Privacy Policy & GDPR

Effective: 1 January 2026 · Last updated: January 2026 · Data Controller: ASCENDIC · Contact: petra.mesarichorvat@ascendic.ai

Table of Contents

  1. Who We Are and GDPR Scope
  2. What Data We Collect
  3. How We Use Your Data
  4. Legal Bases for Processing
  5. Data Sharing and Third Parties
  6. Coaching Session Confidentiality
  7. AI Advisor and Data Processing
  8. Cookies
  9. International Transfers
  10. Data Retention
  11. Your Rights Under GDPR
  12. Children's Privacy
  13. Security
  14. Contact and Complaints

ASCENDIC is committed to protecting your privacy and handling your personal data with transparency and care. We comply with the EU General Data Protection Regulation (GDPR) and applicable national data protection laws.

1. Who We Are and GDPR Scope

ASCENDIC ("we", "us") is the data controller for personal data processed through the ASCENDIC platform at ascendic.ai and in the ASCENDIC mobile application. This Privacy Policy applies to all users — clients, coaches, and visitors — in the European Union and European Economic Area, as well as users in other jurisdictions where GDPR-equivalent standards apply.

2. What Data We Collect

2.1 Data You Provide Directly

2.2 Data Collected Automatically

2.3 Special Category Data

Coaching can involve sensitive personal topics (health, mental wellbeing, relationships). We treat all coaching-related personal data with heightened care. We process such data only on the basis of your explicit consent. You control what you share with coaches through the Platform.

3. How We Use Your Data

PurposeData UsedLegal Basis
Create and manage your accountAccount dataContract performance
AI coach matchingIntake / matching dataContract performance + Consent
Process paymentsPayment data via StripeContract performance
Deliver sessions and track progressSession data, notesContract performance
AI Advisor functionalitySession history, goals, preferencesConsent
Online course deliveryEnrolment, progress dataContract performance
Platform analytics and improvementUsage data, aggregatedLegitimate interest
Legal compliance and accountingTransaction records, identityLegal obligation
Marketing communicationsEmail, preferencesConsent (opt-in only)
Fraud prevention and securityAccount, IP, device dataLegitimate interest

4. Legal Bases for Processing

We rely on the following legal bases under GDPR Article 6:

5. Data Sharing and Third Parties

We do not sell your personal data. We share data only with:

6. Coaching Session Confidentiality

What you discuss in coaching sessions is confidential. Coaches on the ASCENDIC platform are bound by professional confidentiality obligations and ASCENDIC's Coach Terms. ASCENDIC does not access the content of coaching conversations. Session notes created by coaches are accessible only to the coach and, where shared, to the client. ASCENDIC staff do not have access to session content.

Important Note on AI Advisor

If you use the AI Advisor feature, anonymised and aggregated insights from your coaching goals and progress may be used to improve the AI system. This processing is subject to your explicit consent, which you can withdraw at any time in your account settings. Raw session notes are never used to train AI models without separate explicit consent.

7. AI Advisor and Data Processing

The AI Advisor processes your coaching goals, session summaries (where shared by you or your coach), and in-app interactions to provide personalised guidance. This processing requires your explicit consent. The AI system is not used for automated decision-making that produces legal or significant effects — all matching and recommendations are suggestions that require human action.

8. Cookies

We use the following types of cookies:

You can manage cookie preferences at any time via the cookie settings in your browser or the Platform settings menu.

9. International Transfers

Your data is primarily stored within the European Economic Area. Where data is transferred outside the EEA (e.g. certain cloud services), we ensure appropriate safeguards are in place — including EU Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.

10. Data Retention

Data TypeRetention PeriodReason
Account data (active)Duration of account + 30 daysService delivery
Account data (deleted)30 days after deletion requestFraud prevention
Transaction records7 yearsLegal / tax obligation (EU)
Session notesDuration of coaching relationship + 2 yearsCoach professional obligation
Analytics data24 months (aggregated)Platform improvement
Marketing consent recordsUntil consent withdrawn + 3 yearsCompliance documentation

11. Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights. To exercise any right, email petra.mesarichorvat@ascendic.ai — we will respond within 30 days.

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

"Right to be forgotten" — request deletion of your data, subject to legal retention obligations.

Right to Restriction (Art. 18)

Request that we limit processing of your data in certain circumstances.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format to transfer to another service.

Right to Object (Art. 21)

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Withdraw consent for any consent-based processing at any time, with effect going forward.

Right to Lodge a Complaint

Lodge a complaint with your national data protection authority (e.g. AZOP in Croatia).

12. Children's Privacy

The ASCENDIC Platform is not directed at children under 18. We do not knowingly collect data from minors. If you believe we have collected data about a minor, please contact us immediately and we will delete it.

13. Security

We implement appropriate technical and organisational measures to protect your data, including: TLS encryption for all data in transit; encryption at rest for sensitive data; access controls and authentication; regular security reviews; payment card data processed exclusively by Stripe (PCI-DSS compliant). In the event of a data breach that poses a high risk to your rights, we will notify you within 72 hours in accordance with GDPR Article 33.

14. Contact and Complaints

Data protection enquiries: petra.mesarichorvat@ascendic.ai

Croatian supervisory authority: Agencija za zaštitu osobnih podataka (AZOP)azop.hr

EU Online Dispute Resolution: ec.europa.eu/consumers/odr