Agendix Agendix
Features Plans FAQ
PT | EN Login Back to homepage
Back to homepage

Privacy Policy

Last updated: 25 July 2026

Agendix is committed to protecting the personal data of its users and to compliance with the General Data Protection Regulation (GDPR) and applicable Portuguese legislation.

1. Data controller

The data controller for personal data is the entity operating the Agendix platform, developed by Oxion in Portugal. To exercise your rights or for any enquiries, you can contact us through the means available on the site.

2. Data we collect

We collect and process the following types of data:

Account data

  • Email address, name and profile information
  • Business data (name, address, contacts, opening hours)

Your business clients' data

As a Platform user, you enter your clients' data (name, phone, email, service and booking history). Agendix acts as a data processor for this data, on behalf of your business.

Staff data

Information about staff you add to the Platform (name, contact, schedules, commissions).

Transaction and booking data

Records of bookings, sales, cash sessions and expenses, necessary for the operation of the Platform.

Technical and usage data

IP address, device type, browser, access and usage logs of the Platform, for security and service improvement purposes.

Campaign attribution data

When a visitor reaches a public booking page through a campaign, we may collect UTM parameters and advertising click identifiers such as gclid, gbraid, wbraid or fbclid. These data allow a booking to be attributed to the campaign that generated it. Agendix only sends measurement events to advertising platforms when the customer has expressly agreed to campaign measurement during the booking flow.

Payments: Payment processing is carried out by Stripe. Agendix does not have access to complete banking data (card number, etc.). All payment data processing is the responsibility of Stripe, in accordance with its privacy policies.

3. Legal basis and purposes

We process your data with the following legal bases and purposes:

  • Contract performance: Service provision, account management, billing and support.
  • Legitimate interest: Platform improvement, security, fraud prevention and service communications.
  • Consent: When applicable (e.g. newsletters, marketing communications or advertising campaign measurement).
  • Legal obligation: Compliance with tax and legal obligations.

4. Data sharing

We may share data with:

  • Subcontractors: Firebase (Google) for storage, authentication and real-time databases; Stripe for payments. These providers are contractually obliged to comply with data protection standards.
  • Authorised advertising platforms: When a business voluntarily enables an integration, we share only the data needed to measure that business's conversions, in accordance with the applicable consent and configuration.
  • Authorities: When required by law or court order.

We do not sell, rent or transfer your personal data to third parties for marketing purposes.

5. Google Ads and campaign measurement

This feature is optional and configured separately by each business. A business administrator can connect the business's own Google Ads account through Google OAuth. Agendix requests the adwords scope to validate the selected account and conversion action in read-only mode, and the datamanager scope to send and reconcile confirmed-booking conversions. Agendix does not create or manage Google Ads campaigns, ads, audiences, budgets, billing or payment methods.

When campaign measurement consent exists and a booking is successfully confirmed, the backend may send the available campaign identifiers, confirmation date and time, a transaction identifier used to prevent duplicates and, when configured, the conversion value and currency to the connected account. We do not send the customer's name, email address or phone number to Google for this integration.

The refresh token issued by Google is encrypted on the server and isolated by business. It is never returned to the browser and is retained only while the connection remains authorised. Disconnecting Google Ads in Agendix deletes the local credential and stops new deliveries; an administrator can also revoke access directly from the relevant Google Account.

Campaign attribution data and technical conversion records are retained with the booking only for as long as needed to deliver, reconcile and audit the conversion, prevent duplicates, resolve incidents and meet legal obligations. When the account or associated data are deleted, these records are deleted or anonymised unless an applicable legal retention period requires otherwise.

Agendix's use and transfer of information received from Google APIs comply with the Google API Services User Data Policy, including the Limited Use requirements. Google data are used only to provide and improve the measurement feature requested by the business that connected the account.

6. International transfers

Some subcontractors (e.g. Firebase/Google, Stripe) may process data on servers outside the European Union. In these cases, we ensure adequate safeguards under the GDPR (standard contractual clauses, adequacy decisions or equivalent mechanisms).

7. Data retention

We retain personal data for as long as necessary for service provision, compliance with legal obligations and dispute resolution. After account cancellation, data may be retained for the period necessary for tax or legal obligations, after which it will be deleted or anonymised.

8. Your rights

Under the GDPR, you have the right to:

  • Access: Obtain confirmation that your data is being processed and access it.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data (subject to legal exceptions).
  • Portability: Receive your data in a structured, commonly used format.
  • Objection: Object to processing in certain circumstances.
  • Restriction: Restrict processing in certain situations.

To exercise these rights, contact us. You also have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD): www.cnpd.pt.

For step-by-step instructions on how to request deletion of your data (including in the context of authorised integrations such as the WhatsApp Business API), see our dedicated page: Data deletion.

9. Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration, including encryption in transit and at rest, access control and security audits.

10. Cookies and similar technologies

The Platform and site may use cookies and similar technologies for essential functionality, security and usage analysis. You can configure your browser to refuse non-essential cookies; this may affect some features.

11. Changes

This policy may be amended to reflect changes in our practices or the law. Relevant changes will be communicated. The date of last update is at the beginning of this document.

12. Contact

For privacy questions or to exercise your rights, contact us through the means indicated on the site.

Made by Oxion in Portugal.

Agendix

Agendix

Premium technology infrastructure for beauty and wellness businesses.

Quick Links

  • Platform
  • Why Agendix
  • Plans
  • Documentation
  • Blog

Legal

  • Terms of Use
  • Privacy
  • Data deletion

Support

  • FAQ
  • Contact
Made by Oxion in Portugal.
© 2026 Agendix. All rights reserved.