Security and Privacy
Built for Scheduling Data

BookMyDay is designed with enterprise-grade security from the ground up. Your data — and your customers' data — is protected at every layer.

Data Protection

Your scheduling data is encrypted, isolated, and handled with care at every stage.

🔒

Encryption at Rest

All data stored in BookMyDay is encrypted using AES-256 encryption. Database backups are encrypted with the same standard.

🔐

Encryption in Transit

Every connection to BookMyDay is secured with TLS 1.2 or higher. API traffic, webhooks, and calendar sync all use HTTPS exclusively.

🏗️

Secure Infrastructure

BookMyDay runs on hardened cloud infrastructure with network isolation, automated patching, and continuous monitoring.

🗄️

Data Isolation

Each organisation's data is logically isolated. Strict access controls prevent cross-tenant data access at every layer.

💾

Automated Backups

Continuous encrypted backups with point-in-time recovery. Backup data is stored in geographically redundant locations.

🔍

Vulnerability Management

Regular penetration testing, dependency scanning, and security audits. Vulnerabilities are triaged and patched on a defined SLA.

Access Controls

Fine-grained controls ensure the right people have the right access — nothing more.

👤

Role-Based Access (RBAC)

Assign admin, manager, or member roles. Control who can create event types, view analytics, manage billing, or access team settings.

🔑

Single Sign-On (SSO)

SAML 2.0 SSO integration with your identity provider — Okta, Azure AD, Google Workspace, and more. Centralise authentication.

📱

Two-Factor Authentication (2FA)

Enforce 2FA across your organisation. Support for authenticator apps and hardware security keys.

📋

Audit Logs

Comprehensive audit trail of all account activity — logins, setting changes, event type modifications, and data exports.

🔗

API Key Management

Scoped API keys with granular permissions. Rotate, revoke, and monitor key usage from the admin dashboard.

🛡️

Session Management

Configurable session timeouts, forced logout, and active session visibility. Admins can revoke sessions remotely.

Compliance Posture

BookMyDay is committed to meeting the regulatory requirements that matter to your organisation.

🇪🇺 GDPR Compliance

BookMyDay is built to support compliance with the EU General Data Protection Regulation.

  • Lawful basis documentation for data processing
  • Data subject access requests (DSAR) supported
  • Right to erasure — delete user data on request
  • Data portability — export your data in standard formats
  • Data Processing Agreement (DPA) available on request

📄 Data Processing Agreement

We provide a comprehensive DPA for customers who need a formal agreement governing data processing.

  • Covers data processor obligations and sub-processors
  • Details security measures and incident notification
  • Available for review and execution via contact@bookmy.day
  • Updated to reflect current regulatory guidance

🔏 Privacy by Design

Privacy considerations are embedded in our product development lifecycle from day one.

  • Minimal data collection — we only store what's needed
  • Consent management for booking forms
  • Configurable data retention policies
  • Privacy impact assessments for new features

📊 Sub-Processor Transparency

We maintain a list of sub-processors and notify customers of changes.

  • Published sub-processor list with data categories
  • Advance notice of sub-processor changes
  • Right to object to new sub-processors
  • All sub-processors bound by equivalent security standards

What Data We Handle

Transparency about the data BookMyDay processes and how it is protected.

📅

Booking Data

Event times, attendee names, email addresses, and responses to custom intake questions. Encrypted and access-controlled.

🔄

Calendar Metadata

Free/busy information synced from connected calendars. We access only availability — never event details from external calendars.

📝

Activity Logs

Login events, setting changes, and booking actions are logged for security auditing. Logs are retained per your organisation's policy.

⏳

Data Retention

Configurable retention periods. When data expires or is deleted, it is purged from primary storage and backups within 30 days.

💳

Payment Information

BookMyDay never stores credit card numbers. Payments are processed by PCI-DSS compliant providers (Stripe, PayPal).

🌍

Data Residency

Primary data storage in secure cloud regions. Contact us for specific data residency requirements.

Trust & Certifications

Recognised standards and practices that underpin our security commitment.

🛡️

TLS 1.2+ Everywhere

All traffic encrypted in transit with modern TLS. No exceptions.

🔒

AES-256 Encryption

Industry-standard encryption for data at rest across all storage layers.

🇪🇺

GDPR Ready

Tools, processes, and agreements to support your GDPR compliance obligations.

🔑

SSO & 2FA

Enterprise authentication with SAML SSO and enforced two-factor authentication.

📋

Audit Logging

Comprehensive, tamper-evident logs for compliance and incident investigation.

🔍

Regular Pen Testing

Third-party penetration tests conducted regularly. Findings addressed within defined SLAs.

Security FAQ

Common questions from security and compliance teams.

❓ How long do you retain booking data?

Data retention is configurable per organisation. By default, booking data is retained for 12 months after the event date. Admins can adjust this in organisation settings.

  • Custom retention periods from 30 days to unlimited
  • Expired data purged from primary storage and backups within 30 days
  • Audit logs retained independently per compliance requirements

❓ How do I submit a data deletion request?

Data deletion requests can be submitted by account admins or data subjects.

  • Admins can delete individual bookings or entire user records from the dashboard
  • Data subjects can email contact@bookmy.day with a deletion request
  • Requests are processed within 30 days per GDPR requirements
  • Confirmation of deletion is provided to the requestor

❓ Where is my data stored?

BookMyDay uses secure, SOC 2-audited cloud infrastructure for data storage.

  • Primary data centres in secure cloud regions
  • Backups replicated to geographically separate locations
  • Specific data residency arrangements available for enterprise plans
  • Contact contact@bookmy.day for detailed infrastructure documentation

❓ Do you have a bug bounty or responsible disclosure programme?

Yes. We welcome responsible security research.

  • Report vulnerabilities to contact@bookmy.day
  • We acknowledge reports within 2 business days
  • Valid findings are triaged and remediated on a priority basis
  • We do not pursue legal action against good-faith researchers

Have security questions? Let's talk.

Our team is ready to walk through our security posture, provide documentation, or schedule a review.

Contact Sales Explore Features