Legal & Privacy
Privacy Policy
Effective Date: September 11, 2026
Last Updated: September 11, 2026
This Privacy Policy explains how Ephatha collects, uses, stores, protects, and discloses personal information when you use the Ephatha website, online booking service, appointment-management features, and related services (collectively, the “Service”).
Ephatha is operated by Grace Valookkaran Paul, also known as Grace V Paul, an authorized and registered rehabilitation professional in India. Grace V Paul is registered with the Rehabilitation Council of India (RCI) as an Audiologist and Speech-Language Pathologist under Central Rehabilitation Register (CRR) No. A92329. Her RCI registration was issued on September 13, 2023 and is valid until February 22, 2030, subject to applicable RCI requirements.
This policy is intended to provide clear privacy information for clients in India and for international clients, including individuals who may be protected by the GDPR, UK GDPR, Canadian privacy laws, Australian privacy laws, United States state privacy laws, or other applicable privacy legislation. The rights and obligations that apply to you depend on your location and the law applicable to the processing.
1. Data Controller and Privacy Contact
Data Controller / Operator: Grace Valookkaran Paul (Grace V Paul)
Professional Registration: RCI Central Rehabilitation Register (CRR) No. A92329
Professional Category: Audiologist and Speech-Language Pathologist
Privacy Contact: gracepaulaslp@gmail.com
The privacy contact above may be used for privacy questions, data-rights requests, deletion requests, or concerns about the handling of personal information.
2. Professional Qualifications and Regulatory Status
Grace Valookkaran Paul (Grace V Paul) has completed a Bachelor in Audiology and Speech-Language Pathology (BASLP) in 2022 and an M.Sc. in Speech-Language Pathology in 2024 from recognized universities in India. Her additional qualification was recorded by the RCI on February 24, 2025.
The RCI registration identifies her category as Audiologist and Speech-Language Pathologist. Services provided through Ephatha are subject to applicable professional, regulatory, ethical, privacy, telehealth, and scope-of-practice requirements.
3. Information We Collect
3.1 Information You Provide When Booking
Depending on the appointment flow, we may collect:
- Name;
- Email address;
- Telephone number, where requested or provided;
- Appointment service, date, time, and timezone;
- Appointment status and scheduling information; and
- Other information you voluntarily provide during a booking or contact interaction.
Please do not include detailed medical histories, diagnoses, treatment records, passwords, payment-card information, or other highly sensitive information in free-text booking fields unless Ephatha specifically asks for it through an appropriate channel. The booking system is not designed to maintain clinical notes.
3.2 Appointment and Scheduling Information
We create and maintain appointment records needed to provide the requested service, prevent double-booking, permit authorized rescheduling or cancellation, and provide appointment-management links. Appointment-management links may contain a private confirmation token. Treat such links as confidential because possession of a valid token may provide access to the associated appointment-management information.
3.3 Technical and Security Information
The Service may process ordinary technical information necessary to operate and secure the website, such as request metadata, browser or device information, and security-related events. Security controls are designed to minimize unnecessary collection. For example, failed administrator-login rate limiting does not retain raw IP addresses.
3.4 Cookies and Similar Technologies
Ephatha uses essential cookies required for security and authenticated administration, including secure session, OAuth-state, and passkey or WebAuthn challenge cookies. These are not used for behavioral advertising. Please see the Cookie Policy for further information.
4. How We Use Personal Information
We use information only for purposes connected with operating Ephatha, including to:
- provide and administer requested appointments;
- show available appointment times and prevent conflicting bookings;
- process appointment creation, rescheduling, and cancellation;
- provide appointment-management and calendar information;
- operate Google Calendar and Google Meet integration where enabled;
- secure administrative access and prevent abuse or unauthorized access;
- respond to questions, requests, and support communications;
- maintain, troubleshoot, and improve Service reliability and security; and
- comply with applicable legal obligations and protect legal rights.
We do not sell personal information. We do not use personal information for targeted advertising, behavioral advertising, credit decisions, or data-broker activities.
5. Legal Bases Where GDPR or Similar Law Applies
Where applicable, we rely on one or more lawful bases for processing, including:
- Performance of a contract or steps requested before entering into a contract;
- Legitimate interests in operating, securing, and improving the Service, where those interests are not overridden by applicable rights;
- Legal obligations imposed on the operator; and
- Consent where consent is specifically required.
Where processing is based on consent, you may withdraw that consent as permitted by law. Withdrawal does not affect processing that occurred before withdrawal.
6. Google Calendar and Google User Data
Ephatha includes an optional Google Calendar integration used by the therapist/administrator to coordinate appointments. The integration currently requests Google Calendar permissions corresponding to calendar.freebusy and calendar.events. These permissions are requested only to provide the scheduling and calendar functionality described in this policy.
6.1 Google Data We May Access
When the therapist connects Google Calendar, Ephatha may access:
- Calendar availability/free-busy information used to identify scheduling conflicts;
- Calendar event information needed to create, update, or remove Ephatha appointment events;
- Connected account and calendar identifiers needed to operate the integration; and
- Google-issued OAuth credentials necessary to maintain the authorized connection.
6.2 How Google User Data Is Used
Google Calendar data is used only to provide calendar integration, appointment synchronization, conflict checking, and related user-requested scheduling functionality.
We do not sell Google user data. We do not use Google user data for advertising, behavioral profiling, unrelated database creation, or generalized artificial-intelligence or machine-learning model training.
6.3 Google User Data Sharing
Google Calendar data is not disclosed to third parties for their own advertising or marketing purposes. It may be processed by infrastructure providers strictly as necessary to operate the Ephatha Service, subject to applicable contractual and security controls.
6.4 Google OAuth Credential Protection
OAuth refresh credentials are encrypted before storage. Calendar operations are performed server-side and are not exposed to public website visitors.
6.5 Disconnecting Google Calendar
If the therapist disconnects Google Calendar, Ephatha stops using the authorization for subsequent calendar operations and removes the stored connection credentials according to the application's data lifecycle. Google may independently retain or process information under Google's own policies.
7. Sharing and Service Providers
We may use trusted infrastructure and service providers to operate the Service. Depending on the feature being used, these may include:
- Vercel — application hosting and deployment infrastructure;
- MongoDB Atlas — database and application data storage; and
- Google — Google Calendar and Google Meet functionality.
Providers receive only information reasonably necessary for the services they provide and are subject to their own contractual, security, and privacy obligations.
We may disclose information where reasonably necessary to comply with law, respond to lawful requests, prevent fraud or abuse, protect the security of the Service, protect the rights and safety of clients or others, or establish or defend legal claims. We do not otherwise disclose client information to third parties for their own marketing purposes.
8. International Data Transfers
Ephatha and its service providers may process or store information in countries other than the country where you live. Where applicable law requires safeguards for international transfers, we intend to use legally recognized transfer mechanisms or other lawful safeguards.
Because provider infrastructure and applicable law can change, precise storage or processing locations may vary by provider and configuration.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including providing services, maintaining appointment history, resolving disputes, preventing abuse, maintaining security, and meeting legal, accounting, or professional obligations. Different categories of information may therefore have different retention periods.
When information is no longer required, we will delete, securely destroy, or anonymize it where reasonably practicable, subject to legal or legitimate retention requirements. Protected technical backups may persist for a limited period after operational deletion before being overwritten or securely removed.
10. Your Privacy Rights
Depending on where you live, you may have rights including:
- Access to your personal information;
- Correction of inaccurate information;
- Deletion of personal information, subject to lawful exceptions;
- Restriction of certain processing;
- Objection to certain processing;
- Data portability where applicable; and
- Withdrawal of consent where processing is based on consent.
You may also have the right to complain to your local data-protection authority or other privacy regulator.
To make a request, email gracepaulaslp@gmail.com and identify the information or appointment concerned. We may need to verify the requester's identity or authority before disclosing or deleting information. We will respond within the period required by applicable law.
11. Children and Minors
Ephatha's services may be provided to minors. Online booking should be completed by a parent, legal guardian, or other authorized adult where required by applicable law. We do not intentionally request unnecessary personal information directly from children.
If you believe a child has provided information inappropriately, please contact us so that we can review and, where appropriate, delete it.
12. Security
We use technical and organizational measures appropriate to the nature of the information and the Service. These include encrypted connections, secure authentication controls, protected session cookies, server-side authorization checks, encrypted storage of Google OAuth refresh credentials, database controls for booking concurrency, and security headers.
No internet service can guarantee absolute security. Do not send information that the Service does not request.
13. Third-Party Links and Services
The Service may link to or interact with third-party services such as Google. Their privacy practices are governed by their own policies. We encourage you to review those policies before using third-party services.
14. Changes to This Privacy Policy
We may update this policy when our Service, data practices, legal obligations, or security controls change. The updated version will be published on this page with a revised effective date. If a change materially affects how we use personal information, we will provide additional notice where required by law.
15. Contact
For privacy questions, data-rights requests, or concerns about this policy, contact:
Grace Valookkaran Paul (Grace V Paul)
RCI CRR No. A92329
gracepaulaslp@gmail.com