Privacy

PRIVACY NOTICE

Articles 13 and 14 of Regulation (EU) 2016/679 – GDPR

Agendly Platform – web app for managing communications and appointments through artificial intelligence-based voice and messaging assistants

Last updated: August 15, 2026

1. Who is the Data Controller

The Data Controller is Agendly S.r.l., with registered office at Via ai Crotti 39 – 22031 Albavilla (CO), Italy, Tax Code/VAT no. 04236380137, REA 430066, certified email (PEC): agendly@namirialpec.it (hereinafter, “Agendly” or the “Controller”).

For requests relating to the protection of personal data, you may contact the Controller using the details above, indicating “Privacy” in the subject line.

Agendly has not appointed a Data Protection Officer (DPO), unless otherwise stated on the website or communicated to data subjects.

2. Who this notice applies to

This notice describes the processing of personal data carried out by Agendly when:

  • you register for and use the Platform, for example for account creation, user management, support, administration, and billing;
  • you interact with the website contact channels, for example for information requests, demos, quotes, or support;
  • you establish or manage a contractual, pre-contractual, or business relationship with Agendly.

Important: when the Platform is used by a Customer, for example a professional, firm, or company, to manage calls or messaging conversations with its end users, patients, customers, or contacts, the Customer generally acts as the Data Controller of the end users’ data. In such cases, Agendly acts as a Data Processor pursuant to Article 28 GDPR, processing the data on behalf of the Customer and according to its documented instructions, based on the relevant Data Processing Agreement (“DPA”).

3. What data we process

Depending on your relationship with Agendly and the features used, we may process the following categories of personal data.

  • Identification and contact data: first name, last name, email address, phone number, company, role, or professional qualification, if provided.
  • Account and authentication data: credentials, internal identifiers, user roles, account settings, access logs, and data relating to user management.
  • Contractual, administrative, and tax data: data necessary for entering into and performing the contract, managing payments, invoicing, accounting, and compliance obligations.
  • Data for activation or assignment of phone numbers, where applicable: information and documentation required by the telecom operator or telecommunications service providers, such as company data, legal representative data, identification documents, company registry extracts, or registered office information, to the extent necessary.
  • Technical and usage data: IP address, device or browser identifiers, technical logs, application events, diagnostic data, operational metrics, and data relating to security and use of the Platform.
  • Data relating to communications with Agendly: requests sent via email, forms, tickets, chat, or other support channels, as well as the content of the communications transmitted.
  • Data processed in calls or messaging conversations managed on behalf of Customers: depending on the service configuration and the Customer’s instructions, this may include data relating to the communication, the end user’s request, the appointment, the conversation summary, the name, contact details, and other data necessary to provide the service requested by the Customer.

For its own purposes, Agendly does not require the provision of special categories of personal data under Article 9 GDPR, nor data relating to criminal convictions and offences under Article 10 GDPR. However, if the Customer uses the Platform in sectors or contexts that may involve the processing of such data, that processing must be governed by the Customer, as Data Controller, through an appropriate legal basis, privacy notice, service configuration, and documented instructions to Agendly in the DPA.

4. Purposes of processing and legal bases

Agendly processes personal data for the following purposes, based on the corresponding legal bases provided for by Article 6 GDPR.

  • A) Registration, account management, and provision of the Platform: we process data to create and manage the account, authenticate users, enable the Platform’s features, manage authorized users, provide the service, and ensure the ordinary operation of the application. Legal basis: performance of a contract or pre-contractual measures, pursuant to Article 6(1)(b) GDPR.
  • B) Assistance, technical support, and service communications: we process data to respond to support requests, manage tickets, carry out troubleshooting, maintenance, updates, technical communications, or communications relating to the service. Legal basis: performance of the contract pursuant to Article 6(1)(b) GDPR, and/or Agendly’s legitimate interest in the proper management, continuity, and security of the service pursuant to Article 6(1)(f) GDPR.
  • C) Legal, tax, accounting, and regulatory compliance: we process data to comply with legal, tax, accounting, administrative, regulatory obligations or requests from competent Authorities, including obligations connected with telecommunications services and number activation. Legal basis: legal obligation pursuant to Article 6(1)(c) GDPR.
  • D) Security, abuse or fraud prevention, and protection of rights: we process data to monitor Platform security, prevent unauthorized access, abuse, misuse, fraud, or anomalies, manage security incidents, protect infrastructure, data, and systems, and establish, exercise, or defend rights in or out of court. Legal basis: Agendly’s legitimate interest pursuant to Article 6(1)(f) GDPR.
  • E) Management of commercial requests, demos, and contacts: we process data to manage requests for information, demos, quotes, commercial contacts, or pre-contractual communications. Legal basis: performance of pre-contractual measures requested by the data subject pursuant to Article 6(1)(b) GDPR, and/or legitimate interest pursuant to Article 6(1)(f) GDPR.
  • F) Commercial communications to customers or business contacts: Agendly may send communications relating to services, features, or updates similar to those already requested or purchased, where permitted by applicable law. In any case, the data subject may object at any time to receiving such communications. Where required by applicable law, Agendly obtains specific consent. Legal basis: legitimate interest pursuant to Article 6(1)(f) GDPR, and/or consent pursuant to Article 6(1)(a) GDPR, where necessary.
  • G) Statistics, diagnostics, and service improvement: we process technical and usage data to analyze performance, stability, errors, security, and Platform functionality, preferably in aggregated, anonymized, or minimized form. Legal basis: Agendly’s legitimate interest in improving, maintaining, and securing the service pursuant to Article 6(1)(f) GDPR.

5. Use of artificial intelligence and no training on data

The Agendly Platform uses artificial intelligence components and voice and messaging technologies to enable, depending on the configuration chosen by the Customer, the automated management of calls, messaging conversations, requests, appointments, summaries, and routing.

Personal data processed through the Platform is not used by Agendly to train, retrain, or improve general-purpose or third-party artificial intelligence models.

Data is processed exclusively to provide the service, ensure the technical functioning of the Platform, comply with contractual and applicable legal obligations, as well as for the further purposes indicated in this notice.

Agendly does not use Customers’ end users’ data for autonomous commercial profiling, model training, or dataset enrichment purposes.

5A. Optional Google Calendar integration

When a user voluntarily connects a Google Account to an Agendly operator, Agendly accesses only the Google Calendar data needed to synchronize appointments and prevent bookings during times that are already busy.

Google data we access

Agendly does not access aggregated or anonymized Google user-data datasets and does not create such datasets from Google Calendar data.

  • Calendar list: calendar identifier, display name, time zone, access role, and primary-calendar indicator, so the user can choose an appointment destination and the calendars that determine availability.
  • Minimum event data: event identifier, status, transparency, start and end date/time, all-day indicator, and Agendly-created private properties. Requests to Google are technically limited to these fields. Agendly does not request or store the titles, descriptions, attendees, locations, or attachments of Google events used to determine busy times.
  • Connection data: primary calendar identifier/email, selected calendars, encrypted OAuth refresh token, connection status, and last synchronization time.

How we use Google data

Agendly uses this data only to: (i) create, update, and delete events corresponding to Agendly appointments in the calendar selected by the user; (ii) represent Google events as private “busy” time blocks in the Agendly calendar; and (iii) prevent double booking. For Google-originated busy intervals, Agendly stores only the technical event identifier, start and end times, and all-day indicator. No private Google event content is displayed in the Agendly calendar.

When the user enables export, Agendly sends the Agendly appointment data to the selected Google calendar. This may include the customer’s name, services, contact details, address, notes, call summary, and other information entered in the appointment. The exported event is marked private and is created only to provide the synchronization requested by the user.

Sharing, protection, and retention

Google data is not sold or used for advertising, profiling, lending decisions, or any purpose unrelated to the requested feature. It is not shared with artificial-intelligence services and is not used to train, retrain, or improve general-purpose or third-party artificial-intelligence or machine-learning models. It may be processed only by hosting, infrastructure, and security providers acting for Agendly where necessary to provide and protect the feature, or when required by law.

OAuth tokens are encrypted at rest; data is protected in transit, subject to access controls, and limited to personnel and systems with a need to know. Stored busy intervals are replaced on each synchronization. Google connection data and Google-derived busy intervals are retained while the user keeps the integration active and are deleted when the user selects “Disconnect” or deletes the account, subject to any limited periods applicable to backups and security logs under this notice and legal obligations. Disconnecting does not automatically delete events already exported to the user’s Google calendar; those events remain under the user’s control and can be deleted in Google Calendar.

Limited Use compliance: Agendly’s use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5B. Optional WhatsApp Business integration and Meta data

A Customer may voluntarily connect its WhatsApp Business Account to the Platform. Connection takes place through Meta’s onboarding flow integrated directly into Agendly: the user signs in within the Meta environment, selects the WhatsApp Business Account and phone numbers to connect, and expressly authorizes the requested assets. Agendly does not receive or store the user’s Meta password and does not retain the authorization code or temporary token returned during onboarding.

Permissions and data processed

Agendly requests and uses the whatsapp_business_management and whatsapp_business_messaging permissions solely to provide the WhatsApp features requested by the Customer. Depending on the features used, the following data may be processed:

  • WhatsApp Business asset data: Meta Business and WhatsApp Business Account (WABA) identifiers, phone-number identifiers and numbers, display name, verification, connection and messaging-enablement status, and onboarding and synchronization technical data.
  • Business profile: name, category, “about” information, description, email, website, address, and profile image associated with the authorized number.
  • Message templates: identifier, name, language, category, components and variables, version, approval status, and any rejection reason.
  • Messaging data: sender and recipient phone numbers, message identifiers, direction, text, templates and their parameters, attachments or media, dates and times, submission, delivery or error states, and the context needed to manage the conversation.
  • Operational data: assignment of a number to an agent or campaign, webhook events, technical logs, and data strictly necessary for anti-fraud, security, support, and service accounting.

How we use WhatsApp data

The data is used only to import and display authorized assets; manage numbers, profiles, and templates; assign a number to agents or campaigns configured by the Customer; send and receive messages and media; generate responses through the configured messaging assistant in accordance with the Customer’s instructions; handle requests, appointments, and operational workflows; display conversation history where enabled; and provide support, security, abuse prevention, and service accounting.

Agendly does not sell data obtained from Meta, use it for advertising or independent profiling, combine it to create profiles unrelated to the requested conversation, or use it to train, retrain, or improve general-purpose or third-party models. Data from one WhatsApp conversation is not shared with other Customers.

Roles, sharing, and providers

Agendly S.r.l. is the Data Controller for account, connection, and administration data processed for its own purposes. When Agendly handles messages and end-user data on behalf of a Customer, the Customer is generally the Data Controller and Agendly acts as a Data Processor pursuant to Article 28 GDPR and the documented instructions in the DPA.

Data may be disclosed to Meta Platforms/WhatsApp, the communications-infrastructure provider and their respective sub-processors, as well as to the hosting, infrastructure, security, and artificial-intelligence component providers actually needed to provide the configured conversation. These parties receive only the data needed for their respective service and act under the applicable roles, terms, and safeguards. Information about processing independently performed by Meta and WhatsApp is available in their respective notices and terms.

Customer obligations and messaging rules

The Customer is responsible for having an appropriate legal basis, providing required notices, obtaining and documenting the consent or opt-in required before initiating communications on WhatsApp, and promptly honoring every objection, block, or opt-out request. Business-initiated conversations may use only templates approved by Meta; outside the 24-hour customer-service window following the user’s latest message, only approved templates may be sent. The Customer must also provide a clear escalation path and comply with applicable law, the WhatsApp Business Messaging Policy, the WhatsApp Business Terms, and Meta’s instructions.

Protection, retention, and disconnection

Data is protected in transit, subject to access controls, and limited to personnel and systems with a need to know. Conversation content and metadata are retained according to the applicable retention settings, the Customer’s documented instructions, the contract, and section 9 of this notice. Connection and configuration data is retained for the duration of the integration and, afterward, only for the period needed for technical deletion, security, billing, protection of rights, and legal obligations, including any limited backup cycles.

When the Customer selects “Disconnect,” Agendly requests removal of the communications infrastructure’s access to the WABA and disables messaging for the connected numbers. Disconnection does not necessarily result in immediate deletion of records that must be retained for legal obligations, security, billing, or the defense of rights. The Customer may also request data deletion as described in section 13 and in the published data-deletion page.

6. Transparency in interactions handled through a virtual assistant

When a Customer uses Agendly to manage calls or messaging conversations through a voice assistant or virtual agent, the Customer, as Data Controller and holder or user of the phone number, is responsible for providing end users with an adequate privacy notice regarding the processing of personal data and the interaction with an automated system or virtual assistant, where required by applicable law.

Agendly may provide technical features or operational guidance to facilitate such communication, but it remains the Customer’s responsibility to correctly configure the initial message, the short-form notice, or any other communication necessary for end users.

7. Nature of data provision

Providing the data requested during registration, service activation, contractual management, or compliance with legal obligations is necessary to enter into the contract, use the Platform, or receive the requested services.

Failure to provide the necessary data may make it impossible to register, activate the service, use certain features, or comply with contractual and legal obligations.

Providing additional, non-essential data is optional.

8. Processing methods and security measures

Processing takes place using electronic and telematic tools, according to logic strictly related to the purposes indicated in this notice and in compliance with the principles of lawfulness, fairness, transparency, data minimization, storage limitation, integrity, and confidentiality.

Agendly adopts appropriate technical and organizational measures pursuant to Article 32 GDPR, including, by way of example:

  • encryption of data in transit;
  • access controls and authentication;
  • logical segregation of environments and information;
  • security logging and monitoring;
  • backup and restore management;
  • vulnerability management and update procedures;
  • access limitation according to the need-to-know principle;
  • data minimization measures and retention configurations consistent with the chosen service.

9. Data retention

Agendly retains personal data for the time necessary to achieve the purposes for which it was collected and, in any case, in compliance with the principles of data minimization and storage limitation.

For data processed in the context of service delivery to Customers, Agendly offers two main retention options, configured according to the plan, contractual arrangements, and the Customer’s instructions:

A) Zero retention

Under the zero retention mode, conversational content and operational call or messaging data are not retained beyond the time strictly necessary for the technical handling of the communication and the production of the requested service outcome, except for any minimum data necessary for security, technical logging, operation documentation, or legal compliance.

This mode may entail limitations on history, reporting, or later consultation of conversations.

B) 30-day retention

Under the 30-day retention mode, service data, including any summaries, outcomes, appointment-related data, or content strictly necessary for handling the communication, is retained for a maximum period of 30 days, unless a different need is provided by law or a different lawful and documented instruction is given by the Customer.

After this period, the data is deleted or anonymized, except where necessary for legal obligations, security, protection of rights, or technical service management.

Additional retention periods

  • Administrative, tax, and accounting data is retained for the periods required by applicable law, generally up to 10 years.
  • Technical and security logs may be retained for periods consistent with security needs, abuse prevention, technical audit, and protection of rights, in minimized form where possible.
  • Data processed for commercial requests, demos, or contacts is retained for the time necessary to manage the request and, where applicable, for the subsequent period reasonably necessary to document the relationship or manage any further communications, unless the data subject objects.

10. Recipients and categories of recipients

Personal data may be disclosed or made accessible, within the limits of the respective purposes, to the following categories of parties:

  • authorized Agendly personnel, according to the need-to-know principle;
  • IT, cloud, hosting, infrastructure, security, and maintenance providers;
  • telecommunications and telephony service providers, for call routing, number management, and related services;
  • providers of voice components, transcription, text-to-speech, or artificial intelligence, where necessary to provide the requested features;
  • consultants, professionals, lawyers, accountants, auditors, banks, and administrative service providers;
  • competent Authorities, public bodies, or parties entitled to receive the data in cases provided by law.

Where such parties process personal data on behalf of Agendly, they are appointed as Data Processors pursuant to Article 28 GDPR through appropriate contractual agreements.

The updated list of the main providers and sub-processors may be requested from Agendly using the contact details indicated in this notice or consulted, where available, in the contractual or platform documentation.

11. Data residency and transfers outside the EEA

Agendly adopts a data residency configuration within the European Union/European Economic Area.

Data processed in the context of the ordinary provision of the Platform is stored and processed within the European Union or the European Economic Area, according to the technical and contractual architecture of the service.

Some optional integrations enabled by the Customer may, however, involve transfers to countries outside the EEA. In particular, for WhatsApp Business, Meta, the communications-infrastructure provider, and their respective sub-processors may process data in the United States or in other countries identified in their contractual documentation and privacy notices.

Any transfer outside the EEA takes place in compliance with Articles 44 et seq. GDPR on the basis, as applicable, of a European Commission adequacy decision, including the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses, or another appropriate safeguard provided for by applicable law.

12. Cookies and tracking tools

The Agendly website may use cookies and similar tools.

Technical cookies are necessary for the proper functioning of the website and do not require the user’s consent.

Any non-technical cookies or tracking tools, including non-anonymized analytics cookies, marketing, profiling, or equivalent tools, will be used only with the user’s prior consent, where required by applicable law.

The user can manage or modify their preferences through the banner or any consent management tools available on the website.

For more information, including the list of cookies used, their purposes, and durations, please refer to the dedicated Cookie Policy, where published.

13. Data subjects’ rights

Data subjects may exercise, within the limits and under the conditions provided for by the GDPR, the following rights:

  • right of access to personal data;
  • right to rectification of inaccurate data;
  • right to erasure of data, in the cases provided for;
  • right to restriction of processing;
  • right to data portability, where applicable;
  • right to object to processing, where applicable;
  • right to withdraw consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
  • right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect the person, in the cases provided for by Article 22 GDPR.

Requests may be sent to the contact details indicated in section 1 of this notice.

The data subject also has the right to lodge a complaint with the competent supervisory authority, including the Italian Data Protection Authority or the authority of their Member State.

14. Processing carried out by Agendly as Data Processor

When an end user interacts by voice or text with a virtual assistant, agent, or phone number managed through Agendly on behalf of a Customer, the Data Controller is generally the Customer with whom the user is interacting.

In such cases, Agendly processes personal data as a Data Processor pursuant to Article 28 GDPR, exclusively to provide the service to the Customer and according to the documented instructions received.

The Customer is responsible, among other things, for:

  • identifying an appropriate legal basis for the processing;
  • providing end users with the privacy notice;
  • communicating, where necessary, that the call or messaging conversation is handled through a virtual assistant or automated system;
  • correctly configuring the purposes, data processed, retention periods, and service settings;
  • handling requests to exercise data subjects’ rights.

Agendly assists the Customer, within the limits provided by the DPA and applicable law, in responding to data subject requests, managing security, deleting or returning data, and fulfilling the other obligations provided for by Article 28 GDPR.

15. Automated processes and the role of the virtual assistant

The Platform may use automated systems to understand voice or text requests, generate responses, schedule appointments, route calls, produce summaries, or trigger operational workflows configured by the Customer.

Unless otherwise contractually agreed or specifically configured by the Customer, Agendly does not use such systems to make automated decisions that produce legal effects on the data subject or similarly significantly affect them.

The Customer remains responsible for defining the purposes of processing, the logic for using the Platform in its own processes, and any need to provide human oversight, additional notices, or impact assessments.

16. Changes to this notice

Agendly may periodically update this notice to reflect legal changes, technical developments, Platform updates, or organizational changes.

The updated version will be published on the website with the date of the latest update.