Privacy Policy (GDPR)
Last updated: August 6, 2026
1. Data controller
Cadence's publisher is the controller for data related to account creation and the operation of the Service. For the data you enter about your contacts and appointments, you act as data controller and Cadence acts as processor within the meaning of Article 28 of the GDPR.
2. Data collected
- Account : email, display name, encrypted password or authentication provider ID (Google), creation date.
- Business profile : business name, invite message, Google Business/Maps links, rating, and number of reviews shown.
- Contacts : name, email, phone, notes, birthday, city, address, country, languages, hobbies, family situation, number of children, gender.
- Appointments : title, date, time, duration, location, notes, status, invite token, and timestamp of the guest's response.
- Billing : customer and subscription IDs from the payment provider, subscription status. No card data is stored by Cadence.
- Technical : connection and security logs, theme preference, cookie consent choices.
3. Purposes and legal bases
- Providing the Service (calendar, contacts, confirmation links) — performance of the contract.
- Sending invitation and confirmation emails — performance of the contract and the legitimate interest of the appointment organizer.
- Managing the Pro subscription and billing — performance of the contract and legal accounting obligation.
- Security, abuse prevention, and logging — legitimate interest.
- Audience measurement and marketing communications — consent, revocable at any time.
4. Recipients and processors
Data is accessible to the publisher and its technical processors, only to the extent necessary for their services: application hosting and managed database, transactional email service, payment provider for subscriptions. No data is sold or transferred to third parties for advertising purposes.
5. Transfers outside the EU
Data is hosted within the European Union. Where a processor handles data outside the EU, the transfer is governed by the European Commission's standard contractual clauses or an adequacy decision.
6. Retention periods
- Account and associated content: for the entire lifetime of the account.
- After account deletion: erased within 30 days, excluding encrypted backups purged within 90 days.
- Invoices and accounting records: 10 years (legal obligation).
- Technical and security logs: 12 months maximum.
- Proof of cookie consent: 6 months.
7. People invited to an appointment
A person receiving an invitation link accesses a limited public page: appointment title, date, time, location, and organizer information. Their response (acceptance or decline) is recorded with its date. They may request deletion of their data directly from the organizer who added them as a contact, or write to us to be guided.
8. Your rights
In accordance with Articles 15 to 22 of the GDPR, you have the right to access, rectify, erase, restrict, object, and port your data, as well as the right to withdraw your consent at any time. These rights can be exercised from your account or by email at the contact address. A complaint can be filed with the CNIL (cnil.fr) or your local data protection authority.
9. Security
Exchanges are encrypted in transit (TLS), passwords are hashed, data access is isolated per user at the database level through row-level security rules, and invitation tokens are random and limited-use.
10. Cookies
Details of the trackers used and how to manage your preferences can be found on the Cookies page.