SchedulingKit
GDPR Compliance

Booking Software and GDPR Responsibilities

Accept bookings while maintaining a clear process for personal data. SchedulingKit provides booking records and a Data Processing Addendum; your business remains responsible for its lawful basis, privacy notices and responses to client rights requests. SMS opt-in is separate from the legal basis for processing an appointment.

Booking software supports your data-protection process; compliance depends on your use and obligations. Accept bookings while maintaining a clear process for personal data. SchedulingKit provides booking records and a Data Processing Addendum; your business remains responsible for its lawful basis, privacy notices and responses to client rights requests. SMS opt-in is separate from the legal basis for processing an appointment.

What GDPR Requires

The GDPR sets requirements for processing personal data where the regulation applies. Appointment processing needs an appropriate lawful basis, which may be a contract, consent or another applicable basis; consent is not the only option. Businesses must give appropriate notices, protect data and respond to applicable access, erasure and portability requests. Portability and erasure have conditions and exceptions. Processing health data or other special-category data also requires an applicable Article 9 condition; an ordinary appointment-processing lawful basis alone is not enough. Software features support these responsibilities but do not establish compliance by themselves.

European Commission: GDPR information for businesses →

How SchedulingKit Supports GDPR

Consent Management

Booking forms include configurable consent checkboxes for data processing, marketing communications and cookie usage, with timestamped consent records. Document the lawful basis and notices appropriate to each purpose separately.

Right to Erasure

Process client erasure requests through an authorized dashboard workflow covering personal information, booking records and intake data. Apply retention exceptions and legal holds, and record the outcome; the Data Processing Addendum describes assistance with individual rights requests.

Data Portability

Export applicable client personal data and booking history in machine-readable JSON or CSV through the dashboard. Review each request: GDPR portability applies to data the person provided, processed automatically on consent or contract grounds. Access rights have a different scope; the Data Processing Addendum describes assistance.

Data Processing Agreement

SchedulingKit provides a DPA describing processor obligations, subprocessors, security responsibilities and assistance with rights requests. Review the separate GDPR/privacy information for international-transfer safeguards and confirm the arrangements applicable to your account.

Cookie Consent Integration

Embedded booking widgets include configurable cookie-consent controls. Assess cookies and storage used by the host site and embedded services and provide the notices and consent settings required for your deployment.

Data Minimization

Configure booking questions to collect the information needed for the service, and avoid collecting unrelated sensitive information. Review optional fields, staff access and retention as part of your data-minimization process. Form configuration alone does not establish an automatic retention or deletion schedule.

Industries Handling Booking and Client Data

Frequently Asked Questions

Plan Your Booking Data Responsibilities

Configure your booking process and review the Data Processing Addendum, privacy notices and safeguards that apply to your business.

Free forever plan available • No credit card required

When this isn't for you

This is not for you if GDPR compliance doesn't apply to your business. Generic compliance content doesn't substitute for legal advice tied to your specific operation. Skip and consult counsel if regulatory risk is your priority.