Last updated: October 3, 2026
These Terms of Service govern your use of the AscAgent platform. By creating an account you agree to these terms and our Privacy Policy. Read them carefully.
AscAgent provides an AI-powered practice-management and client-retention platform for clinics, beauty salons, and similar service businesses ("the Service"). It includes a calendar and appointment system; a CRM for clients, staff, and services; an automated follow-up system (appointment reminders, post-visit aftercare, review requests, and win-back messages) delivered over email and web push notifications; a loyalty card program; a per-business public website with online booking; installable staff and client apps (Progressive Web Apps); an embedded AI chat widget for 24/7 booking and FAQ; an internal AI assistant for staff ("Maya") with optional voice-to-text input; AI-generated client history summaries; audit logging; and analytics dashboards. The Service is provided on a software-as-a-service basis.
You must provide accurate information when registering. You are responsible for maintaining the confidentiality of your credentials and for all activity under your account. You must notify us immediately of any unauthorised use. By registering or using the Service, whether with an email and password or via a third-party sign-in such as Google, you accept these Terms of Service and our Privacy Policy.
You agree not to: use the Service for unlawful purposes; upload malicious code; attempt to gain unauthorised access to any part of the Service; use the AI chat feature to generate harmful, deceptive, or illegal content; or resell or sublicense the Service without written permission.
We aim for high availability but do not guarantee uninterrupted access. Scheduled maintenance will be communicated in advance where possible. We are not liable for downtime caused by factors outside our control.
AscAgent and its licensors own all intellectual property rights in the Service. You retain ownership of your data. You grant us a limited licence to process your data solely to provide the Service.
To the maximum extent permitted by law, AscAgent's liability for any claim arising from use of the Service is limited to the fees paid by you in the three months preceding the claim. We are not liable for indirect, incidental, or consequential damages.
Either party may terminate the agreement with 30 days written notice. Upon termination, your data remains available for export for 30 days; afterwards it is handled under the retention and erasure terms in our Privacy Policy. We may suspend, restrict, or terminate access to any account immediately and without prior notice for material breach, non-payment, or where we reasonably suspect abuse or a security or legal risk.
These terms are governed by the laws of the Republic of Bulgaria. Disputes shall be resolved in the competent courts of Sofia, Bulgaria.
We may update these terms from time to time. We will notify registered users by email and via in-app news announcements at least 14 days before material changes take effect. Continued use after that date constitutes acceptance.
You may publish a public website through the Service and upload content to it, including business information, services, prices, text, and images (such as your logo and staff photos). You retain ownership of your content and are solely responsible for it. You confirm that you hold all rights necessary to publish it and that it does not infringe any third party's rights or violate any law. You grant AscAgent a non-exclusive licence to host, store, reproduce, and display that content solely to operate the Service and serve your website. AscAgent may remove or disable content it reasonably believes is unlawful, infringing, or in breach of these terms.
If you enable the loyalty card, you define its rules - the stamps or points required for a reward and the reward itself. Stamps and points have no cash value, are not transferable or redeemable for money, and are valid only with your business. You are responsible for honouring the rewards you configure. Stamps may be adjusted or reversed automatically when an appointment is cancelled or missed, or to correct error or abuse.
When you register you provide a phone number and consent to AscAgent contacting you by phone on that number - typically a single onboarding call - to help you set up your account and discuss the Service. You may ask us to stop calling at any time and we will.
Paid plans and add-ons are charged in euro. Prices are shown excluding VAT; VAT is calculated and added at checkout. A billing period is one calendar month (monthly) or one year (yearly) and renews automatically until you cancel. Payment is taken by card through Stripe; we never see or store your card details. Any remaining free trial or bonus days are honored before the first charge. If a renewal payment fails, you keep full access for 7 days to update your card; after that the subscription ends and your account becomes view-only. You can cancel at any time in the billing portal; access continues until the end of the paid period. Refunds follow the money-back guarantee stated on our pricing page and are returned to the original card. We issue an invoice for every payment. Promo codes: a code gives the discount shown when you apply it, for the payments it names; it can be used once per business, only for the plan and billing period it is valid for, and one promo code applies per checkout. A code that adds free days moves the first charge by that many days. A refund does not give a used code back. A refund does not give a used code back. Referral program: when a business you invite pays its first invoice, you earn free days, added to your subscription after a short checking period; a refund or dispute of that payment cancels the reward. Referring your own business does not earn a reward. We may change the program for future referrals. A referral reward is paid as free days or, when the program says so, as a euro amount by bank transfer; it has no other cash value and cannot be transferred. We may withhold a reward in cases of suspected abuse, or when the referred business's payment is refunded or disputed.
This section constitutes a Data Processing Agreement (DPA) between you ("Controller") and AscAgent ("Processor") as required by GDPR Article 28.
AscAgent processes personal data on your behalf for the duration of your subscription to provide the appointment management, AI assistant, follow-up communication, and notification services described in Section 1.
Processing includes: storing and retrieving appointment records; processing patient chat messages through AI to generate booking responses; running an internal AI assistant for your staff (including optional voice-to-text transcription); generating AI summaries of client histories; managing client and staff records; operating the loyalty card program; hosting your public website and the content and images you publish to it; sending transactional and consent-based marketing communications over email and web push; maintaining audit logs of administrative actions; rate-limiting and abuse-prevention; and providing analytics and reporting on appointment, communication, and AI usage activity.
Name, phone number, email address, appointment details, clinical/service notes (which may include Special Category health data under GDPR Art. 9), chat session messages, internal AI assistant conversation history (including transcribed voice input), AI-generated client summaries, loyalty stamp/points balances and redemption history, communication content and delivery status, per-channel/per-category consent records, web push subscription endpoints and device signatures, published website content and uploaded images (including staff photos), audit log entries, AI token-usage attribution records, and short-lived IP-based rate-limit counters.
Your clients and patients (data subjects interacting with your business via the widget or booked by staff); your staff and admin users.
AscAgent shall: (a) process personal data only on your documented instructions; (b) ensure persons authorised to process the data are under confidentiality obligations; (c) implement appropriate technical and organisational security measures (see Section 13.6); (d) not engage sub-processors without your prior authorisation (standing authorisation is given for the sub-processors listed in Section 13.7); (e) assist you in responding to data subject rights requests; (f) delete or return all personal data upon termination of the agreement; (g) provide all information necessary to demonstrate compliance with Art. 28.
AscAgent implements the following measures: HTTPS/TLS encryption in transit; bcrypt password hashing; AES-256 encryption of stored OAuth tokens; database access restricted to internal services; access control by role; refresh token revocation capability; audit logging of administrative actions; nightly off-site backups (compressed pg_dump uploaded to a controller-accessible cloud storage location, retained for 5 days locally and up to 5 most-recent versions off-site).
You confirm that: (a) you have a lawful basis for processing the personal data you instruct us to process; (b) you have provided appropriate privacy notices to your data subjects; (c) you will inform us promptly of any data subject rights requests or regulatory inquiries relating to data we process on your behalf.
AscAgent will assist you in fulfilling data subject access, erasure, portability, and restriction requests within the timelines required by GDPR. Contact [email protected] with such requests.
AscAgent will notify you without undue delay (and in any event within 72 hours of becoming aware) of any personal data breach affecting data processed on your behalf, providing sufficient information for you to meet your own notification obligations to supervisory authorities.
You authorise AscAgent to use the following sub-processors. AscAgent remains liable for their compliance with this DPA. Where the sub-processor offers an EU region, AscAgent uses it so personal data is processed and stored on EU servers. International transfers (where unavoidable) are covered by Standard Contractual Clauses (SCCs).
• OpenAI, L.L.C. (USA) - generates AI responses; used only when the business enables AI features. API data is not used to train OpenAI's models and is retained briefly for abuse monitoring only, then deleted. DPA + SCCs in place.
• Google LLC (USA) - OAuth authentication and optional Calendar integration. DPA + SCCs in place.
• Hetzner Online GmbH (Germany, EU) - Cloud infrastructure and database hosting on EU servers (Falkenstein, Germany). DPA in place.
• Resend - Transactional and operational email delivery. EU region (Frankfurt, Germany) used so email data is processed on EU servers. DPA in place.
• Cloudflare, Inc. (USA) - DNS, CDN/reverse proxy, and object storage (R2) for uploaded website and staff images. R2 uses the EU jurisdiction, so uploaded images are stored on EU servers; as Cloudflare is US-based, any incidental transfers are covered by SCCs.
• PostHog, Inc. (USA) - product analytics and session replay (usage events, IP-based approximate location, and the email and name of staff accounts). EU Cloud region (Frankfurt, Germany) used so data is processed on EU servers; international transfers are covered by SCCs.
• Stripe Payments Europe, Ltd. (Ireland) - payment processing and subscription billing (company and billing details, billing email, payment status). Card details are entered on Stripe's pages and never reach AscAgent. DPA in place.
For questions about these terms, contact us at: [email protected]
Cookies. Essential cookies for core site functions. Analytics and marketing only with your consent.