Privacy policy
Last updated: 11 September 2026
Agenly is a product operated by Manuel Ortega Galiano, a sole trader operating under the trade name Xyvenza, with registered tax address in Baza (Granada). This page describes how we process the personal data for which we are the controller — that of visitors to agenly.io and that of the business that contracts the service — both now and during the product’s operation.
What data this policy covers
This policy covers only the data for which Agenly is the data controller: that of visitors to agenly.io and that of the business that contracts the service. When someone books an appointment on a business’s page, the controller of that data is that business, and Agenly acts as the data processor (art. 28 RGPD), processing it solely on the business’s instructions and under the data processing agreement we sign with each business. Rights over that data — the appointment, the verified phone number, the WhatsApp messages — are exercised with the business, whose contact details appear in the privacy policy of its own booking page.
Data we collect
- Your email address, when you leave it in this website’s “Notify me at launch” form.
- The access logs generated by our own web server when serving you each page: IP address, date and time, page requested and browser. These are used to deliver the site and detect abuse, not to measure audience.
- We have no server-side analytics. Usage metrics only exist if you accept the analytics cookies in the banner, and marketing metrics only if you accept that category: the detail of each cookie is in the cookie policy.
What we use them for
- To notify you by email when Agenly becomes available. Zero spam, and zero disclosures: we do not hand your email address to anyone for their own purposes. It is only processed, on our behalf, by the form provider listed among our processors.
- To improve the pre-launch website by understanding which sections attract the most interest.
Legal basis for processing
Every use we make of your data relies on one of the legal bases set out in Article 6 of the General Data Protection Regulation (RGPD):
- Consent. Your email address for the launch newsletter. The analytics cookies (Google Analytics 4) and marketing cookies (Meta Pixel, TikTok Pixel, LinkedIn Insight Tag). These processing activities are only carried out if you give your explicit consent in the cookie banner.
- Performance of a contract. The data of the contracting business and of the users of its account: sign-up, billing, configuration of its booking page and support.
- Legitimate interest. Website security: the minimal access logs written by our own web server to detect abuse. Having weighed the interest, the processing is proportionate — it is the data any server needs to deliver a page, it is kept for a short time and is not cross-referenced with anything — and you can object by writing to info@agenly.io.
- Legal obligation. Retention of tax and accounting data when you are a business client, for the periods required by Spanish law.
If you do not provide us with the data
We ask you for the minimum data needed for whatever you do in each case. Leaving your email address on the waiting list is voluntary: if you don’t leave it, we won’t be able to notify you of the launch, and nothing else on this site stops working. When you contract the service, the sign-up and billing data are indeed necessary to provide it and issue the invoice: without them we cannot formalise the contract. Accepting analytics or marketing cookies is always optional, and declining them does not limit your use of the site in any way.
Retention period
- Newsletter email address: until you request to unsubscribe or up to 24 months without interaction, whichever comes first.
- Analytics cookies: see the “Cookie policy” for the detail of each cookie.
- Marketing cookies: the duration is set by the provider (Meta, TikTok, LinkedIn) — see the “Cookie policy”.
- Accounting and tax records: 6 years from the last entry made, in accordance with Article 30 of the Spanish Commercial Code.
- Remaining operational data of the commercial service: erased 90 days after the contractual relationship ends, unless blocked under Article 32 of the LOPDGDD for as long as liabilities could arise.
International transfers
Some of the providers listed below are established outside the European Economic Area (EEA) or process data from outside it. This list is generated from the processor and joint-controller entries, so it cannot fall short: if a provider transfers data, it appears here with the safeguard that covers it.
- Cloudflare, Inc. — Certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
- Meta Platforms Ireland Ltd. (WhatsApp Business Platform) — Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses in Meta’s Terms.
- Stripe Payments Europe, Ltd. — Stripe, LLC is certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
- Twilio Inc. — Certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
- Resend (PLUS FIVE FIVE) — Certified under the EU-US Data Privacy Framework under its registered name, PLUS FIVE FIVE: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
- 650 Industries, Inc. (Expo Push) — Expo’s operator, 650 Industries, Inc., states in its privacy policy that it is self-certified under the EU-US Data Privacy Framework and its UK and Swiss extensions: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses (art. 46 RGPD).
- OpenStreetMap Foundation (Nominatim) — The transmission relies on the European Commission’s adequacy decision for the United Kingdom, renewed in December 2025 and valid until 27 December 2031.
- RevenueCat, Inc. — It is not listed under the EU-US Data Privacy Framework: the transfer relies on the Standard Contractual Clauses approved by the European Commission (art. 46 RGPD).
- Anthropic, PBC — The transfer relies on the Standard Contractual Clauses (art. 46 RGPD) included in its data processing agreement. Its inclusion in the EU-US Data Privacy Framework is pending confirmation in our legal review.
- OpenAI Ireland Limited (OpenAI) — For the sub-processing in the United States, the transfer relies on the Standard Contractual Clauses (art. 46 RGPD) included in its data processing agreement. Its inclusion in the EU-US Data Privacy Framework is pending confirmation in our legal review.
- Moonshot AI (Kimi international platform) — Neither Singapore nor China has an adequacy decision from the European Commission: the transfer relies on the Standard Contractual Clauses (art. 46 RGPD) with supplementary measures.
- Functional Software, Inc. (Sentry) — Certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
- Formspree, Inc. — It is not listed under the EU-US Data Privacy Framework — it self-certified under the former Privacy Shield and withdrew in April 2022 — so the transfer relies on the Standard Contractual Clauses (art. 46 RGPD).
- Google Ireland Ltd. (Google Analytics 4, Google Business Profile and Google Calendar) — Google LLC is certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
- Meta Platforms Ireland Ltd. (Meta Pixel) — Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
- TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited (United Kingdom) — The transmission to TikTok Information Technologies UK Limited relies on the European Commission’s adequacy decision for the United Kingdom, renewed in December 2025 and valid until 27 December 2031. Transfers to other group entities established outside the EEA rely on the Standard Contractual Clauses (art. 46 RGPD).
- LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag) — LinkedIn Corporation is certified under the EU-US Data Privacy Framework: the transfer relies on the adequacy decision and, as a backup safeguard, on the Standard Contractual Clauses.
When the provider is certified under the EU-US Data Privacy Framework, the transfer relies on the European Commission’s adequacy decision of 10 July 2023, with the Standard Contractual Clauses as a backup safeguard should that certification lapse. When it is not certified, the safeguard is directly the Standard Contractual Clauses approved by the European Commission (art. 46 RGPD). You can request a copy of the safeguards by writing to info@agenly.io.
Storage
Our infrastructure is hosted in the European Union: the servers and the database run on Hetzner Online GmbH, in data centres in Germany and Finland. Some auxiliary providers are established outside the European Economic Area or process data from outside it; the detail of each one and the safeguard covering its transfer appear in “International transfers” and in the list of data processors.
Your rights
At any time you can request access to your data, its rectification, its erasure, the restriction of its processing (art. 18 RGPD), the portability of the data you have provided us, and to object to processing based on legitimate interest. You also have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (art. 22 RGPD). To exercise any of these, write to info@agenly.io. We handle requests within the maximum one-month period set by the RGPD. If you believe the processing does not comply with the regulations, you can file a complaint with the AEPD (Spanish Data Protection Agency, www.aepd.es).
Withdrawal of consent
When processing relies on your consent — the waiting list, the analytics cookies and the marketing cookies — you can withdraw it at any time, and withdrawing it is as easy as giving it: the unsubscribe link that every email carries, and the “Cookie settings” button in the footer. Withdrawing consent does not affect the lawfulness of the processing carried out before you withdrew it.
Automated decisions
Agenly does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. The conversational assistant manages appointments within conversations that you start, under the supervision of the establishment, which can step in or pause it at any time; booking, confirming or changing an appointment does not produce effects of that kind. If we ever introduce processing of this type, we will inform you beforehand of the logic applied and the envisaged consequences, and we will update this policy.
Data protection officer
We have not appointed a data protection officer because none of the circumstances set out in Article 37 RGPD apply to us: we are not a public authority or body, our core activity does not consist of processing that requires regular and systematic monitoring of individuals on a large scale, and we do not process special categories of data on a large scale. Any query about data protection is handled directly at info@agenly.io.
Data processors
The following providers process personal data on our behalf and following our instructions (art. 28 RGPD), under a data processing agreement signed with each one. Almost all of them are strictly necessary for the product to work; Google Analytics 4 is the exception and is only activated if you accept the “Analytics” category in the banner. The OpenStreetMap Foundation is the only provider on this list without a data processing agreement: its geocoder is a public service used without an account and without a contract, so instead of a contract its entry states exactly what is sent to it and what is not.
- Hetzner Online GmbH — Hosting of the servers and the database.Data centres in Germany and Finland (European Union).
- Cloudflare, Inc. — Authoritative DNS for agenly.io and R2 object storage. R2 holds the images each business uploads to its page — the page photos, the logo and the team portraits — and the database backups. Images are reprocessed on our servers before being saved, and that reprocessing strips the EXIF metadata from the original file, including the GPS coordinate that a phone writes by default. Cloudflare’s proxy is not enabled on this site: it does not see the pages’ traffic or install any cookie in your browser.Cloudflare, Inc. is established in the US and operates a distributed network. The two R2 buckets we use — the one for images and the one for backups — are created with European jurisdiction, so the objects are stored in the European Union.
- Meta Platforms Ireland Ltd. (WhatsApp Business Platform) — Sending appointment reminders and notices through approved templates, under Meta’s Terms. It is the same entity that appears further below as a joint controller for the Meta Pixel: two different roles over two different processing activities. Here it processes the data following our instructions.Ireland (European Union); sub-processing in Meta Platforms, Inc. (US).
- Stripe Payments Europe, Ltd. — Collection of the appointment deposit. The charge is created directly on the establishment’s own Stripe account, with zero platform commission: the card data is processed by Stripe and does not pass through Agenly’s servers.Ireland (European Union); sub-processing in Stripe, LLC (US).
- Twilio Inc. — Verification of the client’s phone number when booking: sending the one-time code by SMS and checking that code.US.
- Resend (PLUS FIVE FIVE) — Transactional email delivery (team invitations, delivery of data exports).US. The region setting may keep processing within the EU; pending confirmation on our account.
- 650 Industries, Inc. (Expo Push) — Delivery of push notifications to the establishment team’s phones — new appointment, cancelled appointment, proposed time change. It only affects the business accounts: the person booking receives none. It is sent the device’s notification token, which is an identifier issued by Expo itself and not a contact detail, along with the notification text. That text is deliberately generic: “You have a new appointment”, “An appointment has been cancelled”. Neither the client’s name, her phone number, nor the service booked is sent to Expo; the notification only carries the appointment’s internal identifier so the app knows which screen to open.US.
- OpenStreetMap Foundation (Nominatim) — Placing the business on its page’s map. When the owner saves the establishment’s address — and only when she changes it, not on every save — our servers query the public Nominatim geocoder with that address and its locality, and store the point it returns. What goes out is the business’s address, not anyone else’s: no appointment, no client data and no cookie is involved, and the query is made by our server, not your browser. Aside from that, each business’s public page carries a collapsed OpenStreetMap map that only loads if you click to open it; opening it connects your browser directly to openstreetmap.org, and that connection shows it your IP address — without any cookies of ours and without telling it which page you came from. Not opening it is how you avoid appearing there. Its processing is governed by the OpenStreetMap Foundation’s privacy policy (osmfoundation.org).United Kingdom (foundation registered in England and Wales).
- RevenueCat, Inc. — Recording the establishment’s subscription status once the product is commercially operational.US. The region setting may keep processing within the EU; pending confirmation on our account.
- Anthropic, PBC — Language model for the AI conversational assistant and for the automatic description of the establishment page’s photos. Which provider handles each call is set by the service configuration. It only processes conversation data from the channels where the establishment has activated the assistant, and the photographs the owner uploads to her gallery; while the AI assistant is deactivated, no data is sent to it.US.
- OpenAI Ireland Limited (OpenAI) — Language model for the AI conversational assistant and for the automatic description of the establishment page’s photos. Which provider handles each call is set by the service configuration. It only processes conversation data from the channels where the establishment has activated the assistant, and the photographs the owner uploads to her gallery; while the AI assistant is deactivated, no data is sent to it.Ireland (European Union) as the contracting entity for the European Economic Area; sub-processing in OpenAI, L.L.C. (US).
- Moonshot AI (Kimi international platform) — Language model for the AI conversational assistant and for the automatic description of the establishment page’s photos. Which provider handles each call is set by the service configuration. It only processes conversation data from the channels where the establishment has activated the assistant, and the photographs the owner uploads to her gallery; while the AI assistant is deactivated, no data is sent to it.Singapore, according to its international platform’s privacy policy; the parent company is headquartered in Beijing (China). Contracting entity pending confirmation on our account.
- Functional Software, Inc. (Sentry) — Backend error observability.US. The region setting may keep processing within the EU; pending confirmation on our account.
- Formspree, Inc. — Receiving and storing the email address you leave in this website’s “Notify me at launch” form, and notifying the account holder of each new sign-up.US. Its infrastructure runs on Amazon Web Services in the United States and does not offer a European region.
- Google Ireland Ltd. (Google Analytics 4, Google Business Profile and Google Calendar) — Three separate services from the same entity, under Google’s Data Processing Terms. Google Analytics 4: aggregate analysis of this site’s usage, and the only one of the three that depends on your consent — it is only activated if you accept the “Analytics” category. Google Business Profile: when a business connects its Google listing, we pull in its public reviews and store them to display on its page, including the name, photo and text of the reviewer, exactly as Google publishes them, because Google’s terms require that attribution to be shown unaltered; this is data that was already public on Google, and that the reviewer can edit or delete there, and when they do, it also disappears from here at the next synchronisation. Google Calendar: when a business syncs its calendar, we write each appointment to its calendar with the service and the establishment’s name, and deliberately without the client’s name — the event simply states that the details are in the Agenly dashboard.Ireland (European Union); sub-processing in Google LLC (US).
Joint controllers
With the advertising platforms we do not act as controller and processor, but as joint controllers (art. 26 RGPD), along the lines set out in the Fashion ID judgment of the Court of Justice of the EU (C-40/17) and Guidelines 8/2020 of the European Data Protection Board. The split is as follows: we inform you and collect your consent before any pixel loads, and we are responsible for that collection and for the transmission to the platform; the platform is responsible for the data once it has received it, including the exercise of your rights over it, and from that point processes it as an independent controller for its own advertising purposes, over which we neither decide nor have access. You can approach either us or the platform to exercise your rights, although only the platform can resolve matters relating to that later processing. Each one’s joint-controller agreement is linked in its entry.
- Meta Platforms Ireland Ltd. (Meta Pixel) — Measurement of campaigns on Meta’s advertising platforms. It only loads after your consent to the “Marketing” category. It is the same entity that appears above as processor for the WhatsApp Business Platform: there it processes data following our instructions, here it decides the collection together with us.Ireland (European Union); sub-processing in Meta Platforms, Inc. (US).
- TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited (United Kingdom) — Measurement of campaigns on TikTok. It only loads after your consent to the “Marketing” category. Both entities act jointly as joint controllers, the Irish one under the RGPD and the British one under the UK RGPD.Ireland (European Union) and the United Kingdom.
- LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag) — Measurement of B2B campaigns on LinkedIn and aggregate demographic audience data. It only loads after your consent to the “Marketing” category.Ireland (European Union); sub-processing in LinkedIn Corporation (US).
Changes
We update this policy every time something material changes in the processing: a new provider, a new purpose, or a change in the safeguard covering a transfer. The date in the header shows the last revision. If the change is material we will notify you by email, and when it affects cookies the banner will ask for your consent again.
Contact
For any query about privacy or the exercise of rights, write to info@agenly.io.