Legal

Data Processing Agreement

This DPA describes controller and processor roles for Nature Therapy Hub during Early Access/Beta testing.

Nature Therapy Hub is currently operating as an Early Access/Beta platform. These policies apply to all users of the platform during the beta testing period.

Roles

For therapist client information entered into the platform, the therapist is generally the Data Controller. Nature Therapy Hub acts as Data Processor by processing that client data on behalf of the therapist to provide the hosted software service at https://naturetherapyhq.co.uk.

Therapist Directory profile information is separate from therapist client records. Where a therapist or applicant submits information for a public directory listing, Nature Therapy Hub may act as an independent controller for directory administration, publication decisions, public display, directory safety, and related communications.

Processing purpose

Processing supports outdoor therapy practice management, including therapist accounts, client records, appointments, session notes, consent forms and signatures, risk assessments, outdoor locations, routes, resources, safety check-ins, uploaded files, client portal sessions, reflections, and form responses.

Directory processing supports public listing applications, review before publication, public display of approved profile information, handling update or removal requests, and responding to concerns about directory listings.

Categories of processed data

Processed data may include account and contact details, practice profile information, client administrative information, clinical and session-related notes entered by therapists, consent and risk records, file metadata and uploaded files, portal invite/session details, feedback submissions, early access requests, and operational email records.

Directory data may include public profile content, contact email, website links, location information, practice descriptions, submitted qualifications or memberships, specialisms, directory application details, and listing review status.

Security measures

Current technical and organisational measures include authentication, HTTPS, protected routes, role-based permissions, Row Level Security, therapist-owned record access controls, admin-only areas, session timeout, private storage planning for uploaded files, environment variable usage, and no service role key exposure in the application.

Hosting and subprocessors

Nature Therapy Hub stores application data using Supabase infrastructure and deploys the web application through a hosting provider. Email delivery may use a configured provider such as Resend. Subprocessors may change as the beta platform develops, and the list will be maintained as part of ongoing operational review.

Assistance with rights requests

Nature Therapy Hub will take reasonable steps to help therapists respond to data subject requests relating to client information processed in the platform, including access, correction, erasure, and portability requests where applicable.

Requests relating to public directory listing information can be sent directly to support@naturetherapyhq.co.uk, including requests to update, hide, remove, or delete listing information where appropriate.

Deletion and return of data

During beta, data deletion and export requests should be raised through support@naturetherapyhq.co.uk. Nature Therapy Hub continues to improve formal export, deletion, retention, and account closure controls.

Contact

Questions about this Data Processing Agreement can be sent to support@naturetherapyhq.co.uk.