Security & GDPR.
You're trusting us with your customer list, calendar and takings. Here's how we look after it.
Encrypted in transit & at rest
TLS 1.2+ on every connection. AES-256 disk encryption on the database. HSTS enforced.
Row-level access controls
Every query is filtered by the current tenant and user role in the database itself — not just the app layer.
EU-region infrastructure
Data stored in the EU. Served from a global edge network for speed, but never egressed outside our controls.
Point-in-time backups
Continuous WAL backups with 7-day point-in-time recovery. Full daily snapshots retained for 30 days.
Audit logs
Every admin action — role changes, exports, deletions — is logged with actor, timestamp and IP.
Your data is yours
Export every booking, customer, service and message to CSV any time. Cancel and take it with you.
GDPR & UK data protection
BookAppointment is designed to make it easy for UK & EU businesses to stay compliant. Below is a plain-English summary — full details in our Privacy Policy and DPA.
Have a security or compliance question?
We're happy to talk through anything before you sign up. Email security@bookappointment.co.uk.
Get in touch