Privacy Policy
Last updated: 2026-07-17
1. Data controller
The controller of the personal data collected through the Therago platform (the "Platform") is the publisher of Therago: WIZE SRL (CBE 0691.653.847), Allée des Chanterelles 14, 5101 Erpent, Belgium, reachable at privacy@wize.be. For the data that therapists process in the course of their own activity, each therapist is the data controller; Therago then acts as a processor (see the Professional Terms of Use).
2. Data we process
We process the following categories of data:
- Account data: name, email address, password (hashed), phone number, preferred language.
- Therapist profile data: identity, titles and diplomas, INAMI/RIZIV or ComPsy number, photograph, description of the practice, fees, consultation addresses, identity verification data (via Stripe Identity).
- Appointment data:patient's name, email and phone number, practitioner consulted, date and time, location or video link.
Health data: the mere fact of booking an appointment with a therapist (psychologist or wellness practitioner) reveals information about your health and therefore constitutes health data within the meaning of Article 9 GDPR. This processing is based on your explicit consent, collected at the time of booking (Art. 9(2)(a) GDPR). You may withdraw this consent at any time (see section 6).
3. Purposes and legal bases
- Providing the service (account creation, booking and managing appointments, confirmation and reminder notifications): performance of the contract (Art. 6(1)(b) GDPR) and, for health data, explicit consent (Art. 9(2)(a) GDPR).
- Billing of therapists' subscriptions: performance of the contract and legal obligation (accounting, tax).
- Security, abuse prevention and improvement of the Platform (logging, rate limiting): legitimate interest (Art. 6(1)(f) GDPR).
- Non-essential communications (where applicable): consent (Art. 6(1)(a) GDPR).
- Responding to requests from authorities: legal obligation (Art. 6(1)(c) GDPR).
4. Recipients and processors
Your data is accessible to the therapist with whom you book an appointment, as well as to our technical processors, strictly to the extent necessary:
- Hosting: Microsoft Azure (European Union region).
- Stripe: payment processing and identity verification of therapists (Stripe Identity).
- Email provider: sending of transactional emails (confirmations, reminders, notifications).
- Twilio: sending of SMS reminders.
Some of these providers may process data outside the European Union. In that case, transfers are governed by appropriate safeguards, in particular the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional measures. We never sell your data.
5. Retention periods
- Account data: duration of the registration, then 1 year after the account is closed.
- Appointment data: 3 years after the appointment.
- Technical logs: 12 months.
Longer periods may apply where required by law (for example accounting obligations) or in the event of a dispute, for its duration.
6. Your rights
In accordance with Articles 15 to 22 GDPR, you have the following rights: right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object (in particular to processing based on legitimate interest) and the right to withdraw your consent at any time, without this withdrawal affecting the lawfulness of the processing carried out before the withdrawal. To exercise these rights, contact us at privacy@wize.be. We respond within one month, extendable by two months for complex requests. Proof of identity may be requested.
7. Complaints
If you believe that the processing of your data violates the GDPR, you may lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be.
8. Security
We implement appropriate technical and organisational measures to protect your data, including: encryption of communications in transit (TLS), strict access control to data based on the principle of least privilege, password hashing, and logging of access and sensitive operations.
Version of 17 July 2026.