary entries, session recordings, transcripts, notes, and AI-generated summaries — is permanently and irreversibly removed from the database.

Encrypted backups are rotated on a schedule, ensuring that deleted data does not persist in backup storage beyond the retention window.

Consent Management

PR-TOP implements granular consent controls that give clients full authority over their data:

  • Clients can grant or revoke therapist access to their data at any time via Telegram
  • When consent is revoked, all client data becomes immediately inaccessible to the therapist — including diary entries, sessions, search, dashboard statistics, and analytics
  • Consent status is checked in real-time on every data access request, with full audit logging of consent changes

Data Processing Agreement (DPA)

For organizations and clinics: PR-TOP acts as a processor for the client data you store in the workspace. If your clinic requires a Data Processing Agreement, contact [email protected] to discuss data-processing terms for your organization.

A DPA covers data processing purposes, security measures, sub-processor agreements, breach notification procedures, and data subject rights.

EU Data Processing

PR-TOP supports deployment within the European Union to ensure that data never leaves EU jurisdictions. This satisfies the GDPR requirement for lawful data transfers.

All data is stored and processed within the European Union, ensuring compliance with GDPR data residency requirements.