Calendo by Organosi
Calendo app privacy policy
This page covers the Calendo app and SaaS service (web and mobile), not only the public marketing website. Final legal wording requires owner/legal review before App Store or Google Play submission.
Notice: draft text for store listing preparation. Not legal advice. Does not claim HIPAA compliance. Trader/legal-entity details and final contacts must be completed manually by the owner.
1. Who operates the service
Calendo is operated by Organosi / Calendo (temporary trade-name reference until the legal entity and trader details are finalized).
Support / privacy contact (placeholder): hello@organosi.com.gr. Postal address and formal legal contact: to be completed by the owner.
Public website: https://organosi.com.gr. This policy is intended for https://organosi.com.gr/privacy/calendo.
2. What Calendo is
Calendo is a clinic / therapy-center operations SaaS: appointment scheduling, calendar, staff roles, child profiles in a clinic context, notifications, and related day-to-day operations tools.
It is not for emergency medical communication, emergency diagnosis, or a substitute for emergency care. In an emergency, contact appropriate emergency services.
3. Data that may be collected or processed
Depending on the clinic customer’s use and service configuration, the following categories may be processed:
- Account / login data: email, hashed password, role, permissions, account status, must-reset-password flags.
- Staff / therapist profile data: profile names, roles, clinic-entered contact details, availability where applicable.
- Child / minor clinic records: names and related operational fields entered by authorized clinic users (not for public/social use).
- Appointments / calendar / attendance: times, status, type, procedure, therapist name, child linkage, cancel/attendance actions where permitted.
- Notifications: in-app inbox messages; device push tokens for delivery when permission is granted.
- Technical logs / security events: IP addresses where needed for security, access-control events, rate limits, session events.
- Support communications: what you voluntarily send for support or privacy requests.
4. Sensitive / health-adjacent data
Because Calendo is used by therapy centers, information relating to children/minors and therapy or appointment operations may be processed (including data that some authorities may treat as sensitive or health-adjacent), depending on what the clinic enters.
The clinic customer is responsible for what it enters and for legal bases toward its own users and families. This text does not replace a DPA or legal advice.
5. Purposes
Data is processed for:
- Authentication and account management
- Clinic operations and appointment scheduling
- Security, access control, and abuse prevention
- Notifications (when enabled)
- Customer support
- Legal and contractual compliance
6. GDPR roles (draft — legal review required)
For data the clinic customer enters and manages in the service (e.g., children, appointments, clinic staff context), Organosi / Calendo may act as a processor on behalf of the clinic.
For platform account data, billing/subscription (where applicable), support, platform security, and public website data, Organosi / Calendo may act as a controller.
Final role allocation, legal bases, and contractual terms require owner/legal review and are not finalized by this page.
7. Children and minors
Children’s data is entered and managed by authorized clinic-customer users for center operations. Calendo is not a social network and is not directed at children for self-signup.
We do not ask children to create a consumer account through the public marketing website.
8. Sharing and processors
We may use service providers to operate the platform, only as needed for the service. Examples:
- Hosting / infrastructure provider
- Email / SMS / push providers if configured by the deployment or customer
- Apple and Google for app distribution and related store services
- Analytics or crash-reporting tools only if actually added to the app (advertising/tracking is not intended in the current product stance)
9. International transfers
Some infrastructure or app-distribution providers may operate outside Greece or the EEA. Where required, appropriate safeguards (e.g., standard contractual clauses or equivalent) are used under applicable law. Provider details are finalized with legal review.
10. Retention
Data is retained while a customer account/service relationship exists and as required by law, contracts, security, or dispute resolution. After end of service, deletion or anonymization processes apply per contractual and legal obligations (details: owner/legal review).
11. Rights
Depending on applicable law (including GDPR where it applies), you may request access, correction, deletion, restriction, objection, portability, and lodge a complaint with a supervisory authority.
Requests about clinic-held records often must go through the clinic customer (controller toward its own data subjects). For platform/account requests contact hello@organosi.com.gr (placeholder).
12. Security
We apply measures such as role-based access control, HTTPS in transit, secure token storage on mobile where supported, audit logging, and least privilege. No system is perfectly secure; report incidents to the support contact.
13. Push notifications
Device tokens are used for notification delivery when the user has granted permission. Lock-screen content should be generic; appointment details or child names must not appear on the lock screen by default product policy.
14. Cookies and the public website
The public marketing website has a separate privacy and cookies policy at /privacy and /cookies. This page covers the Calendo app / SaaS.
15. Contact
Support / privacy (placeholder): hello@organosi.com.gr
Legal contact and trader details: to be completed by the owner before final store submission.
Last updated: July 21, 2026. Status: draft pending legal review.