Privacy Policy
Effective Date: 18 July 2026 · Last Updated: 18 July 2026
Security summary: Two Little Steps stores center and patient records on secure, access-controlled servers. Data is encrypted in transit (HTTPS/TLS), sensitive clinical information is encrypted at rest, each center's data is isolated from every other center, and access to children's records is logged. See Section 8 for details.
Two Little Steps ("Two Little Steps", "we", "our", "us") operates the Two Little Steps platform. This Privacy Policy explains how we collect, use, share and protect personal data, and your rights under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Information Technology Act, 2000 and the rules made thereunder.
1. Our Role
For the account and billing data of a center and its staff, we act as the data fiduciary. For the child, family and clinical records that a center enters, the center is the data fiduciary and we act as its data processor, processing that data only on the center's instructions (see our Data Processing Agreement).
2. Information We Collect
We collect information that centers provide directly and that is generated through use of the Service, including:
- Center & Staff Data: organisation name, contact details, therapist profiles, and administrator/staff accounts.
- Child & Family Records: child names, date of birth, parent/guardian contact details, therapy disciplines, session notes, progress records, and appointment and attendance history.
- Billing Information: when online payments are enabled, card details are collected and processed directly by our payment gateway (Razorpay) and are never stored on our servers. We retain only the resulting transaction reference and your plan and subscription status.
- Usage & Technical Data: security and audit events (such as sign-ins and access to patient records) and limited technical data (IP address, timestamps, browser user-agent) needed to operate and secure the Service.
3. How We Use Information
We use the information we collect solely to:
- provide, maintain, secure and improve the Two Little Steps platform;
- enable scheduling, session documentation, progress tracking, and reporting;
- send transactional communications such as appointment reminders and billing receipts;
- provide customer support and respond to enquiries; and
- comply with applicable laws and protect platform security.
We do not use child or family data for advertising, profiling, or any purpose beyond delivering the Service.
4. Legal Basis & Consent
We process personal data to provide the Service under our contract with the center, to comply with legal obligations, and — where required — on the basis of consent obtained by the center. Centers are responsible for providing the required notices to, and obtaining the required consents from, data principals (including verifiable parental consent for children's data).
5. Children's Data
The Service is used by professionals to manage records of children receiving therapy, and we treat this data with the highest level of care. Centers must obtain verifiable parental or guardian consent before entering a child's data. In line with the DPDP Act, we do not track, behaviourally monitor, profile, or serve advertising to children, and we do not undertake any processing likely to cause a detrimental effect on a child. We act only as a processor for this data, on the center's instructions.
6. Sharing & Sub-processors
We do not sell, rent or trade personal data. We share data only with the service providers listed below, who process it on our behalf under contractual data-protection terms, and with legal authorities where required by law or to protect rights and safety:
- Razorpay (India) — payment processing.
- Meta Platforms / WhatsApp Business API (United States / global) — sending appointment reminders and invoices to parents, where a center enables it.
- Resend (United States) — transactional emails such as password-reset links.
- Web3Forms (United States) — delivering website contact-form enquiries.
- Cloud hosting & database provider (India) — secure cloud hosting and storage of centre and patient data.
- Google Fonts — serving website fonts (receives visitors' IP addresses).
An up-to-date list of sub-processors is available on request. Some of these providers are located outside India; where personal data is transferred outside India, we do so subject to appropriate contractual safeguards and applicable law, and not to any country or territory restricted by the Government of India.
7. Parent Communications & Opt-out
Where a center enables it, we send appointment reminders and invoices to parents by WhatsApp and/or email, limited to the information needed for that message (such as the child's name, session time and invoice). Parents can opt out at any time by replying STOP (WhatsApp) or by contacting their center.
8. Data Security
- Encryption in transit: all connections use HTTPS/TLS.
- Encryption at rest: sensitive clinical fields (diagnosis, address, referral and session notes) are encrypted with AES-256-GCM, so a database backup never exposes plaintext clinical detail.
- Passwords: hashed with argon2id (a memory-hard algorithm) using a per-user salt, and never stored in plain text.
- Tenant isolation: database-level Row-Level Security confines every query to the requesting center, so one center can never read another's data.
- Access control & audit: role-based access ensures staff see only data relevant to their role, and access to children's records is written to an append-only audit log.
- Sessions: managed server-side; the session cookie is httpOnly (not readable by scripts) and stored only as a hash, with idle and absolute expiry.
9. Data Retention
We retain center and account data while the account is active and for up to 3 years after closure to meet legal, tax and clinical record-keeping obligations, unless a shorter period is agreed in writing. For data we process on behalf of a center, retention and deletion follow the center's instructions and our Data Processing Agreement. On request we will delete or return data as required by law.
10. Your Rights
Subject to applicable law, you have the right to access, correct, update, and erase your personal data, to withdraw consent, to nominate another person to exercise your rights, and to grievance redressal. For child and family data held by a center, please direct requests to the relevant center; we will assist the center in fulfilling them. Contact us (Section 13); we will respond within 30 days.
11. Data Breach Notification
If a personal-data breach occurs, we will notify the Data Protection Board of India and affected centers and/or data principals without undue delay, as required by the DPDP Act, and take reasonable steps to contain and remediate the incident.
12. Cookies & Local Storage
Two Little Steps uses strictly necessary cookies to keep you signed in securely — an httpOnly session cookie and a companion CSRF-protection cookie. When you make a payment, our gateway (Razorpay) may set its own cookies within its secure checkout. We do not use tracking, analytics, or advertising cookies at any time. The app may use local browser storage to remember non-sensitive display preferences.
13. Contact & Complaints
Two Little Steps
Hadapsar, Pune — 411028
Email: support@twolittlesteps.com · WhatsApp: +91 98450 12345
We acknowledge complaints within 48 hours and aim to resolve them within 30 days.
14. Changes to This Policy
Two Little Steps reserves the right, at its sole discretion, to amend, modify, update or otherwise revise this Privacy Policy at any time. Any such changes take effect upon posting of the revised policy on our platform, and the "Last Updated" date will be amended accordingly. Where changes are material, we will take reasonable steps to notify active centers. Your continued access to or use of the Service following the posting of any revised Privacy Policy constitutes your acceptance of, and agreement to be bound by, the policy as revised.