Calendo
Health
Pricing

Cookie settings

We use necessary technologies for secure operation and login. With your choice we may also use first-party analytics. You may accept all, reject the optional ones or set your choices in detail.

Cookie settings

Legal

Terms of Use and B2B Subscription Service

Professional application for administrative and organisational support of specialised therapy centres. These Terms apply exclusively to professional use. They do not constitute consumer subscription terms and do not provide a direct account to a patient or minor.

Provider, Customer and Agreement

The Provider is Konstantinos Konstantinou, sole proprietorship, registered office at Rodon 38, Veria, 59100, Greece, AFM 137064830, Tax Office of Veria, GEMI 194995626000, with support contact details hello@organosi.com.gr / +30 694 901 0227, privacy info@organosi.com.gr, security support@organosi.com.gr. The Customer is the professional or entity named in the Order Form.

The Agreement consists of the Order Form, these Terms and the DPA. A specific document prevails only in respect of the subject matter it expressly regulates. The Privacy Policy and Cookie Policy do not constitute contractual warranties or instructions for the processing of the Customer's data.

The person who accepts represents that they have authority to bind the Customer. The Provider may request appropriate evidence of representation.

Electronic formation

Before the final step, the Customer has the opportunity to review and correct the order and to access and store the contractual texts. The agreement is concluded upon active acceptance and electronic confirmation.

The Provider retains the commercial summary, the versions of the texts and the necessary details of the acceptance event. Mere browsing or silence does not substitute for the initial active acceptance.

Subject matter and limits of the Service

The application provides the administrative, secretarial and organisational functions set out in the Order Form and in the documentation from time to time. A function, specialised integration, migration or configuration that is not listed is not included.

The Service does not provide diagnosis, therapeutic recommendation, automated clinical decision-making, emergency incident monitoring or any guarantee of therapeutic outcome. Clinical judgement and every related act belong exclusively to the Customer and its professionals.

A reminder, template, calculation, automation or generated document is an aid and is checked by a competent user before it is used, submitted or sent. The Provider does not assume a general obligation to verify the medical, legal, tax or insurance correctness of the Customer's Content.

A new function that may provide artificial intelligence or clinical decision support is activated only with a separate description and the special terms required by its actual characteristics.

Right of use and intellectual property

For so long as the subscription is active and paid, the Provider grants a limited, non-exclusive, non-transferable right of use for the Customer's internal professional needs and within the limits of the Order.

The Provider and its licensors retain all rights in the application, code, interfaces, documentation and improvements. The Customer's Content remains under the control and rights of the Customer or the relevant right holders.

Accounts and authorised users

The Customer creates named accounts, assigns the minimum necessary rights, promptly revokes access of departing persons and maintains accurate user details.

Users keep credentials confidential, do not share accounts and apply the available security measures. The Customer notifies the Provider immediately of any suspected access, device loss or password compromise.

The Customer is liable for the acts of its users to the extent attributable to it by law. It is not charged with unauthorised conduct that results from a culpable breach of the Provider's security obligation.

Provider's obligations

The Provider supplies the Service with due professional care and in material conformity with the Agreement. Unless a measurable outcome is expressly agreed or a specific Service Level Agreement (SLA) is agreed, it does not undertake a warranty of uninterrupted operation, absolute security or a specific business result.

The Provider applies the actual technical and organisational safeguards of the GDPR, restricts access to authorised persons, addresses verifiable faults according to their severity and notifies of scheduled maintenance with material impact when reasonably practicable.

The Provider is entitled, without a general obligation to examine the underlying documents, to rely on the accuracy, completeness and lawfulness of the Customer's statements, data and documented instructions, unless the unlawfulness is manifest or the law requires flagging, suspension or refusal of performance. The information obligation under Article 28(3) GDPR is preserved.

Customer's obligations

The Customer uses the application lawfully, holds the necessary professional licences and, for each distinct purpose, selects, documents and maintains an applicable legal basis under Article 6 GDPR and, for health or disability data, a specific exception under Article 9(2) GDPR. The contractual or technical ability to enter data does not by itself prove the lawfulness of the processing.

Where the Customer relies on Article 9(2)(h) GDPR, it confirms that the processing is necessary for the specific therapeutic or administrative purpose, is based on applicable law or on a contract with a health professional, and satisfies the professional secrecy conditions of Article 9(3), applicable legislation and, to the extent applicable, Article 22 of Law 4624/2019. If it relies on explicit consent under Article 9(2)(a), it bears the burden of proving all conditions of Articles 4(11) and 7 GDPR.

It verifies the accuracy, completeness and suitability of entries, templates, documents, notifications and exported files before any professional or official use.

For a minor's data it verifies and documents parental responsibility, lawful representation and any consent or other authorisation required by data protection law and the legislation governing the therapeutic act. Article 8 GDPR and Article 21 of Law 4624/2019 are considered when an information society service is offered directly to a child on the basis of consent; this B2B Service does not provide a direct account to a minor.

It provides the required, appropriate and intelligible information to patients and their legal representatives and, upon the Provider's reasonable request, confirms in writing the applicable bases and authorisations without unnecessary disclosure of health data.

It securely manages devices, networks, staff, roles, physical files and third-party connections under its control.

It maintains an appropriate alternative procedure for urgent or time-critical needs and does not use the application as the sole means of patient safety, clinical decision-making or compliance with an irreversible deadline.

It promptly notifies of malfunction, cooperates in investigation, preserves available evidence and takes reasonable measures to prevent or limit damage.

It discloses before use any special risk or likelihood of unusually large loss that the Provider does not know and is not required to know, so that additional measures or a specific SLA may be agreed if feasible.

Personal data and confidentiality

For therapeutic records and other Content entered for the Centre's purposes, the Customer is the Controller and the Provider is the Processor pursuant to their Data Processing Agreement (DPA). For its own contract, billing, support and security data the Provider acts as an independent Controller and informs via the Privacy Policy.

The Provider does not determine the therapeutic need, the legal basis or the Article 9 exception for the Customer's Content and does not certify parental responsibility, professional status or the validity of consent. Storage or other processing pursuant to a lawful instruction does not constitute assumption of the Customer's corresponding obligations.

Each party keeps confidential the other party's non-public business, technical and professional information, uses it only for the Agreement and discloses it only to persons bound by a corresponding obligation or when required by law.

Third-party providers and integrations

Sub-processors used by the Provider for the Customer's data are governed by the DPA, namely the agreement between Controller and Processor under Article 28 GDPR. The Provider is not released from liability that the law attributes to it for a sub-processor or fulfilment assistant.

For a third-party service or integration that the Customer selects, contracts and controls directly, the Provider is not liable for the third party's act, except to the extent the Provider itself contributed culpably or undertook an express integration or control obligation.

Availability, maintenance and changes

The application may be temporarily unavailable due to maintenance, failure, networks or a security incident. A binding availability percentage, response time or recovery time applies only if expressly stated in an SLA.

The Provider may improve or change non-material functions without materially reducing the overall agreed service. For a materially adverse change it gives prior notice and provides a right to terminate the affected service, unless the change is urgently required by law or security.

Price, delay and suspension

The Customer pays the price, VAT and the expressly agreed charges in the Order Form. On delay, statutory interest and reasonable lawful collection costs are owed.

After notice and unused expiry of the agreed period, the Provider may proportionately suspend access. Immediate suspension is permitted when necessary to prevent a serious security risk, unlawful use or harm to other users, with notice as soon as it is safe and lawful.

If there are documented reasonable doubts as to the Article 6 or 9 basis, authority to represent a minor or the lawfulness of a specific instruction, and the Customer does not provide adequate clarification after a request, the Provider may proportionately suspend only the affected processing. Suspension may be immediate when continuation creates a serious risk of breach, subject to mandatory law.

Term and termination

The initial term and any renewal are set out in the Order Form. Either party may terminate for material breach within a reasonable period after written demand, or immediately when the breach creates a serious risk.

Termination without fault before expiry is permitted only if provided in the Order Form. Expiry does not release already accrued debts and does not cause immediate deletion of data in breach of the agreed export procedure and the DPA.

Export, return and deletion

The Customer exports the available data during the subscription and within 30 days after expiry, in CSV formats. The Provider provides the reasonable assistance provided in the Agreement and applicable law.

After the export period the Provider returns or deletes the data according to the Customer's choice and the DPA, unless law requires retention. Isolated backups are deleted within the confirmed technical cycle of 90 days.

To the extent Regulation (EU) 2023/2854 applies, the parties apply the mandatory obligations on switching provider, export, contractual transparency and charges, without this clause creating any additional warranty beyond the law and the express agreement.

Remedies and contractual aids

For a verifiable remediable fault the Customer affords a reasonable opportunity for technical correction or re-performance before selecting a disproportionately more costly measure, unless there is urgent need, risk to persons or data, or the remedy is objectively inadequate.

An SLA credit, price refund, technical correction or goodwill gesture does not by itself constitute an admission of breach, fault, causal link or amount of loss.

Liability and causal link

Liability of the Provider presupposes breach of a specific contractual or legal obligation of the Provider, proven loss and an appropriate causal link. As regards contractual fault, Article 330 of the Greek Civil Code applies and the Provider retains the right to prove that the non-performance results from an event for which it has no fault.

There is no breach by the Provider to the extent the result was caused exclusively by inaccurate or unlawful Content or instruction, a clinical or administrative decision, an insecure device or credentials of the Customer, failure to check, lawful suspension or deletion, or a third-party service that the Customer selected and controls, provided the Provider did not contribute culpably and is not liable for the third party.

A cyberattack, network outage, temporary unavailability or supplier failure does not automatically establish the Provider's liability. It is examined whether the Provider complied with the specific legal and agreed obligations of prevention, selection, supervision, response and remediation.

If the Customer or a person for whom it is liable contributed to the occurrence or extent of the loss, failed to prevent or limit it, or failed to disclose an unusually large risk that the Provider did not know and was not required to know, Article 300 of the Greek Civil Code applies, including non-award or reduction of damages.

Every positive loss and lost profit is proven specifically in accordance with the law. Damages are not owed where applicable law provides only a restorative function.

No provision excludes or limits in advance liability for wilful misconduct or gross negligence, infringement of life, health, liberty, honour or another personality right, rights under Article 82 GDPR, or any other liability that cannot lawfully be limited.

These standardised Terms do not establish a general liability cap nor a blanket exclusion of slight negligence.

The obligation of timely notice of a problem serves limitation of loss and preservation of evidence. It does not shorten the statutory limitation period nor cause automatic loss of a claim.

Third-party claims and indemnification of the Provider

The Customer indemnifies the documented reasonable defence costs, final awards of damages and approved settlements, to the extent a third-party claim was caused directly by its own breach.

The Customer's indemnity obligation to the Provider arises in case of unlawful Content or instruction, absence of or act in breach of Article 6 or an exception under Article 9(2) GDPR, failure to meet the conditions of Article 9(3), invalid or unproven consent, incomplete information, inadequate parental or guardian authorisation, clinical act or omission, infringement of a third party's right, password sharing or insecure device, and a third-party connection selected by the Customer.

No indemnity is owed to the Provider to the extent the claim results from a breach or fault of the Provider or a person for whom it is liable. The clause does not limit third-party rights, authorities' powers or mandatory law and does not pass on an administrative fine where that is prohibited.

The Provider notifies the claim without undue delay and allows the Customer to participate in the defence. No admission of fault or settlement that burdens the Provider is made without its prior written consent, which is not unreasonably withheld.

Force majeure

A party is not liable for delay or inability to the extent it results directly from an extraordinary event beyond its reasonable control that could not be foreseen or prevented with due care. Lack of resources, ordinary failure or supplier failure does not automatically constitute force majeure.

The affected party notifies, limits the impact and resumes performance as soon as possible. If the material inability lasts more than 30 days, the other party may terminate the affected part of the Agreement.

Acceptable use and protection of the Service

Unlawful or abusive use, access to another's account, circumvention of limits, credential sharing, introduction of malicious code, unauthorised copying, resale or attempt to extract source code is prohibited, subject to rights that cannot be excluded by law.

The Provider may take proportionate restriction or suspension measures to protect the Service and third parties, after notice where feasible and without acquiring a general obligation of proactive monitoring of Content.

Notices, assignment and other terms

Contractual notices are sent to the details in the Order Form. Each party must keep them up to date. Specific data incidents are notified via the DPA channels.

The Customer does not assign the Agreement without prior written consent. The Provider may assign it in the context of an actual business transfer or reorganisation, provided it notifies and ensures continuity of the legal safeguards.

Invalidity of a provision does not affect the others. Failure to exercise a right does not constitute a waiver. An oral promise as to a function, discount, timing or SLA does not bind unless recorded in a document or electronic medium accepted by the parties, subject to fraudulent conduct and mandatory law.

Governing law and jurisdiction

Greek law applies, including directly applicable European Union law. The parties first attempt good-faith resolution of the dispute by mediation and, in case of failure, resort to the competent Courts.

The courts of Veria are agreed as exclusively competent, to the extent the prorogation agreement is valid and not excluded by a mandatory rule.

Contact and change of details

Support: hello@organosi.com.gr / +30 694 901 0227. Privacy matters: info@organosi.com.gr. Security incidents: support@organosi.com.gr. The Provider keeps available the then-current version of the Terms and notifies of materially adverse changes in accordance with clause 10.2.

Last updated: 4 September 2026.

Terms review

Prepare commercial-terms questions without private detail.

The helper below is a shareable preparation point. Keep signed annexes, security evidence, and live app details for protected follow-up. The public DPA is at /dpa.

Terms review helper

Prepare a shareable terms review brief.

Choose a reviewer, review stage, public terms areas, and safe questions before opening an email to the Calendo Health contact address.

76%

Review clarity

Clinic leadership

Review public website boundaries before a first product or demo conversation.

First pass

Collect the public terms and obvious questions before booking a demo.

Public terms areas

Safe questions

Generated brief

Terms review brief from the website

Terms review brief from the website:
Reviewer: Clinic leadership
Review stage: First pass
Follow-up owner: Not provided
Reply email: Not provided

Public terms areas:
- Website purpose: Public marketing website only; no medical, clinical, legal, or billing advice.
- Contact messages: Submitting a request does not create a customer agreement or product access.
- No patient information: Patient data, clinical notes, PHI, and sensitive details stay out of public forms.
- Private follow-up: Contract, DPA, pricing, security evidence, and implementation terms need protected channels.

Questions:
- Which public website terms need team review before a demo?
- Does the contact message boundary match our procurement or intake process?
- Which patient data, private access details, contract, pricing, DPA, or live app questions belong in protected follow-up?

Optional note:
Not provided

Safe review boundaries:
- Use this helper for public website terms review only; it is not legal advice.
- Do not include patient data, clinical notes, private access details, private screenshots, contracts, pricing commitments, or live app records.
- Use public page URLs, approximate dates, and plain-language questions instead of sensitive examples.
- Move DPA, contract, security evidence, commercial, implementation, or compliance questions into protected follow-up channels.
Open terms email

Safe review boundaries

  • Use this helper for public website terms review only; it is not legal advice.
  • Do not include patient data, clinical notes, private access details, private screenshots, contracts, pricing commitments, or live app records.
  • Use public page URLs, approximate dates, and plain-language questions instead of sensitive examples.
  • Move DPA, contract, security evidence, commercial, implementation, or compliance questions into protected follow-up channels.