Calendo
Health
Pricing

Cookie settings

We use necessary technologies for secure operation and login. With your choice we may also use first-party analytics. You may accept all, reject the optional ones or set your choices in detail.

Cookie settings

Legal

Provider Privacy Policy

Information on processing operations in which the Provider acts as an independent Controller. This Policy covers details of representatives, users, support, billing, security and visitors. It is not information for patients about their therapeutic record; the Centre is responsible for that.

Controller

The Controller is Konstantinos Konstantinou, sole proprietorship, registered office at Rodon 38, Veria, 59100, Greece, AFM 137064830, Tax Office of Veria, GEMI 194995626000, privacy email info@organosi.com.gr, telephone +30 694 901 0227. Data Protection Officer details, if appointed: not appointed following a documented assessment.

Scope and distinction of roles

This Policy applies to legal representatives and staff of customers, authorised users, prospective customers, suppliers, persons requesting support and visitors of the website or application.

For health data and other patient data entered by a Centre, the Centre determines the purpose, the Article 6 basis and the applicable Article 9 exception and is the Controller, while the Provider acts as Processor under the DPA. This Policy is neither the legal basis nor the information notice for the patient about their record; a related request is forwarded to the competent Centre.

Data, purposes and legal bases

For account creation and management we process identity details, professional capacity, contact details, organisation and credentials. The basis is performance of a contract where the person is a contracting party and, for representatives or users of a legal person, the legitimate interest in proper provision and management of the service.

For billing and payments we process transaction details, invoices and tax details on the basis of contract and legal obligations. Full card details are held by Viva (Viva Wallet / Viva.com); full card details are not held by the Provider.

For support we process requests, communications and strictly necessary technical details on the basis of contract and the legitimate interest in resolving problems. The user must not send patient data unless necessary and permitted.

For security and prevention of abuse we process IP address, device/session identifiers, login times and action logs, on the basis of the legitimate interest in protecting systems, users and claims and, where applicable, legal obligation.

Commercial communications are sent with consent where required or, for similar services to existing customers, only under the conditions of Article 11 of Law 3471/2006 and with an easy opt-out in every message.

Sources of data

Data originate from the person themselves, the employer or collaborating Centre that creates the account, transactions, security systems and, where permitted, public professional sources.

Recipients and service providers

Access may be had by authorised personnel, providers of hosting, support, communications, security, payments and accounting services, professional advisers and public authorities when required. Each entity is characterised according to its actual role and is bound by the required safeguards.

The actual providers that process data on behalf of the Provider are: Render (hosting); Viva (payments); Infobip (SMS); [to confirm] EEA transactional email provider. Updated list also in DPA Annex C.

International transfers

Places of processing: Germany (hosting/backups); Greece (Provider administration, support). If data are transferred or accessible outside the EEA, the following applies: There is no transfer outside the EEA for primary hosting and backups (Render, Germany). If a future sub-processor is located outside the EEA, the safeguards of Chapter V GDPR will apply and Annex C will be updated. If there is no transfer, this is expressly stated after review of the entire chain.

Retention periods

Account and contract details are retained for the duration of the relationship and thereafter for up to 24 months for claims; tax/accounting details for the period required by Greek tax legislation (as a rule up to 5 years or whatever applies from time to time). Tax details are retained for the period required by the applicable tax legislation.

Support requests are retained for 24 months from closure of the request, security logs for 12 months, and details of declined commercial communication on a suppression list for as long as required to respect the choice. Where an exact period cannot be set, documented criteria of necessity, legal obligations, risk and limitation apply.

Cookies and similar technologies

Storage of or access to information on the device is described separately in the Cookie Policy. Optional cookies or similar technologies are activated only in accordance with consent requirements and the user's choices.

  • Demo preferences
  • Selected public resources
  • Evaluation notes
  • Product tour choices
  • Public sharing preferences
  • Updates preferences

Security

The Provider implements appropriate technical and organisational measures proportionate to the risk. No online service can guarantee absolute security; this does not limit the Provider's legal obligations.

Automated decisions and services to children

Status of automated decision-making for the processing under this Policy: THERE IS NO automated decision-making producing legal or similarly significant effects for the processing under the Provider Privacy Policy. If a decision producing legal effects or significantly affecting the person is made solely by automated means, the specific information is provided and the legal safeguards apply.

The professional service is not offered directly to children. Minors' data in a therapeutic record are submitted by the Centre under its own responsibility and are governed by the DPA.

Rights

The data subject may, as applicable, request access, rectification, erasure, restriction, portability, object to processing based on legitimate interest and withdraw consent without retrospective effect. A request is submitted to info@organosi.com.gr and proportionate identity verification may be required.

There is a right to lodge a complaint with the Hellenic Data Protection Authority, 1-3 Kifissias Ave., 115 23 Athens, www.dpa.gr, without prejudice to judicial remedy.

Changes to the Policy

The Policy is updated when the processing or legal framework materially changes. The then-current version is made available through the application or website and for a material change appropriate notice is given.

Related documents: /dpa, /cookies, /terms, /subscription-terms, /privacy/calendo, /security.

Last updated: 4 September 2026.

Privacy request

Prepare a clear public website privacy request.

Use the helper for access, correction, deletion, consent, or saved browser data without adding patient data.

Privacy request helper

Prepare a clear public website privacy request.

Choose the request type, public website scope, and safe questions before opening an email to the Calendo Health contact address.

76%

Request clarity

Access or copy

Ask what public website request, signup, attribution, or receipt data is associated with you.

Public website scope

Safe questions

Generated request

Privacy request from the website

Privacy request from the website:
Request type: Access or copy
Reply email: Not provided

Public website scope:
- Contact message: Name, clinic, contact details, message, consent, attribution, and request reference.
- Updates signup: Email, optional role/interest, update preferences, consent, attribution, and signup reference.
- Saved browser data: Saved page choices and receipt data stored only in this browser.

Questions:
- Which email address or request reference should we use to locate the public website submission?
- Which public website form or tool did you use?
- What information should not be included in the public website request?

Optional note:
Not provided

Safe request boundaries:
- Do not include patient data, clinical notes, minors' information, private access details, private screenshots, contracts, or live app records.
- Use request references, approximate dates, and the email address used on the public website instead of sensitive examples.
- Saved browser data stays on the visitor's device and can be cleared from the relevant page or the cookies and storage controls.
- Private legal, data-processing, security evidence, or live app account questions should move to protected follow-up channels.
Open email request

Safe request boundaries

  • Do not include patient data, clinical notes, minors' information, private access details, private screenshots, contracts, or live app records.
  • Use request references, approximate dates, and the email address used on the public website instead of sensitive examples.
  • Saved browser data stays on the visitor's device and can be cleared from the relevant page or the cookies and storage controls.
  • Private legal, data-processing, security evidence, or live app account questions should move to protected follow-up channels.