Privacy Policy
Last updated: April 2026
This translation is provided for information only; in the event of any discrepancy, the Spanish version shall prevail.
1. Introduction and Data Controller
At Agendio we are committed to protecting your privacy and keeping your personal data secure. This Privacy Policy explains how we collect, use, disclose and protect your information when you use our automated booking platform, in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
Data controller: CEDESA DIGITAL SL (owner of the Agendio brand)
Tax ID (NIF): B06684369
Registered address: Campus Universitario, Avda. de la Investigación S/N, Edificio PCTEX Oficina 2.1 — 06006 — Badajoz (Spain)
Telephone: (+34) 924 090 608
Contact email: hola@agendio.es
Data Protection Officer (DPO): privacidad@cedesa.es — C/ Francisco Guerra 12, Portal 4, 1ºC, 06011 Badajoz (Spain)
Contact form: agendio.es/en/contact
2. Roles in the processing of data
Agendio acts in two distinct roles depending on the type of data:
- As data controller: in respect of the data of visitors to our website (agendio.es), of Customers who subscribe to the Service (registration, billing and support data) and of people who get in touch with us.
- As data processor (Article 28 GDPR): in respect of the data of end customers that the Customer (the business using Agendio) processes through the Platform — for example, the people who make a booking with the Customer's business. In this case, the Customer is the data controller and Agendio acts on its documented instructions, as set out in the Data Processing Agreement incorporated into the Terms and Conditions.
3. Data we collect
3.1. As data controller
- Contact and registration information: name, telephone number, email address, business details, tax ID (NIF).
- Billing information: payment details (processed through the payment provider), invoice history.
- Device information: device type, operating system, browser, IP address (anonymised where possible).
- OAuth credentials: access and refresh tokens that the Customer grants us when connecting third-party services (Google), stored in encrypted form.
3.2. As data processor (data of the business's end customers)
- End customer contact information: name, telephone number.
- Booking information: date, time, number of attendees, special requirements.
- WhatsApp communication history: messages exchanged with the chatbot to manage bookings, date, time and delivery status.
4. Purposes and legal basis for processing
| Purpose | Legal basis |
|---|---|
| Providing the SaaS service to the Customer | Performance of a contract (Art. 6(1)(b) GDPR) |
| Managing and confirming bookings (on behalf of the Customer) | Instructions from the Customer / Performance of the contract between the Customer and its end customer |
| Sending reminders and notifications via WhatsApp | Performance of a contract + the end customer's opt-in |
| Synchronising bookings with Google Calendar | Consent given by the Customer when connecting their account via OAuth (Art. 6(1)(a) GDPR) |
| Analysing use of the Website (Google Analytics 4, Microsoft Clarity) | Consent (Art. 6(1)(a) GDPR) |
| Handling enquiries and support | Legitimate interest (Art. 6(1)(f) GDPR) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
5. Use of Google APIs
Agendio integrates the Google Calendar API so that Customers can synchronise the bookings managed on the Platform with their Google calendar.
5.1. Data and scopes we access
When a Customer connects their Google account via OAuth 2.0, Agendio requests the following minimum necessary scope:
https://www.googleapis.com/auth/calendar.events— to create, modify and delete events in the calendar selected by the Customer.
We do not request access to any other data in the Customer's Google account (email, contacts, files in Drive, etc.).
5.2. How we use Google data
Data obtained from Google APIs is used solely to:
- Create events in the Customer's calendar when a booking is confirmed.
- Update or delete events when a booking is changed or cancelled.
- Check calendar availability to avoid overlaps when allocating bookings.
5.3. Compliance with Google's Limited Use requirements
Agendio's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we expressly declare that:
- We do not sell Google data to third parties.
- We do not use Google data to serve advertising, including retargeting or personalised or interest-based advertising.
- We do not transfer or use Google data to determine creditworthiness or for lending purposes.
- We do not use Google data to train generalised or non-personalised artificial intelligence or machine learning models.
- We do not allow humans to read the user's Google data, except in the following cases permitted by the policy: (i) with the user's express and specific consent, (ii) where necessary for security purposes (for example, investigating a bug or abuse), (iii) to comply with an applicable legal obligation, or (iv) using aggregated and anonymised data for internal operations in accordance with applicable law.
5.4. Storage and security of Google data
- OAuth tokens (access and refresh) are stored encrypted at rest on our servers, with access restricted to authorised personnel.
- Event identifiers (
event_id,calendar_id) are kept only for as long as necessary for the operational traceability of the associated booking. - We do not keep permanent copies or derived databases of the content of users' calendars beyond what is strictly necessary to provide the functionality.
5.5. Revoking access to Google
The Customer may revoke Agendio's access to their Google account at any time from:
- The Agendio admin dashboard: Integrations → Google Calendar → Disconnect.
- The security page of their Google account: myaccount.google.com/permissions.
Once access has been revoked, Agendio will stop accessing the Google API and will delete the stored tokens within a maximum of 7 days.
6. Communications via the WhatsApp Business Cloud API
Agendio integrates with the WhatsApp Business Cloud API (a service provided by Meta Platforms Ireland Limited) so that Customers can manage automated booking communications with their end customers through their own WhatsApp Business Account (WABA). The technical integration is carried out through YCloud, an official Business Solution Provider (BSP) authorised by Meta.
6.1. BYO-WABA model: the Customer owns its own WABA
Each Customer connects its own WhatsApp Business Account (WABA) to Agendio, of which it is the sole owner and administrator vis-à-vis Meta. Accordingly:
- The Customer is responsible for verifying its business in Meta Business Manager and for setting up and maintaining its WABA.
- The Customer decides how its WABA is configured, including the storage region (Local Storage) for messages at rest on Meta's servers, template approval, the display name and its business messaging policy.
- The Customer is responsible for obtaining and maintaining the explicit opt-in of its end customers before sending them proactive messages.
- Agendio acts solely as an integration and automation layer between the Customer's WABA and the Platform. Agendio is neither the owner nor the administrator of the Customer's WABA and makes no decisions about its configuration or storage region.
6.2. Roles in the processing
- The Customer is the data controller in respect of the personal data of its end customers exchanged through its WABA.
- Agendio acts as the Customer's data processor, providing the orchestration platform that connects the Customer's WABA with the Service logic.
- Meta Platforms Ireland Ltd. acts as the Customer's data processor under the WhatsApp Business Data Processing Terms, accepted directly by the Customer when creating its WABA.
- YCloud acts as Agendio's sub-processor under the corresponding DPA, providing the routing layer between the Customer's WABA and the Platform.
6.3. Data processed via WhatsApp
Telephone number, name (if provided by the end customer), content of the messages exchanged, date and time of the message, and delivery/read status.
6.4. Prior consent (opt-in)
Before receiving any proactive message from the Customer or from Agendio via WhatsApp, end customers must have given an explicit opt-in, in accordance with Meta's rules and the GDPR. The Customer is responsible for obtaining and keeping proof of that consent; Agendio provides tools to record and track the opt-in.
6.5. Unsubscribe mechanism (opt-out)
End customers can unsubscribe at any time by:
- Replying
BAJA,STOPorCANCELARto the chatbot. - Blocking the Customer's number from their WhatsApp app.
The unsubscribe request will be processed automatically and no further messages will be sent to that number.
6.6. International transfers relating to WhatsApp
- Meta Platforms Ireland Limited (Ireland) / Meta Platforms, Inc. (USA): the WhatsApp Business Cloud API processes data in the region configured by the Customer as owner of the WABA. Transfers to the USA are covered by the Standard Contractual Clauses and the EU-U.S. Data Privacy Framework, under the WhatsApp Business Data Transfer Addendum accepted directly by the Customer.
- YCloud (operated by YCloud Pte. Ltd., established in Singapore): transfers are covered by the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914). Singapore is not covered by an adequacy decision of the European Commission; the flow of data through YCloud is limited to the routing layer required for the technical integration.
For more information on how Meta processes data on the WhatsApp Business Platform, see the WhatsApp Business Data Processing Terms and the WhatsApp Privacy Policy.
7. Third parties and international transfers
We do not sell your personal data. We share information only with the following service providers, acting as processors or sub-processors:
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| YCloud Pte. Ltd. | WhatsApp Business API BSP (routing layer) | Singapore | SCCs Module 3 (specific DPA pending formalisation) |
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. | WhatsApp Business Cloud API infrastructure (WABA owned by the Customer) | Ireland / USA | SCCs + EU-U.S. DPF |
| Google LLC | Google Calendar API (when the Customer connects it via OAuth) and Google Tag Manager / Google Analytics 4 | USA | SCCs + EU-U.S. DPF |
| Microsoft Corporation | Microsoft Clarity (behavioural analytics for the Website) | USA | SCCs + EU-U.S. DPF |
| Cloudflare, Inc. | CDN, DNS and infrastructure | EU (where possible) | SCCs |
| Formspree | Contact form handling | USA | SCCs |
Business partners: the businesses where you make bookings, which act as independent data controllers in respect of their own customers.
Legal obligations: we may share data with the competent authorities where required by law.
8. Retention period
| Data category | Period |
|---|---|
| Customer account data | For the duration of the contractual relationship + 5 years (Spanish General Tax Act (LGT)/LOPDGDD/commercial law) |
| Billing data | 6 years (Spanish Commercial Code, Art. 30) |
| Data of the business's end customers (bookings) | In accordance with the Customer's instructions; by default, 24 months after the last interaction |
| Google OAuth tokens | Until revoked + 7 days for secure deletion |
| WhatsApp messages | In accordance with the Customer's instructions and the configuration of the Customer's WABA; a maximum of 30 days on Meta's servers before automatic deletion if undelivered |
| Security logs | 12 months |
Once these periods have elapsed, the data is securely deleted or anonymised.
9. Data security
We implement appropriate technical and organisational security measures: SSL/TLS encryption in transit, encryption at rest of credentials and tokens, role-based access control, audit logs, backups and incident management procedures. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the AEPD within 72 hours and, where appropriate, notify you directly.
10. Your rights (ARCO+)
You have the right to: access, rectification, erasure ("right to be forgotten"), restriction of processing, objection, data portability, withdrawal of consent (without retroactive effect) and to lodge a complaint with the Spanish Data Protection Agency (AEPD) (aepd.es).
To exercise them, write to privacidad@agendio.es stating the right you wish to exercise and enclosing a copy of your national ID card (DNI) or another identity document.
If the data in respect of which you wish to exercise a right is processed by Agendio as a data processor on behalf of a Customer (the business where you made your booking), we will refer you to the Customer as data controller, unless a legal obligation requires otherwise.
11. Cookies and similar technologies
We use first-party cookies (essential for the Website to work) and third-party analytics cookies (Google Analytics 4 and Microsoft Clarity, managed through Google Tag Manager with Consent Mode v2). Analytics cookies are only set with your explicit consent, given through the cookie banner on equal terms (Accept / Reject) in line with the AEPD's guidelines. You can withdraw your consent at any time using the "Manage cookies" button in the footer or from our Cookie Policy, where you will find the detailed table of cookies by provider, type and duration.
12. Protection of minors
Our services are intended for adults. We do not knowingly collect personal information from children under 14 without the verifiable consent of their parents or legal guardians (Article 8 GDPR and Article 7 LOPDGDD).
13. Changes to this policy
We may update this Privacy Policy from time to time. We will give notice of any material change by publishing the new version on this page and updating the "last updated" date. Where changes affect the way we process Google data, we will ask for fresh consent before applying the new processing, as required by the Google API Services User Data Policy.
14. Contact
If you have any questions about this Privacy Policy or wish to exercise your rights:
Email: privacidad@agendio.es
DPO: privacidad@cedesa.es
Form: agendio.es/en/contact