Calendo
Health
Pricing

Cookie settings

We use necessary technologies for secure operation and login. With your choice we may also use first-party analytics. You may accept all, reject the optional ones or set your choices in detail.

Cookie settings

Legal

Data Processing Agreement

Article 28 of the General Data Protection Regulation (GDPR). The application processes health data, including data relating to minors. For patient Content the Centre is the Controller and the Provider is the Processor. The Customer completes and documents the legal bases in Annex A; the Provider and its technical staff complete only the actual technical details of Annexes B and C before production use.

Parties and Main Agreement

Controller / Customer: [clinic details from Order Form]

Processor / Provider: Konstantinos Konstantinou, sole proprietorship, registered office at Rodon 38, Veria, 59100, Greece, AFM 137064830, Tax Office of Veria, GEMI 194995626000

Main Agreement: [Order Form and Terms of Use]

Subject matter, duration, nature and purpose

This Agreement regulates the processing of personal data included in the Customer's Content and carried out by the Provider on its behalf in the course of providing, hosting, securing, maintaining, supporting, exporting and deleting the application.

Processing lasts for as long as the Provider retains or has access to data on behalf of the Customer, including the export period and the technical deletion cycle. More specific information is set out in Annex A.

Roles and documented instructions

The Customer determines the purposes and essential means of processing and is responsible for lawfulness, transparency, accuracy, minimisation, retention periods and access rights. The Provider processes only on the basis of the documented lawful instructions of the Main Agreement, this Agreement and the Customer's authorised persons.

Every instruction to collect, enter, access, disclose, retain or delete Content presupposes and incorporates a declaration by the Customer that it has authority to give it and that the specific processing is lawful. The Provider neither determines nor certifies the therapeutic purpose, the legal basis, professional competence or parental representation.

If a provision of Union or Member State law requires the Provider to process differently, it informs the Customer beforehand, unless the information is prohibited for important reasons of public interest.

The Provider is entitled to rely on the Customer's written or electronic declarations and instructions without a general obligation to examine therapeutic records, consents or parental responsibility documents. If it considers that an instruction infringes applicable data protection law, it informs the Customer immediately in accordance with Article 28(3) GDPR and may suspend only the contested act until adequate lawful clarification is given.

The Provider does not use the Content for its own advertising, commercial profiling or training of an artificial intelligence model, unless there is a separate lawful purpose, appropriate information and the required agreement or instruction.

Health data and Article 9 GDPR

The Parties acknowledge that the Content includes or may include health data within the meaning of Article 4(15) GDPR, disability data and other special categories under Article 9(1), including data relating to minors. The prohibition of Article 9(1) is lifted only if the Customer documents a specific applicable exception under Article 9(2). This condition is separate from and cumulative to the Article 6 basis.

The Customer's status as a specialised therapy Centre, the characterisation of information as health data, signature of this Agreement or the technical ability to store do not automatically establish an Article 9 exception. The Customer selects and bears the burden of documenting the appropriate exception for each purpose.

Where the Customer relies on Article 9(2)(h), it declares and warrants that the processing is necessary for medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services, that it is based on Union or Member State law or on a contract with a health professional, and that the professional secrecy conditions of Article 9(3), applicable sectoral legislation and, to the extent applicable, Article 22(1)(b) and (3) of Law 4624/2019 are met.

Where the Customer relies on explicit consent under Article 9(2)(a), it is exclusively responsible for proving that such consent is freely given, specific, informed, explicit and withdrawable in accordance with Articles 4(11) and 7 GDPR and that withdrawal is implemented without undue delay. Consent or approval of a therapeutic act is not automatically identical to explicit consent for every data processing.

Minors, parental responsibility and information

Minority is not in itself an Article 9 exception. The Customer verifies and documents age, parental responsibility or other lawful representation and any consent or authorisation required both for the processing and for the underlying therapeutic relationship. It provides information in clear and, where addressed to a child, age-appropriate language.

Article 8 GDPR and Article 21 of Law 4624/2019 apply when an information society service is offered directly to a child and the processing is based on consent. Under this B2B structure the Provider does not offer an account or service directly to a minor.

Other Customer obligations

Before the first entry and throughout the processing, the Customer records in Annex A the Article 6 basis, the specific Article 9(2) exception and the related legal or contractual foundation. It immediately informs the Provider of any change or withdrawal that affects its instructions.

Upon reasonable request or documented doubt, the Customer provides adequate written confirmation of the above without unnecessary disclosure of health data. If it does not provide it, the Provider may proportionately suspend the affected processing until lawful clarification, and immediately when continuation creates a serious risk of breach.

The Customer determines the information notices, recipients, access rights, minimisation and retention periods, assesses the need for a DPIA, DPO or prior consultation and does not give an unlawful or unclear instruction.

Confidentiality and personnel

The Provider permits access only to authorised persons who need it for a specific task and who are bound by a legal or contractual confidentiality obligation. It applies a process for granting, reviewing and revoking access.

This obligation fulfils the contractual requirement of Article 28(3)(b) GDPR, but does not replace the Customer's independent obligation to ascertain that the specific conditions of Article 9(3) are met for the exception it relies on.

Security of processing

The Provider implements appropriate technical and organisational measures in accordance with Article 32 GDPR, taking into account the state of the art, cost, nature, scope, context and purposes, as well as the likelihood and severity of risks, particularly due to health data and children.

The actual measures are described in Annex B. The description is specific but does not require disclosure of information that would put security at risk. The Provider does not materially reduce the overall level of protection during the processing.

Sub-processors

The Customer grants a general written authorisation for the sub-processors in Annex C. The Provider keeps available and up to date the identity, contact details, service, description of processing, locations and any international transfers throughout the sub-processing chain.

Before adding or replacing a sub-processor, the Provider actively notifies the Customer at least 30 days in advance so that the Customer may raise a documented objection on data protection grounds.

The Provider imposes in writing on the sub-processor the same data protection obligations as this Agreement imposes, to the extent they relate to the entrusted processing, and remains fully liable to the Customer for the performance of the sub-processor's obligations in accordance with Article 28(4) GDPR.

Place of processing and international transfers

The locations of primary hosting, backups, technical support and remote access are set out in Annex C. Access from a third country constitutes a transfer and is not permitted without the conditions of Chapter V GDPR.

Where a transfer exists, Annex C states an adequacy decision or appropriate safeguards, usually the applicable Standard Contractual Clauses, as well as the required assessment and supplementary measures. If the required level of protection cannot be ensured, the transfer is suspended.

Data subject requests

A request concerning the Customer's data is forwarded without undue delay via the channels provided in the section “Communications under the DPA”. The Provider does not respond on the merits without a documented instruction from the Customer, unless required by law.

Taking into account the nature of the processing, the Provider assists with appropriate technical and organisational measures in the fulfilment of rights.

Personal data breach

The Provider notifies the Customer of a breach concerning its data without undue delay from the moment it becomes aware.

It provides, to the extent available, the nature of the incident, the affected categories and approximate numbers, the likely consequences, the containment measures and the point of contact. It preserves evidence and cooperates in assessing notification to an authority or data subjects, without the assistance constituting an admission of liability.

DPIA, consultation and supervisory authorities

The Customer decides and documents whether a data protection impact assessment or prior consultation is required, particularly due to the nature, scale and combination of health data and children. The Provider provides the available necessary information and assistance under Article 28(3)(f), to the extent they relate to its own processing. The assistance does not transfer to the Provider responsibility for the Customer's decision.

The Provider cooperates with the competent supervisory authorities in accordance with the law.

Information and audits

The Provider makes available the information necessary to demonstrate compliance and permits audits by the Customer or its independent auditor, subject to reasonable notice, confidentiality, limitation to the necessary scope and avoidance of unjustified disruption or disclosure of other customers' data.

Audits are as a rule conducted remotely and up to once per year. These limitations do not apply when an additional audit is required due to a documented incident, material indication of breach or order of a competent authority. Reasonable cost of an exceptional audit may be allocated in advance, without impeding a mandatory audit.

Return and deletion

Upon end of the service and at the Customer's choice, the Provider returns or deletes the personal data and deletes existing copies, unless Union or Member State law requires retention.

Active data are deleted after the 30-day export period. Isolated backups are deleted in the actual technical cycle of 90 days, are not used for any other purpose and are protected until final deletion.

Liability and internal allocation

This Agreement does not limit data subjects' rights, authorities' powers or the application of Article 82 GDPR. The Provider is liable as Processor under the conditions of Article 82(2) and is exempted only if it proves that it is not in any way responsible for the event giving rise to the damage under paragraph 3.

Where joint and several liability applies vis-à-vis the data subject, internal recourse between the parties is made under Article 82(5) and according to the share of responsibility attributable to each. Contractual notification, investigation or corrective measure does not by itself constitute an admission of breach, fault or causation.

In the parties' internal relationship the Provider does not assume responsibility for the selection or documentation of the Article 6 basis, the Article 9 exception, the existence of professional secrecy, the validity of consent, parental representation or the lawfulness of the therapeutic act. Mere performance of a lawful instruction, hosting or technical access does not transfer to it the Customer's corresponding obligations, except to the extent the Provider contributed by its own breach or acted outside or contrary to lawful instructions.

The Customer indemnifies the Provider for documented loss it suffers and reasonable defence costs it incurs from an unlawful instruction, absence of or incorrect selection of an Article 6 basis or Article 9 exception, failure to meet Article 9(3), invalid or unproven consent, incomplete information, inadequate parental or other authorisation, unlawful Content or a security breach under its control to the extent the Customer is liable.

No standardised liability cap applies under this Agreement. Any specially negotiated internal financial allocation does not bind data subjects or authorities and does not cover non-limitable liability.

Communications under the DPA

Documented instructions of the Customer are exclusively those provided by an authorised user via the application or from the Customer's last declared corporate communication channel. Notifications of personal data or security incidents, requests concerning data subject rights and requests for audit or information are sent to the details stated in the Main Agreement, the Order Form or the Customer's administrator account.

Each Party must keep its contact details accurate and up to date. Dispatch of a notification by the Provider to the Customer's last declared channel constitutes proper contractual notification, provided the Provider has not received an indication of delivery failure. The Customer bears the risk of delay or non-receipt resulting exclusively from its failure to update its details, subject to the mandatory provisions of the GDPR.

Duration and precedence

The DPA applies for as long as the Provider processes the Customer's data. In case of conflict with the Main Agreement this Agreement prevails on data protection matters.

ANNEX A - DESCRIPTION OF THE PROCESSING

Table 1

FieldDescription
Subject matterProvision, hosting, security, maintenance, support, export and deletion of the Calendo Health application on behalf of the Customer.
DurationFor the duration of the subscription and, after its expiry, for the export period and the applicable technical deletion cycle.
Nature and actsEntry by the Customer, organisation, storage, retrieval, display, alteration, transmission upon action of an authorised user or lawful instruction, creation of backups, support, export and deletion.
PurposeExclusively the provision of the agreed functions of the application and the performance of lawful documented instructions of the Customer.
Data subjectsPatients, including minors; parents or legal representatives; therapists; employees or collaborators of the Customer; other contacts entered lawfully.
DataIdentity and contact details, appointment and attendance details, financial or insurance details where used, account, role and access log details, as well as health or disability data entered by the Customer.
Articles 6 and 9 GDPRDetermined and documented by the Customer per purpose before entry: Article 6(1) basis [completed by the clinic per purpose]; Article 9(2) exception [completed by the clinic]; related legal or contractual foundation and, where required, Article 9(3) conditions [completed by the clinic]. The Provider neither selects nor certifies the legal foundation.
MinorsThe Customer is responsible for verifying age, parental responsibility or other lawful representation, the required information and any consent or authorisation: the clinic maintains an internal process for verifying parental responsibility/representation before entry of a minor.

ANNEX B - TECHNICAL AND ORGANISATIONAL MEASURES

Completed by the Provider with technical assistance and records exclusively the measures actually applied. A general statement about “encryption” or “backups” is not sufficient. Without prejudice to the obligations of Article 32 GDPR, specific RPO/RTO or availability targets bind the Provider only if expressly agreed in a separate SLA.

Access and confidentiality: Unique named accounts; least-privilege roles; MFA available for administrator accounts; recommended; mandatoriness may be enabled per clinic; grant/revoke by clinic administrator; confidentiality undertakings of Provider personnel

Segregation and data protection: Logical segregation of customers per tenant/clinic with role-based authorisation controls; Encryption in transit (TLS 1.2+); encryption at rest at the hosting infrastructure level; secrets/keys via hosting infrastructure settings

Logging and monitoring: Access/error/security logs; restricted access; retention of approximately 90 days for operational/security application logs, unless law or investigation requires longer retention

Backups and recovery: Daily backups (hosting infrastructure); restore tests at intervals; location: Render, Frankfurt, Germany (EEA); deletion of isolated backups in the 90-day cycle

Secure development and vulnerabilities: Infrastructure/application updates; segregation of demo and production where applicable; remediation of vulnerabilities by severity

Incident management: Incident process; notification to support@organosi.com.gr; preservation of evidence for investigation

Support, export, deletion and review: Support with least necessary access; CSV export within 30 days after expiry; deletion of active data after export and of backups within 90 days

ANNEX C - SUB-PROCESSORS, LOCATIONS AND TRANSFERS

Upon conclusion of this Agreement, the Customer approves the following sub-processors. If no sub-processor is used, “None” is expressly stated.

Places of processing by the Provider: Germany (hosting/backups); Greece (Provider administration, support)

Updated list: Annex C / update by email to the declared administrator

Change notification channel: email to the Customer's declared administrator and hello@organosi.com.gr / +30 694 901 0227

Table 2

Identity/contactService and processingCountries/locationsTransfer outside EEA and safeguard
Render, contact details per render.com · service for Calendo HealthHosting of application, database and backupsGermany (EEA)No transfer outside the EEA
Viva.com / Viva Wallet (Greece/EEA)Processing of subscription payments; card details with the payment providerEEANone / within EEA
[to confirm] EEA transactional email providerSending transactional email (reminders, account notifications)EEA (to confirm)None provided within EEA
Infobip (infobip.com)Sending SMS reminders to parents/contacts on the clinic's instructionEEA / according to Infobip statementsWithin EEA where applicable; otherwise SCCs / Chapter V GDPR Infobip

CONTROLLER | PROCESSOR

Table 3

CONTROLLERPROCESSOR
Full name: [●] / Capacity: [●] / Signature: [●]Full name: Konstantinos Konstantinou | Capacity: Processor | Signature: [upon acceptance]

Last updated: 4 September 2026.

DPA

Related contractual documents

This DPA prevails on data protection matters. Related public documents: /terms, /subscription-terms, /privacy, /cookies, /security.