1. Data Controller
Agéndalo ToDo ("we", "us", "our", or "the Platform") informs users that the personal data they provide will be processed by GPS LOBBO TEAM, S.L., with Tax ID B-19401306 and address at Avenida del Paral·lel 144, 2-1, 08015 Barcelona, España. For any questions related to this policy, you can contact us at info@agendalotodo.com.
2. Information We Collect
We collect information to provide and improve our services. This information is divided into two categories:
a) Data from our Clients (Businesses):
- **Account Information:** Business name, Tax ID, address, contact email, phone number.
- **Payment Information:** We collect the necessary data to process subscription payments through our payment provider (Stripe), but we do not store full credit card details.
- **Configuration Data:** Customization of the booking portal, services offered, schedules, employee profiles, etc.
b) Data from our Clients' Customers (End Users):
As a SaaS platform, our Clients (the businesses) use our tools to manage their own customers. Agéndalo ToDo acts as a **Data Processor** for this data, while the Business is the **Data Controller**. The information we process on their behalf includes:
- **Contact Details:** Name, email, phone number.
- **Appointment History:** Services booked, dates, assigned professional.
- **Notes and Consents:** Technical information or informed consents that the Business records on the platform.
- **Clinical history (health data):** In healthcare and aesthetics practices, the Business may record clinical notes, progress images, attached documents and pain-area maps. These are **special category data (art. 9 GDPR)** and we process them solely on behalf of the Business, which is the party obtaining the patient's explicit consent. When the right to erasure is exercised, the associated files are deleted too.
3. Purpose of Processing
We use the information we collect for the following purposes:
- **For Businesses:** To manage their account, process payments, provide the contracted service, offer technical support, and communicate updates about the platform.
- **For End Users (on behalf of the Business):** To manage the appointment system, send automatic reminders via WhatsApp or email, and allow the Business to provide its service efficiently.
4. Legal Basis for Processing
The legal basis for processing the data of our Clients (Businesses) is the **performance of a contract** (the terms and conditions of the service).
The legal basis for processing the data of End Users is the consent they give to the Business when booking an appointment, or the contractual relationship they establish with said Business. Agéndalo ToDo operates under the instructions of the Business, formalized in the data processing agreement.
The legal basis for Google Calendar synchronization (section 6) is the **consent** of the user who connects their account, revocable at any time.
Where the Business records **health data** (clinical history, progress images or pain-area maps), the legal basis is the patient's **explicit consent** or the provision of health care (art. 9.2.a and 9.2.h GDPR), which the Business itself must obtain and evidence as Data Controller.
5. Data Communication to Third Parties
We do not sell or rent your personal data. We only share information with service providers who help us operate, always under strict confidentiality agreements:
- **Payment Gateways (Stripe):** To process subscription payments and advance payments for appointments.
- **Infrastructure and hosting (Google Cloud / Firebase):** Our servers, with data hosted in a European Union region.
- **Email delivery (Resend):** For the Platform's transactional emails and notices.
- **WhatsApp reminders (Meta Platforms, WhatsApp Business Cloud API):** For sending appointment reminders.
- **Google Calendar (Google):** Only if a professional or manager voluntarily connects their calendar (see section 6).
When any of these providers involves an international data transfer (for example, US-based parent companies), it is carried out with the safeguards provided by the GDPR: standard contractual clauses or participation in the EU-US Data Privacy Framework.
6. Google Calendar Synchronization
If a professional or manager of a Business decides to connect their Google account, Agéndalo ToDo syncs the appointments of their agenda with their personal Google Calendar. This feature is optional and only activates if the user expressly authorizes it through Google's secure access system (OAuth).
- **Data we send to Google:** for each appointment, an event is created or updated in the user's calendar with the service, the date and time, and the client's name for that appointment. Private appointment notes never leave the Platform.
- **Data we receive from Google:** only the email address of the connected account and the technical access credentials (tokens). We do not read, store or analyze any other events in the user's calendar.
- **How we protect credentials:** tokens are stored encrypted (AES-256-GCM) and are only used to keep the calendar in sync.
- **Revocation:** the user can disconnect their calendar at any time from the Platform (future events created by Agéndalo ToDo are removed and their credentials are destroyed) or revoke access from their Google account at myaccount.google.com/permissions.
Agéndalo ToDo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: this data is not used for advertising, is not sold or transferred to third parties except to provide the synchronization feature itself, and no human reads it except with the user's consent, for security purposes, or to comply with the law.
7. Data Retention
The account data of Businesses will be kept as long as they maintain an active subscription and, subsequently, for the legally required periods.
The data of End Users will be retained according to the policies defined by the Business (Data Controller). If a Business cancels its account, its data will be deleted from our production systems within 90 days, unless the law requires its retention.
8. User Rights
Both Businesses and End Users can exercise their rights of access, rectification, erasure, opposition, limitation of processing, and portability.
- **If you are a Business (our Client):** You can exercise your rights by contacting us directly at info@agendalotodo.com.
- **If you are an End User (a client of a Business):** You must direct your request to the Business with which you booked the appointment, as it is the Data Controller of your data. We will cooperate with the Business to address your request.
You also have the right to file a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing of your data does not comply with the regulations.
9. Data Security
We implement technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, or alteration, and against unauthorized disclosure or access. This includes encryption of data in transit and at rest, and access controls.
10. Changes to the Privacy Policy
We reserve the right to modify this policy to adapt it to new legislative or jurisprudential developments. Any changes will be notified to our Clients via email or through a notice on the platform.
11. Contact
If you have any questions or concerns about how we process your personal data, do not hesitate to contact us at info@agendalotodo.com.