ASKAReception OS
PrivacyTermsLogin

Trust & data protection

Privacy Policy

This policy explains what ASKA processes, why it is needed, how clinic and patient data stay separated, and how Google Calendar data is used only to provide scheduling features requested by the clinic.
Last updated · 22 August 2026

1. Who this policy covers

ASKA is a reception and scheduling software service for private clinics. This policy covers visitors to ASKA websites, clinic account users, people who contact ASKA, and data processed through the service on behalf of a clinic.

For patient booking and care-workflow data, the clinic normally acts as the data controller and ASKA acts as its processor under the clinic agreement and documented instructions. ASKA acts as a controller for its own account administration, security, support, billing and service-improvement records.

2. Data we process

  • Clinic and account data: clinic identity, business contact details, authorized users, roles, authentication records, package and billing status.
  • Scheduling configuration: services, durations, providers, locations, working hours, closures and appointment capacity rules.
  • Patient workflow data: information a patient provides to the clinic for a booking or follow-up, such as name, contact details, requested service, appointment details and consent evidence.
  • Communication records: message type, delivery state, timestamps and provider identifiers needed to confirm, retry, suppress or audit transactional communication.
  • Security and diagnostics: technical request data, tenant-scoped audit records, error fingerprints and operational health signals. ASKA is designed to exclude patient contact data, secrets and OAuth tokens from technical incident packets.

3. Google Calendar data

A clinic connects Google Calendar only through an explicit OAuth authorization. ASKA requests the following narrowly defined scopes because each one is required by a visible scheduling feature:

https://www.googleapis.com/auth/calendar.events

Create, update and cancel ASKA appointment events in the calendar selected by the clinic.

https://www.googleapis.com/auth/calendar.freebusy

Read free/busy time ranges so ASKA does not offer an unavailable appointment.

https://www.googleapis.com/auth/calendar.calendarlist.readonly

Show the clinic the calendars it can choose for a provider connection.

ASKA stores the selected calendar connection, encrypted OAuth credentials, token expiry, technical event identifiers and the minimum calendar metadata needed to maintain that connection. The booking engine uses free/busy time ranges to block unavailable slots. Events created by ASKA use operational scheduling information and are intentionally kept free of patient contact details and clinical notes.

ASKA does not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Human access is limited to explicit support, security or legal needs.

ASKA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

A clinic can disconnect a provider calendar from ASKA. Access is then revoked for that connection and stored credentials are removed according to the service's deletion workflow. A clinic can also revoke access directly from its Google Account security settings.

4. Why we process data

ASKA processes data only for defined operational purposes:

  • to authenticate authorized clinic users and protect accounts;
  • to understand booking requests and calculate valid availability;
  • to create, update, cancel and display appointments;
  • to send requested confirmations, reminders and follow-up messages;
  • to provide clinic support, billing, audit and security functions;
  • to comply with legal obligations and verified data-subject requests.

Depending on the context, processing is based on performance of a contract or pre-contract steps, legitimate interests in operating and securing the service, legal obligations, or consent. The clinic is responsible for selecting the appropriate legal basis for patient data it controls, including any special-category health data.

5. Service providers and transfers

ASKA uses specialist providers only where needed to operate the service, including Supabase for database and authentication services, Vercel for application hosting, Resend for transactional email, Stripe for billing, and Google when a clinic enables Calendar. AI providers are used only where the relevant function is explicitly enabled and its data-minimization and consent gates are satisfied.

Providers receive only the data required for their role and are subject to contractual and security controls. Where data is transferred outside the EEA, ASKA relies on an applicable transfer mechanism and supplementary safeguards required by law.

6. Retention and deletion

Data is retained only while needed for the clinic service, security, audit, billing and legal obligations. Retention depends on the data category and the clinic's documented instructions. Technical identifiers may be retained briefly after deletion to prevent a late provider retry from recreating a false incident; these records contain no patient name, email, phone number, message content or clinical information.

Verified patient deletion requests enter ASKA's protected erasure workflow. The system is designed to remove linked patient data across booking, communication and calendar mappings and to send a receipt without exposing deleted data. Clinics remain responsible for any records they must retain independently under healthcare or other law.

7. Your choices and rights

Depending on applicable law, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, and withdraw consent. Patients should normally contact the clinic that collected their data; ASKA supports clinics in fulfilling verified requests. You may also complain to the competent data-protection authority.

8. Security

ASKA applies tenant isolation, role-based access, encrypted credentials, least-privilege database controls, audit trails, idempotent workflows, backup/restore testing and production observability. No system can guarantee absolute security, but ASKA continuously monitors failures and is designed to preserve a patient request even when an external integration is unavailable.

9. Contact and policy changes

Privacy questions and verified requests can be sent to vlahinjatin@gmail.com. Commercial customers receive the contracting operator's full legal identity, address, processing terms and subprocessor information in their order form and data-processing agreement.

We may update this policy when the service, law or providers change. Material changes will be identified by a new update date and, where required, communicated directly to affected users.

ASKAReception OS

Reception & Scheduling OS for private clinics.

Privacy PolicyTerms of ServiceContact