Privacy policy
Last updated: August 2, 2026
This is a translation for convenience. The Spanish version is the binding one.
1. Who is responsible for your data
AgendaYa is a scheduling platform operated by CT TECHNOLOGY SOLUTIONS SAS, tax ID 901.864.439-5, a company domiciled in Colombia (ctechsolutions.co).
Two roles need to be told apart, because they determine who you go to for what:
- When you use AgendaYa as a business (you have an account and manage a calendar), CT TECHNOLOGY SOLUTIONS SAS is the controller of your data.
- When you book an appointment at a business that uses AgendaYa, the controller of your data is that business. AgendaYa acts as a processor: it handles that data on the business’s instructions and does not use it for its own purposes. If you want your data deleted or corrected, start with the business you booked with; you can also write to us and we’ll pass it on.
2. What data we process
From the businesses using the platform
- Account data: name, email address and an encrypted password.
- Business data: name, address, phone, time zone, currency, service catalog, team and hours.
- Credentials for the integrations you connect (WhatsApp Business, Meta, Google). They are stored encrypted with AES-256-GCM and the key does not live in the database.
- Technical usage and error logs, to operate and debug the service.
From the end clients who book
- Name, phone and, if provided, email address and postal address.
- The appointments: service, date, time, professional, price, notes the person wrote and the business’s internal notes.
- Messages exchanged over WhatsApp, Instagram or Messenger with the business, including those answered by the automated assistant.
- Advertising attribution data when the person arrives from an ad (Meta click identifiers, UTM parameters, referring site).
From the mobile app
If the business’s team uses the AgendaYa app for iOS or Android, in addition to the above we process:
- The device’s notification identifier (the token issued by Apple and Google), along with the phone’s name, operating system and app version. It is what lets a new appointment be announced on that phone and not another. It is deleted on sign-out or when notifications are turned off.
- The files sent from the phone in a conversation: photos from the library, documents and voice notes. They are accessed only when the person picks them, one by one, and become part of the business’s conversation. The app does not read the photo library, the microphone or files on its own.
- Technical error and performance data: which screen failed, the device model and the OS version. They are sent without request bodies and without the session token, and serve to fix the app.
The app does not use location, does not access contacts or the camera, and shares nothing with third parties for advertising purposes.
Data we receive from Meta
If the business connects its WhatsApp Business account, its Facebook pages or its Instagram account, we receive from Meta the content of the messages people send it, the profile name, the channel identifier and — when the message arrives from an ad — that ad’s attribution data. If the business enables lead forms, we receive the responses to the forms it has explicitly authorized.
3. What we use it for
- Providing the service: calculating availability, creating and managing appointments.
- Handling messaging channels, including the automated reply with artificial intelligence when the business enables it.
- Sending appointment confirmations and reminders.
- Reporting to the business where its clients come from, when it has advertising integrations connected.
- Billing and enforcing the limits of the contracted plan.
- Security: detecting abuse, fraud and unauthorized access.
We do not sell personal data and we do not use it to train artificial intelligence models.
4. Artificial intelligence
When the business enables the assistant, the content of the conversation and the context needed to answer (catalog, availability, that person’s appointments) are sent to a language model provider to generate the reply. That provider processes the content to fulfil the request and does not use it to train its models.
The assistant identifies itself as part of the business’s team. When it can’t resolve something, it hands the conversation to a person.
5. Who we share it with
| Provider | Purpose |
|---|---|
| Vercel | Application hosting |
| Neon | Database |
| Meta Platforms | Messaging (WhatsApp, Instagram, Messenger) and advertising |
| Language model providers | Generating the assistant’s replies |
| Sign-in and, if connected, calendar synchronization | |
| Google Firebase and Apple | Delivering notifications to the mobile app |
| Sentry | Error reporting for the web app and the mobile app |
Some of these providers are outside Colombia, so there is an international transfer of data. We may also share information when a competent authority legally requires it.
6. How long we keep it
- Account and business data: for as long as the account is active. If it’s cancelled, it is deleted after 90 days, except for what must be kept under accounting or tax obligations.
- Appointments and clients: for as long as the business keeps them. That’s the business’s decision, and it can delete them from the dashboard.
- Conversations: the history the assistant uses is trimmed automatically to the most recent turns. The full message log is kept for as long as the business needs it to serve its clients.
- Technical logs: up to 90 days.
7. Your rights
Under Colombian Law 1581 of 2012 and Decree 1074 of 2015 you may access, update, rectify and delete your data, withdraw your authorization, and file complaints with the Superintendency of Industry and Commerce.
To exercise them, write to us at contacto@agendaya.com.co. We answer within the statutory deadlines: 10 business days for enquiries and 15 business days for complaints. If your data is held by a business that uses AgendaYa, we forward the request to that business and let you know.
If you have an AgendaYa account you can delete it yourself from the mobile app, under Configuración → Cuenta y privacidad, or by asking us by email. If you are the sole owner of a business, the business is closed first — from the web panel, under Configuración → Cuenta, with the 90-day window in section 6 — and your account is deleted along with it.
To delete data that arrived from Facebook or Instagram, see the data deletion page.
8. Security
- All traffic is encrypted in transit (HTTPS).
- Integration credentials are stored encrypted with AES-256-GCM.
- Passwords are stored as bcrypt hashes, never in plain text.
- Each business is isolated: every database query filters by its identifier and membership is verified on every request.
- Incoming webhooks are validated by cryptographic signature before being processed.
No measure is infallible. If we detect an incident affecting your data, we will inform you and report it to the authority as appropriate.
9. Minors
AgendaYa is not directed at minors and we do not knowingly collect their data. If a business books an appointment for a minor, it is the business that must have the authorization of their legal guardians.
10. Changes
If we change this policy, we update the date above and notify businesses with an active account by email before the change takes effect.
11. Contact
CT TECHNOLOGY SOLUTIONS SAS · Tax ID 901.864.439-5
contacto@agendaya.com.co
https://ctechsolutions.co/