← Back to home

Privacy Policy

Last updated: August 17, 2026 · The authoritative version of this policy is the Spanish one: Aviso de privacidad.

1. Who we are

Data controller: Zitas, Mexico.

Privacy contact: contacto@zitas.net

“Zitas” is the trade name under which the service is provided. If you need the controller's full legal and tax identification details, or its registered address — for instance to file a formal request or a complaint with the authority — you may request them at the contact address above and they will be provided.

2. What Zitas does

Zitas is appointment-scheduling and customer-service software for small businesses in Mexico that already handle enquiries over WhatsApp — medical and dental practices, clinics, salons and similar appointment-based businesses. On behalf of the business, Zitas answers incoming messages about services, hours, pricing and location; books, reschedules and cancels appointments in the business's calendar; sends appointment confirmations and reminders; and hands the conversation over to the business's staff when a person is needed.

3. Our two roles

Whose dataOur role
Business owners and staff who subscribe to Zitas, and people who contact us through this website. Controller. We determine how this data is processed.
The business's own customers or patients, who message that business's WhatsApp number to book. Processor. The business is the controller. We process this data solely on that business's behalf and instructions, in order to provide the service, and never for our own purposes.

4. Data we process

We do not request financial or payment data, or government identification, in order to book an appointment.

5. Sensitive data

Zitas exists to schedule appointments. It does not ask for health data: no diagnoses, conditions, medications or medical history, none of which are required to book. A person may nonetheless mention, on their own initiative, the reason they are seeking an appointment. When that happens, the mention stays within that business's conversation history, is treated with the same confidentiality as any other message, is not used for any purpose other than providing the scheduling service, and is never combined with other sources to build health profiles.

6. Purposes

Primary (necessary to provide the service): answering messages sent to the business's WhatsApp number; checking real availability and booking, rescheduling or cancelling appointments; sending confirmations and reminders; escalating to the business's staff when human attention is required; displaying the business's own agenda, customer history and conversations in its dashboard; support, abuse prevention and legal compliance.

Secondary (optional): aggregated, anonymised statistics used to improve the product. You may opt out by writing to us; doing so does not affect the service or your appointment.

We do not sell, rent or share personal data with third parties for advertising purposes, and we do not build profiles of individuals beyond the history needed to handle their appointments. We do not use message content to train or improve machine learning models.

7. Subprocessors and international transfers

ProviderPurpose
Meta Platforms, Inc.Sending and receiving WhatsApp messages
Google LLCAppointment calendar and text processing of incoming messages
SupabaseDatabase storing appointments and conversations
RailwayApplication server
VercelBusiness dashboard and this website

These providers operate servers outside Mexico, primarily in the United States, so data may be stored and processed outside Mexican territory under their own contractual security and confidentiality commitments. Apart from the above, we do not transfer personal data to third parties, except where required by law or by a competent authority.

8. Google user data

When a business owner connects their Google Calendar to Zitas, they grant us access to part of their Google Account. This section describes exactly how Zitas accesses, uses, stores and shares that data. It applies in addition to, and does not override, the rest of this policy.

How we obtain access

Only through Google's own consent screen (OAuth 2.0), started by the owner from a button in their dashboard, and only after they approve it. We never ask anyone for their Google password, and we cannot connect an account on someone's behalf. Access can be withdrawn at any time (see "Withdrawing access" below).

What we access, and why each permission is needed

ScopeWhat it is used for
calendar.freebusy Read only the busy time intervals of the owner's calendar, so the assistant never offers a client a slot the owner already has taken. This scope returns start and end times only — it does not reveal event titles, descriptions, guests or locations, and Zitas therefore never sees the content of the owner's other appointments.
calendar.events Create an event when an appointment is booked, and delete it when the appointment is cancelled. Zitas writes only the events it creates itself.
openid, userinfo.email Show the owner which Google account is connected, so that connecting the wrong account is visible immediately rather than after appointments start appearing in the wrong calendar.
gmail.send Send operational notices (for example, "a client could not confirm their appointment") from our own operational mailbox. This permission allows sending only. Zitas does not read, search or access anyone's mailbox, and never accesses the mailbox of a business owner or of their clients.

We deliberately request the narrowest scopes that make the feature work. In particular we do not request full calendar access, the ability to list or modify the owner's other calendars, or the ability to share calendars with anyone.

How we store it

We store the authorisation token that lets Zitas act on the connected calendar, the email address of the connected account, and the identifier of the calendar in use. These are held in a database table that is not readable by the browser or by any client-side code, is protected by row level security, and is excluded from application logs and from the information given to the assistant that talks to clients. For each appointment we store the identifier of the event we created, so that we can cancel it later. We do not copy, index or retain the contents of the owner's calendar.

How we use and share it

Google user data is used only to provide and improve the appointment scheduling features described above, in line with the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Zitas does not transfer or sell this data to third parties; does not use it for advertising, profiling or credit purposes; does not allow humans to read it, except with the owner's explicit consent, where necessary for security purposes such as investigating abuse, or where required by law; and does not use it to develop, train or improve artificial intelligence or machine learning models.

Withdrawing access

An owner can disconnect their calendar at any time from their dashboard, which deletes the stored authorisation immediately, and can additionally revoke Zitas's access from myaccount.google.com/permissions. Events already created remain in their calendar and belong to them; they may delete them as they would any other event. After disconnection the assistant stops booking new appointments unless another calendar connection is configured.

9. Your rights

Under Mexican data protection law you may access, rectify, cancel or object to the processing of your personal data (known as ARCO rights), and limit its use or disclosure. Write to contacto@zitas.net with your name, a means of contacting you, the WhatsApp number you messaged from or the business you booked with, a clear description of your request, and proof of identity.

We answer within 20 business days and, where the request is well founded, act on it within the following 15 business days. Exercising these rights is free of charge. If you believe your rights have been infringed, you may file a complaint with the competent Mexican data protection authority.

10. Deleting your data

See Data deletion for how to request deletion and what is removed.

11. Security and retention

We apply reasonable administrative, technical and physical safeguards: encryption of traffic in transit, restricted database access, per-business access control, and omission of personal data from system operation logs. Data is retained for as long as the business relationship lasts, plus any additional period required by law, after which it is deleted or anonymised.

12. This website

This site is informational and uses no advertising or third-party tracking cookies. Our hosting provider may log ordinary technical connection data such as IP address and browser type for security and operational purposes. The site loads fonts from a Google service, which involves a connection to Google's servers.

13. Changes

We may update this policy to reflect changes in the service or in applicable law. New versions are published at this same address with an updated date.

Back to home