Legal
Privacy Policy
Last updated: July 10, 2026
1. Who We Are
NowAgenda is operated by GOLDENSIO SL, Calle Sabina 89, 35660 La Oliva, Las Palmas, Fuerteventura, Spain. NIF: B72723364.
2. What Data We Process
We process account, business, service, operator, appointment and customer contact data needed to provide online booking, calendar management, reminders and operational notifications.
When a user connects Google Calendar, we process OAuth tokens, calendar identifiers and calendar event data needed to create, read, update, import and synchronize appointment events.
Sensitive data may include Google OAuth access and refresh tokens, customer contact details, appointment details, payment configuration secrets and authentication credentials.
We also store consent timestamps for terms acceptance, privacy acceptance, service communications and optional marketing communications.
3. Why We Process Data
We process personal data to provide the NowAgenda service, manage bookings, send appointment reminders, synchronize calendars, maintain security, support customers and comply with legal obligations.
Service communications may be sent by email, WhatsApp or other enabled channels when needed for confirmations, reminders, changes, cancellations, payment status or operational notices. Promotional communications are processed only where a separate marketing consent has been given.
4. Google Workspace API Data and Limited Use
NowAgenda uses Google Calendar access only to create, read, update, import and synchronize calendar events related to appointments, availability blocks and calendar choices managed through the service.
The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data, use it for advertising, or use it to develop, improve or train generalized AI or machine learning models. Human access to Google user data is limited to cases required for security, abuse prevention, support requested by the user, legal compliance or service operation.
Google OAuth tokens are used only to maintain the calendar connection requested by the tenant or operator. Users can revoke access by disconnecting Google Calendar in NowAgenda or from their Google Account permissions.
5. Data Protection Mechanisms
NowAgenda protects sensitive data through HTTPS/TLS in transit, Laravel application-key encryption for Google Calendar OAuth tokens and payment configuration secrets at rest, hashed API keys and password hashing.
Access to tenant data is restricted to authenticated users assigned to the tenant workspace. Administrative routes, OAuth callbacks and sensitive owner actions use authentication, authorization checks, signed URLs where appropriate and rate limiting.
Operational exports redact secrets such as Google tokens, API key hashes, payment gateway secrets and webhook secrets. Account deletion removes Google Calendar connections and stored tokens, while some records may be retained only where required for tax, accounting, fraud-prevention, security or legal obligations.
6. Sharing Data
We may share data with infrastructure, email, messaging, payment, calendar and AI providers only when necessary to operate the service. These providers act under contractual or technical safeguards.
7. Cookies
NowAgenda uses necessary cookies and local storage for login, security, booking flows and user preferences. Optional analytics or marketing cookies are used only after consent. Users can choose necessary-only cookies from the cookie banner.
8. Retention
We keep data for as long as needed to provide the service, comply with legal obligations, resolve disputes and maintain business records. Calendar connections and stored OAuth tokens are deleted when the integration is disconnected or the tenant workspace is deleted.
9. Your Rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection to processing of your personal data.
Tenant owners can download a structured GDPR export and request deletion of their workspace directly from the account settings area. Some records may be retained where required by tax, accounting, fraud-prevention or legal obligations.
10. Policy Updates
We may update this policy when the service, integrations, legal requirements or data protection practices change. The updated date above identifies the current version.
11. Contact
For privacy requests, contact GOLDENSIO SL at info@goldensio.com.