Security & GDPR.

You're trusting us with your customer list, calendar and takings. Here's how we look after it.

Encrypted in transit & at rest

TLS 1.2+ on every connection. AES-256 disk encryption on the database. HSTS enforced.

Row-level access controls

Every query is filtered by the current tenant and user role in the database itself — not just the app layer.

EU-region infrastructure

Data stored in the EU. Served from a global edge network for speed, but never egressed outside our controls.

Point-in-time backups

Continuous WAL backups with 7-day point-in-time recovery. Full daily snapshots retained for 30 days.

Audit logs

Every admin action — role changes, exports, deletions — is logged with actor, timestamp and IP.

Your data is yours

Export every booking, customer, service and message to CSV any time. Cancel and take it with you.

GDPR & UK data protection

BookAppointment is designed to make it easy for UK & EU businesses to stay compliant. Below is a plain-English summary — full details in our Privacy Policy and DPA.

For customer bookings on your site, you are the controller and we are the processor acting on your instructions under our DPA.

Have a security or compliance question?

We're happy to talk through anything before you sign up. Email security@bookappointment.co.uk.

Get in touch