IASORAReception OS
PrivacyTermsLogin

Trust & data protection

Privacy Policy

This policy explains what IASORA processes, why it is needed, how clinic and patient data stay separated, and how Google Calendar data is used only to provide scheduling features requested by the clinic.
Last updated · 22 August 2026

1. Who this policy covers

IASORA is a reception and scheduling software service for private clinics. This policy covers visitors to iasorahealth.com, clinic account users, people who contact IASORA, and data processed through the service on behalf of a clinic.

For patient booking and care-workflow data, the clinic normally acts as the data controller and IASORA acts as its processor under the clinic agreement and documented instructions. IASORA acts as a controller for its own account administration, security, support, billing and service-improvement records.

2. Data we process

  • Clinic and account data: clinic identity, business contact details, authorized users, roles, authentication records, package and billing status.
  • Scheduling configuration: services, durations, providers, locations, working hours, closures and appointment capacity rules.
  • Patient workflow data: information a patient provides to the clinic for a booking or follow-up, such as name, contact details, requested service, appointment details and consent evidence.
  • Communication records: message type, delivery state, timestamps and provider identifiers needed to confirm, retry, suppress or audit transactional communication.
  • Security and diagnostics: technical request data, tenant-scoped audit records, error fingerprints and operational health signals. IASORA is designed to exclude patient contact data, secrets and OAuth tokens from technical incident packets.

3. Google Calendar data

A clinic connects Google Calendar only through an explicit OAuth authorization. IASORA requests the following narrowly defined scopes because each one is required by a visible scheduling feature:

https://www.googleapis.com/auth/calendar.events

Create, update and cancel IASORA appointment events in the calendar selected by the clinic.

https://www.googleapis.com/auth/calendar.freebusy

Read free/busy time ranges so IASORA does not offer an unavailable appointment.

https://www.googleapis.com/auth/calendar.calendarlist.readonly

Show the clinic the calendars it can choose for a provider connection.

IASORA stores the selected calendar connection, encrypted OAuth credentials, token expiry, technical event identifiers and the minimum calendar metadata needed to maintain that connection. The booking engine uses free/busy time ranges to block unavailable slots. Events created by IASORA use operational scheduling information and are intentionally kept free of patient contact details and clinical notes.

IASORA does not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Human access is limited to explicit support, security or legal needs.

IASORA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

A clinic can disconnect a provider calendar from IASORA. Access is then revoked for that connection and stored credentials are removed according to the service's deletion workflow. A clinic can also revoke access directly from its Google Account security settings.

4. Why we process data

IASORA processes data only for defined operational purposes:

  • to authenticate authorized clinic users and protect accounts;
  • to understand booking requests and calculate valid availability;
  • to create, update, cancel and display appointments;
  • to send requested confirmations, reminders and follow-up messages;
  • to provide clinic support, billing, audit and security functions;
  • to comply with legal obligations and verified data-subject requests.

Depending on the context, processing is based on performance of a contract or pre-contract steps, legitimate interests in operating and securing the service, legal obligations, or consent. The clinic is responsible for selecting the appropriate legal basis for patient data it controls, including any special-category health data.

5. Service providers and transfers

IASORA uses specialist providers only where needed to operate the service, including Supabase for database and authentication services, Vercel for application hosting, Resend for transactional email, Stripe for billing, and Google when a clinic enables Calendar. AI providers are used only where the relevant function is explicitly enabled and its data-minimization and consent gates are satisfied.

Providers receive only the data required for their role and are subject to contractual and security controls. Where data is transferred outside the EEA, IASORA relies on an applicable transfer mechanism and supplementary safeguards required by law.

6. Retention and deletion

Data is retained only while needed for the clinic service, security, audit, billing and legal obligations. Retention depends on the data category and the clinic's documented instructions. Technical identifiers may be retained briefly after deletion to prevent a late provider retry from recreating a false incident; these records contain no patient name, email, phone number, message content or clinical information.

Verified patient deletion requests enter IASORA's protected erasure workflow. The system is designed to remove linked patient data across booking, communication and calendar mappings and to send a receipt without exposing deleted data. Clinics remain responsible for any records they must retain independently under healthcare or other law.

7. Your choices and rights

Depending on applicable law, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, and withdraw consent. Patients should normally contact the clinic that collected their data; IASORA supports clinics in fulfilling verified requests. You may also complain to the competent data-protection authority.

8. Security

IASORA applies tenant isolation, role-based access, encrypted credentials, least-privilege database controls, audit trails, idempotent workflows, backup/restore testing and production observability. No system can guarantee absolute security, but IASORA continuously monitors failures and is designed to preserve a patient request even when an external integration is unavailable.

9. Contact and policy changes

Privacy questions and verified requests can be sent to vlahinjatin@gmail.com. Commercial customers receive the contracting operator's full legal identity, address, processing terms and subprocessor information in their order form and data-processing agreement.

We may update this policy when the service, law or providers change. Material changes will be identified by a new update date and, where required, communicated directly to affected users.

IASORAReception OS

Reception & Scheduling OS for private clinics.

Privacy PolicyTerms of ServiceContact