Skip to content
// Ascend

Privacy policy

Ascend holds data in two different legal roles at once. This policy is written in that order, because the answer to almost every question below depends on which of the two applies to you.

Last updated 20 August 2026

01Who we are and how to reach us

Ascend provides an operating system for independent, appointment based practices, and a remote staffing service for the same practices. Ascend is a registered business name of an individual rather than a separate company, so the party responsible for your data is the proprietor trading under that name.

  • Responsible party: Hamraz Azam Khan Bangash, trading as Ascend
  • Registered in Lahore, Pakistan. A postal address is available on request.
  • Contact: info@goascend.co

02The two roles we act in

Read the role that applies to you. Sections 3, 6 and 11 (practice users) describe the first role. Sections 4, 5, 8 and 11 (patients) describe the second.

Role one: Ascend as controller

For people who visit goascend.co, submit the contact form, apply to join our staffing bench, or hold a login to the Ascend dashboard, we decide what happens to that data and we are the controller of it.

Role two: Ascend as processor and business associate

For patient data a practice puts into Ascend, the practice is the covered entity and the controller. Ascend acts on that practice's instructions as its processor, and in the United States as its business associate. A message a patient sends to a practice on Instagram or Facebook Messenger sits in this second category, because it is a patient communication that belongs to the practice.

03Information we collect as controller

  • Contact form: name, practice name, email, phone, number of locations, approximate patient count, the systems you use today, and anything you write in the free text box.
  • Talent applications: name, contact details, CV content and work history.
  • Account data: name, email, organisation, role and authentication identifiers.
  • Usage and diagnostics: pages viewed, errors encountered, and approximate location derived from IP address.

04Information we process on behalf of practices

A practice decides what to put into Ascend. The categories below are what the platform is built to hold.

  • Contact records: name, phone, email, date of birth and consent state.
  • Appointment and visit history.
  • Message content across web chat, SMS, WhatsApp, Instagram Direct and Facebook Messenger, in both directions.
  • Platform scoped identifiers from Meta, meaning page scoped IDs for Instagram and Messenger users, used only to route a reply back to the right conversation.
  • Clinical records a practice chooses to store, including consultation notes, standing clinical facts and charges.
  • Media a practice uploads, including case photographs and their recorded consent state.

05Meta platform data, specifically

This section describes exactly what Ascend does with data obtained through Instagram and Facebook, and applies only where a practice has connected its own business accounts.

Permissions we request and why

  • pages_messaging and instagram_manage_messages: to receive and reply to messages sent to the practice's own accounts.
  • pages_show_list and instagram_basic: to let the practice select which of its accounts to connect.
  • pages_manage_metadata: to subscribe to message webhooks for the connected account.

Scope of access

We access only messages sent to or from the connected business account. We do not access a person's personal profile content, their friends or connections, or their activity anywhere else on Instagram or Facebook.

How message content is processed

Message content is sent to Anthropic to generate a draft reply or an automated reply on the practice's behalf. Anthropic does not train its models on this content.

What we never do with it

We do not sell, rent or share this data with advertisers or data brokers, and we do not use it to build advertising profiles.

Retention and disconnection

  • Message content is retained for the life of the practice's account and is then deleted as described in section 10 and on the data deletion page.
  • A practice can disconnect its Meta accounts at any time from Settings, which stops all access immediately.

06How we use information

  • Operating the service for the practice that holds the account.
  • Generating replies, drafts and recommendations.
  • Sending consent checked outreach on a practice's behalf.
  • Security, abuse prevention and service support.
We do not use this information for advertising, we do not sell it, and we do not use it to train a general purpose model.

07Subprocessors

Only the subprocessors marked below may process patient data. The rest are architected so that patient data never reaches them.

SubprocessorPurposePatient data
AnthropicAI reasoning and draftingYes
TwilioSMS and WhatsApp messagingYes
NeonApplication databaseYes
RenderApplication hostingYes
Meta PlatformsInstagram Direct and Facebook Messenger message transportYes
ClerkStaff authenticationNo
ResendDelivers enquiries sent through this websiteNo
VercelMarketing site and dashboard hostingNo
InngestBackground jobsNo
SentryError monitoringNo

Resend appears on this list because it delivers the enquiry and application forms on this website. Those forms collect business contact details from the person filling them in, never patient data.

09Security

  • Row level security enforced by the database, so one practice's data cannot be returned to another even if application code forgets to filter.
  • Role gated access to clinical records.
  • An append only access log: opening a clinical record writes an audit row inside the same transaction as the read, and if the log write fails the read fails.
  • Encryption in transit.
  • Least privilege database roles.

10Retention

  • Account and practice data: for the life of the account plus 30 days, then deleted.
  • Diagnostics: 90 days.
  • Where a legal obligation requires us to keep a record for longer, we keep only what that obligation requires, for only as long as it requires.

11Your choices

If you are a patient of a practice

Replying STOP to any SMS or WhatsApp message opts you out immediately and permanently from marketing on that channel. Replying START opts you back in. A request about your own record goes to the practice you are a patient of, because the practice holds that record and we act on its instructions.

If you hold an Ascend account

You can ask us to access, correct, export or delete your data by emailing us, and we respond within 30 days. This is not yet a self-serve action inside the dashboard, and we would rather say so than point you at a button that is not there.

12Deletion

Full instructions for having your data deleted, whether you messaged a practice or hold an account, are on a single page:

goascend.co/legal/data-deletion

13Children

The service is not directed to children. Accounts are held by practices and used by their staff. Where a practice treats a minor, the practice is responsible for the lawful basis on which it holds and shares that patient's information.

14International transfers

The infrastructure that holds patient data is located in the United States. Every subprocessor in section 7 that may process patient data stores and processes it there.

Ascend itself is established in Pakistan, and the people who operate and support the service access it from there. That access is an international transfer of data, including patient data, and we state it here rather than leaving a customer to discover it during diligence.

That access is bound by the same controls described in section 9: row level security enforced by the database, role gating on clinical records, and an audit row written for every clinical read. Where a customer requires specific transfer safeguards or data residency commitments, we agree them in that customer's agreement before signature.

15Changes and effective date

This policy was last updated on 20 August 2026. When we change it materially we will update that date and notify account holders by email.