TerminJet
Security · Hosting · Data protection

No SaaS platform. Your own instance, in Germany.

TerminJet is not just another account on someone else's marketplace. You get your own isolated instance, hosted at Hetzner in Germany, with encrypted contact data and documented consent. Your data belongs to you, not to a platform.

Hosting in GermanyAES-256 encryptedGDPR-aware
your-instance.terminjet.de Live
Template rules · Speech therapy
Reschedule cutoff24 hrs before
Recurring sessionson · weekly
Waitlistauto-refill
Buffer time10 min
Visible reasonoff (privacy)
Terms, appointment types and rules are configurable per industry.
The foundation

What your appointment data stands on

Hosting at Hetzner (Germany)

Operated in Hetzner's German data centres, ISO 27001 certified, EU data protection law, no transfer of data to third countries as standard.

Encrypted contact data

Phone number, email, date of birth and notes are stored in the database encrypted with AES-256-GCM, not in plain text.

Documented consent

Messages only go to contacts with recorded consent. Every consent is traceable and can be withdrawn at any time (GDPR Art. 6).

Complete audit log

Every change to appointments, contacts and offers is logged, who, what, when. Traceability is built in, not bolted on.

Tenant separation

Each practice runs in its own bounded data world. No mixing with the data of other customers.

Backups & recovery

Regular, encrypted backups with a tested recovery path. Your data is secured, not just stored.

The difference

Your own software vs. a SaaS portal

The difference does not show in everyday use, it shows on the day you want to switch or cancel.

TerminJet · Your instanceSaaS portal / marketplace
Who owns the customer data? You the platform
Hosting location Germany (Hetzner) often third countries / unclear
Brand & domain Your own the portal's
Commission per booking
Data export when switching anytime, complete limited / paid
Encryption of sensitive data AES-256 at rest opaque
Competitor ads next to you
Architecture

Cleanly separated: website, engine, data

Your public website and the booking engine are separate systems. The embedded form runs framed and white-label, the engine processes the entries server-side in your own instance. Sensitive data never leaves the server in plain text.

Marketing website and engine as separate, hardened systems
Strict HTTP security headers (CSP, HSTS), framing allowed only for the form
PHI is encrypted and decrypted server-side, never in the browser
Operated via containers, reproducible and versioned
app.terminjet.de/patienten Live
TerminJet: Waitlists & leads

How your patient data is actually managed

When someone joins the waitlist, the form only captures what is needed to fill the slot, data minimisation is a principle, not an option. Sensitive fields such as phone number, email, date of birth and free-text notes are encrypted immediately with AES-256-GCM and stored only in that form.

The Recovery engine works with this data exclusively server-side: to send an offer, the number is briefly decrypted, the message is sent via the official WhatsApp Business or SMS interface, and the plain text never leaves the back end. To search by name, phone or email, the system decrypts server-side, an SQL search over encrypted fields deliberately does not exist.

Every action, create, change, offer, cancel, lands in the audit log with a timestamp and the person who triggered it. This makes processes traceable and meets the accountability requirement of the GDPR. On request, we support you with a data processing agreement (DPA), a record of processing activities and a deletion concept.

Common questions on security & data protection

Is this really "our own" software or a shared system?

You get your own bounded instance with your data, your brand and your domain. It is not a shared marketplace where you are just one account among many.

Where is the data held?

In German data centres at Hetzner. The standard is EU hosting with no transfer of data to third countries.

How are phone numbers and sensitive data protected?

They are stored encrypted at rest with AES-256-GCM. Plain text exists only briefly server-side when sending, never in the browser, never in the log.

Do we get a data processing agreement (DPA)?

Yes. As the implementing agency we provide the DPA and support you with the accompanying GDPR documents.

What happens to our data if we stop?

You receive a complete export and the data is deleted as agreed. No holding back, no export fee.

Questions about configuration?

We walk through setup, hosting and data protection with you

Sign up, we will clarify hosting, the DPA, consent flows and integration specifically for your practice, before anything goes live.

Runs white-label on your domain — no portal
Entries go straight into the engine
Consent is captured cleanly (GDPR)
Request it for my business
Product preview · customer view
your-domain.com/booking
Join the waitlist
We'll get in touch as soon as a suitable slot opens up.
Name
Maria Becker
Contact (WhatsApp)
+49 ··· ·· ··