Data protection

This page sets out how DiaryBook Limited handles personal data across the DiaryBook, Iflow and ExcelSend services. It is written for the people who assess us — procurement teams, IT security reviewers, and data protection officers completing supplier assessments.

DiaryBook Limited is registered in Ireland, company number 296090, at Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593.

Our role under GDPR

Our role depends on the data in question.

DataOur roleExamples
Data about your organisation and its accountControllerOrganisation name, billing details, VAT number, named contacts, IP addresses used to access the service
Data you place in the serviceProcessorContacts, appointments, users, message content and delivery records

Where we act as processor, you are the controller. We process that data only on your documented instructions, and you determine what is entered, how long it is kept, and when it is removed.

Appointment records may include the name of a clinic, department or procedure type. Where that is the case, the customer remains the controller of that data and is responsible for determining the lawful basis for processing it.

Where data is held

The DiaryBook service runs entirely on Microsoft Azure in the Ireland region.

LayerDetail
ApplicationAzure App Service (.NET), protected by Azure Web Application Firewall via Application Gateway
DatabaseManaged Azure SQL database, encrypted at rest
File storageAzure storage within the same Ireland region
Email deliveryOur own mail server, hosted within our Azure environment
BackupsHeld within Microsoft Azure

No personal data processed on behalf of customers is stored or processed outside the European Economic Area.

Support is provided from Ireland. A UK-based sub-contractor provides accounts payable support only; this function does not involve access to customer or patient personal data.

Sub-processors

Sub-processorPurposeLocation
Microsoft Ireland Operations Limited (Azure)Cloud hosting, database, storage and backupIreland

Microsoft Azure holds ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018 certification and CSA STAR certification, and adheres to the EU Cloud Code of Conduct.

Transmission of SMS and voice messages takes place over telecommunications networks. Once a message leaves our platform for delivery, it is carried by network operators in the same way as any other message sent to a mobile number; carriage of a message is not processing on our behalf.

We will notify customers in advance of any change to this list.

Microsoft 365 and OneDrive for Business are used for our own internal business documents. They are not part of the DiaryBook service and hold no customer data.

Security measures

MeasureDetail
Encryption in transitTLS 1.2 or higher
Encryption at restTransparent Data Encryption on the database
Password storageHashed using Argon2
Administrative accessVia managed cloud workstations, authenticated through Azure Active Directory with multi-factor authentication
File upload accessSFTP over SSH v2, restricted by source IP address
Network controlsAzure Network Security Groups, Azure Firewall, Web Application Firewall
Endpoint protectionBitdefender GravityZone across all devices
Customer separationEvery record is bound to a customer reference; all queries are scoped to that reference, which is obtained only after authentication

Access to customer data is limited to staff who need it to provide support, and is removed immediately when an engagement ends. All staff and sub-contractors sign confidentiality agreements before being granted access to any system.

Retention

DataRetention period
Account and organisation data48 months from the date of the last transaction, or 30 days from a written request
Customer data held as processor (contacts, appointments, messages)Determined by the customer. On account closure, 48 months from closure or 30 days from a written request
Authentication and security logs12 months
Application audit recordsRetained for the life of the account
Invoicing and financial records6 years, as required by Irish company and tax law

Backups and deletion

Backups exist to restore the service, not to retain data beyond its useful life. They are held within Microsoft Azure, encrypted at rest and in transit, and access is restricted to authorised personnel through Azure Active Directory with role-based access control and multi-factor authentication. Restores are tested quarterly.

Backup typeRetained for
Point-in-time restore35 days
Monthly12 months
Annual4 years

Data deleted at a customer’s request is removed from live systems within 30 days. Backup copies are not selectively edited, so deleted data persists within the backup cycle until those copies expire on the schedule above. Backups are accessed only for restoration and are not otherwise processed.

Data processing agreement

Where we act as processor, the terms required by Article 28 of the GDPR are set out in a written data processing agreement.

For HSE accounts, we operate under the HSE Service Provider Data Processing Agreement.

All other customers can obtain our standard data processing agreement by contacting support@diarybook.com.

Certifications

CertificationDetail
ISO 9001:2015Certificate Q1032RI, issued by Paragon Assurance
Cyber EssentialsAwarded 26 May 2026, whole organisation, certified by Red Circles Cyber Security

DiaryBook is not ISO 27001 certified. Information security is maintained through our ISO 9001 quality management system, Cyber Essentials controls, and the certified Microsoft Azure platform on which the service runs.

Breaches and incidents

We maintain a documented incident response procedure covering classification, detection, reporting, containment, eradication, recovery and communication.

Where we become aware of a personal data breach affecting data we process on a customer’s behalf, we will notify that customer without undue delay so that they can meet their own notification obligations as controller.

Contact

Data protection queries, data subject requests and requests for supporting documentation should be sent to support@diarybook.com, or by post to Customer Services, DiaryBook Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593.

Back to Trust