Privacy notice
What Bookpitch stores, why, where it lives, and what can be removed.
Draft — not legally reviewed
This document describes how the software actually behaves, but it has not been reviewed or approved by a qualified legal adviser. It is not a contract, and it is not a statement of regulatory compliance. Do not rely on it. Sections marked “not yet supplied” are genuinely incomplete.
version 2026-08-18.draft-1
Who is responsible for your data
Bookpitch is scheduling and records software used by clinics and salons. Each organisation using it controls its own patient and client records; the operator of this installation runs the platform those records sit on.
Not yet supplied. The operating entity’s registered name, company registration number, postal address and privacy contact have deliberately not been filled in, because inventing them would misstate who is legally responsible for your data. Until this section names a real entity, this notice is incomplete.
What is stored
The database holds the following categories of personal data:
- Account data for staff users — email address, authentication credentials, organisation membership and role, and multi-factor enrolment state.
- Client and patient identity — name, email address, telephone number, date of birth, gender, and an optional avatar image reference.
- Health data — recorded allergies, clinical notes, and treatment history entries. This is special-category data and is treated as the most sensitive content in the system.
- Insurance data — insurer name and policy number, where an organisation records them for claim exports.
- Appointments and payments — times, services, assigned staff, status, prices, payment method and status, and where recorded, a diagnostic code for a completed visit.
- Operational records — an append-only audit log of actions taken inside an organisation, message delivery records, and security events such as sign-in attempts and rate-limit decisions.
How it is protected
- Allergies and clinical notes are encrypted at rest at the field level, so they are not readable from the raw database rows. Outbound email addresses queued for delivery are encrypted the same way.
- Every query against tenant data is filtered by organisation, and the database enforces row-level isolation independently of the application code.
- Access is governed by named roles and permissions. Reaching client contact details or clinical records as a platform operator additionally requires a recorded reason, re-authentication, and expires automatically; those reads are themselves audited.
- Message bodies, recipients and tokens are kept out of application logs.
Where it is processed
The application runs in Frankfurt, Germany, and the primary database is hosted in the European Union. Encrypted backups are taken on a schedule; the storage region for backup copies is not currently guaranteed to be EU-only, and that gap is deliberately stated here rather than glossed over.
Third parties that necessarily process data to make the service work: the application host, the managed database provider, the transactional email provider, the bot-protection provider used on the signup form, and an error-monitoring service. Their identities belong in this notice and are pending completion alongside the operator details above.
How long it is kept
Each organisation sets a retention window for its client records, defaulting to seven years. A scheduled job finds clients whose records have been untouched for longer than that window and who have had no appointment inside it, and redacts them.
Erasure, and its limits
A client record can be redacted on request. Redaction clears name, email address, telephone number, date of birth, gender, avatar, allergies, clinical notes, insurer name and insurance policy number. The row itself is retained in a redacted form so that linked appointments and payments remain coherent.
Two things are not removed, and you should know this before relying on a deletion request:
- The audit log is append-only and cannot be edited or deleted by anyone, including platform administrators. It records that an action happened, by which account, and when.
- Treatment history entries are retained. Whether they should survive an erasure request, or be covered by a clinical-records retention duty instead, is an open question flagged for legal review rather than decided in software.
A machine-readable export of an individual client’s stored data can be produced by their organisation.
Exercising your rights
If you are a client or patient of a clinic or salon that uses Bookpitch, that organisation holds your records — contact them first. Requests about the platform itself should go to the privacy contact named above, which is not yet supplied.
What this notice does not claim
This page describes implemented behaviour. It does not assert compliance with the GDPR, HIPAA, Georgian data-protection law, or any other regime, and no part of it has been approved by a qualified adviser. Automated checks cannot establish legal compliance, and nothing here should be read as if they had.