This Statement explains the scope of security information and responsible-use expectations for CalendNow, a product of Software Programming Group LLC. Binding safeguards for Customer Personal Data are set out in the completed DPA security schedule and any signed security commitments. This Statement is not a certification report or an absolute security guarantee.
1. Account and organizational controls
CalendNow’s product scope includes two-factor authentication and organizational roles and permissions. Availability and configuration depend on the released service and Plan. Customers should enable appropriate authentication controls, assign only necessary permissions, review team membership, and remove access promptly when a person leaves or changes responsibilities.
Organization administrators control their authorized workspace functions; platform administration and support access must be limited to legitimate operational needs. Recovery requests may require verification to reduce unauthorized account takeover.
2. Integrations and credentials
Meeting integrations and custom SMTP may require tokens or other credentials. Customers should connect only authorized accounts, inspect requested scopes, protect sender credentials, and revoke unused connections. Do not submit passwords or full payment-card information through support tickets or booking fields.
A meeting platform’s independent certifications or safeguards do not automatically certify CalendNow. A connection may send data outside the CalendNow environment, subject to the selected provider’s terms and the Customer’s configuration.
3. Security information and incidents
The Provider will make appropriate security information available through security@calendnow.ai. Any statement about encryption, independent testing, SOC 2, ISO certification, penetration testing, availability, disaster recovery, or data residency must identify its verified scope and current status. No such certification or numeric recovery objective is asserted by this Statement without supporting evidence.
Report a suspected compromise to security@calendnow.ai with a concise description and relevant identifiers. Do not include exploitable secrets in an unprotected message. The Provider’s handling of Customer Personal Data incidents is governed by the DPA, including notification without undue delay after awareness of a qualifying incident.
4. Responsible data use and automation
Scheduling rules, time-zone conversion, round-robin assignment, and notification workflows should be configured and reviewed by the Customer. Automated assignment is not a guarantee of fairness, attendance, or suitability of a particular professional. Customers should check important events and maintain appropriate fallback procedures.
The product name and .ai domain do not establish a recording, transcription, or generative-AI capability. The Customer Agreement does not grant permission to train general-purpose AI models on Customer Data. If an AI or recording feature is introduced, its data flows, providers, notices, permissions, retention, and contractual terms must be addressed before use.
5. Sensitive information and improvement
Use minimal event titles and booking questions. Ordinary scheduling should not collect confidential case narratives, diagnoses, banking credentials, or other information beyond its purpose. The Industry Specific Supplemental Terms explain when additional arrangements are required.
The Provider will review security information when material changes occur and align public descriptions with actual implemented controls. Questions about contractual safeguards should be directed to legal@spgamerica.com. Business address: 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States.