01Roles and scope
This agreement (“DPA”) applies where you use Cadenva as a business customer and, in doing so, cause personal data to be processed. In respect of the meeting content and the commitments derived from it, you are the controller and Cadenva is your processor: you decide what goes into Cadenva, whose voices are in it, and what is done with the result. Cadenva processes that data only to provide the service to you.
Cadenva is an independent controller for a narrow, separate set of data: the account and billing records it needs in order to operate as a business — who holds an account, which plan a workspace is on, and the records of payment handled through Stripe. That processing is described in the Privacy Policy and is not governed by this DPA.
Terms used here that are defined in the GDPR carry their GDPR meaning. Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA governs.
02Subject matter and duration
Subject matter. Cadenva transcribes and analyses the meeting material you submit, extracts the commitments, owners and deadlines it contains together with the passage each one came from, presents them for a person to review and approve, and — only for what is approved — creates, updates or deletes events in the calendar account you have connected.
Nature and purpose. Collection, recording, storage, transcription, automated analysis, structuring, display, transmission to the providers listed in the Privacy Policy so they can perform those functions, erasure, and the calendar writes you approve. The purpose is to provide the service and nothing else. Your data is not used for advertising, is not sold or licensed, and is not used to train any artificial intelligence model — not Cadenva’s, and not a provider’s.
Duration. This DPA takes effect when you begin using Cadenva and continues for as long as Cadenva processes personal data on your behalf. §13 governs what happens at the end.
03Data and data subjects
Categories of personal data
Determined by you, because you choose what to submit. In ordinary use they are:
Meeting content
Recordings you upload, audio captured in a browser by one of your users, transcripts you paste, transcripts imported from Google Meet where you have enabled that, and everything derived from them — the transcript text, its timestamps, the speaker names the source supplied, and the commitments, owners, deadlines and source passages Cadenva extracts.
Account data
Email address and password hash for each of your users, workspace membership, and the email address and display name of the calendar account connected to the workspace.
Calendar data
Upcoming events read from the connected calendar to display what is next, which are not stored; and the identifiers and links of events Cadenva created on your instruction, which are.
Operational data
Error diagnostics, request identifiers and audit records of approvals and executions. These carry error types and identifiers rather than meeting content.
Correspondence
Anything you send us in support of a request, including the request itself.
Categories of data subjects
Your personnel who use Cadenva; anyone who speaks in, is named in, or is assigned a commitment in a meeting you submit — which in ordinary use includes your customers, suppliers and other third parties; and the holder of the calendar account you connect.
Special categories
Cadenva is not designed for special categories of personal data under Article 9, for criminal-offence data under Article 10, or for the meetings of a business whose subject matter is inherently sensitive — a clinical consultation, for example. A meeting transcript records whatever was said, so you should assess this before submitting a recording and should not use Cadenva for material of that kind without agreeing it with us first.
04Your instructions
Cadenva processes personal data only on your documented instructions, including as to transfers, unless required to do otherwise by EU or member-state law — in which case it will inform you before processing, unless that law forbids it on important grounds of public interest.
Your documented instructions are: this DPA, the Terms of Service, the Privacy Policy, the settings you choose in the product, and the actions your users take in it. Approving a commitment is an instruction to write that event to your connected calendar; enabling Google Meet transcript import is an instruction to read transcripts Google Meet has already produced for meetings you have set to be captured; a deletion request under §13 is an instruction to erase.
Cadenva will tell you if, in its opinion, an instruction infringes the GDPR or other data-protection law. Additional instructions outside the product’s normal operation are agreed in writing and may be chargeable.
05Confidentiality
Cadenva keeps your personal data confidential and ensures that every person authorised to process it is bound by an obligation of confidentiality. Access is limited to those who need it to operate or support the service, and is not granted for convenience.
06Security measures
Cadenva implements appropriate technical and organisational measures under Article 32. The measures in place are described in the Trust & Security page and are, in summary:
Encryption of all traffic in transit over HTTPS; application-level encryption of stored calendar credentials, with the service refusing to start in production unless its encryption key is configured; encryption at rest of off-site backups by the storage provider, with a write-only credential held by the running service so that a compromise of the service cannot read or delete the backup history; separation of customer data by workspace, enforced on every request against the workspace the caller’s session was issued for, so that one customer’s data is not reachable from another’s session; salted PBKDF2-SHA256 password hashing; server-revocable sessions; deletion of raw audio once a meeting has been processed; and logging and error reporting designed to carry error types and identifiers rather than meeting content, credentials or account emails.
These measures are reviewed as the service changes and may be updated, provided the level of security is not reduced. Cadenva does not hold an ISO 27001 certification or a SOC 2 report and has not commissioned a third-party penetration test; no statement in this DPA should be read as claiming otherwise.
07Information and audits
Cadenva makes available the information necessary to demonstrate compliance with Article 28 and will respond to a reasonable security or data-protection questionnaire from you or your auditor. Because no third-party audit report exists to send you instead, this is a direct answer from us rather than a certificate, and we would rather say that plainly.
You may audit Cadenva’s compliance with this DPA once in any twelve-month period, and additionally where a supervisory authority requires it or following a personal data breach affecting your data. Audits are conducted remotely and documentarily unless an on-site element is genuinely necessary, on at least thirty days’ written notice, during business hours, without unreasonable disruption, subject to confidentiality, at your cost, and not by a competitor of Cadenva.
08Subprocessors
You give Cadenva general authorisation to engage subprocessors. The current list — each one named, with what it receives — is published in the Privacy Policy, which is the single authoritative list and is kept there deliberately so that two pages cannot disagree.
Cadenva imposes on each subprocessor data-protection obligations no less protective than those in this DPA, and remains fully liable to you for a subprocessor’s performance.
Before adding or replacing a subprocessor, Cadenva will give you at least thirty days’ notice, by email to your account address and by updating the Privacy Policy. You may object on reasonable data-protection grounds within those thirty days. If we cannot resolve your objection, you may terminate your subscription and receive a refund of any prepaid fees covering the period after termination.
09International transfers
The providers Cadenva uses are established outside the EEA, principally in the United States, so providing the service involves transferring personal data outside the EEA. You instruct Cadenva to make those transfers for the purpose of providing the service.
Cadenva will only transfer personal data outside the EEA where a transfer mechanism under Chapter V of the GDPR applies — an adequacy decision covering the recipient, Standard Contractual Clauses, or another lawful mechanism — and will not engage a subprocessor for which no such mechanism is available. On request, Cadenva will tell you which mechanism applies to a given subprocessor.
10Data-subject requests
If a data subject contacts Cadenva directly about data processed on your behalf, Cadenva will not respond to the substance of the request and will refer them to you, telling you without undue delay.
Cadenva assists you, by appropriate technical and organisational measures and so far as is possible, in meeting your obligation to respond to requests to exercise rights under Chapter III — access, rectification, erasure, restriction, portability and objection. There is no self-service export or deletion tool in the product today: assistance is provided by us on request to hello@cadenva.com, and that is what §6 of this DPA’s security description means when it says the measures are those that exist.
11Personal data breaches
Cadenva notifies you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and in any event in time for you to meet your own obligation under Article 33.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point. Where the full picture is not yet available, Cadenva notifies what it knows and follows up rather than waiting for certainty. Cadenva assists you with your obligations under Articles 33 and 34.
12DPIAs and authorities
Taking into account the nature of processing and the information available to it, Cadenva assists you with data protection impact assessments under Article 35 and with prior consultation of a supervisory authority under Article 36, and cooperates with a supervisory authority in the exercise of its functions.
13Return and deletion
At any time, and on termination, you may instruct Cadenva to erase the personal data it processes on your behalf. Email hello@cadenva.com and name the workspace. Cadenva confirms and completes erasure from the live service within 48 hours.
Erasure removes the workspace and everything reachable from it: transcripts, commitments, approvals, stored calendar credentials and any remaining files. It is irreversible. It does not delete the user accounts themselves, because a person may belong to other workspaces — those are deleted on request as a separate step — and it does not touch events already created in your calendar, which belong to you.
Off-site backups taken before your request still contain earlier copies. Backups are whole snapshots and individual records cannot be cut out of them, so they are instead expired automatically about thirty days after each one is taken, after which no copy remains. Until then those copies remain subject to this DPA and are not accessed for any other purpose. Cadenva states this plainly rather than promising an immediate deletion it cannot perform.
Cadenva does not return data in a structured export today. If you need a copy before erasure, ask and we will provide what we hold.
14Your users
A Cadenva workspace can be shared by several of your people, and everyone in a workspace sees the same meetings, commitments and source evidence, and can approve and schedule any of them. There are no permission levels within a workspace. You decide who belongs in yours, and you are responsible for your users’ access to the personal data in it.
Membership is added and removed through us — write to hello@cadenva.com — and removal takes effect immediately, ending every session that account holds. You should tell us promptly when someone leaves.
You are also responsible for having a lawful basis for the meeting material you submit, and for any notice or consent your own jurisdiction requires before a conversation is recorded or transcribed. Cadenva does not obtain that on your behalf.
15Term and changes
This DPA takes effect with your use of Cadenva and ends when Cadenva no longer processes personal data on your behalf. §§5, 6, 9 and 13 survive termination for as long as any data remains, including in the backups described in §13.
Cadenva may update this DPA to reflect a change in law, in the service, or in the measures described in §6, provided the update does not reduce your protection. Material changes are notified by email to your account address at least thirty days before they take effect. The version and effective date are at the top of this page.
16Contact
Write to hello@cadenva.com for anything arising under this DPA — a questionnaire, a data-subject request, a deletion instruction, or a signed counterpart if your procurement requires one. We respond within one business day.