Calendo
Health
Pricing

Cookie settings

We use necessary technologies for secure operation and login. With your choice we may also use first-party analytics. You may accept all, reject the optional ones or set your choices in detail.

Cookie settings

Security

Security and trust for clinics.

Calendo Health is a live product. This page explains what applies to the public website and what a clinic needs for GDPR, children's data, and a data processing agreement (DPA).

No live patient records

This public website does not contain patient records. Screenshots and videos come from a demo workspace with no real child details.

Minimal browser storage

The site stores privacy preferences, checklist progress, attribution context, and non-sensitive demo or updates receipts locally.

Validated contact messages

Contact messages are validated, rate-limited, size-limited, protected by a honeypot, verified with Turnstile when configured, and guide visitors to a clear contact path if online sending is unavailable.

Hardened public delivery

Security headers include a same-origin content policy, HSTS, frame blocking, MIME sniffing protection, referrer controls, and restricted browser permissions.

GDPR and children's data

What clinics handling children's data need to know.

Therapy clinics in Greece often process data about minors. You need a real answer, not only a note that this page is not a DPA.

Children's data in the app

The live Calendo Health app is for clinic coordination, including schedules, reminders, and parent communication. Children's data stays in your clinic workspace. This public website does not collect or display patient or child data.

Data processing agreement (DPA)

For activated clinics, the provider acts as processor for the data you enter in the app. The clinic remains the controller. The public DPA is published at /dpa and in English at /en/dpa. A signed DPA can still be added at activation.

Open the public DPA. For a DPA, children's/GDPR questions, or a vulnerability report, email hello@organosi.com.gr. hello@organosi.com.gr.

Disclosure

A clear path for security reports.

If you find a vulnerability or public website issue, use the published disclosure contact instead of submitting sensitive details through the contact form.

Responsible disclosure

Security contact metadata is published at /.well-known/security.txt. Reports can also be sent to hello@organosi.com.gr.

Scope note

This page describes the public website and the public trust framework. The public DPA is at /dpa. A signed DPA can still be added at activation.

Clinic-ready habits

Keep public material clean.

The marketing site is designed to help teams evaluate Calendo Health while keeping sensitive clinic details out of public forms, screenshots, and launch copy.

  • Do not submit patient data through the contact form.
  • Use privacy-safe screenshots and recordings for public materials.
  • Review privacy preferences before enabling analytics.
  • Use the security contact for vulnerability reports or public-site concerns.