Trust
Security & data protection
How CalRemind protects practice and patient data — encryption, EU hosting, and clear GDPR roles. For full legal detail, see our Privacy Policy.
At a glance
- Patient names and phone numbers are encrypted at rest in our database.
- Apple app-specific passwords and doctor phone fields are stored encrypted.
- Production runs on Hetzner Cloud in Helsinki, Finland (EU).
- HTTPS for the public site; secrets kept out of source code.
- Reminders are sent from your work WhatsApp — not a shared spam number.
- We do not sell personal data.
Your role vs ours (GDPR)
For patient data used to send reminders (names, phones, appointment details), your practice is typically the data controller. CalRemind acts as a data processor on your instructions.
For your CalRemind account (login email, settings, logs), CalRemind is the controller. See the Privacy Policy for categories of data and legal bases.
What we encrypt
Sensitive fields are encrypted in the application database using Laravel’s encryption (AES-256-CBC with your application key), including:
- Patient name, phone, and WhatsApp identifier (where stored).
- Doctor alert phone and linked WhatsApp phone metadata.
- Apple Calendar app-specific password.
Passwords for CalRemind accounts are stored as one-way hashes, not plain text.
Where data lives
Primary production hosting is in the European Union (Hetzner Cloud, Helsinki, Finland). Some sub-processors — for example transactional email (Resend) — may process data in other regions under their terms and appropriate safeguards.
Sub-processors we rely on include Hetzner (hosting), Resend (email), and WhatsApp’s network when you connect your work number. Ask via Contact for the current list when signing a DPA.
WhatsApp and your patients
CalRemind does not require patients to install an app. Reminders leave from the work WhatsApp session you connect. Patients see messages from your number, as if you sent them yourself.
Your practice is responsible for having a lawful basis to message patients (for example consent where required) and for the content of reminder messages.
Data Processing Agreement (DPA)
If your practice needs a formal processor agreement under GDPR or similar law, request a DPA via the Contact form. We typically respond within a few business days with a standard agreement covering sub-processors, security measures, and breach notification.
Honest limits
CalRemind is built for solo and small private practices — not hospitals or large clinics requiring certified US HIPAA compliance. No online service can guarantee 100% security. Protect your Apple app-specific password and account credentials.
Questions
Privacy and security requests: use Contact on https://calremind.com/contact. For patient-data rights, contact your practice first (controller); we assist practices as processor.