Privacy policy
Ascend holds data in two different legal roles at once. This policy is written in that order, because the answer to almost every question below depends on which of the two applies to you.
Last updated 20 August 2026
01Who we are and how to reach us
Ascend provides an operating system for independent, appointment based practices, and a remote staffing service for the same practices. Ascend is a registered business name of an individual rather than a separate company, so the party responsible for your data is the proprietor trading under that name.
- Responsible party: Hamraz Azam Khan Bangash, trading as Ascend
- Registered in Lahore, Pakistan. A postal address is available on request.
- Contact: info@goascend.co
02The two roles we act in
Read the role that applies to you. Sections 3, 6 and 11 (practice users) describe the first role. Sections 4, 5, 8 and 11 (patients) describe the second.
Role one: Ascend as controller
For people who visit goascend.co, submit the contact form, apply to join our staffing bench, or hold a login to the Ascend dashboard, we decide what happens to that data and we are the controller of it.
Role two: Ascend as processor and business associate
For patient data a practice puts into Ascend, the practice is the covered entity and the controller. Ascend acts on that practice's instructions as its processor, and in the United States as its business associate. A message a patient sends to a practice on Instagram or Facebook Messenger sits in this second category, because it is a patient communication that belongs to the practice.
03Information we collect as controller
- Contact form: name, practice name, email, phone, number of locations, approximate patient count, the systems you use today, and anything you write in the free text box.
- Talent applications: name, contact details, CV content and work history.
- Account data: name, email, organisation, role and authentication identifiers.
- Usage and diagnostics: pages viewed, errors encountered, and approximate location derived from IP address.
04Information we process on behalf of practices
A practice decides what to put into Ascend. The categories below are what the platform is built to hold.
- Contact records: name, phone, email, date of birth and consent state.
- Appointment and visit history.
- Message content across web chat, SMS, WhatsApp, Instagram Direct and Facebook Messenger, in both directions.
- Platform scoped identifiers from Meta, meaning page scoped IDs for Instagram and Messenger users, used only to route a reply back to the right conversation.
- Clinical records a practice chooses to store, including consultation notes, standing clinical facts and charges.
- Media a practice uploads, including case photographs and their recorded consent state.
05Meta platform data, specifically
This section describes exactly what Ascend does with data obtained through Instagram and Facebook, and applies only where a practice has connected its own business accounts.
Permissions we request and why
pages_messagingandinstagram_manage_messages: to receive and reply to messages sent to the practice's own accounts.pages_show_listandinstagram_basic: to let the practice select which of its accounts to connect.pages_manage_metadata: to subscribe to message webhooks for the connected account.
Scope of access
We access only messages sent to or from the connected business account. We do not access a person's personal profile content, their friends or connections, or their activity anywhere else on Instagram or Facebook.
How message content is processed
Message content is sent to Anthropic to generate a draft reply or an automated reply on the practice's behalf. Anthropic does not train its models on this content.
What we never do with it
We do not sell, rent or share this data with advertisers or data brokers, and we do not use it to build advertising profiles.
Retention and disconnection
- Message content is retained for the life of the practice's account and is then deleted as described in section 10 and on the data deletion page.
- A practice can disconnect its Meta accounts at any time from Settings, which stops all access immediately.
06How we use information
- Operating the service for the practice that holds the account.
- Generating replies, drafts and recommendations.
- Sending consent checked outreach on a practice's behalf.
- Security, abuse prevention and service support.
07Subprocessors
Only the subprocessors marked below may process patient data. The rest are architected so that patient data never reaches them.
| Subprocessor | Purpose | Patient data |
|---|---|---|
| Anthropic | AI reasoning and drafting | Yes |
| Twilio | SMS and WhatsApp messaging | Yes |
| Neon | Application database | Yes |
| Render | Application hosting | Yes |
| Meta Platforms | Instagram Direct and Facebook Messenger message transport | Yes |
| Clerk | Staff authentication | No |
| Resend | Delivers enquiries sent through this website | No |
| Vercel | Marketing site and dashboard hosting | No |
| Inngest | Background jobs | No |
| Sentry | Error monitoring | No |
Resend appears on this list because it delivers the enquiry and application forms on this website. Those forms collect business contact details from the person filling them in, never patient data.
08Legal bases and HIPAA
For practices in the United States, Ascend acts as a business associate under a business associate agreement. For processing Ascend performs at a practice's direction, the practice is the covered entity, and its own notice of privacy practices governs its relationship with its patients.
Where we act as controller, our basis for processing is our legitimate interest in operating and securing the service, and performance of the contract we have with the account holder.
09Security
- Row level security enforced by the database, so one practice's data cannot be returned to another even if application code forgets to filter.
- Role gated access to clinical records.
- An append only access log: opening a clinical record writes an audit row inside the same transaction as the read, and if the log write fails the read fails.
- Encryption in transit.
- Least privilege database roles.
10Retention
- Account and practice data: for the life of the account plus 30 days, then deleted.
- Diagnostics: 90 days.
- Where a legal obligation requires us to keep a record for longer, we keep only what that obligation requires, for only as long as it requires.
11Your choices
If you are a patient of a practice
Replying STOP to any SMS or WhatsApp message opts you out immediately and permanently from marketing on that channel. Replying START opts you back in. A request about your own record goes to the practice you are a patient of, because the practice holds that record and we act on its instructions.
If you hold an Ascend account
You can ask us to access, correct, export or delete your data by emailing us, and we respond within 30 days. This is not yet a self-serve action inside the dashboard, and we would rather say so than point you at a button that is not there.
12Deletion
Full instructions for having your data deleted, whether you messaged a practice or hold an account, are on a single page:
13Children
The service is not directed to children. Accounts are held by practices and used by their staff. Where a practice treats a minor, the practice is responsible for the lawful basis on which it holds and shares that patient's information.
14International transfers
The infrastructure that holds patient data is located in the United States. Every subprocessor in section 7 that may process patient data stores and processes it there.
Ascend itself is established in Pakistan, and the people who operate and support the service access it from there. That access is an international transfer of data, including patient data, and we state it here rather than leaving a customer to discover it during diligence.
That access is bound by the same controls described in section 9: row level security enforced by the database, role gating on clinical records, and an audit row written for every clinical read. Where a customer requires specific transfer safeguards or data residency commitments, we agree them in that customer's agreement before signature.
15Changes and effective date
This policy was last updated on 20 August 2026. When we change it materially we will update that date and notify account holders by email.