TherapyAlly legal
Bethel Therapy LLC (“Bethel Therapy,” “Company,” “we,” “us,” or “our”) operates the TherapyAlly product family, including our public websites, TherapyAlly Practice, Allie by TherapyAlly, Channel by TherapyAlly, APIs, integrations, and client, guardian, and workforce portals (collectively, the “Services”).
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information across the Services. It should be read with our Terms of Service and, where applicable, a customer agreement and Business Associate Agreement (“BAA”).
A healthcare practice may use TherapyAlly to process identifiable health information on behalf of the practice. When Bethel Therapy LLC performs a function involving Protected Health Information (“PHI”) for a practice that is a HIPAA Covered Entity, we act as its Business Associate as described in the applicable BAA and HIPAA. The practice remains responsible for the clinical record and for responding to most client or patient rights requests concerning that record.
Information is PHI only when it meets the legal definition and is maintained or transmitted by a Covered Entity or Business Associate. If this Policy conflicts with an executed BAA regarding PHI, the BAA controls.
We also process information outside our Business Associate role, including public-website activity, demo requests, business contact details, account administration, subscription records, and general service analytics. This Policy governs that information directly.
We collect names, business and email addresses, phone numbers, job titles, practice affiliations, roles, professional identifiers and credentials, identity-provider details, account preferences, and other information supplied during registration, onboarding, or company setup.
At a practice’s direction, the Services may process client and guardian demographics, contact information, intake forms, appointments, attendance, locations, plans of care, goals, session and progress notes, signatures, provider assignments, insurance coverage, member identifiers, eligibility responses, claims, fee schedules, remittances, and related clinical or billing information. This information may be PHI.
Payment providers collect payment-card, bank, identity-verification, and payout information under their own terms. TherapyAlly generally receives limited transaction, status, account-readiness, and reconciliation information rather than complete payment credentials. Practice Complete may also process payable activity, time review, supervision, approvals, exceptions, and payroll-export information.
We collect information submitted through demo and support forms, emails, surveys, feedback, and other communications. When Channel features are enabled, we may process messages, participant identifiers, virtual-waiting-room activity, call or session metadata, connection and quality information, presence, transcripts, translations, recordings, and auditable communication events according to the practice’s settings and instructions.
We may collect IP address, browser and device type, operating system, referring page, access time, requested route, feature interaction, authentication event, diagnostic data, and security or audit events. We use cookies, local storage, and similar technologies for authentication, session security, preferences, analytics, and marketing attribution. Advertising technologies are not intended for authenticated areas where PHI is processed.
We use information to:
We do not sell personal information or PHI, and we do not disclose it for cross-context behavioral advertising. We may disclose information as follows:
Service providers may process information only for contracted purposes and subject to applicable confidentiality, security, data-processing, and BAA requirements.
Allie and AI-assisted documentation features may process prompts, authorized TherapyAlly context, documented session evidence, transcription fragments, and generated outputs to answer a request or create a draft. TherapyAlly currently uses enterprise Google Cloud generative-AI services, including Vertex AI, for these workflows.
We do not use Customer Data or PHI to train a general-purpose AI model. AI providers may process inputs and outputs to deliver and secure the contracted service under their applicable enterprise terms and, where required, a BAA. TherapyAlly stores only the information needed for the requested workflow, account operation, security, and audit purposes according to its product behavior and retention controls.
AI Outputs require authorized human review before they are relied on, signed, placed in a clinical record, submitted to a payer, or used for another consequential clinical or financial action.
We use administrative, technical, and physical safeguards designed to protect information, including encrypted connections, encryption at rest where supported by the service, authentication, role-based access, practice separation, audit and security events, environment separation, backups, monitoring, vulnerability management, and incident-response processes. No method of storage or transmission is completely secure.
We retain information for as long as reasonably necessary to provide the Services, maintain active accounts, follow customer instructions, meet contractual and BAA commitments, protect the Services, resolve disputes, and comply with applicable law. Practices determine the retention requirements for their clinical records. When an account ends, information is made available, retained, deleted, or de-identified according to the applicable agreement, BAA, product controls, our retention schedule, legal holds, and backup practices.
We may verify identity and authority before completing a request. To submit a request concerning information Bethel Therapy controls directly, use the contact information below.
Our public marketing websites and practice-administration tools are directed to adults, not children. TherapyAlly may process information about minor clients when a practice, clinician, parent, or authorized guardian uses the Services for care, scheduling, billing, intake, or communication. The practice is responsible for determining and documenting the authority and consent required for a minor’s care and portal or Channel access. We do not knowingly collect personal information from children for behavioral advertising.
The Services may link to or integrate with third-party services. A connected service may receive information at Customer’s direction and is governed by its own terms and privacy policy, except where it acts as our contracted service provider or subprocessor. We are not responsible for independently operated third-party websites or services.
We may update this Policy as the Services, laws, or data practices change. We will revise the effective date and provide reasonable notice of material changes through the Services, email, or another appropriate channel.
For privacy questions, requests, or regulatory notices, contact:
Bethel Therapy LLC