Trust centre
Security & trust
We treat the security of customer and end-customer data as a first-class product requirement. This page summarises the controls we operate today, the vendors we rely on, and where to find authoritative information. For the contractual version, see Schedule 2 of our DPA.
Last updated: 3 June 2026
Data protection
In transit: all public traffic is encrypted using modern TLS.
At rest: the production database, backups, and object storage are encrypted.
Your clients are yours alone: one salon can never see another salon’s customers. We test for that continuously.
Card details: never touch BookOS. They go straight to Stripe, at the highest level of card-industry certification (PCI-DSS Level 1).
Access & authentication
- BookOS operator credentials are isolated in the environment, not stored in the application database.
- Only the people who need access have it, and we check that regularly.
- We never store your customers’ passwords, and signing out on one device doesn’t sign you out everywhere.
Reliability & recovery
- Encrypted backups with point-in-time recovery on the production database.
- Restore procedures are documented and tested regularly.
- Your data stays in the EU.
Vulnerability management
- Automated dependency updates across our repositories.
- Security patches applied promptly; critical issues prioritised.
- Coordinated disclosure programme: see vulnerability disclosure and /.well-known/security.txt.
Monitoring & incident response
- Centralised application logs, security event logs, and immutable audit trails.
- Error tracking and anomaly alerting on production systems.
- Documented incident-response playbook with prompt triage of suspected breaches.
- Customer notification of confirmed personal-data breaches within 72 hours under GDPR Art. 33 / DPA § 9.
Data residency & sub-processors
Application and database are hosted in the EU. A small set of sub-processors is engaged to deliver the Service. The current list, with role, location, and transfer mechanism, is published at /legal/subprocessors and forms part of our DPA.
Compliance & certifications
- GDPR & ePrivacy:
- we operate under EU data-protection law; our DPA incorporates the EU Standard Contractual Clauses (2021/914) for any necessary international transfers.
- Danish Bookkeeping Act:
- 7-year retention of invoices and accounting records.
- Digital Services Act:
- single point of contact published at /legal/dsa-contact.
- Independent certifications:
- a current compliance summary is available to enterprise customers under NDA.
