GDPR-Compliant Appointment Scheduling for Healthcare & Medical Practices

Medical practices, clinics, therapists, and healthcare professionals handle highly confidential patient appointments. When appointment data reveals health information, Article 9 GDPR applies. The controller must identify an Article 9 condition, establish an Article 6 legal basis, minimise the data collected and apply appropriate security and processor terms; EU hosting is helpful but is not itself a compliance guarantee.

Executive Summary (TL;DR)

Kalendarius keeps its core application and database hosting in the EU and loads no advertising, analytics or error-monitoring trackers on public booking pages. Business and Enterprise customers can obtain a signed Article 28 DPA. Healthcare providers remain responsible for determining the lawful basis and Article 9 condition for their use, configuring forms to minimise sensitive data, and assessing any connected Google or Microsoft calendar service.

Compliance Comparison: Healthcare Scheduling Security & Data Sovereignty

Requirement / Capability Kalendarius (EU) Other scheduling vendors (verify current terms)
Server & Data Hosting Location ✓ Core application and database hosted in the EU Varies by vendor, product and customer configuration
GDPR Article 9 Health Data Protection ✓ Supports minimisation and tracker-free booking; controller must establish lawful conditions Review permitted data, contract, security controls and configuration
Third-Party Advertising Scripts & Trackers ✓ Zero trackers or marketing cookies on patient booking pages Varies; verify the live booking page and cookie documentation
Data Processing Agreement (DPA) ✓ Signed Article 28 DPA available on Business and Enterprise plans Availability and transfer mechanisms vary by vendor and plan
Calendar Synchronization ✓ Two-way real-time sync with Google Calendar & Microsoft 365 Two-way real-time sync with Google Calendar & Microsoft 365
US CLOUD Act Extraterritorial Jurisdiction ✓ EU operator and EU-hosted core service; assess connected providers Jurisdiction and lawful-access exposure vary by provider

Why Standard Scheduling Software Creates Regulatory Liabilities in Healthcare

Online scheduling tools collect patient names, email addresses, phone numbers, appointment timestamps, and consultation descriptions (such as 'Cardiology Consultation' or 'Therapy Intake Session').

Under the GDPR, personal data revealing an individual's physical or mental health status is special-category data. Article 9 generally prohibits its processing unless a listed exception applies. International transfers are governed separately by GDPR Chapter V and may proceed only under an applicable transfer mechanism and safeguards.

Article 9 GDPR: Protecting Sensitive Patient Appointment Data

A clinic should map what the booking form reveals, identify every recipient and processor, document its lawful bases, and apply data minimisation. If data leaves the EEA, the clinic must also assess the relevant Chapter V transfer mechanism and safeguards.

Kalendarius hosts its core application and database with Hetzner in the EU. This reduces transfers at the core-hosting layer, but clinics must still assess any Google or Microsoft calendar connection they enable and avoid placing unnecessary health details in external calendar events.

Zero Tracking Cookies & Maximum Patient Confidentiality

Third-party marketing or analytics scripts on a healthcare booking page can disclose IP addresses and visit context and therefore require a careful confidentiality, transparency and legal-basis assessment.

Kalendarius public booking links operate with zero third-party advertising scripts, zero tracking pixels, and zero profiling cookies. Patients book appointments in an entirely private, secure environment.

Seamless Two-Way Sync with Microsoft 365 and Google Calendar

Kalendarius synchronizes directly with your existing Microsoft 365 (Outlook/Exchange) or Google Workspace calendars in real time. Busy clinic hours or private consultations automatically block booking slots, preventing accidental double bookings.

Doctors, therapists, and clinic staff can manage multiple practitioner schedules simultaneously, with automated buffer times between patient visits.

Automated Patient Reminders That Reduce No-Shows

Missed appointments cost healthcare practices thousands of euros each year. Kalendarius automatically sends patient confirmations and timely email reminders with secure links to cancel or reschedule independently.

Patients can use 24/7 self-service booking, while practitioners can reduce manual phone and email coordination. Actual time savings and no-show outcomes depend on each practice's workflow.

Primary sources and verification

The legal summary is based on GDPR Article 9 and Chapter V, the European Commission's international-transfer guidance, and Hetzner's ISO/IEC 27001 certification information. Product-specific statements should be checked against the current Kalendarius DPA and configured integrations. Sources checked 20 September 2026.

Frequently Asked Questions

Is Kalendarius compliant with GDPR Article 9 for healthcare providers?

No scheduling product can make a healthcare provider automatically compliant with Article 9. Kalendarius provides EU-hosted core infrastructure and tracker-free public booking pages, while the provider must establish an Article 6 legal basis and Article 9 condition, minimise collected data, configure retention and assess connected services.

Does Kalendarius use tracking pixels or advertising cookies on patient booking links?

No. Kalendarius strictly adheres to privacy by design. Public patient booking links contain zero third-party advertising cookies, zero analytics trackers, and zero marketing pixels.

Can Kalendarius synchronize with our existing Microsoft Outlook or Google Calendar?

Yes. Kalendarius connects seamlessly via official OAuth 2.0 APIs to Microsoft 365 (Outlook) and Google Workspace calendars, checking availability in real time and automatically blocking booked slots without storing patient details on external ad networks.

Do we receive a legally binding Data Processing Agreement (DPA)?

A signed Article 28 GDPR Data Processing Agreement is available to Business and Enterprise customers. Healthcare providers should review its technical and organisational measures, sub-processors and retention terms against their own use case before processing patient data.

How does Kalendarius compare to Calendly or Acuity for medical practices?

Kalendarius hosts its core application and database in the EU and does not load third-party trackers on public booking pages. Other vendors differ by product, plan and configuration. Compare current DPAs, hosting locations, permitted-data terms, sub-processors and any enabled calendar integrations rather than relying on a blanket compliance label.

Use EU-hosted, tracker-free public booking pages

Start free with up to 15 appointments per month. No credit card required.

Start free medical scheduling

Medical & Legal Disclaimer: This page provides general product and compliance information, not legal or medical advice. Kalendarius does not certify a healthcare provider's Article 9 compliance. Each provider remains responsible for its lawful basis, Article 9 condition, configuration, notices, retention, security and professional obligations.