Terms and GDPR
General Terms and Conditions, Privacy Policy (GDPR) and NDA of the iAsist platform.
PART I: General Terms and Conditions
1. Introductory provisions and contracting parties
The platform iAsist is operated by Alavia Education s.r.o., Company ID: 04579356, VAT ID: CZ04579356, registered office: Sládkova 372/8, Ostrava, Czech Republic (hereinafter the "Operator"). The user of the platform is a natural or legal person (typically a virtual assistant) who completes the registration process on the iAsist website. A consumer is a User — a natural person — who concludes the contract outside the scope of their business activity.
2. Subject of service
The Operator grants the User a non-exclusive right to use the Platform in the form of Software as a Service (SaaS). The Platform is primarily used to organise the work of virtual assistants, including client management (CRM), time tracking, invoicing, contract generation and a client portal.
3. User rights and obligations and data ownership
- 100% data ownership: All data (client databases, invoices, timesheets, documents) that the User uploads to the Platform remain the exclusive property of the User. The Operator makes no claim to this content.
- Data export: The User has the right to export their data from the Platform at any time in a machine-readable format.
- Prohibited activities: The User undertakes not to use the Platform for sending spam, uploading malicious code (viruses) or any activity in breach of applicable EU and national law.
- Account security: The User is fully responsible for the security of their login credentials.
4. Payment terms and subscription
The Platform is provided on a subscription model. The first 45 days of use are provided free of charge as a trial period. After this period, use is charged according to the current price list. Payments are processed via the secure payment gateway Stripe. The subscription renews automatically until cancelled by the User.
5. Limitation of liability
The Platform is provided "as is". The Operator does not guarantee 100% continuous availability of the service and is not liable for outages caused by third parties.
- Exclusion of liability for damages: To the maximum extent permitted by law, the Operator is not liable for any direct or indirect damages, including lost profits, data loss or other intangible losses arising from the use of or inability to use the Platform.
- Maximum liability limit: The Operator's total liability is limited to the amount paid by the User to the Operator for use of the Platform in the last 12 months.
6. Termination and account management
An entity that does not use a paid plan and whose account shows no activity for 180 days will be considered inactive. Entity administrators will receive a warning by email. If activity is not resumed within 30 days of the warning, the entity including all data will be permanently deleted. This deletion is irreversible.
7. Consumer right of withdrawal
A consumer has the right to withdraw from a distance contract within 14 days of its conclusion without giving any reason (Directive 2011/83/EU as implemented in national law). If the consumer expressly requested that the provision of the service begins during the withdrawal period (by ticking the relevant box at purchase), the right of withdrawal is not thereby lost, but the Operator is entitled to a proportionate part of the price for services provided up to the moment of withdrawal. The right of withdrawal is extinguished once the service has been fully performed with the consumer's prior express consent. Withdrawal may be sent by email to info@iasist.cz; the consumer may use the model form below.
Annex 1 — Model withdrawal form
(Complete and return this form only if you wish to withdraw from the contract)
To: Alavia Education s.r.o., Sládkova 372/8, Ostrava, Czech Republic, Company ID: 04579356, VAT ID: CZ04579356, Email: info@iasist.cz
I/We(*) hereby give notice that I/we(*) withdraw from my/our(*) contract for the provision of the following service:
Name of service: ………………………………… | Date of conclusion of the contract: ………………………………… | Name of consumer(s): ………………………………… | Address of consumer(s): ………………………………… | Signature of consumer(s) (only if this form is notified on paper): ………………………………… | Date: …………………………………
(*) Delete as appropriate.
8. Changes to these Terms
The Operator will notify the User of any change to these Terms by email at least 14 days before the change takes effect. A User who does not accept the change may terminate the contract before its effective date without any penalty. Continued use of the Platform after the effective date is deemed acceptance of the change.
9. Governing law and dispute resolution
The legal relationship between the Operator and the User is governed by Czech law. This does not affect the consumer's rights under mandatory provisions of the law of their habitual residence. Consumers have the right to out-of-court resolution of consumer disputes with an alternative dispute resolution entity in their EU member state; for users in the Czech Republic this is the Czech Trade Inspection Authority (www.coi.cz). A list of consumer dispute resolution bodies in EU member states is available at:
https://consumer-redress.ec.europa.eu/dispute-resolution-bodies
PART II: Privacy Policy and GDPR
1. Basic role definitions
- Operator as Controller: With respect to the personal data of Users (assistants) themselves, the Operator acts as the Controller (name, email, billing details).
- Operator as Processor: With respect to client data entered into the system by the assistant, the User acts as the Controller and the iAsist Operator as the Processor (pursuant to Art. 28 of the GDPR).
2. Scope and purpose of processing
- Account creation: First name, last name, email, password (Performance of contract).
- Invoicing: Billing details, company ID, payment history (Legal obligation).
- Support: Communication logs, IP addresses (Legitimate interest).
3. Data processing agreement (Art. 28 GDPR)
The Operator undertakes to process data only on the basis of the User's instructions via the application and to ensure data security at SSL encryption level and at-rest database encryption. The database and hosting of personal data are located exclusively in the European Union. The Operator uses the following sub-processors: Supabase, Cloudflare and Lovable (hosting and database, EU); Postmark (sending transactional e-mails); Stripe (payment processing); Anthropic (Claude API for AI iAsist features). The Operator has concluded data processing agreements pursuant to Art. 28 GDPR with all sub-processors. For sub-processors established outside the EU/EEA (in particular Postmark, Stripe, Anthropic), transfers are safeguarded by the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
4. Retention period for personal data
Personal data associated with inactive entities without a paid plan are retained for a maximum of 210 days from the last activity (180 days of inactivity + 30-day period after notification), after which they are permanently deleted in accordance with the data minimisation principle under Art. 5(1)(e) of the GDPR.
5. Google user data (Google API Services)
If the User connects their Google account to the Platform (Google Calendar or Google Drive integration), the Platform accesses only the data necessary for the given integration to work: calendar events, files that the User creates or selects within the Platform, and the Google account email address for identification purposes.
- Scope of access: The Platform requests access only to the minimum necessary extent. For Google Drive, this is a permission limited exclusively to files and folders the User has created or explicitly selected within the Platform — the Platform has no access to any other files on the User's Drive. For Google Calendar, this is a permission to read and write events in the calendars whose identifier the User uses within the Platform, without general access to manage or delete entire calendars of the account.
- Data sharing: We do not sell, share or transfer Google User Data to third parties, and we do not use it for advertising or profiling, with the sole exception of the sub-processors necessary to operate the Platform. If the User uses the AI iAsist feature and asks a question related to the calendar or schedule, event data from the connected Google Calendar (title, time, place) may be transmitted to the AI provider (Anthropic, Claude API) solely to process that question; Anthropic does not use this data to train its models. Data from Google Drive does not reach the AI iAsist feature or Anthropic in any form. Google User Data is not otherwise shared with any other third party.
- Retention and deletion: Google Drive: The Platform does not store the content of Drive files — these remain solely on the User's Drive; we store only the identifier of the connected folder/file and an encrypted access token, which is permanently deleted immediately upon disconnection by the User (Settings → Storage → Disconnect). Google Calendar: we store a mirrored copy of event data (title, time, description, place) for display in the Platform's unified calendar; this data is permanently deleted immediately upon disconnection of Google Calendar (Settings → Calendar → Disconnect). In both cases, permanent deletion also occurs automatically upon full deletion of the User's account.
- Limited Use: iAsist's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data subject rights
Anyone whose personal data the Operator processes as Controller has the right of access to their data, the right to rectification, erasure, restriction of processing, data portability, the right to object to processing based on legitimate interest, and the right to withdraw consent at any time. Requests may be submitted by email to info@iasist.cz; the Operator will respond without undue delay, at the latest within one month. The data subject also has the right to lodge a complaint with a supervisory authority — for the Operator the lead authority is the Czech Office for Personal Data Protection (www.uoou.gov.cz) — or with the supervisory authority in the member state of their habitual residence. Requests concerning data entered into the Platform by a virtual assistant acting as Controller will be forwarded by the Operator to the relevant assistant.
PART III: Non-Disclosure Agreement (NDA)
1. Subject of confidential information
Confidential information means all data entered by the User into the Platform. This includes in particular client databases, financial transactions, invoices, time tracking records, task structures and the content of generated contracts.
2. Operator's commitment
The Operator expressly undertakes to maintain absolute confidentiality of all uploaded data. It will not use confidential information for its own benefit, will not copy it, and will not disclose, sell or otherwise make it available to third parties. It will not carry out any content data analytics for the purpose of commercial profiling for third parties.
Last updated: 10 July 2026