This Privacy Policy explains how [Legal Entity] ("AsherSupport", "we", "us", or "our") collects, uses, shares, and protects personal information in connection with the AsherSupport platform — a business-to-business help desk and scheduling service that lets organizations run customer support desks, communicate with their own end-users, and book meetings. AsherSupport is operated by [Legal Entity], a company organized under the laws of [Jurisdiction], with its registered office at [Company Address].
We take a deliberately clear approach to a distinction that matters throughout this document: for some data we are the party that decides why and how it is processed (a controller), and for other data we merely handle it on behalf of our customers under their instructions (a processor). The section below explains both roles.
1. Who we are and the scope of this policy
This policy applies to the AsherSupport marketing website, the account dashboard, the customer subdomain portals we provision (for example, your-company.ashersupport.com), our APIs, and related services (collectively, the "Service"). It does not apply to third-party websites, products, or services that may link to or integrate with the Service, which are governed by their own privacy notices.
2. Controller vs. processor: our two roles
AsherSupport handles two broad categories of personal data, and our responsibilities differ depending on the category.
When we act as a controller
We are the controller for the personal data we collect to run our own business and provide the Service to our customers. This includes account and profile information for the administrators and agents who sign up, billing information, and data about how those users interact with our website and dashboard. For this data, we decide the purposes and means of processing, and this Privacy Policy governs it directly.
When we act as a processor
We are a processor for the personal data that our customers submit, upload, or collect through their desks — for example, the content of support tickets, messages from an end-user seeking help, contact records, and scheduling or booking details captured through a customer's portal. For that data, the customer is the controller and decides why and how it is processed; AsherSupport processes it only on the customer's documented instructions, as set out in our Terms of Service and, where applicable, a Data Processing Addendum (DPA).
If you are an end-user who contacted a business that uses AsherSupport and you have questions about your data or want to exercise your rights over it, please contact that business directly — they are the controller. See Section 11 for how we route such requests.
3. Information we collect
The categories below describe information we collect in our role as controller, unless noted.
- Account and profile information. Name, email address, password (stored hashed), organization name, job title, subdomain choice, profile picture, and preferences you set for administrators and agents.
- Billing information. Subscription plan, billing contact details, and transaction records. Card and bank details are collected and stored by our payment processor; we receive limited information such as the last four digits of a card and its expiry.
- Usage and log data. IP address, browser and device type, operating system, pages viewed, features used, referring URLs, timestamps, and diagnostic or error logs.
- Cookies and device data. Identifiers and settings stored on your device through cookies and similar technologies. See Section 6.
- Support tickets and messages (as processor). The content of tickets, conversations, attachments, and notes that our customers and their end-users create within a desk.
- Contacts (as processor). End-user contact records — names, email addresses, and any other fields a customer chooses to store about the people they support.
- Scheduling and booking data (as processor). Meeting requests, availability, booking details, and video-meeting metadata created when end-users schedule time with a customer.
4. How we use information
- Provide and operate the Service — create and manage accounts, provision subdomain portals, deliver tickets and messages, and enable scheduling and video meetings.
- Secure the Service — authenticate users, detect and prevent fraud and abuse, monitor for security incidents, and maintain the integrity of our systems.
- Improve the Service — understand how features are used, troubleshoot problems, and develop new functionality. We use aggregated or de-identified data where practical.
- Billing and administration — process subscriptions, invoices, and payments, and manage renewals and cancellations.
- Communications — send service, security, and transactional messages, respond to inquiries, and (where permitted) send product updates you can opt out of.
- Legal compliance — comply with applicable laws, respond to lawful requests, and enforce our agreements.
When we act as a processor, we use the data described in Section 2 only to provide the Service to the relevant customer and per that customer's instructions.
5. Legal bases for processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or another region with similar laws, we rely on the following legal bases when we act as a controller:
- Performance of a contract — to provide the Service you or your organization have signed up for and to administer billing.
- Legitimate interests — to secure and improve the Service, prevent abuse, and communicate about our products, balanced against your rights and freedoms.
- Consent — for non-essential cookies and certain marketing communications, where required. You may withdraw consent at any time.
- Legal obligation — to comply with tax, accounting, and other legal requirements.
6. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. You can control non-essential cookies through your browser and our cookie controls. For details on the specific cookies we use, see our Cookie Policy.
7. Sharing and subprocessors
We do not sell personal data. We share it only as described here, and every vendor that processes personal data on our behalf is bound by a written data-processing agreement that limits their use of the data to providing services to us and requires appropriate security measures. We share information with the following categories of recipients:
- [cloud hosting provider] — hosts and runs the Service infrastructure.
- [database/Postgres host] — stores account, desk, and application data in a managed Postgres/Supabase database.
- [email delivery provider] — sends transactional and notification email on our behalf.
- [Zoom for video meetings] — powers scheduled video meetings booked through the Service.
- [payment processor] — processes subscription payments and stores cardholder data.
- Professional advisers and authorities — we may disclose data to legal, accounting, or regulatory bodies where required by law, or in connection with a merger, acquisition, or sale of assets (subject to this policy).
Subprocessors
The table below summarizes the subprocessors we engage and their purpose.
| Subprocessor | Purpose | Data categories |
|---|---|---|
| [cloud hosting provider] | Application hosting and compute | All Service data in transit and at rest |
| [database/Postgres host] | Managed database and storage | Account, ticket, contact, and scheduling data |
| [email delivery provider] | Transactional and notification email | Email addresses, message content |
| [Zoom for video meetings] | Video meetings for scheduled bookings | Meeting metadata, participant details |
| [payment processor] | Subscription billing and payments | Billing contact and payment details |
8. International data transfers
We and our subprocessors may process personal data in countries other than the one in which you are located, including the United States. Where we transfer personal data across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary technical and organizational measures where needed.
9. Data retention and deletion
We retain personal data for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data category:
- Account and desk data is retained for the life of the account.
- Billing records are retained as required by tax and accounting law.
- Logs and diagnostics are retained for a limited period, then deleted or de-identified.
On account closure, we make the account's data available for export for a limited window and then delete it from active systems, with residual copies removed from backups on our normal backup rotation. When we act as a processor, we return or delete customer data as directed by the customer per the applicable DPA.
10. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit (TLS), encryption of data at rest where supported by our infrastructure, role-based access controls, network isolation between customer subdomains, audit logging, and regular review of our security practices. For customers with heightened requirements, a self-hosted option lets you run AsherSupport within your own infrastructure so that support data never leaves your environment. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your privacy rights
GDPR / UK GDPR
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Port your data to another provider in a machine-readable format.
- Object to processing based on legitimate interests or for direct marketing.
- Restrict processing in certain circumstances.
You also have the right to lodge a complaint with your local data protection authority.
CCPA / CPRA (California)
California residents may have the right to:
- Know what personal information we collect, use, and disclose.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information.
AsherSupport does not sell personal data and does not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights.
To exercise any right, contact us at [privacy@ashersupport.com]. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent to submit a request on your behalf.
12. Data we process on behalf of customers (their end-users)
Much of the data flowing through a desk — tickets, messages, contacts, and bookings — belongs to our customers, who are the controllers of that data. If you are an end-userof a business that uses AsherSupport and you wish to access, correct, or delete your data, or exercise any other right, you should direct your request to that business. If you send such a request to us, we will route it to the relevant customer and assist them in responding as required by the applicable DPA, but we generally cannot act on that data without the customer's instructions.
13. Children
The Service is intended for businesses and is not directed to children under [13/16]. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.
15. How to contact us
For privacy questions, requests, or to reach our Data Protection Officer, contact:
- Email: [privacy@ashersupport.com]
- Entity: [Legal Entity]
- Address: [Company Address]
- Governing jurisdiction: [Jurisdiction]