Legal
Privacy Policy
What Cadentia AI collects, why, who else touches it, and how to get it back or get rid of it.
1. The short version
Cadentia holds the details of your one-on-ones: who meets whom, how often, what was agreed, and the answers each person wrote. We use it to run the service for you and for nothing else. We do not sell it, we do not advertise against it, and we do not use it to train AI models.
Inside your company, conversation content is visible to the two participants. Leadership sees whether conversations are happening and whether commitments are being closed — not what was said. That is a structural property of the product, not a preference you can quietly switch off.
2. Who is responsible for your data
Where your employer has a Cadentia workspace, your employer is the data controller and Cadentia AI is the processor: they decide what goes in, we handle it on their instructions. For our own website visitors and prospective customers, we are the controller. If you are an employee with a question about your own records, ask your workspace administrator first — they can access, correct and export them.
3. What we collect
| Category | Examples |
|---|---|
| Account and profile | Name, work email, job title, department, manager, access level, time zone, phone if you add one, hashed password. |
| Organization | Company name, primary email domain, size band, industry, department list, org structure and open positions. |
| Conversation records | Scheduled and completed 1:1s, cadence, agendas, questions and answers, notes, action items and their status, sentiment you record. |
| Templates | Question sets you create, including any images you upload to explain a question. |
| Billing | Billing contact, seat counts and subscription status. Card details are handled by Rippling; we never see or store them. |
| Technical | Sign-in timestamps, IP address at authentication, browser type, and error diagnostics. |
| Correspondence | Anything you send us by email or through the contact form on this website. |
We do not collect keystrokes, screen activity, location, biometrics, or message content from other tools. We do not use tracking cookies for advertising.
4. Why we collect it
To provide the service (host your workspace, schedule and remind, carry commitments forward, produce cadence reporting); to authenticate and secure accounts; to bill correctly; to provide support; and to comply with law. Our legal bases are performance of a contract, legitimate interests in operating and securing the service, and consent where we ask for it — for example before sending marketing email.
5. Who inside your company sees what
The two participants see everything about their own conversation: agenda, answers, notes, action items, sentiment and any AI summary of it.
Managers up the chain see cadence and completion signals for the teams below them: whether 1:1s are happening on schedule, how many are overdue, how many commitments are open or late, and department rollups.
Administrators can manage people, departments, templates, access levels and billing, and can export the workspace's data. Administrative access does not grant access to other people's private conversation content.
Shared access beyond a participant pair is explicit, recorded per relationship, and visible to the people involved. There is no hidden observer mode.
6. Sub-processors
We use a small number of vendors to run Cadentia. Each is bound by contract to protect your data and to process it only on our instructions.
| Vendor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication and file storage | All workspace data |
| Netlify | Application hosting and delivery | Technical and request data |
| Rippling | Subscription billing and payment processing | Billing contact and subscription data |
| Anthropic or OpenAI | AI drafting, only if your administrator connects a key | Only the text sent for a specific AI request |
| Squarespace | This marketing website and its contact form | Website enquiries only |
7. AI providers
AI features are off until an administrator connects your organization's own API key. When a request is made, only the text needed for that request — for example the agenda being summarized — is sent to the provider. Nothing is sent in the background, on a schedule, or for any purpose you did not trigger.
Because the key is yours, the provider's terms govern that processing and bill you directly. Anthropic and OpenAI both state that API content is not used to train their models by default; confirm the current position with them before enabling AI on sensitive content.
8. Retention and deletion
We keep workspace data for as long as the workspace is active. Deactivating a person retains their conversation history so the record of the relationship survives, while removing their access. Deleting a person or a workspace removes the associated records.
After cancellation, a workspace is read-only for 30 days and then eligible for deletion. Suspended-for-nonpayment workspaces are retained for 60 days. Backups roll off within 30 days. Billing records are kept as long as tax law requires.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent. Under GDPR you may also complain to your local supervisory authority; under CCPA/CPRA note that we do not sell personal information and do not share it for cross-context behavioural advertising.
Employees should raise requests with their workspace administrator, who can act immediately. If you cannot reach them, write to support@cadentiaai.com and we will route the request to the controller and respond within 30 days.
10. Security, international transfers and contact
Data is encrypted in transit and at rest. Access inside the product is enforced at the database level per person and per organization, not only in the interface. Internally, access to production data is limited to staff who need it and is logged. We will notify affected customers of a personal-data breach without undue delay.
Our infrastructure is hosted in the United States. Where data is transferred from the UK, EEA or Switzerland we rely on Standard Contractual Clauses with our sub-processors.
Contact us at support@cadentiaai.com for any privacy question, including a data processing agreement or a security review.
This policy describes how the product actually works today. It is not legal advice — have counsel review it against your obligations before you rely on it commercially.