— Privacy by architecture

GDPR that'sengineered in.Not checked off.

Most booking apps claim GDPR compliance with a cookie banner and a vague privacy policy. Scisso encrypts every piece of personal data, hosts exclusively in the EU, and embeds a real Data Processing Agreement into the terms you sign at signup.

Start free trial
30-day free trialEU-only hostingEmbedded DPA
🔐

PII encryption

Names, phone, notes · AES-256-GCM

active
💬

SMS auto-deleted

Content deleted immediately after delivery

active
🌍

EU hosting

European cloud operator

EU
📄

DPA in the Terms

Controller: you. Processor: Scisso.

signed
How we built it

Four layers of real protection.

AES-256-GCM

Encrypted at rest

Phone numbers, emails, notes, billing details. All personal data is AES-256-GCM encrypted before it hits the database. Even with full database access, the data is unreadable without the encryption key.

Hetzner DE

EU-only infrastructure

Servers in Germany (Hetzner). Database in EU. No data leaves the European Economic Area. No US subprocessors with access to personal data.

Art. 28 GDPR

Real DPA, not a link

The Data Processing Agreement is Section 6 of the Terms of Service. You accept it at signup. It defines roles (you: controller, Scisso: processor), retention periods, breach notification timelines, and subprocessor list.

Art. 17

Erasure that works

One click deletes all personal data from a customer record. Phone number added to the opt-out list. Record shell retained for statistics integrity. Audit log entry created. Irreversible.

Under the hood

The specifics matter.

SMS content deleted after delivery

The body of every SMS is nulled from our database immediately after the Android relay confirms delivery. We never retain message content.

Audit logging for every access

Every time personal data is read, modified, exported, or deleted, an audit log entry is written. The log itself contains only IDs and action types. Never personal data.

Role-based access control

Employees only see customers they have a relationship with. Receptionists see all customers in the organization. Nobody sees data from other organizations. Ever.

Opt-out enforcement at two layers

SMS opt-out is checked when the job is queued AND when the message is about to be sent. Double enforcement prevents edge cases where a customer opts out between queuing and delivery.

No tracking, no profiling

We don't build customer profiles. We don't sell data. We don't track behavior across organizations. Your client data belongs to you.

Data export on demand

Export all customer data in a standard format. Portable. Yours to take if you leave. No data hostage situations.

The difference

Compliance vs. architecture.

Personal data storage

AES-256-GCM encrypted at rest
Plaintext in database

Hosting location

EU only (Germany)
US or mixed, varies

DPA

Embedded in Terms, accepted at signup
Separate PDF, often unsigned

Customer erasure

One-click, immediate, audited
Email support, days/weeks

SMS content retention

Deleted immediately after delivery
Retained indefinitely

Audit trail

Every access logged automatically
None or manual
Try it yourself

This is what your clients see.

A live booking page, not a mockup. Pick a service, pick a slot, walk through the exact steps your clients get.

Loading the live demo…

Questions

Common questions

Your clients' data deserves
real protection.

Not a checkbox. Not a banner. Encryption, EU hosting, and a real DPA from day one.

Start free trial
30-day free trialNo card requiredCancel anytime

We use cookies

We use essential cookies to keep you signed in and protect against bots. With your consent, we also use analytics to improve the experience. Privacy Policy