Privacy Policy

Last updated: October 7, 2026

AscAgent is an AI-powered appointment management platform for clinics, beauty salons, and similar businesses. This policy explains what personal data we collect, why, and how we protect it. AscAgent acts as a Data Processor on behalf of the businesses (Data Controllers) that use our platform.


Data Controller

Each business using AscAgent is the Data Controller for the personal data of their clients and patients. AscAgent processes that data only on their behalf and under their instruction.

Data we collect
Platform users (staff and admins)

Name, email address, hashed password, role, language and theme preferences, optional avatar colour, and Google account ID (if using Google sign-in). If a staff member opts in to web push notifications, we also store their browser-issued push subscription endpoint, encryption keys, and a device signature derived from the user-agent string (so multiple subscriptions for the same physical device collapse into one). If a staff member uses the internal AI assistant (Maya), the assistant's conversation history (including any voice-to-text transcripts) is stored on the staff member's account, along with per-message AI token usage. If a staff member connects a Google Calendar, their OAuth refresh token is stored encrypted (AES-256) and used to read that calendar's busy periods and event titles, so appointments never double-book against it, and, with the staff member's consent, to keep their AscAgent appointments in sync with it: AscAgent creates, updates, and deletes calendar events for those appointments (service, client name, and time - never the client's phone number, email, or notes) and for their blocked time (the time and its reason) and changes made to those events in Google are not applied back to the appointment (the next sync overwrites them); event titles are visible to other staff only if the calendar's owner turns on "Show event titles".

Widget visitors and patients

When a patient interacts with the chat widget, we collect their chat messages and - if they book an appointment - their name and phone number. Chat messages are sent to OpenAI to generate AI responses (see AI Processing below). The name and phone number are stored to manage the appointment and to send appointment-related transactional notifications (booking confirmations, reminders before the appointment, and cancellation or rescheduling notices) by email and, where the client has installed your client app and enabled notifications, web push. By providing a phone number or email when booking, the patient acknowledges these transactional messages will be sent.

Appointment records

Appointment details including date, time, assigned staff member, service, and any clinical notes entered by clinic staff. Clinical notes may contain health-related information and are treated as Special Category data under GDPR Article 9. If the business enables the loyalty card, we also store each client's stamp/points balance and redemption history. If the business publishes a public website through AscAgent, the content and images it uploads (including staff photos) are stored and served via our storage sub-processor (see Third-Party Processors).

Billing data

When you subscribe, we collect your company name, company ID (EIK), VAT number, billing address and billing email to issue invoices, and we keep invoice and payment status. Card payments are processed by Stripe: your card details go directly to Stripe and are never stored by AscAgent. We keep invoicing records for the period required by Bulgarian accounting and tax law.

Lawful basis for processing

We process personal data under the following legal bases: (a) Contract - processing necessary to provide the booked service; (b) Legitimate Interests - operating and improving the platform; (c) Legal Obligation - where required by law. Clinical notes containing health data are processed under Article 9(2)(h) - provision of health or social care.

AI processing

AscAgent offers optional AI features, all running on OpenAI models under a Data Processing Agreement. A business that does not enable them sends no data to OpenAI. OpenAI does not use API data to train its models; data is retained only briefly for abuse monitoring, then deleted. The AI features are: (1) generating responses in the patient chat widget, when the business enables it; (2) the internal staff assistant ("Maya"), which lets your team query clinic data conversationally - Maya's tools are read-only and limited to the data the staff member is already authorised to see; (3) optional AI summaries of a client's history (which may include health-related notes - these are processed under Article 9(2)(h) along with the underlying clinical data and stored on the client record); (4) optional voice-to-text transcription of staff messages to Maya - audio is sent only for transcription; (5) automatic short summaries of widget chat sessions, written into the corresponding client record so staff have context for follow-up. We track token usage per AI feature and per staff user (counts only - not message content) for billing and analytics. OpenAI (OpenAI, L.L.C., USA) is AscAgent's sole third-party AI/ML service provider; no other AI vendors are used. Google user data (profile information from Google Sign-In and Google Calendar free/busy windows) is never sent to OpenAI or any other AI system.

Google user data

AscAgent accesses only the Google user data needed for the feature you turn on. Google is used for two things: signing in with your Google account, and Google Calendar sync.

What we access

Sign-in: your name, email address and Google account ID. Google Calendar (scopes https://www.googleapis.com/auth/calendar.readonly and https://www.googleapis.com/auth/calendar.events): the busy periods and event titles on the calendars you link, and the list of your calendars so you can pick one. You can untick the write permission on Google's consent screen; AscAgent then works read-only.

How we use it

Reading shows your busy time on the shared calendar view and prevents double-booking. Writing (with your consent) creates, updates and deletes events on the calendar you select for your AscAgent appointments and blocked time. An event holds the service, client name and time - never the client's phone number, email or notes - or only "AscAgent Appointment" / "Blocked" if you share time only. Events have no guests, invitations or reminders. AscAgent only changes events it created and never edits or deletes your other events. Changes made to these events in Google are not applied to the appointment; the next sync overwrites them. Event titles are visible to other staff only if you turn that on in your profile.

Where it is stored and how it is protected

Your Google access and refresh tokens are stored encrypted (AES-256) in our database, hosted by Hetzner Online GmbH in the EU, together with your Google account email, the calendar's ID and name, and technical sync identifiers (event IDs and change tokens). We do not keep a copy of your Google events: the busy periods and titles we read are held in a short-lived cache for up to 30 seconds to build the calendar view, then discarded. Events AscAgent writes are stored by Google in your Google account.

Who we share it with

AscAgent does NOT share, sell, transfer, or otherwise disclose Google user data to any third party, except (i) Hetzner Online GmbH (Germany, EU), which hosts our encrypted database and application servers under a Data Processing Agreement, and (ii) where required by law. Google user data is never disclosed to OpenAI or any other AI/ML provider.

Retention and deletion

We keep Google data only while the calendar is linked. When you remove a linked calendar in your AscAgent profile, the token is revoked at Google (unless another linked calendar on the same Google account still uses it) and the stored tokens and sync records are deleted. The same happens when a staff member is removed from AscAgent. Events AscAgent already created in Google Calendar stay there unless you choose to delete them when you remove the calendar. You can also revoke access directly at myaccount.google.com/permissions: AscAgent loses access immediately, and the leftover tokens are deleted when you remove the calendar in AscAgent. Copies in database backups expire with the backup retention period (up to 5 days locally and a small number of recent versions off-site). To have us delete your Google data for you, write to [email protected]; requests are honoured within 30 days.

Limited Use

AscAgent's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements (developers.google.com/terms/api-services-user-data-policy). Specifically: we use Google user data only to provide the sign-in and calendar features visible in AscAgent; we never use it for advertising or sell it to data brokers; we never use it to train, fine-tune, or improve any AI/ML model, ours or a third party's; and we do not allow humans to read it unless you ask us for support, it is needed to investigate security or abuse, or the law requires it.

Notifications & multi-channel communications

In addition to the appointment-related transactional messages described above, your business may use AscAgent to send automated follow-up communications (e.g. recall messages, post-visit feedback) over email and web push via the relevant sub-processors listed below. Per-channel and per-category (transactional vs. marketing) consent is recorded for each client, and every marketing-category message includes a one-click unsubscribe link backed by a signed token. Clients can also manage their preferences directly via a self-service preference centre. Staff and admin users can additionally opt in to browser web push notifications; subscriptions are stored as described under "Platform users" above and are automatically removed after 60 days of inactivity.

Audit Logs, Abuse Prevention & Browser Storage

We log administrative actions performed in the platform (who created, modified, cancelled, or deleted appointments, clients, automations, templates, channels, and similar records, and when) for security, compliance, and dispute resolution. Audit logs are retained alongside the underlying records. To prevent automated abuse of the booking widget, we temporarily store rate-limit counters keyed by IP address, chat session, and business in our cache; these counters automatically expire within minutes to a few hours and are not used for profiling or analytics. Your browser additionally stores small items in localStorage to improve the experience: a session-scoped "last visited page" pointer, your theme preference, and a flag recording whether you declined push notifications. These are not transmitted to our servers and can be cleared by clearing your browser data.

Data retention

Appointment and client records are kept for as long as the business (the Data Controller) needs them - to run its services and meet its own legal and regulatory retention obligations, which for healthcare providers is often several years. The business controls its own retention. We do not auto-delete business or client data on a fixed timer. Short-lived technical data - expired login tokens, background-job records, and old in-app notifications - is cleared automatically. Erasure requests under the GDPR right to erasure are honoured within 30 days by anonymising the personal data on the record (name, contact details, and other identifying fields); the anonymised record itself may be retained where the business has its own legal or regulatory retention obligations. Platform user accounts are kept while the account is active.

Security

All data is transmitted over HTTPS (TLS 1.2+). Passwords are hashed using bcrypt (12 rounds) and never stored in plain text. Stored OAuth refresh tokens (e.g. Google Calendar) are encrypted with AES-256. Google connections use a one-time state token to protect against cross-site request forgery. Database access is restricted to internal services only - the database port is not exposed to the internet. Refresh tokens are stored in the database and can be revoked. Our servers are hosted on Hetzner Cloud infrastructure in the EU. Compressed nightly database backups are uploaded off-site to a cloud storage location for disaster recovery, retained for up to 5 days locally and a small number of recent versions off-site, and subject to the same access controls as live data.

Your rights under GDPR

If you are located in the EU/EEA, you have the following rights regarding your personal data:

  • • Right of Access (Art. 15) - request a copy of the data we hold about you

  • • Right to Erasure (Art. 17) - request deletion of your personal data

  • • Right to Portability (Art. 20) - receive your data in a machine-readable format

  • • Right to Restriction (Art. 18) - request that we limit how we process your data

  • • Right to Object (Art. 21) - object to processing based on legitimate interests

  • • Right to Lodge a Complaint - with the Bulgarian Commission for Personal Data Protection (CPDP) at cpdp.bg

Third-party processors

We work with the following sub-processors, each bound by a Data Processing Agreement. Wherever the sub-processor offers an EU region, we use it so that personal data is processed and stored on EU servers in line with GDPR. For sub-processors based outside the EU, transfers are covered by Standard Contractual Clauses (SCCs) and supplementary safeguards.

  • • OpenAI (USA) - generates AI responses; used only when the business enables AI features. API data is not used to train OpenAI's models and is retained briefly for abuse monitoring only, then deleted. International transfers covered by SCCs.

  • • Google LLC (USA) - Google OAuth sign-in and optional two-way Google Calendar sync. International transfers covered by SCCs.

  • • Hetzner Online GmbH (Germany, EU) - cloud infrastructure and database hosting on EU servers (Falkenstein, Germany).

  • • Resend - delivery of transactional and operational emails. EU region used (Frankfurt, Germany) so email data is processed on EU servers.

  • • Cloudflare, Inc. (USA) - DNS, CDN/reverse proxy, and object storage (R2) for static assets and business-uploaded website and staff images. Acts as a network intermediary for traffic to our platform (including widget conversations) and may terminate TLS at the edge. R2 uses the EU jurisdiction, so uploaded images are stored on EU servers; as Cloudflare is US-based, any incidental transfers are covered by SCCs.

  • • PostHog, Inc. (USA) - product analytics and session replay. Records usage events, IP-based approximate location, and (for staff accounts) the account email and name; public site and widget visitors are tracked under an anonymous identifier. EU Cloud region (Frankfurt, Germany) used so data is processed on EU servers; international transfers are covered by SCCs.

  • • Stripe Payments Europe, Ltd. (Ireland) - payment processing and subscription billing: company and billing details, billing email and payment status. Card details are entered on Stripe's pages. DPA in place.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered platform users by email and via in-app news announcements at least 14 days before the changes take effect. The current version is always available on this page, with the "Last updated" date at the top.

Contact & data requests

To exercise your rights, request data deletion, or ask questions about this policy, contact us at: [email protected]