buq.pt is now agend.pt. New branding, the same product you already know — nothing changes in your account.

agend.pt

Privacy Policy

Last updated: 25 July 2026

1. Data controller

agend.pt is operated by Diogo Dias and based in Portugal. For privacy questions, contact privacidade@agend.pt.

2. Data we collect

Account data (professionals)

  • Name, email address, and authentication data.
  • Business name, description, and time zone.
  • Billing data processed by Stripe.

Booking data (clients)

  • Name, email address, and phone number submitted through the booking form.
  • Booking date, time, service, and professional.
  • With marketing consent, tagged campaign, traffic source, referrer domain, and first/last touch timestamps associated with the booking.

3. Why we process data

  • Create and protect user accounts.
  • Manage bookings between professionals and clients.
  • Send transactional messages such as confirmations, declines, rescheduling updates, and reminders.
  • Sync Google Calendar when the professional enables the integration.
  • Process subscriptions and deposits through configured payment providers.
  • Measure product activation and campaign performance according to consent preferences.

3.1. Use of Google data

Signing in with Google requests only your name and email address. Google Calendar access is requested separately when a professional chooses to enable the integration.

Data accessed

  • Google account name and email address for authentication.
  • Busy and free periods from Google Calendar when sync is enabled.
  • Event times and attendance status from the primary Google Calendar when the calendar overlay is enabled. Event titles, descriptions, locations, and attendee identities are not requested for this view.
  • Permission to create, update, and delete booking events in Google Calendar when sync is enabled.

How we use the data

  • Name and email are used to create and authenticate the agend.pt account.
  • Availability is checked in real time to prevent scheduling conflicts.
  • Busy events can be displayed as generic, read-only blocks in the professional's agend.pt calendar.
  • We create or remove events when a booking's status changes.

How we store the data

  • OAuth tokens are encrypted at rest to maintain the connection authorized by the professional.
  • Busy and free periods used for conflict checks are not stored. Privacy-safe event times used by the calendar overlay may be cached for up to two minutes; event titles, descriptions, locations, and attendee identities are not cached.

How we protect sensitive data

  • Data is transmitted over secure HTTPS/TLS connections.
  • Internal access is limited to authorized people and only when needed to operate or protect the service.
  • We reduce exposure of tokens, secrets, and sensitive identifiers in application logs.
  • If the integration is disconnected or the account deleted, we stop using and remove associated tokens according to this policy.

Sharing Google data

  • We do not sell data obtained from a Google account.
  • We use that data only for the features described in this policy.
  • We do not use Google data for advertising, retargeting, or profiling.

Our use of data received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

4. Legal basis

We process data to perform our service contract, comply with legal obligations, protect legitimate security and product-improvement interests and, where required, based on consent.

5. Data sharing

We do not sell personal data. We use the following processors only to provide and measure the service:

  • Stripe — subscription billing and payment processing.
  • Brevo — transactional email delivery.
  • Google — authentication and calendar sync when enabled.
  • Hetzner — European infrastructure hosting.
  • Himetrica — privacy-focused usage analytics, with consent only.
  • Google Tag Manager and Google Ads — campaign measurement, with consent only.

6. Data retention

We retain data while an account is active and as long as needed to meet legal obligations. When an account is deleted, data is removed from active systems; residual backups are deleted through the normal cycle within 30 days.

7. Your rights

Under the GDPR, you may request access, correction, deletion, restriction, objection, and portability of your data. To exercise these rights, contact privacidade@agend.pt.

8. Cookies and local storage

We use browser cookies and local storage for the following purposes:

Strictly necessary (no consent required)

  • Session, authentication, and CSRF protection.
  • Theme and language preferences.
  • Remembering your consent choice.

Usage analytics (optional)

With consent, Himetrica measures usage with anonymous identifiers in local and session storage. It does not use tracking cookies or fingerprinting, does not share data for advertising, and respects the Do Not Track signal.

Marketing (optional)

With consent, Google Tag Manager and Google Ads measure clicks and sign-ups using Google's consent mode. agend.pt also keeps a first-party attribution cookie for up to 30 days so a professional can see the source of a public-page reservation.

You can change your choice at any time through or the link in the footer.

9. Changes

We may update this policy to reflect changes to the product, providers, or legal requirements. The latest update date appears at the top of the page.