Security & compliance
Built for records that carry consequences.
Calendia holds health journals, signed consent, identity data, and fiscal receipts. That is not ordinary CRM data, and it is not treated as such. This page describes the controls that exist in the product, not aspirations.
Access is scoped, not assumed
Roles plus per-user overrides decide what each person can reach. In health-journal mode, staff who are not on a customer’s care team do not see that customer at all.
Sensitive reads are logged
Opening a customer’s journal is recorded. So is switching who is at the till, rebinding a cash drawer, and resetting another user’s access.
Tenancy is enforced in the data layer
Every record belongs to a business and every query is scoped to it. It is not a filter the interface applies politely.
Nothing sensitive travels in a URL
Booking management, receipts, pay pages, and video rooms use signed, time-limited links rather than guessable identifiers.
Health journals and consent
For clinics, the record is the product. These are the controls around it.
Care-team scoping
A business in health-journal mode restricts non-owner, non-admin staff to the customers on their own care team. Reception can still run the till and the calendar without reading clinical history.
Record-open auditing
Each time a journal is opened it is written to an audit trail with the user, the customer, and the time — so an access question has an answer.
Step-up authentication
Sensitive areas can require the user to confirm their password again, and two-factor authentication is available for every account.
Consent stored with the person
Disclaimers, contraindication answers, marketing permissions, and doctor approvals live on the customer record, not in an inbox, and carry the version of the form that was signed.
Identity verification
Where a country’s national eID is supported, a customer can be verified with BankID or the local equivalent before booking, before signing, or at login.
Cash register and fiscal records
Where a country regulates cash register systems, Calendia is built to that regulation rather than around it.
A product-declared cash register
In Norway, Calendia is a declared cash register system (kassasystem). Carnivore AS files the produkterklæring for the software, and the declared version is pinned in the code with a fingerprint over every file that forms part of it.
An append-only electronic journal
Every fiscal event is written once. There is no edit path and no delete path. A correction is a new, signed entry that references the original, exactly as the rules require.
Receipts that cannot be quietly reprinted
A reprint is marked as a copy, a return is its own document, and a training-mode sale can never be mistaken for a real one.
Country-scoped rules
Fiscal behaviour keys off the business’s legal country. Norwegian rules apply to Norwegian businesses; they are not imposed on everyone else.
Daily settlement that ties out
Z reports, drawer counts, custody handover between staff, and register sanity checks, so the day closes with a number you can defend.
Data, hosting, and the providers we use
Where your data lives, who else touches it, and what happens when you leave.
Encrypted in transit and at rest
Traffic is served over TLS, and files and databases are encrypted at rest by the hosting and storage providers we use.
A published subprocessor list
Every third party that processes data on our behalf is named, with what it is used for. The list is public and kept current.
Your integrations are yours
Payment providers, accounting systems, and calendars that you connect with your own credentials are not our subprocessors. They are your providers, under your agreements.
Export and deletion
You can export your data, and you can ask us to delete it — subject to the records that bookkeeping, tax, and fiscal law require us to retain for a fixed period.
GDPR roles set out plainly
For your customer data you are the controller and we are the processor. For your own account, billing, and security data we are the controller. The privacy policy says which is which for each activity.
The documents
The binding versions, not a summary of them.
Reporting a security issue
If you believe you have found a vulnerability, tell us before you tell anyone else. We will confirm receipt, keep you updated, and will not pursue anyone who reports in good faith.
Email the security contact