Security at BookMe AI

Last updated: 31 July 2026

BookMe AI handles conversations between businesses and their customers — including medical and dental practices, where scheduling data is sensitive by nature. This page describes the technical and organizational measures we maintain. It is the Security Policy referenced in our Data Processing Agreement.

Encryption

TLS 1.2+ for all data in transit; AES-256 encryption at rest for the production database and backups. WhatsApp transport is end-to-end encrypted between your customer and the WhatsApp Business Platform endpoint.

Data residency

Production personal data is stored in the European Union (Dublin, Ireland). AI processing and application compute involve transfers to the United States under the safeguards listed on our subprocessors page.

Access control

Role-based access on a least-privilege, need-to-know basis; per-tenant data isolation in our multi-tenant database; multi-factor authentication required on all administrative accounts; access logging.

Data minimization by design

The scheduling assistant is instructed to collect only what booking requires — name, phone number, service, time slot. It identifies itself as automated and does not ask for symptoms, diagnoses, or other sensitive details.

AI processing

Message text is processed by Google Gemini or OpenAI (your choice) solely to generate scheduling replies. Prompts and outputs are not used to train AI models. Your data is never used for advertising or profiling.

Backups & deletion

Automated daily backups with point-in-time recovery. When you delete your account, data is removed from production immediately; backups are purged within 90 days. On contract termination, data is deleted or returned within 30 days.

Incident response

Documented incident response process. Affected customers are notified without undue delay and no later than 72 hours after we become aware of a personal data breach, including scope, likely consequences, and measures taken.

Personnel & subprocessors

Everyone with data access is bound by written confidentiality obligations. All subprocessors sign GDPR Art. 28(3) data processing agreements; international transfers rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.

Certifications

Mythril-Tech S.R.L. is an early-stage company and does not yet hold third-party certifications such as SOC 2 or ISO 27001. In their place, we provide this security overview and respond to reasonable security questionnaires from customers once per year, as set out in our Data Processing Agreement.

Report a vulnerability or ask a security question: security@mythril-tech.com