Skip to content
Legal

Data and Compliance

Learn how Booqself approaches data protection, platform security, and compliance responsibilities.

Effective: 2026-06-22Updated: 2026-09-29

1. Overview

Booqself is built to help businesses manage appointments, customers, services, resources, booking pages, and notifications in a structured and secure way.

This page explains our approach to data protection and compliance. It is not a certification statement and does not replace a legal agreement.

2. Data We Process

Booqself may process:

  • Business account data
  • Business settings
  • Team member information
  • Customer contact information
  • Appointment information
  • Service and service option data
  • Resource and staff information
  • Public booking page content
  • Notification and integration data
  • Operational and security logs

3. Data Ownership

Businesses remain responsible for the customer and appointment data they collect through Booqself.

Booqself provides the software infrastructure used to store, organize, and process that data.

4. Access Controls

Booqself supports role-based access patterns so businesses can control what owners, admins, and team members can access.

Users should only be granted access needed for their business role.

5. Multi-Tenant Data Separation

Booqself is designed as a multi-tenant system where each organization manages its own data.

Application logic and database access rules should prevent users from accessing information belonging to another organization.

6. Security Measures

Booqself uses reasonable technical and organizational safeguards, which may include:

  • Authentication
  • Authorization checks
  • Organization-based data access
  • Secure database access patterns
  • Server-side validation
  • Audit-friendly timestamps
  • Secure file storage patterns
  • Infrastructure monitoring
  • Principle of least privilege

7. Data Retention

Data is retained as needed to provide the platform, support business operations, comply with legal obligations, resolve disputes, and maintain security.

Businesses may delete or modify certain information from the dashboard, subject to platform limitations and legal requirements.

8. Backups and Recovery

Booqself may rely on infrastructure providers for database, storage, backup, and recovery capabilities.

Backup retention and recovery processes may vary based on the provider and platform configuration.

9. Third-Party Service Providers

Booqself may use third-party providers for:

  • Hosting
  • Database infrastructure
  • File storage
  • Email delivery
  • Authentication
  • Analytics
  • Error monitoring
  • Automation
  • Messaging integrations
  • Voice or AI-powered integrations when enabled

Provider access, retention, and contractual responsibilities depend on the service and configuration. Businesses with specific processor, residency, or transfer requirements should confirm the applicable arrangements with Booqself before submitting that data. This page is not a data-processing agreement or a complete subprocessor register.

10. Compliance Responsibilities

Booqself helps businesses manage appointment data, but each business is responsible for understanding and meeting its own legal and industry obligations.

Businesses should evaluate whether their use of Booqself is appropriate for their industry, region, and data requirements.

11. Regulated Data

Do not submit highly sensitive regulated data unless Booqself has expressly approved the intended use and the necessary contracts, provider arrangements, and technical safeguards are in place. A general subscription does not establish that approval.

This includes protected health information, financial account credentials, and government identifiers. For healthcare, even an appointment's customer identity, provider, service, or notes can be protected health information; the restriction is not limited to medical records. Where HIPAA applies, a business associate agreement and appropriate safeguards across the applicable service providers are necessary before processing electronic protected health information. Do not enter payment card details in booking notes; use the designated payment checkout.

12. Current Compliance Position

Booqself makes no SOC 2 attestation, ISO 27001 certification, PCI DSS validation, or HIPAA compliance claim on this page. HIPAA is a legal framework, not a product certification. Neither a provider's certification nor a signed agreement alone establishes compliance for a particular use of Booqself.

13. Incident Response

If Booqself becomes aware of a security incident affecting user data, we will take reasonable steps to investigate, mitigate, and notify affected parties when required.

14. Contact

For data or compliance questions, contact:

Booqself
Email: hello@booqself.com