BookedSolid is built for healthcare from the ground up. That means security and compliance are not an afterthought — they are built into every part of how we work.

When a patient calls your clinic, their name, contact details and appointment history pass through BookedSolid. We handle that data the same way a trusted member of your team would — carefully, minimally, and only when necessary.
BookedSolid is built entirely in-house by our own team. We do not use third-party agent building tools to construct the platform. That gives us full control over how patient data is accessed, stored and protected — and it means we can fix issues and improve things faster than platforms built on top of other tools.
We only access the patient data that is strictly necessary to handle a call, message or booking. Nothing more is collected or stored.
Every part of the platform is built and maintained by the BookedSolid team. No third-party agent tools, no shortcuts, no black boxes.
Every patient interaction — calls, messages, records — is protected with advanced encryption in transit and at rest.
Only authorised personnel can access patient data, and only when there is a legitimate reason to do so.
We are working towards ISO 27001 certification — the international standard for information security management.
BookedSolid serves clinics across the UK, Australia, New Zealand and the EU. We apply the relevant privacy laws for each region as a baseline — not as a minimum to be stretched.
EU GDPR
New Zealand Privacy Act
ISO 27001 certification in progress.Patient name, contact details and appointment information — only what is needed to handle the specific interaction.
We do not sell patient data. We do not share it with third parties for advertising or analytics. We do not retain it beyond what is necessary.
Only your team, through the BookedSolid dashboard. Access is role-based and fully auditable.
Everything you need to understand how BookedSolid handles your data and your patients' data. If you have a question that is not answered here, get in touch.
How BookedSolid collects, handles and protects your data and your patients' data across every region we operate in.
Read policy →The agreement that governs your use of BookedSolid — what we offer, what you can expect, and what is expected in return.
Read terms →Need a DPA for your compliance records? View ours or get in touch if you need a customised version.
Read DPA →What cookies BookedSolid uses on our website, why we use them, and how to manage your preferences.
Read policy →Questions about data privacy or a specific compliance request? Our Data Protection Officer is available to help.
Yes. BookedSolid is built in-house with data minimisation principles applied throughout. Every interaction is encrypted and access is strictly controlled. We are compliant with UK GDPR, EU GDPR, Australian Privacy Principles and the NZ Privacy Act.
No. Patient data is never sold or shared with third parties for any commercial purpose.
Data is stored securely and within the relevant jurisdiction for your region. UK and EU clinic data stays within the UK and EU.
Yes. Download our standard DPA from the documentation section above, or contact us if you need a customised version for your organisation.
Reach our Data Protection Officer directly at info@waivern.com.
We are happy to talk through anything — whether you are doing due diligence before signing up or have a specific compliance question. Get in touch and we will get back to you as soon as we can.