No SaaS platform. Your own instance, in Germany.
TerminJet is not just another account on someone else's marketplace. You get your own isolated instance, hosted at Hetzner in Germany, with encrypted contact data and documented consent. Your data belongs to you, not to a platform.
What your appointment data stands on
Operated in Hetzner's German data centres, ISO 27001 certified, EU data protection law, no transfer of data to third countries as standard.
Phone number, email, date of birth and notes are stored in the database encrypted with AES-256-GCM, not in plain text.
Messages only go to contacts with recorded consent. Every consent is traceable and can be withdrawn at any time (GDPR Art. 6).
Every change to appointments, contacts and offers is logged, who, what, when. Traceability is built in, not bolted on.
Each practice runs in its own bounded data world. No mixing with the data of other customers.
Regular, encrypted backups with a tested recovery path. Your data is secured, not just stored.
Your own software vs. a SaaS portal
The difference does not show in everyday use, it shows on the day you want to switch or cancel.
| TerminJet · Your instance | SaaS portal / marketplace | |
|---|---|---|
| Who owns the customer data? | You | the platform |
| Hosting location | Germany (Hetzner) | often third countries / unclear |
| Brand & domain | Your own | the portal's |
| Commission per booking | ||
| Data export when switching | anytime, complete | limited / paid |
| Encryption of sensitive data | AES-256 at rest | opaque |
| Competitor ads next to you |
Cleanly separated: website, engine, data
Your public website and the booking engine are separate systems. The embedded form runs framed and white-label, the engine processes the entries server-side in your own instance. Sensitive data never leaves the server in plain text.

How your patient data is actually managed
When someone joins the waitlist, the form only captures what is needed to fill the slot, data minimisation is a principle, not an option. Sensitive fields such as phone number, email, date of birth and free-text notes are encrypted immediately with AES-256-GCM and stored only in that form.
The Recovery engine works with this data exclusively server-side: to send an offer, the number is briefly decrypted, the message is sent via the official WhatsApp Business or SMS interface, and the plain text never leaves the back end. To search by name, phone or email, the system decrypts server-side, an SQL search over encrypted fields deliberately does not exist.
Every action, create, change, offer, cancel, lands in the audit log with a timestamp and the person who triggered it. This makes processes traceable and meets the accountability requirement of the GDPR. On request, we support you with a data processing agreement (DPA), a record of processing activities and a deletion concept.
Common questions on security & data protection
Is this really "our own" software or a shared system?
You get your own bounded instance with your data, your brand and your domain. It is not a shared marketplace where you are just one account among many.
Where is the data held?
In German data centres at Hetzner. The standard is EU hosting with no transfer of data to third countries.
How are phone numbers and sensitive data protected?
They are stored encrypted at rest with AES-256-GCM. Plain text exists only briefly server-side when sending, never in the browser, never in the log.
Do we get a data processing agreement (DPA)?
Yes. As the implementing agency we provide the DPA and support you with the accompanying GDPR documents.
What happens to our data if we stop?
You receive a complete export and the data is deleted as agreed. No holding back, no export fee.
We walk through setup, hosting and data protection with you
Sign up, we will clarify hosting, the DPA, consent flows and integration specifically for your practice, before anything goes live.
