Calendo
Health
Pricing

Cookie settings

We use necessary technologies for secure operation and login. With your choice we may also use first-party analytics. You may accept all, reject the optional ones or set your choices in detail.

Cookie settings

Calendo Health

Calendo app privacy policy

This page covers the Calendo app and SaaS service (web and mobile: iOS, Android, and https://app.organosi.com.gr), not only the public marketing website. The public site has separate policies at /privacy, /cookies, and /dpa.

1. Who operates the service

The controller for the platform data described below is Konstantinos Konstantinou (Κωνσταντίνος Κωνσταντίνου), a sole trader / ατομική επιχείρηση in Greece, trading as Calendo Health.

Postal address: Rodon 38 (Ρόδων 38), 59100 Veria (Βέροια), Greece.

Privacy and support email: hello@organosi.com.gr. Alternate contact (so requests actually arrive): konstantinou.kostas@gmail.com. Phone: +30 6949010227.

No data protection officer (DPO) has been appointed. For privacy matters, use the emails above.

Public website: https://organosi.com.gr. App / SaaS: https://app.organosi.com.gr and the Calendo iOS and Android apps (bundle identifier gr.com.organosi.calendo). This policy is published at https://organosi.com.gr/privacy/calendo (Greek) and https://organosi.com.gr/en/privacy/calendo (English).

2. What Calendo is

Calendo is B2B clinic operations software for speech and multidisciplinary therapy clinics in Greece: appointment scheduling, calendar, staff roles, child records in a clinic context, and notifications.

It is not emergency medical care, emergency diagnosis, or a social network. In an emergency, contact appropriate emergency services.

3. Data that may be collected or processed

Depending on the clinic customer’s use and service configuration, the following categories may be processed. This is consistent with App Store / Play App Privacy declarations (identifiers, contact info, and Health & Fitness or health-adjacent fields the clinic enters):

  • Account / login data: email, hashed password, role, permissions, account status, must-reset-password flags.
  • Identifiers: account identifiers and, when notifications are enabled, device push tokens.
  • Contact info: names, email addresses, and phone numbers the clinic enters for staff, parents, or other authorized users.
  • Staff / therapist profile data: profile names, roles, clinic-entered contact details, availability where applicable.
  • Child / minor clinic records: names and related operational or health-adjacent fields entered by authorized clinic users (not for public or social use).
  • Appointments / calendar / attendance: times, status, type, procedure, therapist name, child linkage, cancel/attendance actions where permitted.
  • Notifications: in-app inbox messages; device tokens for delivery when permission is granted.
  • Technical logs / security events: IP addresses where needed for security, access-control events, rate limits, session events.
  • Billing / subscription: details needed for invoices, accounting, and account activation.
  • Support communications: what you voluntarily send for support or privacy requests.
  • Marketing-site data: what is described in the /privacy policy (forms and optional first-party analytics with consent).

4. Sensitive / health-adjacent data

Because Calendo is used by therapy centers, clinics may enter information relating to children/minors and therapy or appointment operations, including data that may be special-category data (GDPR Article 9) or health-adjacent.

We process that data as a processor on the clinic’s instructions. The clinic is the controller toward families and staff and is responsible for Article 9 legal bases and parental authority. We do not use that data for advertising.

5. Purposes

Data is processed for:

  • Providing the SaaS service to the clinic customer and managing user accounts
  • Clinic operations and appointment scheduling
  • Security, access control, and abuse prevention
  • Notifications (when enabled)
  • Customer support and privacy requests
  • Billing, accounting, and legal compliance

6. GDPR roles

Processor: for clinic-held records in the service (children, appointments, clinic staff profiles the clinic enters). The clinic is the controller toward families and staff. Deletion of those records goes through the clinic. A data processing agreement (DPA) is available on request at hello@organosi.com.gr.

Controller: for platform accounts we issue, billing/subscription, support tickets sent to us, platform security logs, and marketing-site data.

7. Legal bases (controller processing)

When we act as controller, the legal bases are:

  • GDPR Art. 6(1)(b) contract — providing the SaaS to the clinic customer and operating user accounts.
  • GDPR Art. 6(1)(f) legitimate interests — security, abuse prevention, and limited first-party product analytics on the marketing site only, with the existing consent banner where required.
  • GDPR Art. 6(1)(c) legal obligation — tax/accounting and responding to lawful requests.
  • GDPR Art. 6(1)(a) consent — optional push notifications on the device and optional marketing-site analytics.
  • Special-category / children’s data: processed as processor on the clinic’s instructions. The clinic is responsible for Art. 9 and parental authority. We do not use that data for ads.

8. Children and minors

Children do not self-sign-up. Clinic staff and parents receive accounts from the clinic. Children’s data is entered and managed by authorized clinic-customer users for center operations.

Calendo is not a social network and is not directed at children for self-signup. We do not ask children to create a consumer account through the public marketing website.

9. Sharing and processors

We use service providers only as needed to operate the platform. The current processors / subprocessors are:

  • Render — app / API hosting (app.organosi.com.gr).
  • Vercel — hosting for the public marketing site organosi.com.gr.
  • Cloudflare Turnstile — login bot protection.
  • Apple — App Store and TestFlight distribution, and Apple Push Notification service (APNs) for iOS notifications when permission is granted.
  • Google — Google Play distribution and Google push services (FCM) for Android notifications when enabled.
  • Expo / EAS — building and delivering the mobile apps.
  • Optional first-party analytics on the marketing site, only after consent in the existing preferences banner (see /privacy and /cookies).

10. No sale of data, advertising, or cross-app tracking

We do not sell personal data. We do not use third-party advertising SDKs. We do not engage in cross-app tracking. We do not use clinic or children’s data for advertising profiles.

11. International transfers

Some providers (Apple, Google, and, as applicable, Vercel, Render, or Cloudflare) may process data in the United States or outside the EEA. Where required, we rely on standard contractual clauses (SCCs) or equivalent safeguards under applicable law.

12. Retention

Data is retained while the clinic subscription or account lasts. After that ends, platform data we control is deleted or anonymized within 30 days, unless law requires longer retention (for example security logs or invoices).

Clinic-held records follow the clinic’s instructions. See section 16 for the account-deletion path.

13. Your rights and how to exercise them

Where GDPR applies, you may request access, correction, deletion, restriction, objection, portability, and withdraw consent where processing is based on consent.

How to exercise rights: email hello@organosi.com.gr or konstantinou.kostas@gmail.com. We may need to verify the requester’s identity. Requests about clinic-held records (children, appointments, clinic-entered profiles) must go to the clinic; we route them there when needed.

For deletion of account or platform data we control, the completion target is 30 days; see section 16.

You have the right to lodge a complaint with the Hellenic Data Protection Authority (ΑΠΔΠΧ), https://www.dpa.gr. Users in other EU member states may also contact their local supervisory authority.

14. Security

We apply measures such as role-based access control, HTTPS in transit, secure token storage on mobile where supported, audit logging, and least privilege. We do not claim ISO, SOC 2, or similar certifications.

Report security incidents to hello@organosi.com.gr. When we act as processor, we notify the clinic customer.

15. Push notifications

Device tokens are used for notification delivery only when the user has granted permission on the device. Lock-screen content should be generic; appointment details or child names must not appear on the lock screen by default product policy. You can turn notifications off in the device settings.

16. Data deletion (30-day target)

For deletion of account or platform data we manage as the service provider (for example login accounts, platform security logs, and support messages sent to us), email hello@organosi.com.gr or konstantinou.kostas@gmail.com. We aim to complete the request within 30 days after we can confirm the requester, unless law, security, or an outstanding dispute requires longer retention.

Deletion requests for child records, appointments, or other clinic-held records must go through the clinic customer. We do not delete clinic-held records on a third-party request without the clinic customer's process.

17. Cookies and the public website

The public marketing website has a separate privacy and cookies policy at /privacy and /cookies, including the consent banner for optional first-party analytics. This page covers the Calendo app / SaaS.

18. Policy changes

If we change this policy, we update the “Last updated” date at the bottom of this page. The current version is always the one published here.

19. Contact

Privacy and support: hello@organosi.com.gr

Alternate email: konstantinou.kostas@gmail.com

Phone: +30 6949010227

Address: Rodon 38 (Ρόδων 38), 59100 Veria (Βέροια), Greece

Last updated: 31 August 2026.