# Data protection

This page sets out how DiaryBook Limited handles personal data across the DiaryBook, Iflow and ExcelSend services. It is written for the people who assess us — procurement teams, IT security reviewers, and data protection officers completing supplier assessments.

DiaryBook Limited is registered in Ireland, company number 296090, at Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593.

## Our role under GDPR

Our role depends on the data in question.

| Data | Our role | Examples |
|---|---|---|
| Data about your organisation and its account | Controller | Organisation name, billing details, VAT number, named contacts, IP addresses used to access the service |
| Data you place in the service | Processor | Contacts, appointments, users, message content and delivery records |
{.table}

Where we act as processor, you are the controller. We process that data only on your documented instructions, and you determine what is entered, how long it is kept, and when it is removed.

Appointment records may include the name of a clinic, department or procedure type. Where that is the case, the customer remains the controller of that data and is responsible for determining the lawful basis for processing it.

## Where data is held

The DiaryBook service runs entirely on Microsoft Azure in the Ireland region.

| Layer | Detail |
|---|---|
| Application | Azure App Service (.NET), protected by Azure Web Application Firewall via Application Gateway |
| Database | Managed Azure SQL database, encrypted at rest |
| File storage | Azure storage within the same Ireland region |
| Email delivery | Our own mail server, hosted within our Azure environment |
| Backups | Held within Microsoft Azure |
{.table}

No personal data processed on behalf of customers is stored or processed outside the European Economic Area.

Support is provided from Ireland. A UK-based sub-contractor provides accounts payable support only; this function does not involve access to customer or patient personal data.

## Sub-processors

| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Ireland Operations Limited (Azure) | Cloud hosting, database, storage and backup | Ireland |
{.table}

Microsoft Azure holds ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018 certification and CSA STAR certification, and adheres to the EU Cloud Code of Conduct.

Transmission of SMS and voice messages takes place over telecommunications networks. Once a message leaves our platform for delivery, it is carried by network operators in the same way as any other message sent to a mobile number; carriage of a message is not processing on our behalf.

We will notify customers in advance of any change to this list.

Microsoft 365 and OneDrive for Business are used for our own internal business documents. They are not part of the DiaryBook service and hold no customer data.

## Security measures

| Measure | Detail |
|---|---|
| Encryption in transit | TLS 1.2 or higher |
| Encryption at rest | Transparent Data Encryption on the database |
| Password storage | Hashed using Argon2 |
| Administrative access | Via managed cloud workstations, authenticated through Azure Active Directory with multi-factor authentication |
| File upload access | SFTP over SSH v2, restricted by source IP address |
| Network controls | Azure Network Security Groups, Azure Firewall, Web Application Firewall |
| Endpoint protection | Bitdefender GravityZone across all devices |
| Customer separation | Every record is bound to a customer reference; all queries are scoped to that reference, which is obtained only after authentication |
{.table}

Access to customer data is limited to staff who need it to provide support, and is removed immediately when an engagement ends. All staff and sub-contractors sign confidentiality agreements before being granted access to any system.

## Retention

| Data | Retention period |
|---|---|
| Account and organisation data | 48 months from the date of the last transaction, or 30 days from a written request |
| Customer data held as processor (contacts, appointments, messages) | Determined by the customer. On account closure, 48 months from closure or 30 days from a written request |
| Authentication and security logs | 12 months |
| Application audit records | Retained for the life of the account |
| Invoicing and financial records | 6 years, as required by Irish company and tax law |
{.table}

## Backups and deletion

Backups exist to restore the service, not to retain data beyond its useful life. They are held within Microsoft Azure, encrypted at rest and in transit, and access is restricted to authorised personnel through Azure Active Directory with role-based access control and multi-factor authentication. Restores are tested quarterly.

| Backup type | Retained for |
|---|---|
| Point-in-time restore | 35 days |
| Monthly | 12 months |
| Annual | 4 years |
{.table}

Data deleted at a customer's request is removed from live systems within 30 days. Backup copies are not selectively edited, so deleted data persists within the backup cycle until those copies expire on the schedule above. Backups are accessed only for restoration and are not otherwise processed.

## Data processing agreement

Where we act as processor, the terms required by Article 28 of the GDPR are set out in a written data processing agreement.

For HSE accounts, we operate under the HSE Service Provider Data Processing Agreement.

All other customers can obtain our standard data processing agreement by contacting support@diarybook.com.

## Certifications

| Certification | Detail |
|---|---|
| ISO 9001:2015 | Certificate Q1032RI, issued by Paragon Assurance |
| Cyber Essentials | Awarded 26 May 2026, whole organisation, certified by Red Circles Cyber Security |
{.table}

DiaryBook is not ISO 27001 certified. Information security is maintained through our ISO 9001 quality management system, Cyber Essentials controls, and the certified Microsoft Azure platform on which the service runs.

## Breaches and incidents

We maintain a documented incident response procedure covering classification, detection, reporting, containment, eradication, recovery and communication.

Where we become aware of a personal data breach affecting data we process on a customer's behalf, we will notify that customer without undue delay so that they can meet their own notification obligations as controller.


## Contact

Data protection queries, data subject requests and requests for supporting documentation should be sent to support@diarybook.com, or by post to Customer Services, DiaryBook Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593.

[Back to Trust](/trust/)

---
Source: https://diarybook.com/docs/trust/data-protection/
