Loading...

Privacy Policy

Your mental health data is protected with the highest standards of privacy and security.

Read Policy View Security

Introduction

At ThinkDoctor, we understand that mental health data is among the most sensitive personal information. We are committed to protecting your privacy and ensuring the confidentiality of your psychological assessment data.

This Privacy Policy explains how ThinkDoctor Assessments ("we," "our," or "us") collects, uses, discloses, and safeguards your information when you use our platform, website, and services.

By using our services, you consent to the data practices described in this policy.

Data We Collect

We collect several types of information to provide and improve our services to you:

Personal Information

Name, email address, phone number, date of birth, and contact details provided during account creation.

Assessment Data

Responses to psychological assessments, test results, progress tracking data, and clinical notes.

Health Information

Mental health history, treatment information, medication details, and clinical observations.

Technical Data

IP addresses, device information, browser type, and usage patterns through cookies and analytics.

Sensitive Data: We treat all mental health assessment data as sensitive personal information and apply enhanced protection measures in accordance with healthcare privacy regulations.

How We Use Your Data

We use your information for the following purposes:

  • Service Delivery: To provide psychological assessments, generate reports, and enable communication with healthcare providers
  • Personalization: To tailor assessment experiences and provide relevant mental health resources
  • Clinical Care: To support treatment planning and progress monitoring when used by healthcare providers
  • Research & Development: To improve our assessment tools and develop new features (using anonymized data)
  • Security: To protect against fraud, abuse, and security threats
  • Communication: To send important updates, service notifications, and support responses

Data Sharing & Disclosure

We do not sell your personal or health information. We may share your data only in the following circumstances:

  • With Your Consent: When you explicitly authorize sharing with specific healthcare providers
  • Healthcare Providers: With practitioners you choose to connect with through our platform
  • Legal Requirements: When required by law, court order, or government request
  • Emergency Situations: When necessary to prevent serious harm to you or others
  • Service Providers: With trusted partners who help us operate our platform (under strict data protection agreements)
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Research Data: For research purposes, we only use completely anonymized and aggregated data that cannot be traced back to individual users.

Data Security

We implement comprehensive security measures to protect your data:

  • Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Access Controls: Strict role-based access controls and authentication requirements
  • Secure Infrastructure: Data hosted on HIPAA-compliant cloud infrastructure
  • Regular Audits: Continuous security monitoring and regular penetration testing
  • Employee Training: All staff trained in data privacy and security protocols
  • Breach Response: Comprehensive incident response plan for potential data breaches

Your Privacy Rights

You have the following rights regarding your personal data:

Right to Access

Request a copy of all personal data we hold about you in a portable format.

Right to Rectification

Correct inaccurate or incomplete personal information in your account.

Right to Erasure

Request deletion of your personal data, subject to legal retention requirements.

Right to Restrict

Limit how we use your data in certain circumstances.

Right to Object

Object to certain data processing activities, including direct marketing.

Data Portability

Receive your data in a structured, machine-readable format for transfer.

To exercise any of these rights, please contact our Data Protection Officer at privacy@thinkdoctorassessments.com.

Compliance & Regulations

ThinkDoctor complies with major international privacy and healthcare regulations:

HIPAA Compliant

US Healthcare Privacy

GDPR Compliant

EU Data Protection

HITRUST Certified

Healthcare Security

SOC 2 Type II

Security & Availability

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes, we will update the "Last Updated" date at the bottom of this policy and, if the changes are significant, we will provide a more prominent notice, which may include email notification or in-app alerts.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

Questions About Our Privacy Policy?

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer.

Contact Data Protection Officer

Last Updated: December 1, 2023

This policy may be updated to reflect changes in our practices or legal requirements.