Privacy policy
This policy describes how Nowo Insurance Services, S.L. processes personal data on this AgendaDesk instance (GDPR, LOPDGDD). It is adapted from the Nowo platform privacy policy of 1 June 2025 to the AgendaDesk product (agendas, clients, appointments, optional AI secretary).
1. Who is who
Nowo Insurance Services, S.L. is the controller of staff and operator accounts, security logs, cookie-consent records, and instance administration on this deployment. Each organisation (tenant) is the controller of its clients, appointments, and secretary conversations. Nowo processes that tenant data as a processor under GDPR article 28 on the tenant’s documented instructions, except where Nowo itself is the tenant organisation, in which case Nowo is controller of those records too.
2. Controller and contact
Controller for instance accounts and logs — Nowo Insurance Services, S.L., Calle Marie Curie 20, bajo izquierda, 29590 Campanillas (Málaga). Phone +34 951 204 864. Email hola@nowo.tech. CIF B01772607.
Data Protection Officer — nowo@delegadoprotecciondedatos.es (same DPO contact as published on nowo.tech).
3. Categories of data
Depending on how this instance is configured, processing may include:
- Staff and operator accounts (e-mail, display name, password hash, roles, locale/theme preferences, last activity)
- Organisation membership, roles, and integration settings (including encrypted API secrets)
- Client identity and contact data needed to book agendas (names, e-mail, phone, identifiers). Selected fields are encrypted at rest with Halite (nowo-tech/doctrine-encrypt-bundle). Display name and phone used for the staff desk may remain searchable in plaintext as documented in docs/product/GDPR.md
- Optional AI-secretary transcripts/summaries, messaging channel identifiers, and voice-agent configuration when the organisation enables those features
- Operational logs, optional cookie-consent audit rows, HTTP request metadata (path, status, duration, IP and user id when http-log is enabled; default retention 30 days), and admin activity history
- Cookies and similar technologies described on the Cookies page (nowo-tech/cookie-consent-bundle)
AgendaDesk is not designed to store special-category data (GDPR article 9) as a primary purpose. Organisations must not record health, religion, or similar data in notes unless they have a separate lawful basis and DPIA. Telephony recordings, if enabled, may contain incidental sensitive data; tenants remain responsible for minimisation.
4. Purposes
Data are processed to create and authenticate accounts, run shared agendas and reminders, provide staff access, operate the optional secretary, secure the service, meet legal duties, and — only with consent — optional cookie categories. Magic-link and operational e-mail are service messages, not marketing. Commercial e-mail about Nowo products is sent only with GDPR article 6(1)(a) consent.
5. Legal bases
Staff accounts and bookings are processed to perform the service contract (GDPR article 6(1)(b)), including the licence with the customer organisation. Security, fraud prevention, and HTTP/audit logs rely on legitimate interests (article 6(1)(f)) and, where applicable, legal obligation (article 6(1)(c), LOPDGDD). Optional cookies require consent (article 6(1)(a); LSSI-CE / ePrivacy). Tenant client files are processed as a processor on the tenant’s bases; tenants must inform their clients.
6. Recipients and processors
Recipients include Nowo staff who operate this instance, the tenant organisation that owns a record, and processors under article 28 (hosting, e-mail delivery, backups). Optional subprocessors when a tenant enables them — ElevenLabs (voice agents / ConvAI preview after an operator starts it), messaging or telephony providers configured by the organisation, and error monitoring (Beacon) if a DSN is set. Authorities receive data only when legally required. Secrets and webhook URLs are encrypted at rest where the encrypt bundle is applied.
7. International transfers
Default hosting and the primary database are intended to remain in the EEA. If a tenant enables ElevenLabs or another non-EEA processor, that transfer uses the supplier’s GDPR terms (typically Standard Contractual Clauses). Do not enable those integrations without reading the supplier DPA. Empty Beacon DSN means no Beacon transfer.
8. Automated decisions
Slot suggestions and reminders are not solely automated decisions producing legal effects (GDPR article 22). Staff confirm appointments. Secretary replies assist staff; they do not replace a human decision about a person’s legal position.
9. Retention
Account data are kept while the account is active and then blocked for limitation periods (typically up to six years for commercial/tax duties in Spain, and up to five years for personal actions without a special term), then securely deleted or anonymised. Tenant client and appointment retention follows the organisation’s instructions and product retention settings. HTTP logs default to 30 days (`nowo_http_log.retention.days`) and should be purged with `nowo:http-log:purge`. Cookie-consent logs follow the cookie-consent bundle retention. Anonymise/export tools live under Account → Privacy and Admin → Users.
Nowo applies technical and organisational measures appropriate to the risk (TLS, hashed passwords, role-based access, optional FrankenPHP hardening, Halite encryption for selected PII and secrets). Measures are reviewed periodically. Request more detail at hola@nowo.tech.
Signed-in users may download a JSON export of their account fields and allowlisted security activity. Instance admins may export or anonymise other accounts. Anonymise does not by itself delete tenant appointment history; organisations must use product retention for those files.
10. Minors
Accounts are for professionals. Information-society consent of children under 14 in Spain requires a holder of parental authority (LOPDGDD article 7). Do not create staff accounts for children.
11. Your rights
You may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent without affecting prior lawful processing. Write to hola@nowo.tech, nowo@delegadoprotecciondedatos.es, or the postal address above. Staff should use Account → Privacy where the product already exposes export. Tenant clients should contact their organisation first; Nowo will assist as processor.
You may lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es) or the supervisory authority of your EU/EEA residence (GDPR article 77).
12. Cookies
Strictly necessary cookies support authentication, CSRF protection, consent records, and device-intelligence abuse prevention. Optional categories (preferences, analytics) stay off until you accept them in the cookie banner provided by nowo-tech/cookie-consent-bundle. No analytics or marketing tag is loaded before consent.
Cookie inventory (summary)
Necessary first-party cookies: session (OPEN_AGENDADESK_SESSID), remember-me, CSRF, Cookie_Consent / Cookie_Consent_Key / category flags, and di_obs. Provider: Nowo Insurance Services, S.L. Full table on the Cookies page.
Cookie notice · Cookie settings
This AgendaDesk adaptation is dated 3 October 2026 (identity aligned with the Nowo.tech notice of 14 November 2021 and platform privacy policy of 1 June 2025). Material changes will be published on these pages.