5 guides
Security & Payments
How your data is protected and how payments and deposits are handled safely.
"Is it safe to process payments through CallidusOS?"
Absolutely. Payments are handled by an industry-leading payment processor used by millions of businesses worldwide. Your patients' card details never pass through CallidusOS, they go directly to the payment processor, which holds the highest security certifications.
What CallidusOS sees:
- ✅ Confirmation that a payment succeeded
- ✅ Last 4 digits of the card (for identification)
What CallidusOS never sees:
- ❌ Full card number
- ❌ CVV code
- ❌ Expiry date
Money goes directly to your connected payment account, CallidusOS is just the interface.
"What happens to my patient data?"
Your clinic's data is stored in encrypted cloud storage with strict access controls:
- Each clinic's data is completely separate, no other clinic can see your information
- Access is controlled by your team's roles (owner, admin, practitioner, receptionist)
- All connections are encrypted in transit
- Data is stored in compliance with UK data protection requirements
"Who can see what?"
| Data type | Who can access |
|---|---|
| Patient records (basic info) | All staff roles |
| Clinical notes & photos | Practitioners, managers, admins, owners |
| Financial data (invoices, revenue) | Managers, admins, and owners (practitioners can view patient invoices) |
| Settings & configuration | Admins and owners |
| Audit log | Owners and admins only |
| Patient data export/deletion | Owners and admins only |
Two-Factor Authentication (2FA)
CallidusOS supports two-factor authentication using authenticator apps (TOTP). Your clinic owner or admin can make 2FA mandatory for all staff.
How to set it up: Go to Settings → Profile and follow the 2FA setup steps. You'll scan a QR code with an authenticator app like Google Authenticator or Authy.
If you're locked out: Ask your clinic admin or owner to reset your 2FA. If the owner is locked out, they should contact the CallidusOS support team.
Recovery chain: Staff → admin/owner resets it. Admin → owner resets it. Owner → contact CallidusOS support.
GDPR & Data Protection Rights
CallidusOS has built-in tools to help you comply with data protection regulations:
| Right | How it works in CallidusOS |
|---|---|
| Right of Access | Patient data is viewable in their profile. Admins/owners can export a patient's full data record. |
| Right to Rectification | Edit any patient's details at any time through their profile. |
| Right to Erasure | Owners and admins can anonymise or delete patient records, this is irreversible. |
| Data Portability | The Export Patient Data function provides data in a portable format. |
| Marketing Consent | Communications settings let you control automated emails. |
Still need a hand?
Ask Calia inside the app, or talk to our UK team by live chat, email or phone.