Privacy policy
What data we process, why, for how long and who we share it with. Without the legal fog — you should be able to see what happens to your data.
Last updated on 2 August 2026
Who is responsible
Bookised is the controller for the data of our own customers: the business owners with an account. For the data of your clients — the people who book with you — you are the controller and we are the processor. See the data processing agreement at the bottom of this page.
Questions or a request? E-mail info@bookised.com.
What data we process
From you as a business owner: your name, e-mail address, password (stored encrypted, we cannot read it), your business details, your subscription status and the billing details our payment provider passes on to us.
From your clients: name, e-mail address, phone number if given, the chosen service, the time and whatever they write in the notes field. Reviews they leave on your page.
From use of the site: which pages are visited and whether someone is active right now. For the live-visitor overview in our own admin screen we look up a city and country for the IP address. We do not store the IP address itself — only the city and country, and those disappear as soon as the visit is over.
E-mail: if someone sends a message to your business address, we store that message so you can read and answer it in your dashboard.
Why we process it
- To provide the service: show your page, process bookings, send confirmations and reminders.
- To handle your subscription and payments.
- To help you when you ask a question.
- To prevent abuse and spam, and to trace outages.
- To see how the service is used, so we can improve it.
The legal basis is usually the performance of our agreement with you, and otherwise a legitimate interest (security, improvement) or a legal obligation (the retention period for invoices, for example).
Who we share it with
Only with parties needed to make the service work. A processing agreement is in place with each of them, and data stays inside the EU as much as possible.
- Our hosting provider and database, for running the application.
- Our payment provider, for collecting the subscription.
- Our e-mail service, for confirmations, reminders and your business mailbox.
- Our storage and CDN provider, for the photos you upload.
We do not sell your data, and we do not use it for advertising.
Cookies
We only use cookies needed to make the site work. No tracking cookies:
- bk_session — keeps you logged in. Expires after 30 days.
- bk_admin — keeps our own backoffice logged in. For us only.
- bk_vid — a random number that recognises one browser, so ten tabs on one laptop count as one visitor. It contains no personal data.
How long we keep it
- Your account and your page: as long as your subscription runs, plus 30 days after.
- Bookings and reviews: as long as your page exists, unless you delete them sooner.
- Invoices and payment data: 7 years, because tax law requires it.
- Live-visitor data: an hour at most, then it is cleaned up automatically.
Security
Traffic is encrypted over https, passwords are stored hashed, and database access is limited to those who genuinely need it. Spotted something that isn't right? Mail it to info@bookised.com — we'll pick it up immediately.
Your rights
You may access, correct, delete or take your data with you. You may also object to certain processing. One e-mail to info@bookised.com is enough; we respond within 30 days.
If we can't work it out together, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your own national supervisory authority.
Data processing agreement
For your clients' data you are the controller and we are the processor. These arrangements apply automatically as soon as you have an account; there is nothing to sign.
- What we process: the details your clients leave when booking — name, e-mail address, phone number, chosen service, time and notes — plus reviews and e-mails to your business.
- What for: solely to provide the service to you. We never use your clients' data for ourselves.
- On instruction: we process only according to your instructions, unless the law requires otherwise.
- Confidentiality: everyone with access on our side is bound to confidentiality.
- Security: we take appropriate technical and organisational measures, as described above.
- Sub-processors: the parties listed above. If one is added, we tell you and you can object.
- Data breaches: if we notice a breach, we report it to you without undue delay, with what we know and what we are doing about it.
- Data subject rights: if we receive a request from one of your clients, we forward it to you and help you handle it.
- At the end: 30 days after your subscription ends we delete the data, or sooner if you ask. You can export it for as long as your account exists.
- Where: processing takes place inside the EU. If anything does go outside it, that happens with appropriate safeguards.