LEGAL
Privacy notice
What personal data Bexus Booking holds, why, for how long, and what a person can ask for.

1. Two different relationships
This notice covers two things that are easy to confuse, so it separates them from the start.
- When you visit our own pages, or apply for a founding place
- Bexus Systems is the controller of that data. This notice tells you what we do with it.
- When you book an appointment at a business that uses Bexus Booking
- The business is the controller of your appointment and of their record of you. Bexus Systems is their processor: we hold and handle it on their instructions and for no purpose of our own. The business’s own privacy notice governs what they do with it, and the data processing agreement sets out the split.
2. What we hold, and why
If you apply for a founding place
Your business name, your name, your email address, and optionally your telephone number, roughly how many customers you have, how you run your work today and anything else you write. We hold it to reply to you about a founding place. The basis is our legitimate interest in responding to somebody who has asked us to.
Applying does not create an account, a business, a trial or an invitation. It writes one record of your enquiry, which a person reads.
Marketing is a separate question, asked separately. The application form has one optional, unticked box for hearing from us about anything other than your application. Leaving it alone records a no, and we will still reply to you about the application itself — that reply is not marketing and does not depend on the box. Where you do tick it, the basis is your consent, we record the moment you gave it, and you can withdraw it at any time by replying to any message or writing to us.
If you have an account with us as a business
Your name, your email address, whether that address has been confirmed, and your business’s own settings. The basis is the contract between us. Your password is never stored — only a one-way hash of it, which we cannot reverse.
If you book an appointment
Your name, your email address, optionally your telephone number, and the appointments you make. If you choose to create an account, also a password hash and whether you asked to be reminded about appointments. All of it is held for the business you booked with; the basis for our part is that business’s instruction to us.
If a business you already use brings its records into Bexus Booking
A window cleaner who has been running a round for years may import the customers they already have — names, addresses, telephone numbers, what is done and how often, and access notes such as which gate is unlocked. That business is the controller of those records and always was; we hold them on its instructions so its round works. The basis for our part is that instruction.
Being imported does not put anybody on a mailing list. It is how the business you already deal with keeps doing the work you expect. We do not market to you, and the business is asked to confirm, before the import runs, that it is entitled to hold your details and that importing them is not a licence to market to you.
What happens to the file. The business chooses a CSV and their browser reads it. Its contents are then sent over an encrypted connection to Bexus Booking, which checks every row and shows the business what the import would do. Nothing is created at that point. Only when the business confirms are the customer records written.
The uploaded file is not retained as a file. What is retained is what the confirmed import created — the customer, property and service records themselves, which are the business’s round and the reason for the import — together with a short record of the import having happened: the file’s name in a tidied-up form, a fingerprint of its contents, how many rows were accepted, skipped and refused, which version of the import wording was confirmed, who did it and when. That record describes the import rather than the people in it: none of the customer details from the file is copied into it.
The fingerprint is a one-way digest rather than a copy: it cannot be turned back into the file, and its purpose is to recognise the same file if it is uploaded again, so a round is not imported twice by accident. If the business downloads a list of rows to fix, that list is put together by their own browser from what is already on their screen and is never sent to us or stored by us.
3. What we deliberately do not hold
This section is specific because “we take your privacy seriously” is not information.
- No advertising or analytics trackers. There is no Google Analytics, no advertising pixel, no session recording and no third-party script of any kind on these pages.
- No payment details. There is no payment processing in the product at all, so there is nothing to hold.
- No message contents. The queue that decides which confirmation emails are owed stores a reference to the appointment and nothing else — no recipient address, no subject and no message body. Each message is composed from the appointment at the moment it is sent and is not kept afterwards.
- No values in the audit trail. Records of who changed what store the NAME of the field that changed, never its old contents — so a correction to a customer’s telephone number does not become a second permanent copy of that number.
- No telephone numbers or message text from WhatsApp. The WhatsApp integration is disabled, and even when enabled it records only that a recognised business number received something. It stores no sender number and no hash of one.
4. Who else sees it
- Your business, if you booked an appointment. That is the point.
- Our hosting provider, Hetzner Online GmbH, whose servers in Germany run the application and the database.
- An email provider, for confirmations and account recovery. At the date of this notice none has been engaged and no message has been sent to anybody; when one is, this notice will name it before it starts.
We do not sell personal data, we do not share it for anybody else’s marketing, and we do not use it to train anything.
5. Where it is
In the United Kingdom and the European Economic Area. At the date of this notice there is no transfer outside them. If engaging an email provider changes that, this notice will say so and name the safeguard before the transfer begins.
6. How long we keep it
- Appointments and customer records
- For as long as the business uses Bexus Booking, because a business needs its own history.An account being suspended or closed does not delete anything. The business keeps signing in, keeps seeing its records and keeps being able to download them, and we do not delete anything without asking first. Deletion is a separate, deliberate step arranged with the business rather than something that happens on a date — see “What you can ask for” below.
- Our own record of an invoice
- What we invoiced a business for, whether it was paid and when, plus the reason for any change to its account. This is about our relationship with the business rather than about anybody’s customer, it contains no customer details, and it is kept for as long as accounting and tax rules require even where the rest has been deleted.
- Booking-management links
- Two days after the appointment ends, or a week after a cancellation. Only a one-way digest of the link is stored, never the link itself.
- Founding applications
- Until we have finished talking to you, and no more than twelve months after that.
- A marketing consent, where one was given
- Until you withdraw it, and reviewed after two years without a response — a consent nobody has acted on in two years is not one anybody remembers giving. The record of the consent itself is kept while we rely on it, because being able to show it was given is the point of recording it.
- Abuse counters
- About an hour. They hold a one-way hash of an address and a network location, a count and two timestamps — nothing that reverses to a person.
7. How it is kept safe
In summary, and in full in the data processing agreement. Every connection is encrypted in transit. Passwords are stored only as a one-way hash. A business’s data is separated from every other business’s by row-level security in the database itself, so the separation is enforced below the application rather than by it. The credential the running application holds cannot change the schema, cannot read another business’s rows, and cannot issue itself an invitation. Sign-in, password reset and every public form are rate-limited, and those counters hold one-way hashes rather than addresses.
We do not claim to be certified against any standard, because we are not. What is written here is what is built, and it is checked by an automated test suite on every change rather than asserted once in a document.
8. What you can ask for
You can ask for a copy of what we hold, for it to be corrected, for it to be deleted, for our use of it to be restricted, and to object to it. You can also complain to the Information Commissioner’s Office at ico.org.uk.
A copy of your data, if you are a business using Bexus Booking, is something you do yourself and do not have to ask for. Your customers and addresses, your round, and your bookings each download as a spreadsheet from your Plan and billing screen. Those downloads keep working if your account is suspended or closed.
Deletion is an assisted request and there is deliberately no delete-my-account button. A person carries it out, by hand, against the database — because it is the one thing that cannot be undone, and a business that deletes its round by accident has lost years of work.
If you are not a business — a customer who booked an appointment, or somebody who applied for a founding place — a copy of your data is produced for you in a readable form on request. Where the law requires us to keep something we will say what and why rather than deleting it quietly. We will agree with you when each will happen rather than quoting a period we have not committed to. No request costs anything, and we will not ask you to justify it.
If your request is about an appointment, ask the business first — they are the controller and they hold the answer. If you ask us, we will pass it to them and help them respond. Contact us through support.
9. Cookies
Every cookie and every piece of browser storage this product sets is listed on the cookies page. There are no advertising or analytics cookies, which is why there is no consent banner.
Who we are
- Trading name
- Bexus Systems, a UK sole trader established in England and Wales.
- Trader
- Carl Guinney
- Contact
- hello@bexusbooking.com
- Trading address
- 30 The Perrings, Bristol, BS48 4YL