The problem
Aesthetic clinics hold some of the most sensitive data any small business deals with. A practitioner offering anti-wrinkle injections or skin consultations needs to take a medical history, capture signed consent before every treatment, record what was done, take payment, and bring the patient back when their next appointment is due. A typical clinic does all of that across a diary app, a card reader, a folder of paper consent forms, a spreadsheet and a phone full of messages.
That set-up is slow on a busy day, but the bigger problem is the data. Patient records are special category data under UK GDPR, the most demanding tier the law has. Spreading them across five tools, none of which was designed for health information, leaves clinic owners exposed, and most of them know it. What they wanted was one system that did the lot, was built for the regulation rather than patched to cope with it, and could be set up without calling in an IT person.
The approach
We made four decisions at the start and held to them through every release.
GDPR by design, not by checklist
Compliance was treated as a product requirement from the first sketch. Data is collected for a clear purpose and nothing more, consent is captured inside the product rather than in a drawer, and the clinic's data stays the clinic's. If a clinic ever leaves, it can take its records with it.
Built and hosted in the UK
Patient data is stored and hosted in the UK, on Google Firebase in the London region, so a clinic owner has a simple, honest answer when a patient, an insurer or a regulator asks where the records live.
Tested before every release
Software that holds health records cannot ship on a hunch. Every change runs through automated tests before it reaches a clinic, so a fix in one corner does not quietly break something in another.
Plain UX for people who are not technical
Practitioners are trained in treatments, not in software. The platform had to be set up in a day with no technical skills, and usable between patients on a phone or a tablet. Every screen was designed around the question "what does this person need to do in the next thirty seconds?"
What was built
CallidusOS brings the whole clinic into one platform, so the diary, the records, the paperwork and the payments finally agree with each other.
- Appointments. A clinic diary that practitioners and front desk staff share, with the booking linked directly to the patient record.
- Patient records. Medical history, treatment notes and documents held in one place against each patient, rather than scattered across tools.
- Consent forms. Digital consent captured and stored against the patient record before treatment, so the paper folder can be retired.
- Payments. Taken through Stripe, so card details are handled by a specialist payment provider and never stored on the platform.
- Calia Copilot. An AI assistant that sends appointment reminders, automates rebooking when a patient is due back, and runs marketing campaigns to the clinic's own patient list.
Calia Copilot is the part people ask about most, and the rule for it was simple: AI only where it earns its place. Reminders, rebooking and campaigns are repetitive, time-consuming jobs that a busy clinic owner would otherwise do late at night or not at all. Those are the jobs the assistant takes on. Clinical judgement stays with the practitioner.
The result
CallidusOS is live, with paying clinics running their day on it. Plans start from a monthly subscription, with a free trial so a clinic can set itself up and see how it feels before committing. We will not quote customer counts or revenue on this page. What matters here is that the platform exists, it is in daily use, and it was built to the standard that patient data demands.
That is the standard we bring to every piece of software we build, whether or not it touches health records. A client portal, a booking platform or a B2B ordering system does not hold special category data, but it does hold your customers' details and your own commercial information, and it deserves the same care.
If your business is not a clinic
The point of showing CallidusOS is not the sector. It is that our team has designed, built, shipped and kept running a product at the most demanding compliance tier in UK law, and that the same habits carry over to everything else we build: GDPR from the first sketch, UK hosting, automated testing before every release, and interfaces that people who are not technical can use without a manual.
If you need a portal, a booking or management platform, an internal tool, a B2B ordering system, an integration or an MVP, see our bespoke software development page for what we build and how we engage.