BookOS

Trust centre

Security & trust

We treat the security of customer and end-customer data as a first-class product requirement. This page summarises the controls we operate today, the vendors we rely on, and where to find authoritative information. For the contractual version, see Schedule 2 of our DPA.

Last updated: 3 June 2026

Data protection

In transit: all public traffic is encrypted using modern TLS.

At rest: the production database, backups, and object storage are encrypted.

Your clients are yours alone: one salon can never see another salon’s customers. We test for that continuously.

Card details: never touch BookOS. They go straight to Stripe, at the highest level of card-industry certification (PCI-DSS Level 1).

Access & authentication

  • BookOS operator credentials are isolated in the environment, not stored in the application database.
  • Only the people who need access have it, and we check that regularly.
  • We never store your customers’ passwords, and signing out on one device doesn’t sign you out everywhere.

Reliability & recovery

  • Encrypted backups with point-in-time recovery on the production database.
  • Restore procedures are documented and tested regularly.
  • Your data stays in the EU.

Vulnerability management

Monitoring & incident response

  • Centralised application logs, security event logs, and immutable audit trails.
  • Error tracking and anomaly alerting on production systems.
  • Documented incident-response playbook with prompt triage of suspected breaches.
  • Customer notification of confirmed personal-data breaches within 72 hours under GDPR Art. 33 / DPA § 9.

Data residency & sub-processors

Application and database are hosted in the EU. A small set of sub-processors is engaged to deliver the Service. The current list, with role, location, and transfer mechanism, is published at /legal/subprocessors and forms part of our DPA.

Compliance & certifications

GDPR & ePrivacy:
we operate under EU data-protection law; our DPA incorporates the EU Standard Contractual Clauses (2021/914) for any necessary international transfers.
Danish Bookkeeping Act:
7-year retention of invoices and accounting records.
Digital Services Act:
single point of contact published at /legal/dsa-contact.
Independent certifications:
a current compliance summary is available to enterprise customers under NDA.