Sovereign scheduling infrastructure

Own your scheduling. Not someone else's calendar.

Not another booking SaaS. Sovereign workflow infrastructure for any organisation that coordinates people in the field — healthcare, field services, government, utilities, logistics, security and financial or professional services. Deployed inside your own boundary as a module of the PSCE platform.

Booking requestIn your environment

Sovereign appointment booking flow

A booking request is raised in the client app from a saved location against live slots. It travels to a coordinator, who can approve, modify or reassign it — on approval the slot locks. The approved visit syncs to the field calendar as part of the rota, where double-booking is impossible, and is then delivered using sovereign routing with nothing logged onward. Every stage runs inside your environment.

RequestClient app · saved location, live slotsCoordinator approvalApprove, modify or reassign — the slot locksField calendarSynced rota · double-booking impossibleVisit deliveredSovereign routing · nothing logged onward
UK hostedZero telemetryGDPR

Appointment data stays within your designated deployment boundary.

Everyone else says “book online in seconds.”

Pryvate says your diary is not our dataset.

THE OPERATIONAL CASE

One workflow instead of six systems.

Every hand-off between tools is an integration to maintain, a contract to renew and a gap in the record.

  1. Booking
  2. Approval
  3. Rota
  4. Routing
  5. Encrypted communication
  6. Live ETA
  7. Completion
  8. Audit

One deployment boundary.

One audit trail.

One accountable infrastructure layer.

WHY IT MATTERS

The schedule itself is the sensitive record.

Before anyone opens a file, the diary has already said too much.

Healthcare

A visit diary is clinical data.

Frequency, address and practitioner type reveal diagnoses, care intensity and vulnerability — before a single clinical note is read.

Financial Services

The diary leaks before the deal does.

An adviser repeatedly visiting one family office, or a restructuring team booked into a struggling issuer, is exactly the signal MiFID II recordkeeping exists to govern.

Government

Field schedules are operationally sensitive.

Where inspectors will be, which addresses receive welfare visits and how teams are deployed carries direct operational and personal-safety consequences.

Built on PSCE
  • Designed for GDPR-regulated deployments
  • HIPAA-aligned workflows
  • MiFID II recordkeeping support
  • AES-256 · RSA-4096
  • ZRTP-PQ hybrid key exchange
  • UK / EU residency options
THE DIFFERENCE · 01

Not another booking SaaS.

Mainstream scheduling platforms typically require appointment and operational metadata to be processed within the provider's cloud environment. Pryvate is designed differently: the infrastructure, deployment model and data boundary remain under organisational control. Who meets whom, how often and where is a behavioural map of your organisation.

Appointment metadata
Global scheduling platforms — no: Global scheduling platformsProcessed within the provider's cloud environment
Scheduling on PSCE — yes: Scheduling on PSCEStays inside your PSCE tenant or on-premise deployment
Locations & addresses
Global scheduling platforms — no: Global scheduling platformsGeocoded via global map APIs, logged by third parties
Scheduling on PSCE — yes: Scheduling on PSCEResolved by Pryvate Location Intelligence, in-boundary
Reminders & updates
Global scheduling platforms — no: Global scheduling platformsSMS/email via external gateways in cleartext
Scheduling on PSCE — yes: Scheduling on PSCEDelivered over PSCE's end-to-end encrypted messaging
Live ETA sharing
Global scheduling platforms — no: Global scheduling platformsContinuous location upload to vendor servers
Scheduling on PSCE — yes: Scheduling on PSCEPer-session keys, point-to-point, minimised retention
Compliance
Global scheduling platforms — no: Global scheduling platformsData processing agreements with a dozen sub-processors
Scheduling on PSCE — yes: Scheduling on PSCEDesigned for GDPR, HIPAA-aligned and MiFID II deployments, inheriting PSCE controls
Scheduling control
Global scheduling platforms — no: Global scheduling platformsSelf-serve booking only — no human in the loop
Scheduling on PSCE — yes: Scheduling on PSCEFull coordinator workflow: review, approve, modify, reassign
Branding
Global scheduling platforms — no: Global scheduling platformsTheir logo on your booking page
Scheduling on PSCE — yes: Scheduling on PSCEFully white-label, your apps, your domain
0

third-party data processors in the booking path — by architecture

6→1

disconnected systems consolidated into one governed workflow

1

contract, SDK and audit trail from booking to completion

100%

of appointment data held within your deployment boundary

Architectural guarantees, not performance benchmarks — each is verified with you during the assessment.

CONSOLIDATION · 02

Replace six disconnected systems with one governed workflow.

The realistic alternative isn't one competitor — it's all six of these, stitched together, each seam a sub-processor and a compliance question.

Six disconnected systems consolidated into one governed workflow

Six separate systems — Booking & appointment SaaS, Staff rota software, SMS / email notification gateway, Consumer messaging apps, Global map & routing APIs, Field tracking application — converge into a single governed workflow, Scheduling & Field Coordination on PSCE. Five of the six are third-party sub-processors and one, consumer messaging, is ungoverned entirely.

  • Booking & appointment SaaSSUB-PROCESSOR
  • Staff rota softwareSUB-PROCESSOR
  • SMS / email notification gatewaySUB-PROCESSOR
  • Consumer messaging appsUNGOVERNED
  • Global map & routing APIsSUB-PROCESSOR
  • Field tracking applicationSUB-PROCESSOR

Scheduling & Field Coordination on PSCE

  • Booking, rotas and approvals in one engine
  • Encrypted messaging and notifications built in
  • Routing, geocoding and live ETA via Location Intelligence
  • One audit trail, one contract, one deployment boundary
  • Fewer integrations, sub-processors and licence duplications
ARCHITECTURE · 03

Every component inside the boundary.

Scheduling is a module of the Pryvate Secure Communications Engine. It shares PSCE's identity, encryption and data-residency guarantees — and composes natively with Location Intelligence for routing, geocoding and live tracking.

Sovereign scheduling architecture

Three client surfaces — a white-label client app, a field app and a coordinator console — call into your own PSCE tenant, in your own jurisdiction. Inside that boundary sit four modules: the scheduling engine, Location Intelligence, encrypted messaging, and audit and residency. Global calendar clouds, map APIs, SMS gateways and analytics trackers sit outside the boundary and are not in the path.

Client app

Booking flows, addresses, reminders, ratings — white-label iOS / Android / web

Field app

Agenda, calendars, navigation, visit documentation — tablet & mobile

Coordinator console

Rotas, approvals, oversight, requests, audit

Your PSCE tenant · Your jurisdiction

Scheduling engine

Rotas, availability, approvals, lifecycle, timezone logic

Location Intelligence

Geocoding, routing, geofencing, ETA

Encrypted messaging

Reminders, updates, coordinator chat

Audit & residency

Event log, retention policy, compliance export

Global calendar clouds · map APIs · SMS gateways · analytics trackersNot in the path
CAPABILITIES · 04

Everything a scheduling platform does. Without surrendering operational data.

Appointment Booking

Guided multi-step flows — profile, location, live slots, intake notes — in your own apps, including on behalf of others.

Availability & Slots

Clients see only slots the rota can actually serve — timezone-aware, served from your tenant.

Shift & Rota Management

Coordinators manage working schedules and availability for every field worker from the admin console.

Approval Workflow

Every request is reviewed: approve, reject, modify or reassign. On approval the slot locks.

Smart Reassignment

Rebalance visits by availability, workload and proximity — without breaking the audit trail.

Calendar Views

Approved visits sync straight to staff calendars — day, week and month, with workload badges.

Visit Lifecycle

Full state history from request through to completion.

Live ETA & Tracking

End-to-end encrypted location sharing and arriving-soon alerts via Location Intelligence.

Address Book & Profiles

Saved service locations and recipient profiles with map-pin capture, geocoded in-boundary.

Coordinator Chat

Integrated encrypted chat between coordinators and clients — negotiate times, confirm details.

Reminders & Notifications

Delivered over PSCE encrypted channels — no SMS gateways, no cleartext.

SDKs & APIs

The same unified PSCE SDK — add scheduling to existing apps in weeks.

IN THE PRODUCT · 05

Built for the people doing the visits.

Reference implementations for client booking and field delivery, ready to white-label. Healthcare configuration shown — terminology, workflows and branding adapt per sector.

This is one configuration, not the product. The same engine runs dispatch boards, inspection rounds, maintenance schedules and client meetings — the labels change, the infrastructure does not.

Field app week calendar: a Sunday-to-Saturday grid of scheduled visits with a live now-line marking the current time, and per-day visit counts.
FIELD APP — WEEK CALENDAR WITH LIVE NOW-LINE
Field app en-route navigation: turn-by-turn guidance to a patient visit with distance, duration, speed and live ETA, and a mark-as-arrived action.
FIELD APP — EN-ROUTE NAVIGATION WITH ENCRYPTED LIVE ETA
Client app booking flow, step two: picking a date and time from live appointment slots, with unavailable slots struck through.
CLIENT — LIVE SLOTS
Client app appointments list: upcoming and past visits with their date, type, reference and confirmed, completed or pending status.
CLIENT — APPOINTMENTS
Field app daily agenda: the next appointment, a today's-overview panel counting visits, patients, remaining visits and average visit time, and a timeline of the day's visits.
FIELD APP — TODAY'S AGENDA & WORKLOAD
SCENARIOS · 06

Built for organisations where a leaked diary is a breach.

How the module is designed to be used, in three deployments.

Illustrative deployment scenario
Home healthcare network

Replacing a US-cloud booking SaaS for nurse home visits, so patient addresses and visit patterns never leave the provider's own tenant.

High-volume
visit scheduling, entirely in-boundary
Illustrative deployment scenario
Private wealth manager

Client meetings booked and confirmed over encrypted channels — no external calendar metadata to account for.

0
third-party processors in the booking path
Illustrative deployment scenario
Government field services

Air-gapped deployment scheduling inspections with sovereign routing and offline-tolerant field sync.

Offline-first
field sync for disconnected estates

Named references are available under NDA through your account team.

WHO IT'S FOR · 07

One platform. Your sector's language.

Built for sectors where the diary itself is sensitive. Labels, workflows and roles are configured per deployment; select a sector to see how.

A visit diary is clinical data.

Who is being visited, how often, at what address and by which specialism reveals diagnoses, care intensity and vulnerability — before a single clinical note is read. Under GDPR and HIPAA-aligned regimes, an appointment book of home visits deserves the same protection as the record itself. Mainstream booking SaaS, SMS reminder gateways and consumer map APIs each become a sub-processor of that data.

How Healthcare deployments map platform concepts onto their own terminology
Platform conceptIn your language
Service recipientPatient
Field professionalNurse / Carer
CoordinatorCare coordinator
AssignmentHome visit / Clinic round
Service locationPatient home address
Completion recordVisit record & escalations
  • Rota-driven availability

    Patients only ever see slots the nursing rota can actually serve.

  • Coordinator approval

    Every booking is clinically triaged before it is confirmed — no unsupervised self-serve.

  • Live ETA for patients

    “Your nurse is 15 minutes away” — end-to-end encrypted, no location broker involved.

  • Escalation trail

    Clinical concerns raised during a visit are captured and routed with full audit.

  • Family booking

    Carers and relatives can book and manage visits on behalf of a patient profile.

  • Encrypted reminders

    Appointment reminders over PSCE channels — no PHI in SMS gateways.

Deployment fit — Most care providers deploy Private Cloud or On-premises alongside their PSCE tenant; NHS-aligned and sovereign estates are individually scoped.

PRIVACY BY DESIGN · 08

Scheduling without surveillance.

  • Appointment metadata minimised and retained under your policy, not ours
  • Per-session encryption keys on every reminder, update and ETA share
  • No advertising identifiers, no analytics trackers, no data resale — ever
  • Geocoding and routing performed by Location Intelligence, in-boundary
  • Designed to support GDPR, HIPAA-aligned and MiFID II recordkeeping requirements — subject to your configuration and governance
  • ZRTP-PQ hybrid key exchange inherited from PSCE — algorithms and scope detailed in the cryptography technical note
DEPLOYMENT · 09

Runs where you need it to run.

Pryvate Cloud

Managed within Pryvate's sovereign infrastructure. Fastest to live.

Private Cloud

Your cloud account, your region, your keys — operated with our tooling.

On-premises

Deployed inside your data centre alongside your PSCE tenant.

Air-gapped

Fully disconnected estates with offline-tolerant field sync.

Government

Accredited environments, sovereign hosting and clearance-ready support.

Enterprise

1,000+ users, dedicated tenant, audit and compliance tooling.

An enterprise module, priced like one.

Scheduling is licensed as an enterprise PSCE module — one contract, one SDK, no new data processors.

Enterprise and sovereign deployments are configured around organisation size, infrastructure requirements and deployment model. Packaged deployments are available for smaller organisations.

QUESTIONS · 10

Asked by every security review so far.

Does this replace our existing calendar system?

No. It runs the operational scheduling of visits inside your boundary. Read-only sync to corporate calendars is available where your policy allows — the system of record stays in your tenant.

Can we keep using our own apps?

Yes. Scheduling ships as SDK modules and APIs for your existing iOS, Android and web apps, plus white-label reference apps for a faster start.

What actually leaves the boundary?

Appointment content and operational metadata remain within your designated deployment boundary. That boundary is defined per deployment model: for on-premises and air-gapped estates it is your own infrastructure; for managed deployments Pryvate operates it and holds only the limited operational data needed to run and support the service. In every model, your data is never used for advertising, profiling or unrelated analytics.

How long does deployment take?

Timelines are confirmed during the workflow and security assessment — managed-cloud tenants are fastest; on-premises and air-gapped estates are scoped during technical evaluation.

Can bookings require human approval?

Yes — that's the default. Requests route to a coordinator who can approve, reject, modify or reassign before anything is confirmed. Fully self-serve confirmation can be enabled per workflow if you prefer.

Do we need Location Intelligence too?

Booking, availability and lifecycle work standalone. Live ETA, tracking and field navigation compose with the Location Intelligence module — most scheduling customers deploy both.

Security review still open? Request the security whitepaper.

Scheduling · PSCE platform

Scheduling is one module.
The platform is the product.

Scheduling & Field Coordination is not a secure version of a booking app. It is one layer of the PSCE platform, for organisations whose appointments, people and operating patterns cannot safely pass through a collection of third-party platforms.

  1. PSCE
  2. Secure Communications
  3. Location Intelligence
  4. Scheduling & Field Coordination
  5. AI / operational intelligenceRoadmap

Modules of one platform — one boundary, one contract, extended a module at a time.

AI and operational intelligence are on the roadmap — the same boundary, the same guarantees.

Explore PSCE — the core platform underneath every module, including Location Intelligence.