Privacy policy

Last Updated: July 24, 2025

Your privacy is of the utmost importance to us. This Privacy Policy outlines our practices regarding the collection, use, and protection of your information. This policy is incorporated into our Terms and Conditions.

1. Information We Collect

We collect information to provide and improve our Services.

  • Personal and Account Information: When you register, we collect information such as your name, email address, date of birth, and phone number.
  • Health and Session Information: To match you with a Therapist, we may collect information through intake questionnaires. This information is considered Protected Health Information (PHI). Details discussed within your therapy sessions are confidential between you and your Therapist, subject to the limits described in Section 3.
  • Emergency Contact Information: We collect the name and phone number of an emergency contact, whom you authorize us to contact in a crisis situation.
  • Payment Information: Payment details are collected and processed by our secure third-party payment processors. We do not store your full credit card information on our servers.
  • Technical and Usage Data: We automatically collect data like your IP address, device type, browser information, and interaction with our Platform through cookies and similar technologies to ensure functionality and improve our service.
  • Communications Data: We collect information when you contact our support team or provide feedback.

2. How We Use Your Information

  • To Provide and Manage Services: To create your account, match you with a Therapist, schedule sessions, and process payments.
  • To Communicate With You: To send administrative information, appointment reminders, and service updates.
  • For Safety and Security: In a crisis, your Therapist may use your Emergency Contact Information or contact relevant authorities to ensure your safety or the safety of others.
  • To Improve Our Platform: We use anonymized and aggregated data for analytics, research, and to enhance the user experience. We will never use your identifiable personal health information for marketing.
  • To Comply with Legal Obligations: To respond to court orders, legal processes, and to comply with applicable Lebanese laws and professional regulations.

3. Confidentiality and Information Disclosure

We are committed to maintaining the confidentiality of your information. We will not disclose your personal information except in the following limited circumstances:

  • With Your Therapist: We share your intake and contact information with your assigned Therapist to facilitate your care.
  • For Safety Emergencies: We are legally and ethically obligated to breach confidentiality in specific situations, including:
    • If there is a serious risk of harm to yourself or to another person.
    • In cases of suspected child or vulnerable adult abuse or neglect.
    • When required by a court order.
  • With Service Providers: We share information with third-party vendors (e.g., hosting providers, software developers) who are bound by strict confidentiality agreements to help us operate the Platform.
  • Platform Oversight: To ensure quality of care and safety, authorized Clinical Oversight Personnel may need to review de-identified session data or, in rare cases (such as a formal complaint or safety concern), specific session transcripts. This access is strictly controlled and limited.
  • With Your Explicit Consent: For any other purpose, we will only share your information after obtaining your explicit consent.

4. Data Security

We implement robust administrative, physical, and technical safeguards to protect your information. This includes data encryption, firewalls, and strict access controls. However, no online transmission or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee its absolute security.

5. Data Retention

We retain your personal data for as long as necessary to provide our Services and to comply with our legal and professional obligations. In accordance with Lebanese law and professional standards for health records, therapy records and personal data must be retained for a minimum period (typically ten years) after your last contact with the service. This information cannot be deleted upon request before this period has elapsed, as it is required for legal and safety purposes.

6. Your Rights

In accordance with Lebanese Law No. 81/2018 on Electronic Transactions and Personal Data, you have certain rights regarding your data, including the right to access and rectify your information. To exercise these rights, please contact our support team.

7. Use of Cookies

We use cookies to operate and secure the platform, remember your preferences, and analyze usage. You can control the use of cookies through your browser settings.

8. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the “Last Updated” date.

9. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: doors@xrapy.com