Sovereign scheduling infrastructure

Own your scheduling. Not someone else's calendar.

Not another booking SaaS. Sovereign workflow infrastructure for any organisation that coordinates people in the field — healthcare, field services, government, utilities, logistics, security and financial or professional services. Booking, rotas, approvals, visit lifecycle and live ETA from a single SDK, deployed inside your own boundary as a module of the PSCE platform.

Booking requestIn your environment

Sovereign appointment booking flow

A booking request is raised in the client app from a saved location against live slots. It travels to a coordinator, who can approve, modify or reassign it — on approval the slot locks. The approved visit syncs to the field calendar as part of the rota, where double-booking is impossible, and is then delivered using sovereign routing with nothing logged onward. Every stage runs inside your environment.

RequestClient app · saved location, live slotsCoordinator approvalApprove, modify or reassign — the slot locksField calendarSynced rota · double-booking impossibleVisit deliveredSovereign routing · nothing logged onward
UK hostedZero telemetryGDPR

Appointment data stays within your designated deployment boundary.

Everyone else says “book online in seconds.”

Pryvate says your diary is not our dataset.

THE OPERATIONAL CASE

One workflow instead of six systems.

Every hand-off between tools is an integration to maintain, a contract to renew and a gap in the record. Run the whole visit lifecycle as one chain and the seams disappear.

  1. Booking
  2. Approval
  3. Rota
  4. Routing
  5. Encrypted communication
  6. Live ETA
  7. Completion
  8. Audit

One deployment boundary.

One audit trail.

One accountable infrastructure layer.

WHY IT MATTERS

The schedule itself is the sensitive record.

Before anyone opens a file, the diary already says who is being visited, how often, and by whom.

Healthcare

A visit diary is clinical data.

Frequency, address and practitioner type reveal diagnoses, care intensity and vulnerability — before a single clinical note is read.

Financial Services

The diary leaks before the deal does.

An adviser repeatedly visiting one family office, or a restructuring team booked into a struggling issuer, is exactly the signal MiFID II recordkeeping exists to govern.

Government

Field schedules are operationally sensitive.

Where inspectors will be, which addresses receive welfare visits and how teams are deployed carries direct operational and personal-safety consequences.

Built on PSCE
  • Designed for GDPR-regulated deployments
  • HIPAA-aligned workflows
  • MiFID II recordkeeping support
  • AES-256 · RSA-4096
  • ZRTP-PQ hybrid key exchange
  • UK / EU residency options
THE DIFFERENCE · 01

Not another booking SaaS.

Mainstream scheduling platforms require appointment metadata to pass through third-party infrastructure. Pryvate Scheduling is designed to keep that operational data within your chosen deployment boundary. Who meets whom, how often, and where is a behavioural map of your organisation — and it stays inside your walls, while coordinator workload drops through automated availability, approvals, reassignment and encrypted notifications.

Appointment metadata
Global scheduling platforms — no: Global scheduling platformsPasses through third-party infrastructure
Scheduling on PSCE — yes: Scheduling on PSCEStays inside your PSCE tenant or on-premise deployment
Locations & addresses
Global scheduling platforms — no: Global scheduling platformsGeocoded via global map APIs, logged by third parties
Scheduling on PSCE — yes: Scheduling on PSCEResolved by Pryvate Location Intelligence, in-boundary
Reminders & updates
Global scheduling platforms — no: Global scheduling platformsSMS/email via external gateways in cleartext
Scheduling on PSCE — yes: Scheduling on PSCEDelivered over PSCE's end-to-end encrypted messaging
Live ETA sharing
Global scheduling platforms — no: Global scheduling platformsContinuous location upload to vendor servers
Scheduling on PSCE — yes: Scheduling on PSCEPer-session keys, point-to-point, minimised retention
Compliance
Global scheduling platforms — no: Global scheduling platformsData processing agreements with a dozen sub-processors
Scheduling on PSCE — yes: Scheduling on PSCEDesigned for GDPR, HIPAA-aligned and MiFID II-regulated deployments, inheriting PSCE controls
Scheduling control
Global scheduling platforms — no: Global scheduling platformsSelf-serve booking only — no human in the loop
Scheduling on PSCE — yes: Scheduling on PSCEFull coordinator workflow: review, approve, modify, reassign
Branding
Global scheduling platforms — no: Global scheduling platformsTheir logo on your booking page
Scheduling on PSCE — yes: Scheduling on PSCEFully white-label, your apps, your domain
0

third-party data processors in the booking path — by architecture

6→1

disconnected systems consolidated into one governed workflow

1

contract, SDK and audit trail from booking to completion

100%

of appointment data held within your designated deployment boundary

Architectural guarantees, not performance benchmarks — each is verified with you during a workflow and security assessment.

CONSOLIDATION · 02

Replace six disconnected systems with one governed workflow.

Named specifically, the six systems that chain replaces are a booking SaaS, a rota tool, an SMS gateway, consumer messaging, a map API and a tracking app. The realistic alternative isn't one competitor — it's all of them, stitched together, each seam a sub-processor and a compliance question.

Six disconnected systems consolidated into one governed workflow

Six separate systems — Booking & appointment SaaS, Staff rota software, SMS / email notification gateway, Consumer messaging apps, Global map & routing APIs, Field tracking application — converge into a single governed workflow, Scheduling & Field Coordination on PSCE. Five of the six are third-party sub-processors and one, consumer messaging, is ungoverned entirely.

  • Booking & appointment SaaSSUB-PROCESSOR
  • Staff rota softwareSUB-PROCESSOR
  • SMS / email notification gatewaySUB-PROCESSOR
  • Consumer messaging appsUNGOVERNED
  • Global map & routing APIsSUB-PROCESSOR
  • Field tracking applicationSUB-PROCESSOR

Scheduling & Field Coordination on PSCE

  • Booking, rotas and approvals in one engine
  • Encrypted messaging and notifications built in
  • Routing, geocoding and live ETA via Location Intelligence
  • One audit trail, one contract, one deployment boundary
  • Fewer integrations, sub-processors and licence duplications
ARCHITECTURE · 03

Every component inside the boundary.

Scheduling is a module of the Pryvate Secure Communications Engine. It shares PSCE's identity, encryption and data-residency guarantees — and composes natively with Location Intelligence for routing, geocoding and live tracking.

Sovereign scheduling architecture

Three client surfaces — a white-label client app, a field app and a coordinator console — call into your own PSCE tenant, in your own jurisdiction. Inside that boundary sit four modules: the scheduling engine, Location Intelligence, encrypted messaging, and audit and residency. Global calendar clouds, map APIs, SMS gateways and analytics trackers sit outside the boundary and are not in the path.

Client app

Booking flows, addresses, reminders, ratings — white-label iOS / Android / web

Field app

Agenda, calendars, navigation, visit documentation — tablet & mobile

Coordinator console

Rotas, approvals, oversight, requests, audit

Your PSCE tenant · Your jurisdiction

Scheduling engine

Rotas, availability, approvals, lifecycle, timezone logic

Location Intelligence

Geocoding, routing, geofencing, ETA

Encrypted messaging

Reminders, updates, coordinator chat

Audit & residency

Event log, retention policy, compliance export

Global calendar clouds · map APIs · SMS gateways · analytics trackersNot in the path
CAPABILITIES · 04

Everything a scheduling platform does. Without surrendering operational data.

Appointment Booking

Guided multi-step flows — profile, location, live slots, intake notes — in your own apps, including booking on behalf of others.

Availability & Slots

Clients see only slots that staff rotas actually allow — timezone-aware, served from your tenant.

Shift & Rota Management

Coordinators create and manage working schedules and availability for every field worker from the admin console.

Approval Workflow

Every request is reviewed: approve, reject, modify or reassign. On approval the slot locks — double-booking is impossible.

Smart Reassignment

Rebalance visits across staff by availability, workload and geographic proximity — without breaking the audit trail.

Calendar Views

Approved visits sync straight to staff calendars — day, week and month views with workload badges.

Visit Lifecycle

Request → approval → en-route → in progress → complete, with full state history.

Live ETA & Tracking

End-to-end encrypted location sharing and arriving-soon alerts via Location Intelligence.

Address Book & Profiles

Saved service locations and recipient profiles with map-pin capture, geocoded in-boundary, never logged externally.

Coordinator Chat

Integrated encrypted chat between coordinators and clients — negotiate times, confirm details, share updates.

Reminders & Notifications

Delivered over PSCE encrypted channels — no SMS gateways, no cleartext.

SDKs & APIs

The same unified PSCE SDK — add scheduling to existing apps in weeks, not quarters.

IN THE PRODUCT · 05

Built for the people doing the visits.

Reference implementations for client booking and field delivery, ready to white-label. Healthcare configuration shown — terminology, workflows and branding adapt per sector.

This is one configuration, not the product. The same engine runs dispatch boards, inspection rounds, maintenance schedules and client meetings — the roles, labels and records change, the infrastructure does not.

Field app week calendar: a Sunday-to-Saturday grid of scheduled visits with a live now-line marking the current time, and per-day visit counts.
FIELD APP — WEEK CALENDAR WITH LIVE NOW-LINE
Field app en-route navigation: turn-by-turn guidance to a patient visit with distance, duration, speed and live ETA, and a mark-as-arrived action.
FIELD APP — EN-ROUTE NAVIGATION WITH ENCRYPTED LIVE ETA
Client app booking flow, step two: picking a date and time from live appointment slots, with unavailable slots struck through.
CLIENT — LIVE SLOTS
Client app appointments list: upcoming and past visits with their date, type, reference and confirmed, completed or pending status.
CLIENT — APPOINTMENTS
Field app daily agenda: the next appointment, a today's-overview panel counting visits, patients, remaining visits and average visit time, and a timeline of the day's visits.
FIELD APP — TODAY'S AGENDA & WORKLOAD
SCENARIOS · 06

Built for organisations where a leaked diary is a breach.

Illustrative deployment scenarios showing how the module is designed to be used. Named references are available under NDA through your account team.

Illustrative deployment scenario
Home healthcare network

Replacing a US-cloud booking SaaS for nurse home visits, so patient addresses and visit patterns never leave the provider's own tenant.

High-volume
visit scheduling, entirely in-boundary
Illustrative deployment scenario
Private wealth manager

Client meetings booked and confirmed over encrypted channels — no external calendar metadata for the front office to worry about.

0
third-party processors in the booking path
Illustrative deployment scenario
Government field services

Air-gapped deployment scheduling inspections with sovereign routing and offline-tolerant sync for field devices.

Offline-first
field sync for disconnected estates

Named references are available under NDA through your account team.

WHO IT'S FOR · 07

One platform. Your sector's language.

Built for sectors where the diary itself is sensitive — healthcare, field services, government, utilities, logistics, security and financial or professional services. Labels, workflows and roles are configured per deployment; select a sector to see how.

A visit diary is clinical data.

Who is being visited, how often, at what address and by which specialism reveals diagnoses, care intensity and vulnerability — before a single clinical note is read. Under GDPR and HIPAA-aligned regimes, an appointment book of home visits deserves the same protection as the record itself. Mainstream booking SaaS, SMS reminder gateways and consumer map APIs each become a sub-processor of that data.

How Healthcare deployments map platform concepts onto their own terminology
Platform conceptIn your language
Service recipientPatient
Field professionalNurse / Carer
CoordinatorCare coordinator
AssignmentHome visit / Clinic round
Service locationPatient home address
Completion recordVisit record & escalations
  • Rota-driven availability

    Patients only ever see slots the nursing rota can actually serve.

  • Coordinator approval

    Every booking is clinically triaged before it is confirmed — no unsupervised self-serve.

  • Live ETA for patients

    “Your nurse is 15 minutes away” — end-to-end encrypted, no location broker involved.

  • Escalation trail

    Clinical concerns raised during a visit are captured and routed with full audit.

  • Family booking

    Carers and relatives can book and manage visits on behalf of a patient profile.

  • Encrypted reminders

    Appointment reminders over PSCE channels — no PHI in SMS gateways.

Deployment fit — Most care providers deploy Private Cloud or On-premises alongside their PSCE tenant; NHS-aligned and sovereign estates are individually scoped.

PRIVACY BY DESIGN · 08

Scheduling without surveillance.

  • Appointment metadata minimised and retained under your policy, not ours
  • Per-session encryption keys on every reminder, update and ETA share
  • No advertising identifiers, no analytics trackers, no data resale — ever
  • Geocoding and routing performed by Location Intelligence, in-boundary
  • Designed to support GDPR-regulated deployments, HIPAA-aligned workflows and MiFID II recordkeeping — subject to your configuration and governance
  • ZRTP-PQ hybrid key exchange inherited from PSCE — algorithms, scope and status detailed in the cryptography technical note
DEPLOYMENT · 09

Runs where you need it to run.

Pryvate Cloud

Managed within Pryvate's sovereign infrastructure. Fastest to live.

Private Cloud

Your cloud account, your region, your keys — operated with our tooling.

On-premises

Deployed inside your data centre alongside your PSCE tenant.

Air-gapped

Fully disconnected estates with offline-tolerant field sync.

Government

Accredited environments, sovereign hosting and clearance-ready support.

Enterprise

1,000+ users, dedicated tenant, audit and compliance tooling included.

An enterprise module, priced like one.

Scheduling is licensed as an enterprise PSCE module. Pricing is based on active users, appointment volumes, deployment model, support requirements and Location Intelligence usage — one contract, one SDK, no new data processors. Sovereign, government and air-gapped deployments are scoped individually.

Enterprise licensing; packaged deployments available for smaller organisations.

QUESTIONS · 10

Asked by every security review so far.

Does this replace our existing calendar system?

No. It runs the operational scheduling of visits and appointments inside your boundary. Read-only sync to corporate calendars is available where your policy allows it — the system of record stays in your tenant.

Can we keep using our own apps?

Yes. Scheduling ships as SDK modules and APIs for your existing iOS, Android and web apps, plus white-label reference apps if you want a faster start.

What actually leaves the boundary?

Appointment content and operational metadata remain within your designated deployment boundary, which is defined per deployment model — for on-premises and air-gapped estates that boundary is your own infrastructure; for managed deployments Pryvate operates the infrastructure and holds the limited operational data needed to run and support the service. In every model, geocoding and routing run on Location Intelligence in-boundary, notifications ride PSCE's encrypted channels, and your data is never used for advertising, profiling or unrelated analytics.

How long does deployment take?

Timelines are confirmed during the workflow and security assessment — managed-cloud tenants are fastest; on-premises and air-gapped estates are scoped during technical evaluation.

Can bookings require human approval?

Yes — that's the default. Requests route to a coordinator who can approve, reject, modify or reassign before anything is confirmed. Once approved, the slot locks and syncs to the assigned worker's calendar. Fully self-serve confirmation can be enabled per workflow if you prefer.

Do we need Location Intelligence too?

Booking, availability and lifecycle work standalone. Live ETA, tracking and field navigation compose with the Location Intelligence module — most scheduling customers deploy both.

Scheduling · PSCE platform

Scheduling is one module.
The platform is the product.

Scheduling & Field Coordination is not a secure version of a booking app. It is one layer of the PSCE platform — a sovereign coordination capability for organisations whose appointments, people, locations and operating patterns cannot safely pass through a collection of third-party platforms.

  1. PSCE
  2. Secure Communications
  3. Location Intelligence
  4. Scheduling & Field Coordination
  5. AI / operational intelligenceRoadmap

Communications, Location Intelligence, Scheduling, Workflow, Identity and Audit are modules of one platform — one boundary, one contract, extended a module at a time.

AI and operational intelligence are on the roadmap — the same boundary, the same guarantees.

Explore PSCE — the core platform underneath every module, including Location Intelligence.