Privacy Policy
Last updated: March 2026
1. Introduction
AgendaX (“we”, “our” or “the company”) is committed to protecting its users' privacy. This Privacy Policy explains how we collect, use, store and protect your personal information when you use our appointment management platform.
2. Data We Collect
We collect the following types of information:
- Registration data: name, email, phone, company name and address.
- Usage data: information about how you use the platform, including appointments, services and interactions.
- Payment data: billing information processed securely through Stripe. We do not store credit card data on our servers.
- Technical data: IP address, browser type, device and cookies essential to the platform's operation.
- Communication data: phone numbers and emails used to send appointment notifications and reminders.
3. How We Use Your Data
We use your information to:
- Provide and maintain the appointment management service.
- Send appointment notifications and reminders by email and SMS.
- Process payments and manage subscriptions.
- Improve the platform and the user experience.
- Meet legal and regulatory obligations.
- Communicate important updates about the service.
4. Third-Party Services
We use the following third-party services to operate the platform:
- Stripe: secure payment processing and subscription management.
- Resend: transactional email delivery (confirmations, reminders, notifications).
- Infobip: SMS delivery for appointment notifications and reminders.
- Vercel: platform hosting and file storage.
- Neon: secure, encrypted PostgreSQL database.
Each of these services has its own privacy policy and complies with the applicable data protection regulations.
5. Cookies
We use cookies essential to the platform's operation, including authentication and session preference cookies. We may also use analytics cookies (Google Analytics) to understand how users interact with the platform and improve the service.
6. Data Security
We apply technical and organisational measures to protect your data:
- Encryption of data in transit (HTTPS/TLS) and at rest.
- Secure authentication with JWT tokens.
- Role-based access control (RBAC) restricting data access.
- Regular backups and data redundancy.
- Continuous security monitoring.
7. Your Rights (LGPD/GDPR)
In accordance with the General Data Protection Law (LGPD) and the General Data Protection Regulation (GDPR), you have the right to:
- Access your personal data.
- Rectify incorrect or outdated data.
- Request deletion of your data.
- Request portability of your data.
- Withdraw consent for data processing.
- Object to the processing of your data in certain circumstances.
8. Data Retention
Your personal data is kept while your account is active or as needed to provide our services. After the account is deleted, data is removed within 30 days, except where retention is required to meet legal obligations.
9. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by email or by notice on the platform. Continued use of the service after the changes constitutes acceptance of the updated policy.
10. Contact
For privacy questions or to exercise your rights, get in touch:
- Email: suporte@agendax.pt
- Contact page: agendax.pt/contact