Last updated: 25 July 2026
Agendix is committed to protecting the personal data of its users and to compliance with the General Data Protection Regulation (GDPR) and applicable Portuguese legislation.
The data controller for personal data is the entity operating the Agendix platform, developed by Oxion in Portugal. To exercise your rights or for any enquiries, you can contact us through the means available on the site.
We collect and process the following types of data:
As a Platform user, you enter your clients' data (name, phone, email, service and booking history). Agendix acts as a data processor for this data, on behalf of your business.
Information about staff you add to the Platform (name, contact, schedules, commissions).
Records of bookings, sales, cash sessions and expenses, necessary for the operation of the Platform.
IP address, device type, browser, access and usage logs of the Platform, for security and service improvement purposes.
When a visitor reaches a public booking page through a campaign, we may collect UTM parameters and advertising click identifiers such as gclid, gbraid, wbraid or fbclid. These data allow a booking to be attributed to the campaign that generated it. Agendix only sends measurement events to advertising platforms when the customer has expressly agreed to campaign measurement during the booking flow.
Payments: Payment processing is carried out by Stripe. Agendix does not have access to complete banking data (card number, etc.). All payment data processing is the responsibility of Stripe, in accordance with its privacy policies.
We process your data with the following legal bases and purposes:
We may share data with:
We do not sell, rent or transfer your personal data to third parties for marketing purposes.
This feature is optional and configured separately by each business. A business administrator can connect the business's own Google Ads account through Google OAuth. Agendix requests the adwords scope to validate the selected account and conversion action in read-only mode, and the datamanager scope to send and reconcile confirmed-booking conversions. Agendix does not create or manage Google Ads campaigns, ads, audiences, budgets, billing or payment methods.
When campaign measurement consent exists and a booking is successfully confirmed, the backend may send the available campaign identifiers, confirmation date and time, a transaction identifier used to prevent duplicates and, when configured, the conversion value and currency to the connected account. We do not send the customer's name, email address or phone number to Google for this integration.
The refresh token issued by Google is encrypted on the server and isolated by business. It is never returned to the browser and is retained only while the connection remains authorised. Disconnecting Google Ads in Agendix deletes the local credential and stops new deliveries; an administrator can also revoke access directly from the relevant Google Account.
Campaign attribution data and technical conversion records are retained with the booking only for as long as needed to deliver, reconcile and audit the conversion, prevent duplicates, resolve incidents and meet legal obligations. When the account or associated data are deleted, these records are deleted or anonymised unless an applicable legal retention period requires otherwise.
Agendix's use and transfer of information received from Google APIs comply with the Google API Services User Data Policy, including the Limited Use requirements. Google data are used only to provide and improve the measurement feature requested by the business that connected the account.
Some subcontractors (e.g. Firebase/Google, Stripe) may process data on servers outside the European Union. In these cases, we ensure adequate safeguards under the GDPR (standard contractual clauses, adequacy decisions or equivalent mechanisms).
We retain personal data for as long as necessary for service provision, compliance with legal obligations and dispute resolution. After account cancellation, data may be retained for the period necessary for tax or legal obligations, after which it will be deleted or anonymised.
Under the GDPR, you have the right to:
To exercise these rights, contact us. You also have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD): www.cnpd.pt.
For step-by-step instructions on how to request deletion of your data (including in the context of authorised integrations such as the WhatsApp Business API), see our dedicated page: Data deletion.
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration, including encryption in transit and at rest, access control and security audits.
The Platform and site may use cookies and similar technologies for essential functionality, security and usage analysis. You can configure your browser to refuse non-essential cookies; this may affect some features.
This policy may be amended to reflect changes in our practices or the law. Relevant changes will be communicated. The date of last update is at the beginning of this document.
For privacy questions or to exercise your rights, contact us through the means indicated on the site.
Made by Oxion in Portugal.