Who answers for the records in Calcendar.
These are the data protection terms between your practice and us. They apply to every account, they are accepted in the app before the software is used, and they sit alongside the privacy policy and the terms of use. Version 2026-09-22.
This page is written in plain language and is not legal advice. Your own duties depend on where you practise and what profession you are in.
Two roles, and they are not the same
Your practice decides what is recorded about a patient, why, for how long, and who on your team may see it. Lebanese Law 81/2018 calls that the data processing officer; the GDPR calls it the controller. Either way it is you, and the duties that come with it are yours: they cannot be handed to a software supplier, and this page does not pretend to take them.
We hold the records for you and do with them only what you and the software ask: store them, show them back to your team, send what you tell us to send. That is a processor, and a processor may not decide what the data is for. We do not sell it, mine it, profile anybody with it, or use it to train any model.
One set of data is ours to decide about rather than yours: your own account. The address you sign in with, your name, your licence and what you paid for it, the devices you signed in from, and the fact that you accepted these terms. We are the controller of that, and the privacy policy says what we do with it.
What we process for you
- Whose data: your patients, the people who book with them, and the staff you invite.
- What kind: names and contact details, appointments, clinical history, consultation notes, treatment plans, reports and their attachments, scored assessments, and money owed and paid. Clinical records are health data, which is a special category in both bodies of law.
- Why: so your practice can run. No other purpose, and no purpose of ours.
- How long: until you delete it, or until you ask us to delete the practice. We do not age records out on our own.
- On whose instruction: yours. What you do in the app is the instruction; anything outside it we would ask you for in writing first.
What is yours to do
These are the duties the law puts on the practice, not on the software. They are listed because a practice that meets them is a practice this page can actually stand behind.
- Have a lawful reason to record what you record. Under Lebanese Law 81/2018, health data may be processed where the patient has explicitly agreed, where it is necessary for a healthcare professional to diagnose or treat, to prove or defend a right in court, or under a licence (Article 91). Under the GDPR the equivalent is Article 9(2)(h) for care, or explicit consent.
- Tell your patients what you keep. Lebanese Law 81/2018 Article 88 lists what they must be told: who is processing their data, what for, whether answering is optional and what happens if they do not, who the data goes to, and how to see and correct it. You are the one who has that conversation; we never meet your patients.
- Hold whatever permit or licence your country asks of you. In Lebanon, processing health data is licensed rather than merely declared: Article 97 puts it under a decision of the Minister of Public Health, and Articles 95 and 96 cover the filing with the Ministry of Economy and Trade. Getting that is yours; we cannot hold it for you.
- Keep medical confidentiality. In Lebanon that is professional secrecy under the Penal Code and the Code of Medical Ethics, and the patient rights and informed consent act (Law 574/2004). Sharing a login, or leaving the app open on a shared screen, is how that gets broken.
- Decide who on your team sees what, and keep it current. The permissions are yours to set, and a staff member who has left should be removed the day they leave.
- Keep the records accurate, and answer your patients when they ask to see or correct them. Under Lebanese law a correction is due within ten days and free of charge (Article 101), and an unanswered request is itself an offence (Article 107). We help you answer; we cannot answer for you.
- Look after your own sign-in. Use a password you use nowhere else, do not share it, and tell us at once if you think somebody else has it.
What is ours to do
- Process the records only for you, on your instruction, and for nothing else.
- Keep them confidential. Access is limited to the people who run this service and only where a job needs it: support, a fault, a migration. Nobody browses.
- Apply the measures in the next section, and keep applying them as the service changes.
- Use only the other companies listed below, hold them to the same duties, and tell you before that list grows.
- Help you answer a patient who asks to see, correct or delete their records, inside the time your law gives you. The export is in the app; anything it cannot do, ask us.
- Tell you about a breach, on the terms set out below.
- Give the records back or delete them when you stop, and delete a practice when you ask.
- Keep a record of what we process for you, so we can show it if either of us is asked.
The security measures, as they actually are
Lebanese Law 81/2018 Article 93 and GDPR Article 32 both ask for measures appropriate to the data and the risk. These are the ones this software has. They are written plainly because a list of things we do not do would be the more useful half, and it is here too.
- Everything between the app and the server travels over HTTPS. There is no plain-text door.
- Every read and write is scoped to one practice. A practice cannot address another practice's records, and the check is at the query, not in the screen.
- Inside a practice, what a person can reach follows the role you gave them.
- Passwords are stored as bcrypt hashes, never as passwords. Sign-in and sign-up are rate limited, and repeated failures are throttled per connection.
- Secrets we hold on your behalf, such as a connected Google Calendar token, are encrypted in the database. Administrator sign-in to the dashboard needs a second factor.
- Attachments live in a private bucket or inside the record itself. Nothing is reachable by guessing a URL.
- Each signed-in device is its own session and can be signed out on its own.
- The database is backed up, and backups are held no longer than the records they came from.
- Dependencies are checked for known vulnerabilities on every release, and a release that fails that check does not ship.
What we do not claim. We are not certified to ISO 27001 or any equivalent, we are not audited by a third party, and we do not offer end-to-end encryption: the server can read the records, because it has to in order to search them, bill from them and email about them. We are not a HIPAA business associate and we do not sign a business associate agreement, so if HIPAA applies to your practice, this is not the software for it. No system is unbreakable, and a page that told you otherwise would be a page to distrust.
Who else touches it
The companies below are the only ones involved, each doing one job. Several of them are switched off unless you turn them on, and those say so.
- The server this deployment runs on, rented from an infrastructure provider: it runs the application.
- A managed MongoDB database: it holds the records.
- Oracle Cloud Infrastructure object storage: it holds attachments, in a private bucket.
- Cloudflare: it carries the traffic to the site and runs the check that tells a person from a script on the public forms.
- An email delivery provider: it sends the reminders, receipts and codes you ask the software to send.
- Google, for notifications on a phone: a device token, and a line saying a session is coming. Nothing clinical.
- Google Calendar, only if you connect it: the time, the length, the location and who the session is with, in a calendar the app creates for the purpose. No notes, no history, no fee.
- A payment provider, only where a licence is bought here: the amount, the plan, and the address it is for. We never see a card number.
If that list is going to change, we will say so on this page and by email to the account address before the new one starts. If you object to an addition, tell us and we will either keep you off it or let you leave with the unused part of your licence refunded.
Where it is, and crossing a border
The records are held on the infrastructure listed above, which is outside Lebanon, and support is provided from Lebanon. Lebanese Law 81/2018 says nothing about transfers abroad, so nothing there forbids this; it is named because you may not assume it. If the GDPR applies to your practice, tell us and we will put the European Commission's standard contractual clauses in place for the transfer.
If something is breached
If we confirm that patient data has been reached, altered or taken by somebody who should not have, we will tell you without undue delay, and within 48 hours of confirming it, at the account address. The notice says what we know: what happened, when, what data is involved, what we have done, and what we advise you to do. We will keep you updated as we learn more, and we will help you notify anybody your own law requires you to notify (the GDPR gives a controller 72 hours; Lebanese law has no notification duty of its own, which is exactly why this one is contractual).
The other direction matters too: if you think a sign-in of yours has been taken, tell us immediately. Most of what reaches records that should not be reached, anywhere, arrives through a real password.
Who answers for what goes wrong
This is the part everybody skips, so it is written in short sentences.
- We answer for our own failures as the processor: breaking these terms, ignoring your instructions, or failing to keep the measures above.
- You answer for yours as the practice: what you chose to record, whether you had the right to record it, whether you told your patients, what your staff did with the access you gave them, and the licences your profession asks of you. If we are pursued because of one of those, you cover our costs.
- Neither of us answers for the other's. A criminal attack on our systems is not your fault; a password written on a whiteboard is not ours.
- Except where the law does not allow it, our total liability to you for anything arising out of the service is limited to the fees you paid us in the twelve months before the claim, and we are not liable for lost profit, lost business or indirect loss. This limit does not apply to our own fraud, our wilful misconduct, or anything the law says may not be limited.
- Nothing here takes anything away from a patient. Lebanese Law 81/2018 Article 85 says no agreement may contravene the rights of the people the data is about or the obligations of whoever processes it, and GDPR Article 82 keeps a processor liable directly. A limit between you and us is a limit between you and us, and nobody has been contracted out of their rights.
On a cyber attack specifically, since it is the case people ask about: an attack is a crime committed by somebody else, and we are not insurers against crime. What we owe you is the measures above, honestly applied, and the notice in the section above when one succeeds. What we do not owe is a guarantee that no attack will ever succeed, and no supplier who gives you one in writing is telling the truth.
Ending, and getting it all back
Patients, sessions, transactions and documents export from inside the app whenever you like, and you do not need our permission or our help. When you stop using the service, ask and we will delete the practice and everything in it; if you do not ask, it stays where it is so that a lapsed licence never costs anybody their records. Backups age out on their own schedule after a deletion.
Which law, and which court
These terms are governed by Lebanese law, and the courts of Beirut have jurisdiction, without prejudice to any right you have to bring a claim where you live. Where the GDPR applies to your practice, this page is also the written contract its Article 28 requires, and the duties in it are read as that Article requires them to be read.
Changes
When these terms change in a way that affects what is stored, who can reach it or who answers for it, the version at the top changes, we say so on this page and by email, and the app asks you to read and accept the new version before you carry on. Small corrections that change no duty do not trigger that: wearing the ask out is how it stops being read.
Asking us something
Write to us from the contact page or at [email protected]. If you are a patient, ask the practice that treats you: the records are theirs, they are the ones the law asks, and they can answer faster than we can.