Security and Privacy
Built for Scheduling Data
BookMyDay is designed with enterprise-grade security from the ground up. Your data — and your customers' data — is protected at every layer.
Data Protection
Your scheduling data is encrypted, isolated, and handled with care at every stage.
Encryption at Rest
All data stored in BookMyDay is encrypted using AES-256 encryption. Database backups are encrypted with the same standard.
Encryption in Transit
Every connection to BookMyDay is secured with TLS 1.2 or higher. API traffic, webhooks, and calendar sync all use HTTPS exclusively.
Secure Infrastructure
BookMyDay runs on hardened cloud infrastructure with network isolation, automated patching, and continuous monitoring.
Data Isolation
Each organisation's data is logically isolated. Strict access controls prevent cross-tenant data access at every layer.
Automated Backups
Continuous encrypted backups with point-in-time recovery. Backup data is stored in geographically redundant locations.
Vulnerability Management
Regular penetration testing, dependency scanning, and security audits. Vulnerabilities are triaged and patched on a defined SLA.
Access Controls
Fine-grained controls ensure the right people have the right access — nothing more.
Role-Based Access (RBAC)
Assign admin, manager, or member roles. Control who can create event types, view analytics, manage billing, or access team settings.
Single Sign-On (SSO)
SAML 2.0 SSO integration with your identity provider — Okta, Azure AD, Google Workspace, and more. Centralise authentication.
Two-Factor Authentication (2FA)
Enforce 2FA across your organisation. Support for authenticator apps and hardware security keys.
Audit Logs
Comprehensive audit trail of all account activity — logins, setting changes, event type modifications, and data exports.
API Key Management
Scoped API keys with granular permissions. Rotate, revoke, and monitor key usage from the admin dashboard.
Session Management
Configurable session timeouts, forced logout, and active session visibility. Admins can revoke sessions remotely.
Compliance Posture
BookMyDay is committed to meeting the regulatory requirements that matter to your organisation.
🇪🇺 GDPR Compliance
BookMyDay is built to support compliance with the EU General Data Protection Regulation.
- Lawful basis documentation for data processing
- Data subject access requests (DSAR) supported
- Right to erasure — delete user data on request
- Data portability — export your data in standard formats
- Data Processing Agreement (DPA) available on request
📄 Data Processing Agreement
We provide a comprehensive DPA for customers who need a formal agreement governing data processing.
- Covers data processor obligations and sub-processors
- Details security measures and incident notification
- Available for review and execution via contact@bookmy.day
- Updated to reflect current regulatory guidance
🔏 Privacy by Design
Privacy considerations are embedded in our product development lifecycle from day one.
- Minimal data collection — we only store what's needed
- Consent management for booking forms
- Configurable data retention policies
- Privacy impact assessments for new features
📊 Sub-Processor Transparency
We maintain a list of sub-processors and notify customers of changes.
- Published sub-processor list with data categories
- Advance notice of sub-processor changes
- Right to object to new sub-processors
- All sub-processors bound by equivalent security standards
What Data We Handle
Transparency about the data BookMyDay processes and how it is protected.
Booking Data
Event times, attendee names, email addresses, and responses to custom intake questions. Encrypted and access-controlled.
Calendar Metadata
Free/busy information synced from connected calendars. We access only availability — never event details from external calendars.
Activity Logs
Login events, setting changes, and booking actions are logged for security auditing. Logs are retained per your organisation's policy.
Data Retention
Configurable retention periods. When data expires or is deleted, it is purged from primary storage and backups within 30 days.
Payment Information
BookMyDay never stores credit card numbers. Payments are processed by PCI-DSS compliant providers (Stripe, PayPal).
Data Residency
Primary data storage in secure cloud regions. Contact us for specific data residency requirements.
Trust & Certifications
Recognised standards and practices that underpin our security commitment.
TLS 1.2+ Everywhere
All traffic encrypted in transit with modern TLS. No exceptions.
AES-256 Encryption
Industry-standard encryption for data at rest across all storage layers.
GDPR Ready
Tools, processes, and agreements to support your GDPR compliance obligations.
SSO & 2FA
Enterprise authentication with SAML SSO and enforced two-factor authentication.
Audit Logging
Comprehensive, tamper-evident logs for compliance and incident investigation.
Regular Pen Testing
Third-party penetration tests conducted regularly. Findings addressed within defined SLAs.
Security FAQ
Common questions from security and compliance teams.
❓ How long do you retain booking data?
Data retention is configurable per organisation. By default, booking data is retained for 12 months after the event date. Admins can adjust this in organisation settings.
- Custom retention periods from 30 days to unlimited
- Expired data purged from primary storage and backups within 30 days
- Audit logs retained independently per compliance requirements
❓ How do I submit a data deletion request?
Data deletion requests can be submitted by account admins or data subjects.
- Admins can delete individual bookings or entire user records from the dashboard
- Data subjects can email contact@bookmy.day with a deletion request
- Requests are processed within 30 days per GDPR requirements
- Confirmation of deletion is provided to the requestor
❓ Where is my data stored?
BookMyDay uses secure, SOC 2-audited cloud infrastructure for data storage.
- Primary data centres in secure cloud regions
- Backups replicated to geographically separate locations
- Specific data residency arrangements available for enterprise plans
- Contact contact@bookmy.day for detailed infrastructure documentation
❓ Do you have a bug bounty or responsible disclosure programme?
Yes. We welcome responsible security research.
- Report vulnerabilities to contact@bookmy.day
- We acknowledge reports within 2 business days
- Valid findings are triaged and remediated on a priority basis
- We do not pursue legal action against good-faith researchers