Handling Client Data: A Practical Guide for Solo Professionals
Names, phone numbers, emails and appointment notes are all personal data. What to collect, what never to put in notes, how long to keep it, and what to do when a client asks you to delete it.
Photo: Towfiqu barbhuiya / Unsplash
Every client who books leaves data with you: a name, a phone number, an email, sometimes a note. Most solo professionals don't think of it as data — it's a line in a notebook, a contact on a phone, a thread in a messaging app.
But added up, you're holding contact details for hundreds of people and, for some of them, quite private information. That responsibility is yours, regardless of who provides the system.
This isn't legal advice — it's a practical routine that works day to day. For your actual regulatory obligations, talk to a lawyer.
One question: why am I collecting this?
It's the most reliable filter there is. For every field you collect, ask: would the appointment still work without it?
- Name — necessary; you need to know who the appointment is for.
- Phone — necessary for reminders and urgent contact.
- Email — necessary for confirmations, reminders and calendar invites.
- Date of birth, national ID number, home address — for most services, not necessary.
That last line matters. Not collecting data you don't need is the easiest way to protect it. Data you never collected can't leak, can't go to the wrong person, and never needs deleting.
The riskiest field: appointment notes
The "Notes (optional)" field on the booking form makes your job easier — and it's also where the most sensitive information accumulates.
If you work in psychology, nutrition or physiotherapy, what gets written there turns into health data fast. A note saying "herniated disc", "on antidepressants" or "pregnant" turns an ordinary appointment record into a much more sensitive one.
A practical rule: the minimum needed to run the appointment. "Lower back is sensitive, plan the session around it" is enough; diagnoses, medication names and medical history aren't the job of an appointment note. If you need to keep clinical records, those belong somewhere else.
The same goes for notes clients write themselves. One line in your service description helps: "No need to put health details in the booking note — we'll cover it in the session."
Why messaging apps and paper books are riskier
Running appointments through chat means keeping the data in its most exposed place:
- Lose your phone, or have it stolen, and all your client communication goes with it.
- Backups usually go to a personal cloud account; who can reach them is unclear.
- Chat history piles up for years and nobody ever clears it.
- Hand your phone to someone and other clients' names appear in notifications.
A paper book is no different: it sits open on a desk, it gets lost, the wrong person reads it.
Keeping appointments in one system doesn't remove these risks, but it reduces them noticeably: access is tied to an account, losing a device doesn't lose the data, and it's clear who can see what.
Who can actually see it?
Ask yourself honestly: who could reach your client list today?
- Does anyone else know your account password?
- Is there a shared tablet or computer at work with a session left open?
- Does your phone have a screen lock?
Those three cause most leaks — not sophisticated attacks. Turning on two-factor authentication and not leaving sessions open on shared devices are the highest-return steps available to you.
How long should you keep it?
"Keep everything just in case" is common and weak. Past appointment records genuinely matter to a business — knowing who came and when serves both the client relationship and your accounts.
Notes are a different matter. If carrying a sensitive note from a session years ago serves no purpose today, there's no reason for it to still be there. Reviewing old records once a year and clearing unnecessary sensitive notes is a ten-minute job.
When a client asks you to delete their data
Start by separating two things. The appointment record itself is a business record — a service was given, a payment was taken. Erasing that entirely may not always be possible or appropriate.
Unnecessary detail is different. Sensitive information in notes, communication channels you no longer use, old message threads — you have room to act there, and that's the first thing to do when a request comes in.
Take the request seriously and tell them in writing what you did. Most clients are unsettled by the feeling that nothing happened, not by the process itself.
Deleting your own account
In Randevunu AI you can permanently delete your account: "Delete my account" sends a confirmation link to your email address, and the link is valid for 24 hours. It's a deliberate step that prevents accidental deletion.
If you're thinking about closing your account, remember to take a copy of anything you still need — appointment history for your accounts, for instance — before you do.
A short checklist
- Are you collecting any field you don't need?
- Do your appointment notes contain diagnoses or medication?
- Is two-factor authentication on for your account?
- Are sessions left open on shared devices?
- Does your phone have a screen lock?
- Do you review old notes once a year?
In short
Handling client data doesn't have to become a compliance project. Don't collect what you don't need, keep sensitive information out of notes, control who has access, and clear unnecessary detail over time — those four cover most of what a solo business needs.
In Randevunu AI your client information sits in one place tied to your account, it's clear who can reach it, and you can delete your account whenever you choose. Pick a username — and work without scattering your data.
Create your own booking page
In minutes, free. Let your clients book from your real calendar through natural conversation.
Start free