Data Processing Agreement (DPA)

Last updated: April 2026 — Version 1.0

This translation is provided for information only; in the event of any discrepancy, the Spanish version shall prevail.

This Data Processing Agreement (hereinafter, the "DPA") is incorporated by reference into the Terms and Conditions of the Agendio Service (hereinafter, the "Terms") and forms an integral part of them. In the event of any conflict between this DPA and the Terms regarding the protection of personal data, this DPA shall prevail.

This DPA is deemed to be entered into between:

  • CEDESA DIGITAL SL, owner of the Agendio brand, with Spanish tax ID (NIF) B06684369 and registered address at Campus Universitario, Avda. de la Investigación S/N, Edificio PCTEX Oficina 2.1, 06006 Badajoz (Spain), hereinafter "Agendio" or "the Processor".
  • The Customer identified in the Agendio Account, hereinafter "the Controller".

(Together, "the Parties".)

1. Definitions

Capitalised terms not defined herein shall have the meaning given to them in the Terms. In addition:

  • GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
  • Data Protection Laws: the GDPR, Spanish Organic Law 3/2018 (LOPDGDD) and any other applicable data protection legislation.
  • Personal Data: the personal data (within the meaning of Article 4(1) GDPR) that the Controller, its employees or its Data Subjects enter or generate when using the Service and that are processed by the Processor on behalf of the Controller.
  • Data Subject: the natural person to whom the Personal Data relate (typically, the Controller's end customer who makes a booking).
  • Sub-processor: a third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • SCCs: the Standard Contractual Clauses approved by the European Commission by means of Commission Implementing Decision (EU) 2021/914.
  • Security Breach: a breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, the Personal Data (Article 4(12) GDPR).

2. Roles and subject matter

The Controller determines the purposes and means of the processing of the Personal Data and acts as controller within the meaning of Article 4(7) GDPR. The Processor processes the Personal Data solely on behalf of the Controller and acts as processor within the meaning of Article 4(8) GDPR.

The subject matter, duration, nature, purpose, categories of data and categories of Data Subjects are described in Annex I.

3. Controller's instructions

3.1. The Processor shall process the Personal Data only on the documented instructions of the Controller, unless required to do so by law (in which case it shall inform the Controller, unless the law prohibits this).

3.2. The Controller's documented instructions are: (i) those set out in the Terms and in this DPA; (ii) the settings the Controller configures through the admin dashboard (retention policies, automations, templates, opt-ins, etc.); (iii) any additional written instruction communicated to the Processor through the official support channels.

3.3. The Processor shall inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.

4. Processor's obligations

The Processor undertakes to:

  • a) Process the Personal Data only in accordance with the Controller's instructions (clause 3).
  • b) Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • c) Implement the appropriate technical and organisational measures described in Annex III to ensure a level of security appropriate to the risk (Article 32 GDPR).
  • d) Respect the conditions for engaging Sub-processors set out in clause 5 and Annex II.
  • e) Assist the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests from Data Subjects to exercise their rights (clause 6).
  • f) Assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, breaches, impact assessments and prior consultation), taking into account the nature of the processing and the information available to the Processor.
  • g) At the Controller's choice, delete or return all the Personal Data once the provision of the Service has ended, and delete existing copies, unless retention is required by law.
  • h) Make available to the Controller all information necessary to demonstrate compliance with the obligations of this DPA, and allow for and contribute to audits in accordance with clause 8.

5. Sub-processors

5.1. General authorisation. The Controller authorises the Processor to engage the Sub-processors listed in Annex II and to engage new Sub-processors to provide the Service, in accordance with Article 28(2) GDPR (general written authorisation).

5.2. Notification of changes. The Processor shall notify the Controller at least 30 days in advance (by email or by notice on the Platform) of the addition or replacement of Sub-processors that process Personal Data. Annex II will be updated accordingly.

5.3. Right to object. The Controller may object, on reasoned grounds, to a new Sub-processor within 30 days of the notification. In that case, the Parties shall negotiate a solution in good faith. If no solution is reached, the Controller may terminate the part of the Service that depends on that Sub-processor, with the right to a proportional refund of the unused subscription.

5.4. Obligations imposed on Sub-processors. The Processor shall enter into a written contract with each Sub-processor imposing data protection obligations no less protective than those of this DPA, in accordance with Article 28(4) GDPR. The Processor shall remain liable to the Controller for any failure by any Sub-processor to fulfil its obligations.

6. Assistance to the Controller: Data Subjects' rights

6.1. The Processor shall make functionality available to the Controller within the Platform to respond to Data Subjects' requests for access, rectification, erasure, restriction, portability and objection.

6.2. If a Data Subject submits a request directly to the Processor, the Processor shall forward it to the Controller without undue delay and shall refrain from responding to the Data Subject, unless instructed otherwise by the Controller.

6.3. The Processor shall provide reasonable assistance to the Controller in handling such requests. Additional assistance beyond what can reasonably be automated may be invoiced to the Controller at standard support rates.

7. Security Breaches

7.1. The Processor shall notify the Controller of any Security Breach affecting the Controller's Personal Data without undue delay and in any event within 48 hours of becoming aware of it.

7.2. The notification shall include, to the extent known at that time: (i) a description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (ii) the contact details of the Processor's DPO; (iii) the likely consequences; (iv) the measures taken or proposed to mitigate its effects.

7.3. Where it is not possible to provide the information at the same time, it shall be provided in phases without further undue delay.

7.4. Notification of a Security Breach by the Processor does not constitute an acknowledgement of fault or liability in respect of the incident.

8. Audits

8.1. The Processor shall provide the Controller, at the Controller's request, with the most recent audit reports (for example, ISO 27001, SOC 2 or equivalent reports it is able to obtain), together with up-to-date descriptions of the technical and organisational measures (Annex III).

8.2. If the above information is not sufficient to demonstrate compliance, the Controller may request an additional audit, which shall be carried out:

  • With at least 30 days' notice.
  • No more than once a year, except for justified cause (for example, an instruction from a supervisory authority or following a Security Breach).
  • During the Processor's business hours and in a manner that does not disrupt its operations.
  • By an independent auditor bound by a duty of confidentiality and agreed upon by both Parties (who may not be a competitor of the Processor).
  • At the Controller's expense, unless a material breach of the DPA is found, in which case the cost shall be borne by the Processor.

9. International transfers

9.1. The Processor may transfer Personal Data outside the European Economic Area only to Sub-processors that provide appropriate safeguards under Chapter V GDPR: an adequacy decision, Standard Contractual Clauses (SCCs), the EU-U.S. Data Privacy Framework or another valid mechanism.

9.2. The SCCs are deemed to be incorporated into this DPA by reference in respect of the relevant transfers, with the following parameters:

  • Applicable module: Module 3 (processor to processor) where the Processor transfers data to a Sub-processor outside the EEA.
  • Clause 7 (docking clause): applies.
  • Clause 9 (use of sub-processors): Option 2, general authorisation with 30 days' prior notice.
  • Clause 11 (redress): the optional independent dispute resolution mechanism does not apply.
  • Clause 17 (governing law): Spanish law.
  • Clause 18 (choice of forum and jurisdiction): Spanish courts.

9.3. Annex II identifies the Sub-processors located outside the EEA and the safeguard applicable to each of them.

10. Return and deletion of data

10.1. When the provision of the Service ends (on termination of the Terms or at the express request of the Controller), the Processor shall make available to the Controller, for a period of 30 days, an export tool to download the Personal Data in a structured, commonly used format.

10.2. Once that period has elapsed, the Processor shall delete the Personal Data from its production systems within a maximum of 30 additional days, and from its backup systems within their normal rotation cycle (maximum 90 days).

10.3. The Processor may retain Personal Data beyond the above periods only where required by applicable law (for example, tax or commercial law), for the time strictly necessary and with appropriate security measures.

11. Liability

11.1. Each Party's liability arising from this DPA shall be subject to the limitations of liability set out in the Terms.

11.2. The foregoing does not limit either Party's liability towards Data Subjects under Article 82 GDPR or towards supervisory authorities.

12. Term and termination

12.1. This DPA shall enter into force upon acceptance of the Terms and shall remain in force for as long as the contractual relationship lasts.

12.2. Obligations which by their nature are intended to survive termination (in particular those relating to confidentiality, return/deletion and cooperation with authorities) shall remain enforceable.

13. Final provisions

13.1. Amendments. The Processor may amend this DPA to reflect regulatory changes or operational adjustments. Material changes will be notified 30 days in advance.

13.2. Governing law and jurisdiction. This DPA is governed by Spanish law and, where applicable, by the GDPR. For any dispute, the Parties submit to the courts and tribunals of the Processor's registered address.

13.3. Acceptance. The Controller expressly accepts this DPA by accepting the Terms when the Account is created. Customers who require a physical signature may request a copy for signature from privacidad@agendio.es.

Annex I — Description of the processing

A. Subject matter and duration

  • Subject matter: provision of the Agendio Service described in the Terms (automated booking management via WhatsApp, access control, calendar synchronisation).
  • Duration: for as long as the contractual relationship between Agendio and the Customer lasts, plus the retention periods set out in clause 10.

B. Nature and purpose of the processing

Collection, storage, organisation, consultation, disclosure by transmission, alteration, erasure and blocking of Personal Data, for the purpose of providing the Service to the Controller: managing Data Subjects' bookings, sending and receiving messages via the WhatsApp Business Cloud API, synchronising events with external calendars (Google Calendar) if the Controller sets this up, and providing operational analytics and reports to the Controller.

C. Categories of Personal Data

  • Data Subject identification data: name, phone number, email address (if provided).
  • Booking data: date, time, number of people, preferences.
  • Content of communications: messages exchanged through the chatbot, with their date, time and status.
  • Technical metadata: WhatsApp identifiers, internal Platform identifiers.
The Controller undertakes not to enter into the Platform any special categories of data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR), unless expressly configured in advance with the Processor.

D. Categories of Data Subjects

  • The Controller's end customers who make bookings or communicate with the business.
  • The Controller's employees or collaborators authorised to use the Platform.

E. BYO-WABA model and the Controller's third-party connections

The Controller connects its own accounts on third-party services to the Platform, of which it is the sole owner and administrator vis-à-vis the respective providers. In particular:

  • WhatsApp Business Account (WABA): the Controller owns its WABA vis-à-vis Meta. It accepts the WhatsApp Business Data Processing Terms directly with Meta when creating the WABA. The Controller decides the configuration of its WABA, including the storage region (Local Storage) for messages at rest, template approval, Data Subjects' opt-in and its business's messaging policy.
  • Google Account (Google Calendar): the Controller owns its Google account and grants Agendio access via OAuth 2.0 with the strictly necessary scope (calendar.events).

The Processor acts solely as an orchestration and integration layer between these accounts of the Controller and the Platform. The Processor is neither the owner nor the administrator of the Controller's accounts and does not make decisions about their configuration. Decisions on storage region, retention and the policies of each third-party service rest with the Controller as the account owner.

Annex II — Authorised sub-processors

As of the date of this DPA, the Processor uses the following Sub-processors:

Sub-processor Service provided Processing location International transfer safeguard
YCloud Pte. Ltd. WhatsApp Business API Business Solution Provider (routing layer) Singapore SCCs Module 3 (specific DPA with the sub-processor pending formalisation)
Meta Platforms Ireland Ltd. WhatsApp Business Cloud API infrastructure (ownership of the Controller's WABA) Ireland N/A (EEA)
Meta Platforms, Inc. WhatsApp Business Cloud API infrastructure USA SCCs + EU-U.S. Data Privacy Framework
Google LLC Google Calendar API (when the Controller connects it via OAuth) USA SCCs + EU-U.S. Data Privacy Framework
Cloudflare, Inc. CDN, DNS, DDoS protection EU (where possible) SCCs
The Processor will keep an up-to-date list of Sub-processors available on this same page (agendio.es/en/dpa/#anexo-ii).

Annex III — Technical and organisational measures (Article 32 GDPR)

The Processor implements, as a minimum, the following measures:

A. Encryption and communications

  • Encryption in transit using TLS 1.2 or higher for all external communications and all internal communications between services.
  • Encryption at rest of databases and storage volumes (AES-256 or equivalent).
  • Specific encryption of stored credentials and OAuth tokens (Google Calendar and others).

B. Access control

  • Least-privilege, role-based access policy (RBAC).
  • Mandatory multi-factor authentication (MFA) for staff with access to production environments.
  • Periodic review of privileges (at least quarterly).
  • Bastion host and infrastructure access logs.

C. Pseudonymisation and minimisation

  • Anonymisation or pseudonymisation of data in non-production environments.
  • Minimisation policy: only the data strictly necessary to provide the Service is collected.

D. Continuity and resilience

  • Daily encrypted backups, with periodic restore tests.
  • Business continuity and disaster recovery plan (documented RTO/RPO).
  • Redundancy of critical infrastructure.

E. Operational security

  • Vulnerability management: periodic scans and patching according to severity.
  • Security testing (including penetration testing at least once a year) of critical components.
  • Security monitoring and alerting (SIEM or equivalent).
  • Incident management policy and documented response plan.

F. Personnel

  • Confidentiality agreements signed by all staff with access to Personal Data.
  • Regular training in data protection and information security.
  • Formal joiner and leaver procedures for employees, including revocation of access.

G. Physical security

  • Data hosted with certified cloud providers (ISO 27001 or equivalent) with physical access controls, 24/7 surveillance and power redundancy.

H. Sub-processor management

  • Selection of Sub-processors with security and privacy due diligence.
  • Contracts with data protection clauses equivalent to those of the DPA.
  • Periodic review of compliance.

Need a copy for signature or have questions about this DPA?

Write to us at privacidad@agendio.es · DPO: privacidad@cedesa.es