Security

Enterprise-grade security built in from the start

Velixa protects your data and your clients' data with layered, serious-business security — not tick-box theatre. PCI-compliant, GDPR-aware and hardened against common attacks by default.

Included in every Velixa subscription
Velixa-Secure

What you get

Encryption in transit and at rest

TLS everywhere, sensitive data encrypted at rest.

CSRF protection on every form

Every state-changing request is verified — no cross-site request forgery.

Rate limiting on sensitive endpoints

Public booking and login endpoints are rate-limited to slow brute-force and abuse.

PCI-compliant card processing

Stripe handles all card data — Velixa servers never see card numbers.

GDPR customer deletion

Delete any customer's data from the dashboard — compliant with right-to-erasure obligations.

Role-based access and audit logs

Every sensitive action is logged with who, what and when.

How it fits into your day

PCI-SCC certified checkout

Card tokenisation and 3D Secure handled entirely within Stripe's certified environment.

Per-customer consent records

Marketing consent is captured with timestamp, IP and source — full audit trail.

Transparent incident policy

Any breach affecting your data triggers notification within 72 hours as required by UK GDPR.

Common questions

All data is stored on servers in the United Kingdom and European Economic Area. We do not transfer data to third countries outside the UK/EEA.

Yes — Velixa is registered with the Information Commissioner's Office (ICO) as a data controller.

Role-based permissions control what each team member can see and do. Staff are restricted to their own diary by default; managers see the whole team; owners have full access. Every sensitive action is logged.

From any customer profile, use the "Delete customer" action. This complies with right-to-erasure obligations under UK GDPR. For a full Subject Access Request export, contact support.

Yes — Velixa uses Stripe for all card processing. Stripe is a PCI-SCC Level 1 certified provider — the highest certification available. Velixa servers never store or process card numbers.

Yes — every sensitive action (booking changes, charges, refunds, staff edits) is logged with the user account, timestamp and action. Audit logs are available to platform administrators on request.

Ready to switch on?

Every feature is yours from day one of your free trial — no contracts, cancel any time.

Start 7-day free trial