Privacy Policy
Last updated: July 13, 2026
This Privacy Policy explains how Aotoz (“we”, “us”, or “our”) collects, uses, stores, and shares information when you use our scheduling platform and services at https://aotoz.com.
1. Overview
Aotoz is a multi-tenant scheduling SaaS platform used by businesses (“Operators”) to offer appointment booking to their own customers (“End Users”). This policy covers both relationships.
We act as a data processor for Operators and as a data controller for information we collect about Operators and their account users. Operators are responsible for the privacy rights of their own End Users.
By using Aotoz, you agree to the collection and use of information as described in this policy.
2. Information We Collect
Account & operator information
- Name, email address, and password when you create an account
- Organization name, industry, timezone, and branding preferences
- Billing information (processed securely by our payment provider — we do not store full card numbers)
- IP addresses and browser/device information for security and fraud prevention
Booking & scheduling data (processed on behalf of Operators)
- Customer names, email addresses, and phone numbers entered by Operators or End Users
- Appointment dates, times, services, and notes
- Responses to intake forms created by Operators
- Payment amounts, coupon codes, and transaction status
Usage & technical data
- Pages visited, features used, and time spent on the platform
- API requests, response times, and error logs
- Cookie identifiers and session tokens
Third-party integrations (when you connect them)
- Google Calendar: event data and free/busy information (only when you connect your Google account)
- Email providers: delivery status and open rates for notifications
3. How We Use Information
We use information we collect to:
- Provide, operate, and improve the Aotoz platform
- Send transactional emails (booking confirmations, reminders, password resets)
- Process payments and prevent fraud
- Respond to support requests and communicate about your account
- Generate aggregated analytics to improve the product
- Comply with legal obligations
- Send product updates and marketing communications (you may opt out at any time)
We do not sell your personal data or your customers’ data to third parties. We do not use your booking data for advertising purposes.
5. Data Retention
We retain data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
- Account data: Retained until account deletion, then deleted within 90 days
- Booking records: Retained for 7 years for financial compliance purposes unless you request earlier deletion
- Audit logs: Retained for 2 years
- Session and security logs: Retained for 90 days
You may request deletion of your account and data at any time by contacting privacy@aotoz.com. Some data may be retained where required by law.
6. Security
We implement industry-standard technical and organizational measures to protect your data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Tenant isolation — each workspace’s data is logically separated
- Granular role-based access controls
- Immutable audit logs for all sensitive operations
- Regular security reviews and dependency updates
- Bcrypt password hashing — we never store plain-text passwords
No system is completely secure. If you discover a security vulnerability, please report it responsibly to security@aotoz.com.
7. Healthcare Data (HIPAA)
Aotoz provides technical controls that healthcare organizations can use to support HIPAA compliance, including PHI access logging, audit trails, role-based permissions, and retention controls.
Important: These controls do not make Aotoz automatically HIPAA-compliant for your organization. HIPAA compliance also requires your organization to:
- Execute a Business Associate Agreement (BAA) with Aotoz
- Maintain appropriate internal policies and staff training
- Conduct a risk assessment
- Implement required administrative and physical safeguards
To request a BAA, contact privacy@aotoz.com. BAAs are available on Business and Enterprise plans.
Protected Health Information (PHI) entered into Aotoz is processed on behalf of the covered entity Operator. Aotoz acts as a Business Associate under HIPAA when processing PHI.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (right to erasure)
- Portability: Receive your data in a machine-readable format
- Restriction: Request that we restrict processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent, withdraw it at any time
EU/EEA and UK residents have these rights under GDPR/UK GDPR. California residents have rights under CCPA/CPRA. To exercise any right, contact privacy@aotoz.com.
We will respond to rights requests within 30 days. We may ask you to verify your identity before processing requests.
10. Children's Privacy
Aotoz is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us at privacy@aotoz.com and we will delete it promptly.
11. International Data Transfers
Aotoz is operated from servers in the European Union and the United States. If you are located outside these regions, your data may be transferred to and processed in countries with different data protection laws.
For transfers from the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or other lawful transfer mechanisms. For transfers from the UK, we use the UK International Data Transfer Agreement (IDTA) or equivalent mechanisms.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a prominent notice on the platform at least 30 days before the change takes effect.
Continued use of Aotoz after the effective date constitutes acceptance of the updated policy. If you do not agree with the changes, you may close your account before the effective date.
13. Contact Us
For privacy-related questions, requests, or complaints, contact us at:
If you are an EU/EEA resident and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.
See also: Terms of Service · Security · Contact