Trust & Compliance
Last updated: July 28, 2026
Everything you need to know about how we protect your data, secure our platform, and where we currently stand on certifications. We would rather show you what we actually do than rent a badge.
Data protection
Your customers' data belongs to you. When your business uses BookZync, you are the data controller and we act as your processor — the commitments are written down in our Data Processing Agreement and the providers we rely on are published on the sub-processor list.
- Export your customer data at any time; delete any record from your dashboard.
- On cancellation: 30 days to export, then deletion (unless the law requires longer, e.g. tax records).
- We never use customer data to train or fine-tune large language models.
- Each customer's AI knowledge base stays isolated from every other customer's.
- The AI assistant is instructed never to collect medical details — only a name, contact information, and the requested time.
Security measures
- Encryption in transit (HTTPS/TLS) and at rest on our managed database.
- Strict tenant isolation: every record is scoped to your business; cross-tenant access is treated as not-found by design.
- Administrator accounts are protected with two-factor authentication, with step-up verification for sensitive actions.
- Every administrative change is recorded in an audit log.
- Error messages are scrubbed so internal details never leak to a browser.
Payments
Payments run through Paddle, our merchant of record. Your card details are encrypted and handled entirely by Paddle — BookZync never stores or has access to your full payment details — and Paddle handles each country's taxes (VAT/GST) and currency at checkout. Details in our Refund Policy.
Messaging compliance
- SMS is consent-based: waitlists and campaigns only text people who opted in.
- STOP is honored automatically: one STOP reply is recorded across our systems, and that person is never texted again by any feature. START re-subscribes them.
- You stay responsible for your own marketing-consent laws (for example TCPA in the US, GDPR in Europe, CASL in Canada) — our Terms spell this out.
AI safety
- The AI assistant quotes only your real services, prices, and hours — it is instructed never to invent information.
- It never diagnoses or gives medical advice; urgent symptoms are directed to local emergency services.
- It never asks for card numbers, passwords, or IDs in chat — payment happens only in secure checkout.
- You can review its full conversation history and have its behavior adjusted.
Canada — health privacy (PIPEDA & PHIPA)
BookZync is available to Canadian dental, medical, and medspa practices. The Services are designed to support Clients in meeting applicable obligations under PIPEDA and provincial health privacy legislation, including PHIPA where applicable — documentation available on request.
One honest thing every Canadian practice should know: there is no such thing as a PIPEDA or PHIPA certification. No regulator issues one, so any vendor displaying a "PIPEDA certified" or "PHIPA approved" seal made it up. Instead of a badge, we maintain a documented privacy program — consent-before-retention enforced in the product, deletion of non-consented records within 24 hours of a completed visit, cross-border disclosure, a breach response plan, an access-request procedure, and vendor sections ready for your Privacy Impact Assessment — reviewed by counsel and shared with your practice on request. Email [email protected] to request it.
Certifications — our honest status
We do not yet hold ISO 27001, SOC 2, or HIPAA certification, and we will never imply otherwise. These certifications require significant operational controls and formal audit processes, and we plan to pursue them as BookZync grows. HIPAA compliance is on our roadmap and is not currently supported; our HIPAA-readiness work for medical and dental practices is stated plainly on those industry pages today. (For Canadian privacy law, which has no certification scheme at all, see the Canada section above.) What you see on this page is what we actually do right now.
Questions or security reports
Found a vulnerability or have a security question? Email [email protected] and we will respond quickly. Everything else: [email protected].