Security & privacy

Your clients trust you. Here's how that trust is kept.

Your clients' data — our promise
No one at Holder will ever access your clients' data without your written permission.
Encrypted in transit and at rest.
Completely sealed from every other practice.
Your data is yours — export it, or delete it, whenever you want.
AI is optional, and can be switched off entirely.
We never sell anything, and we set no tracking cookies.

No one reads your client data without your permission.

You control your data; Holder manages it for you, automatically. No one at Holder reads the records of the people you work with unless you've asked us to — and when support does look, with your permission, it's recorded in your own activity log for you to see. The product is built so we don’t need to in the normal run of things.

Sealed, and encrypted.

Every practice's data is sealed off from every other, enforced with row-level security at the database itself. No other practitioner — and none of their clients — can ever see yours. Everything is encrypted in transit and at rest.

Backed up, off-site, encrypted.

Your practice's data is backed up every day, with independent encrypted copies held off-platform — so a failure in one place can never take your records with it. Restore procedures are written down and rehearsed, not improvised.

Two-factor authentication, for your whole team.

Protect your account with a second step at sign-in — a code from an authenticator app — so a stolen password alone can't reach your clients' records. Owners can require it across their whole team in one switch.

An activity log you can read.

Every security-relevant action in your practice — sign-ins, client changes, settings updates, and any time support viewed your account — is written to an activity log in Settings, kept for 90 days. Transparency you can check for yourself.

EU-hosted, under GDPR.

Your data lives on secure servers in the EU (Ireland), under the GDPR. Your data is yours — export everything, delete everything, whenever you choose. No lock-in.

Abuse-resistant by default.

Sign-in and sign-up are rate-limited to blunt password-guessing and scripted abuse, and your public booking and enquiry pages are protected the same way — without ever getting in a real client's way.

Sessions keep nothing.

Online sessions run on encrypted, ephemeral video: the room exists only while you're in it, and nothing — no recording, no audio — is stored once you leave.

AI is optional — and never trains on your data.

Holder's AI features are a switch you can leave off entirely — one switch covers the whole practice, and Starter is AI-free apart from one optional action — generating client-facing pages in another language. When they're on, data is sent to Anthropic only to produce what you asked for, never used to train their models, and automatically deleted within 30 days — other than narrow exceptions such as a legal hold. For UK and EU practices, Anthropic contracts through its EU entity in Ireland under a GDPR Data Processing Addendum.

Consent kept as evidence.

Marketing email is opt-in — a clear, separate choice at booking, never pre-ticked — and every change of consent is written to an append-only record. If anyone ever asks how you had permission to email someone, you can show exactly when and how it was given.

A client can always request a copy of their record.

If someone you work with asks for everything you hold about them — as the law lets them — you can hand it over in minutes. Open their record and press Print, and your own browser makes a PDF of the lot: their details, the history of what they've agreed to, their form answers just as they filled them in, their sessions, and every note with any later corrections kept beside the original. It's put together on your own screen, never sent to another company to assemble. Only you and your practitioners can do it — an assistant account can't — and every copy is written to your activity log.

No tracking, no cookie banners.

Holder doesn't use cookies to track you, so there's nothing on our side that needs a consent banner. If your only client-facing pages are your Holder booking pages, that's one compliance headache fewer.

Your data is never the product.

Holder is paid for by subscriptions, and nothing else. We don't sell data, we don't run ads, and your clients' records are never mined, profiled, or passed on. Plenty of free tools make their real money from what passes through them — that's not our model. Your subscription is the whole of what we make.

A commitment you can hold us to.

We're your data processor; you're the controller. Our standard Data Processing Agreement binds us in law to all of the above, and takes effect automatically when you create your account — no signature is needed. We're working toward Cyber Essentials, and a full security summary is available on request.

Privacy from the first line of code.

We assess new features for their privacy impact before we build them, not after.

Your data is yours — always.

Export everything, delete everything, whenever you choose — whether you stay with Holder or move on. No lock-in and no hostage data: deletion is self-serve and immediate — the moment you ask, it's yours.