New: BookedSolid now integrates with PracSuite. Read more
Security & Compliance

The most secure AI receptionist for healthcare.

BookedSolid is built for healthcare from the ground up. That means security and compliance are not an afterthought — they are built into every part of how we work.

BookedSolid dashboard for physiotherapy

Your patients trust you with their information. We take that seriously.

When a patient calls your clinic, their name, contact details and appointment history pass through BookedSolid. We handle that data the same way a trusted member of your team would — carefully, minimally, and only when necessary.

We are not a general-purpose AI tool. BookedSolid is built specifically for healthcare clinics, and every decision we make about data reflects that.

Built from scratch. No shortcuts.

BookedSolid is built entirely in-house by our own team. We do not use third-party agent building tools to construct the platform. That gives us full control over how patient data is accessed, stored and protected — and it means we can fix issues and improve things faster than platforms built on top of other tools.

Data minimisation

We only access the patient data that is strictly necessary to handle a call, message or booking. Nothing more is collected or stored.

Built in-house

Every part of the platform is built and maintained by the BookedSolid team. No third-party agent tools, no shortcuts, no black boxes.

End-to-end encryption

Every patient interaction — calls, messages, records — is protected with advanced encryption in transit and at rest.

Strict access controls

Only authorised personnel can access patient data, and only when there is a legitimate reason to do so.

ISO 27001 in progress

We are working towards ISO 27001 certification — the international standard for information security management.

Compliant wherever your clinic operates.

BookedSolid serves clinics across the UK, Australia, New Zealand and the EU. We apply the relevant privacy laws for each region as a baseline — not as a minimum to be stretched.

EU GDPREU GDPR
UK GDPRUK GDPR
Australian Privacy PrinciplesAustralian Privacy Principles
New Zealand Privacy ActNew Zealand Privacy Act
ISO 27001ISO 27001 certification in progress.

What BookedSolid does
and does not do, with your patient data.

What we access

Patient name, contact details and appointment information — only what is needed to handle the specific interaction.

What we do not do

We do not sell patient data. We do not share it with third parties for advertising or analytics. We do not retain it beyond what is necessary.

Who can access it

Only your team, through the BookedSolid dashboard. Access is role-based and fully auditable.

Frequently Asked Questions

Is my patient data secure?

Yes. BookedSolid is built in-house with data minimisation principles applied throughout. Every interaction is encrypted and access is strictly controlled. We are compliant with UK GDPR, EU GDPR, Australian Privacy Principles and the NZ Privacy Act.

Do you sell or share patient data?

No. Patient data is never sold or shared with third parties for any commercial purpose.

Where is patient data stored?

Data is stored securely and within the relevant jurisdiction for your region. UK and EU clinic data stays within the UK and EU.

Can I get a Data Processing Agreement?

Yes. Download our standard DPA from the documentation section above, or contact us if you need a customised version for your organisation.

Who do I contact with a data privacy question?

Reach our Data Protection Officer directly at info@waivern.com.

Questions about how we handle your data?

We are happy to talk through anything — whether you are doing due diligence before signing up or have a specific compliance question. Get in touch and we will get back to you as soon as we can.