These Supplemental Terms form part of the Customer Agreement for the uses described below. They allocate permitted use and additional conditions; they do not certify compliance with an industry standard or supply a missing regulated-data agreement. The Provider is Software Programming Group LLC.
1. General restrictions on sensitive deployments
The Customer must assess whether its event names, participant identity, booking responses, integrations, and notifications reveal information regulated by its industry. Appointment metadata can be sensitive even when no document is uploaded. The Customer must use data-minimizing labels, restrict access, and avoid collecting information that the Services are not approved to handle. Provider obligations imposed directly by law remain unaffected by the Customer’s duties.
The standard Services are not an emergency dispatch system, clinical record system, regulated archive, or legal deadline-management guarantee. Customers must maintain appropriate alternative procedures for urgent care, safety, mandatory filings, and records required by law.
2. Healthcare and health information
The Customer must not submit protected health information subject to HIPAA unless the Provider has expressly approved the relevant workflow in writing, the parties have executed a business associate agreement when required, and the necessary security and downstream arrangements are in place. The ordinary DPA is not a business associate agreement. Merely calling an entry a scheduling record does not remove it from health-information rules.
Without that arrangement, the Customer must avoid patient-specific health information in titles, forms, notifications, support tickets, and connected services. A Customer providing healthcare remains responsible for professional duties, consent, emergency escalation, and its own regulatory obligations. These Terms do not state that CalendNow is HIPAA certified or approved for all healthcare use.
3. Education and minors
The standard service is designed for adult use. A school or educational institution must obtain the Provider’s prior written approval and an appropriate agreement before permitting child access or sending protected education records. The arrangement must define authorized educational purposes, control of records, security, retention, access, deletion, and any applicable parental or school authorization.
A school cannot authorize unrelated commercial use of children’s information merely by opening an account. A generic booking form does not itself satisfy COPPA, FERPA, or local student-data requirements. Adults arranging a meeting with a teacher should use their own details and avoid unnecessary student information until an approved process is in place.
4. Legal and financial professional services
The Customer must assess professional confidentiality, privilege, recordkeeping, client identification, and financial-information requirements before using the Services. CalendNow supplies scheduling functionality and does not provide legal, investment, accounting, or other professional advice. A booking does not establish a professional engagement, and availability does not guarantee compliance with a filing or regulatory deadline.
Do not enter payment card credentials, bank access credentials, full government identifiers, or confidential case narratives into ordinary booking fields. The Customer must use independently approved systems for regulated records and must inform clients of appropriate communication channels.
5. Government and public bodies
A governmental Customer must confirm authority, procurement requirements, public-records obligations, accessibility requirements, data-location restrictions, and legally permissible contract terms before purchase. No sovereign immunity waiver, appropriation obligation, endorsement, security authorization, or federal cloud certification is implied. Any required departure from standard indemnity, governing-law, renewal, or payment terms must be recorded in a signed addendum.
6. Restricted data and future features
Unless expressly permitted under an appropriate written arrangement, do not submit classified information, export-controlled technical data, biometric identifiers used for identification, or data requiring a protection regime not supported by the contracted Services. A new recording, AI, messaging, or payment-collection feature requires its own assessment and any supplemental terms before use. These provisions do not establish that such features currently exist.
7. Noncompliant use
The Provider may require corrective action or suspend the affected use under the Customer Terms if it reasonably identifies a prohibited deployment. Where lawful, it will explain the concern and cooperate on controlled retrieval or deletion. The Customer must notify legal@spgamerica.com before enabling a regulated use, rather than relying on a product’s name, general marketing, or a third-party integration’s certification.