Slotara Logo Slotara
Slotara / Security

Your data belongs to you. Period.

Slotara runs its main infrastructure and primary application data in Germany, includes a DPA automatically, sets no tracking cookies, and encrypts every connection with TLS 1.3. Billing for your Slotara subscription also stays entirely within the EU: Mollie (Netherlands) is our payment provider for subscription billing — no US Cloud Act, no data transfer to the US.

🇩🇪 Main infrastructure in Germany
📄 DPA included
👁️ No tracking cookies
🔒 TLS 1.3
Technical security

8 security measures that are standard at Slotara.

No paid security add-ons for core operation. The measures described below are part of the standard product.

🇩🇪

Main infrastructure in Germany

Main infrastructure and primary application data are processed on servers in Germany.

Data center operations in Germany. Subscription billing runs through Mollie B.V. (Netherlands, EU) — no data transfer to the US. Optionally enabled AI features (Anthropic) use Standard Contractual Clauses under Art. 46(2)(c) GDPR.

🔒

TLS 1.3 encryption

Every connection is encrypted with TLS 1.3 — dashboard, booking widget and API.

HSTS enabled, Certificate Transparency, automatic certificate renewal. No unencrypted HTTP access is possible.

📄

DPA included automatically

The data processing agreement (Art. 28 GDPR) is active automatically upon registration.

No paperwork, no separate request. In German, legally valid, effective immediately. No English-language DPA.

👁️

No tracking cookies

No tracking, analytics or advertising cookies in product operation.

The booking widget sets no marketing or analytics cookies. Technically necessary cookies for security and login are unaffected.

🏢

Tenant isolation

Every customer has a fully isolated data area. No access to other customers' data is possible.

Technically: an automatic tenant scope on every database query. No cross-tenant access — not even for administrators.

🔑

Password security (bcrypt)

Passwords are never stored in plain text. Bcrypt hashing with an individual salt per user.

Brute-force protection through rate limiting. No password reset by plain-text email. Secure reset processes and encrypted transmission are standard.

🗑️

Right to erasure (Art. 17)

Deletion requests are processed and carried out according to clearly defined procedures.

A 30-day grace period applies after cancellation. After that, data is deleted from production systems; statutory retention obligations and technical backup cycles still need to be taken into account.

API security

API access via bearer tokens with tenant isolation. No cross-tenant access is possible.

Rate limiting (60 requests/minute), webhook signatures for payload integrity, token rotation recommended.

Legal compliance

GDPR requirements — all covered.

GDPR (EU General Data Protection Regulation) Compliant

The requirements from Art. 5, 6, 12–23, 25, 28 and 32–34 GDPR that are material to current product operation are reflected in our processes and systems.

DPA under Art. 28 GDPR Included automatically

Active upon registration, in German, no request needed.

TOMs (technical and organizational measures, Art. 32) Documented

Encryption, access control, pseudonymization, availability.

Data portability (Art. 20) Supported

Exporting all data as CSV/JSON is available in the dashboard at any time.

Record of processing activities (Art. 30) Maintained

Available to data protection officers on request.

Fact

For many clients, the booking widget is the first data-protection touchpoint with your business — and the only one they consciously notice before entering their data.

Ready to go in 5 minutes.

No credit card. No contract commitment. The DPA is active automatically. Main infrastructure in Germany. No tracking cookies.

Request access Security questions?

Data protection officers can request the full TOM (technical and organizational measures) document.

Frequently asked questions

FAQ: privacy & security

Main infrastructure and primary application data run in Germany. Subscription billing is handled by Mollie B.V. (Netherlands, EU) — no US transfer in standard operation. Optionally enabled AI features (Anthropic, USA) use Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR. Full details are in our privacy policy.

No. The DPA is active automatically upon registration. You don't have to sign or request anything. It's in German, under Art. 28 GDPR. On request, you can get a signed copy.

No. Slotara does not use tracking, analytics or advertising cookies. Technically necessary cookies may be used to keep the platform running securely. The booking widget sets no marketing or analytics cookies.

Yes. All bookings, clients and settings can be exported as CSV or JSON at any time (Art. 20 GDPR). No vendor lock-in.

After cancellation there's a 30-day grace period during which data can still be exported. After that, personal data is deleted from production systems. Statutory retention obligations and technical backup cycles still need to be taken into account.

Slotara stores booking data (name, contact details, appointment), not medical diagnoses or patient records. Application data sits on servers in Germany, and the DPA under Art. 28 GDPR applies from the start of the contract. Whether your processing as a whole is permissible also depends on what data you collect and why. Medical patient records belong in your practice management software.

Keep reading

All features

Online booking, skill matching and reminders at a glance

Pricing & plans

Every privacy feature included in every plan