Security

Security & GDPR, built for sensitive data

IDs, screening answers and documents are special-category data. Booked keeps them encrypted, on your own server, and never handed to a third-party cloud.

Security & GDPR

Built for the data pharmacies can't afford to leak.

IDs, screening answers and uploaded documents are special-category data. Booked treats them that way — encrypted, on your own server, and never handed to a third-party cloud.

Your server, your data

Self-hosted on your own WordPress. Patient data never leaves your infrastructure — no third-party processor, no foreign cloud. You stay the data controller.

Encrypted at rest — AES-256-GCM

Every uploaded ID and document is sealed with authenticated AES-256-GCM encryption. A server misconfiguration only ever exposes unreadable ciphertext, never the file.

Locked away from the web

Files sit behind a deny-all rule under random names — the database only stores metadata, never the bytes. Guessing a URL returns nothing.

Access-controlled & audited

Only authorised staff can open a document, and every view, change and deletion is written to an activity log you can review.

Your key, your control

Hold the encryption key in wp-config so it never lives in the database. Rotate it, back it up, keep it off-site — it's yours.

Encrypted in transit · delete on request

TLS everywhere, and deleting a booking removes the ciphertext. Data-minimisation and erasure are built in for subject-access and right-to-be-forgotten requests.

Booked gives you the tooling to meet your GDPR obligations; you remain the data controller for your patients' information. Encryption at rest uses your server's OpenSSL and is strongest with a wp-config-managed key.

Get started

Start taking bookings today.

One plugin — video, AI notes, payments and reminders, on your own site. No commission.