Room Flow
Room Flow
Healthcare

Room booking for healthcare

Consultation rooms, staff meetings, shared equipment (mobile ultrasound scanner, trolleys, liaison vehicles): in a healthcare facility, the schedule touches on care. A meeting title, a practitioner's name, a consultation room at a given time — this metadata can reveal health information and deserves the same minimisation reflex as the patient record.

Your sector's context

The sector demands controlled hosting and strict traceability; a scheduling tool that does not collect your data simplifies the analysis instead of weighing it down.

Regulatory framework

The obligations specific to your sector.

Health data hosting (HDS)

In France, hosting health data on behalf of a third party is a regulated activity: HDS certification is required (Article L.1111-8 of the French Public Health Code). Room Flow does not claim that certification — and does not need it for your schedules: it does not host them. They stay in your calendars, on your infrastructure, under your own compliance framework.

Medical confidentiality and metadata

Confidentiality covers all information that comes to the professional's knowledge (Article L.1110-4 of the French Public Health Code). A consultation schedule is metadata that can touch on it: entrusting it to a SaaS creates one more recipient to govern. Not outsourcing it removes the question at the source.

Switzerland: Swiss FADP and professional secrecy

On the Swiss side, the Swiss FADP (in force since 1 September 2023) and medical professional secrecy (Article 321 of the Criminal Code) impose the same discipline: reducing the third parties with access to patient data — scheduling metadata included.

On the ground

Three typical use cases.

Consultation and staff rooms

Each room is a calendar in your facility's mail system: booked by the secretariats, approved by the unit managers (administrator role) — without exposing the schedule to any third party.

Shared medical equipment

Mobile ultrasound scanner, emergency trolley, liaison vehicle: anything that is a calendar can be booked, with no per-resource billing — the entire inventory can be covered.

Service continuity

A network outage does not block booking a room across the corridor: the application works offline, and the licence is verified locally with a signed certificate.

For your DPO: the portal holds only the organisation's account (name, e-mail addresses, seats, hashed device fingerprints) — never your bookings, attendees or purposes. The compliance sheet generated from the customer area lists exactly this data, its purposes and its retention periods, ready to feed into your analysis.

By architecture, not by promise

What the architecture guarantees.

Your bookings stay with you

Schedules, attendees and bookings live in your Zimbra/CalDAV calendars and on your workstations — not with the vendor, not in a foreign cloud subject to extraterritorial laws.

The network goes down, your bookings don't

The licence is a signed certificate verified locally: the app keeps working without a connection, network outage included.

A lean, auditable client

No trackers, no embedded analytics, no CDN: what the app does can be verified — nothing has to be taken on faith.

These points describe the product's architecture, not a sector certification. They are not legal advice: have your compliance reviewed by a specialist. Content to be reviewed by a lawyer before publication.

Your cookie preferences

Choose what you allow. Your choice is stored for 6 months and can be changed at any time via “Manage cookies” in the footer.

Necessary Always on

Session, security (CSRF protection), and remembering your language and cookie choices. Without these, the site does not work.

Audience measurement (Matomo, self-hosted) Off by default

Anonymized visit statistics, processed on our own servers. No data shared with third parties, no ad profiling.