Your data, handled like infrastructure.
EU-hosted scheduling with a documented subprocessor list, single-tenant Postgres, and TLS end-to-end. The boring stuff, done right.
EU - Germany
Hetzner Cloud hosting with single-tenant Postgres.
GDPR-aligned
Documented subprocessors, DPA available on request.
TLS end-to-end
Encrypted in transit between browser, app, and integrations.
Responsible disclosure
A direct channel for reporting vulnerabilities.
How we keep your data safe.
Data handling
We store only what scheduling needs: contact details, appointment data, and the calendar availability required to route bookings.
- Client names and emails
- Appointment dates and times
- Calendar availability
- Payment information
- Account credentials
We never sell your data or use it to train models.
Authentication and sessions
Accounts are protected with hashed passwords, signed sessions, and standard safeguards against common web attacks.
- Hashed password storage
- Secure session management
- HTTP-only cookies
- CSRF protection
- Rate limiting
Sessions expire automatically and can be revoked at any time.
Encryption
Traffic is encrypted in transit with TLS, and data is encrypted at rest by our EU hosting provider.
- TLS / HTTPS in transit
- Encryption at rest
- Encrypted keys and tokens
- Card data handled by Stripe
We never store raw card numbers. Payments go straight to Stripe.
Infrastructure
Ordinus runs on EU cloud infrastructure with daily backups, monitoring, and regular security updates.
- Daily backups
- Uptime monitoring
- EU cloud hosting
- Monitoring and alerting
- Regular security updates
Backups are encrypted and kept in the EU.
GDPR
Ordinus is built for GDPR. You can access, export, and delete your data, and we document how every subprocessor handles it.
- GDPR-compliant processing
- Right to access
- Right to deletion
- Data portability
- Clear policies
Report a vulnerability
Found a security issue? We want to hear about it, and we take responsible disclosure seriously.
Email us at security@ordinus.io
We aim to acknowledge reports within 48 hours.
Subprocessors and policies.
We work with a small set of vetted vendors. All data stays in the EU unless explicitly noted.
Hetzner Online GmbH (Hetzner Cloud)
Application hosting, database hosting, backups
EU · Germany
Industriestr. 25, 91710 Gunzenhausen, Germany · datenschutz@hetzner.com
Google Cloud EMEA Limited (Google Workspace SMTP relay)
Transactional email delivery
EEA / US
70 Sir John Rogerson's Quay, Dublin 2, Ireland · https://support.google.com/policies/contact/general_privacy_form
Twilio Ireland Limited (only where SMS is enabled)
SMS delivery for booking notifications and phone verification
Ireland / US
3 Dublin Landings, North Wall Quay, Dublin 1, Ireland · privacy@twilio.com
OpenAI Ireland Limited (only where AI features are enabled)
Generation of AI summaries and suggestions
EEA / UK / US
1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland · dsar@openai.com
Payments (Stripe)
Stripe is not an Ordinus subprocessor. For your own Ordinus subscription, Stripe and Ordinus each act as independent controllers for the payment and invoicing data involved. For paid bookings, you connect your own Stripe account: charges are created directly on that account, funds go straight to you, and your agreement is with Stripe. We never receive or store card data.
PostgreSQL, Redis, RabbitMQ, Umami (cookieless analytics), Tolgee, and Zammad run on our own EU infrastructure and are not third-party subprocessors.
Before we add or replace a subprocessor, we notify workspace owners by email and update this list at least 45 days in advance. You can object on reasonable data-protection grounds within 30 days of that notice, and we hold off transmitting your data to the new provider until the objection is resolved.
Subprocessor list last updated: 7 August 2026.
Found something? Tell us.
Responsible disclosure is welcome. Email security@ordinus.io with the issue and a way to reach you - we triage within 48 hours.