Security Contact
Support Request
Feedback

Data Processing Agreement

Version: 2.3Effective: July 31, 2026
Last updated: July 31, 2026

Data Processing Agreement under GDPR Article 28, applying to every plan (FREE, PRO, ENTERPRISE). This document governs the relationship between the data controller (you) and the data processor (Cadensa).

📄 This DPA applies to every plan

The moment you invite a second user into your workspace, we process their data on your behalf — and GDPR Article 28(3) requires a written contract for that. This DPA is therefore incorporated into the Terms of Service and takes effect on registration, on all three plans, at no extra cost. You do not need to request it, and it is not an enterprise add-on.

When it takes effect: on registration, when you accept the Terms of Service (ToS sections 2 and 12) — on FREE, PRO and ENTERPRISE alike

Signed, countersigned copy: available for procurement on request: (subject: "Signed DPA")

Response time: Within 5 business days

1. Definitions

Controller: The natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data. Your organization.
Processor: The natural or legal person which processes personal data on behalf of the controller. Cadensa / Axeri Labs Bt.
Personal Data: Any information relating to an identified or identifiable natural person (GDPR Article 4(1)).
Data Subject: The identified or identifiable natural person (e.g., your employees).
Sub-processor: A third-party service provider engaged by the processor to assist in processing activities.

2. Subject Matter and Duration

Subject Matter: Cadensa (processor) provides time tracking and project management services to the controller on any plan (FREE, PRO, ENTERPRISE). The processor processes personal data on behalf of and according to the instructions of the controller.

Duration: This DPA takes effect on registration and remains in effect for the entire lifetime of the account; it terminates automatically when the account ends. Data deletion follows section 10.

3. Nature and Purpose of Processing

Processing Activities:

  • Storage: Storage of user accounts, time entries, projects, tasks
  • Processing: Report generation, analytics, billing data production
  • Transfer: Data transmission to controller users (only within controller organization)
  • Deletion: Data deletion upon controller request or expiration of legal retention period

Purpose of Processing:

  • Time tracking and attendance management
  • Project management support
  • Billing data generation (billable hours)
  • Productivity reporting
  • Ensuring service availability

4. Categories of Data and Data Subjects

Data Categories:

  • Identification data (name, email)
  • Work-related data (time entries, projects)
  • Technical data (IP address, browser info)
  • Usage data (login history)
  • Settings (language, timezone, avatar)

Data Subjects:

  • Controller's employees
  • Controller's contractors
  • Controller's team members
  • Administrators

5. Controller Obligations and Instructions

The controller shall ensure that:

  • 1. It has a legal basis for processing personal data
  • 2. Data subjects have been properly informed
  • 3. Processing complies with GDPR and applicable national laws
  • 4. Instructions given to the processor are lawful

Processing Instructions:

The processor shall process personal data only on written instructions from the controller. The following instructions apply:

  • As specified in the ENTERPRISE subscription agreement
  • As outlined in the Terms of Service
  • As per written requests sent to by the controller

6. Processor Obligations

The processor (Cadensa) undertakes to:

a) Confidentiality (GDPR Article 28(3)(b))

Ensures that persons authorized to process personal data have committed themselves to confidentiality.

b) Technical and Organizational Measures (GDPR Article 32)

Implements appropriate technical and organizational measures to protect data:

  • Encryption: TLS 1.3 (transit), AES-256 (storage)
  • Access control: RBAC, optional 2FA
  • Audit logging: 30 days (FREE) / 90 days (PRO) / 1 year (ENTERPRISE), security events 1 year
  • Backups: Daily, encrypted
  • System updates: Regular security patches

c) Deletion or Return of Data (GDPR Article 28(3)(g))

At the end of the provision of services, deletes or returns all personal data at the controller’s choice, and deletes existing copies. The controller may state that choice when the account ends, or at any point before; absent a choice, deletion is the default. Return happens through self-service export (JSON or CSV) or, on request, as a complete data package.

Exception: retention required by Union or Member State law — this covers the processor’s own accounting records (issued subscription invoices, Hungarian Accounting Act §169), not workspace content data. Section 10 lists the affected data and its legal basis item by item.

d) Audit Rights (GDPR Article 28(3)(h))

Makes available all information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits — including inspections — conducted by the controller or an auditor mandated by the controller. This right applies to every controller regardless of plan. Practical frame: one audit per calendar year with 30 days’ prior written notice, during business hours, under an NDA; out of cycle where justified (an incident, a regulator’s investigation). Reasonable costs of additional audits are borne by the controller. Document-based evidence (the Annex II TOM list, the sub-processor list, an extract of the breach register) is free of charge on every plan.

e) Transfers to Third Countries (GDPR Article 28(3)(a))

Processes personal data only on documented instructions from the controller, including with regard to transfers to a third country or an international organisation — unless required to do so by Union or Member State law. In such a case, the processor informs the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

In its default state the service performs no third-country transfer. This only occurs if a user activates the Google Calendar integration themselves (see section 7).

f) Assistance with Articles 32–36 (GDPR Article 28(3)(f))

Taking into account the nature of processing and the information available to it, assists the controller in complying with Articles 32–36: security of processing (Article 32), breach notification and communication (Articles 33–34), data protection impact assessment (Article 35) and prior consultation (Article 36). For this we provide the Annex II TOM list, the data-flow description and the technical inputs needed for a DPIA, free of charge, on every plan.

g) Notifying Unlawful Instructions (GDPR Article 28(3), second subparagraph)

Immediately informs the controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. Until it has done so — or until the instruction is confirmed — the processor may suspend execution of the instruction in question.

h) Data Breach Notification (GDPR Article 33)

Notifies the controller of any personal data breach without undue delay and in any event within 48 hours of becoming aware of it, via . Where all the information is not available within that window, it is provided in phases as the facts emerge, under Article 33(4) — the first notice does not wait for the investigation to finish.

7. Sub-processors

The controller grants general authorization to the processor to engage sub-processors. The processor shall notify the controller at least 30 days in advance of any new sub-processor engagement.

The current complete list — with contracting entity, storage location, transfer basis, version history and an email notice subscription — lives on the Sub-processors page. In case of any discrepancy that page prevails; the list below is a snapshot of it.

Current Sub-processors (2026-07-31):

1. Hetzner Online GmbH
Service: Server hosting
Location: Germany (EU)
DPA: hetzner.com/legal/data-privacy-faq
2. Mollie B.V.
Service: Payment processing, subscription management
Location: Netherlands (EU) — Amsterdam
DPA: mollie.com/en/legal/data-processing-agreement
3. Tarhely.eu / EZIT Kft.
Service: Email delivery (SMTP)
Location: Hungary (EU)
Terms: tarhely.eu/aszf
4. Vercel Inc.
Service: Landing page hosting + CDN
Location: Global (EU edge servers)
DPA: vercel.com/legal/dpa
5. Wasabi Technologies, LLC
Service: S3-compatible object storage with three separate buckets: (1) encrypted database backups on a rotating schedule (daily 30 days, weekly 6 months, monthly 2 years) with no Object Lock — so a controller’s deletion instruction is executable; (2) the processor’s own invoice PDF archive under WORM Object Lock in COMPLIANCE mode, 8 years per §169 of the Hungarian Accounting Act; (3) profile pictures in a publicly readable bucket so the image can render in the interface. Bucket (2) holds the processor’s own accounting records and contains no customer time entry data. Bucket (3) holds optional content uploaded by the data subject and can be deleted at any time.
Location: Germany (eu-central-2 / Frankfurt — EU)
DPA: wasabi.com/legal/data-processing-addendum
6. Billingo Technologies Zrt.
Service: Electronic invoice issuance + NAV Online Számla 3.0 reporting (subscription invoices)
Location: Hungary (EU)
Data transferred: customer name, billing address, tax / EU VAT number, email, invoice line items and amounts
DPA: billingo.hu/adatvedelem
7. OVH Hosting Limited
Service: Managed database service (MongoDB) — storage of all operational data
Location: Data center: Gravelines, France (EU) / Contracting entity: Dublin, Ireland (EU)
DPA: OVH Data Protection Agreement (IE)
8. Plausible Insights OÜ
Service: Cookie-free website analytics — no personal data collected
Location: Estonia (EU)
DPA: Not required (not personal data under GDPR)

Notification and objection to a new sub-processor

  • Notification channel: At least 30 days before engaging a new sub-processor we email the account’s billing contact and record the change on this page by updating the list date. You can also subscribe to the notice separately at (subject: “Sub-processor notices”).
  • Objection: The controller may object within 30 days of the notice, stating its reasons, at .
  • Consequence of an objection: We first try to provide the affected function without that sub-processor, or with a different one. If that is not possible with reasonable effort, the controller may terminate the subscription before the planned change takes effect, without penalty — and we refund the pro-rata share of any prepaid, unused subscription fee. While an objection is pending, that sub-processor does not process the controller’s data.

8. Data Subject Rights Assistance

The processor assists the controller, using appropriate technical and organizational measures, in fulfilling data subject rights (GDPR Articles 15-22):

Right to Access:
Profile → Export Data (JSON or CSV)
Right to Rectification:
Profile → Edit
Right to Erasure:
Settings → Delete Account (7-day grace period)
Data Portability:
JSON / CSV export

Response time: The processor fulfills controller requests within 5 business days ().

9. Data Breach Management

Notification Obligation:

The processor notifies the controller of any personal data breach without undue delay and in any event within 48 hours of becoming aware of it. Where some information is not yet available at that point, notification continues in phases under Article 33(4).

Notification channel:

Contents:

  • Nature of the breach
  • Categories of data and number of data subjects affected
  • Consequences of the breach
  • Measures taken and planned

10. Term and Termination

Effective Date: This DPA becomes effective upon commencement of the ENTERPRISE subscription.
Termination: This DPA terminates automatically upon termination of the ENTERPRISE subscription.
Processing after termination:
  • 7-day grace period: data can be exported or deletion can be cancelled
  • After 7 days: all personal data deleted (except legal obligations)
  • The processor’s own outgoing subscription invoices: 8 years (Hungarian Accounting Act §169). This obligation falls on the processor in its capacity as a controller, and does not extend to workspace content data.
  • Audit logs: 30 days / 90 days / 1 year depending on plan (anonymized)

11. Liability and Indemnification

Liability allocation under GDPR Article 82:

Processor Liability:
The processor is liable only if it has not complied with GDPR obligations specifically directed to processors or has acted outside or contrary to lawful instructions of the controller.
Limitation of Liability:
Total aggregate liability of the processor is limited to 12 times the monthly subscription fee (subject to mandatory GDPR liability rules).

Let us spell out what that means: on the PRO plan (€4.99/mo) the cap works out to roughly €60, on ENTERPRISE (€12.99/mo) to about €156. That is usually not enough for a larger organisation’s procurement template, and we understand why. On an ENTERPRISE contract the liability framework is negotiable — write to our legal contact and we set it against the actual data involved. This cap does not touch direct liability towards data subjects under Article 82 GDPR in any case: that cannot be excluded by contract.

12. Governing Law and Jurisdiction

Governing Law: This DPA is governed by Hungarian law and EU GDPR.

Jurisdiction: Disputes shall fall under the jurisdiction of the Pest County Court (Hungary).

Annex I — Description of the Processing

Following the structure of Commission Implementing Decision (EU) 2021/915 (standard contractual clauses under Article 28).

A) PartiesController: the subscribing organisation (the account owner). Processor: Axeri Labs Bt. (CADENSA), Brassói utca 7., 2120 Dunakeszi, Hungary, company reg. 13-06-060656.
B) Subject matter and durationTime tracking, project and task management, reporting and billing preparation delivered as SaaS. Duration: the lifetime of the account, followed by the deletion process in section 10.
C) Nature and purposeCollection, recording, storage, organisation, retrieval, aggregation (reporting), export and erasure — for the purpose of the controller recording and billing its staff’s working time. No automated decision-making and no profiling.
D) Categories of personal dataIdentification and contact data (name, email address, avatar), organisational data (workspace, role, hourly rate), activity data (start/end of time entries and their free-text description, project and task assignment), technical logs (IP address, user agent, timestamp, action).
E) Special categories (Article 9)The service neither requests nor processes special category data. The controller must not direct or encourage entry of health or other Article 9 data into the free-text description of a time entry (e.g. “sick leave”, “prenatal appointment”). The controller is responsible for informing its staff of this.
F) Categories of data subjectsThe controller’s employees, contractors and subcontractors present in the workspace as users; and the contact persons of the controller’s own clients, to the extent the controller records them as project or client data.
G) Frequency of transferContinuous (in real time, as the service is used).
H) RetentionWorkspace content data for the lifetime of the account, then deletion or return at the controller’s choice (section 6(c)). Audit logs: 30 days (FREE) / 90 days (PRO) / 1 year (ENTERPRISE), security events 1 year. Backups: daily 30 days, weekly 6 months, monthly 2 years. The processor’s own accounting records: 8 years.

Annex II — Technical and Organisational Measures (Article 32)

The measures listed here apply to the production environment. We also issue them as a signed PDF for procurement (TOM-Liste nach Art. 32 DSGVO).

MeasureImplementation
Physical access controlData centres are operated by sub-processors (Hetzner DE, OVHcloud FR/IE, Wasabi DE): access control, video surveillance, ISO 27001 certification as held by each provider. The processor operates no server room of its own.
System access controlPassword and Google OAuth sign-in, bcrypt (12 rounds) password storage, optional TOTP two-factor authentication, JWT sessions expiring in 7 days, per-endpoint rate limiting, Helmet security headers and a strict CORS allowlist on the server side.
Data access controlRole-based access control (RBAC) at workspace and organisational-unit level with permission inheritance; IP allowlisting on ENTERPRISE. Each controller’s data is isolated in its own database (database per tenant).
SeparationPer-tenant (unit) database separation; separate production and staging environments; development does not run on production data.
EncryptionTLS 1.3 in transit (with HSTS), backups encrypted with AES-256-GCM before upload, user email addresses stored as SHA-256 hashes in the global database.
Logging and traceabilityAudit log of sign-ins (successful and failed), data modifications, role changes and security events; per-request correlation ID; log retention by plan (30 / 90 days / 1 year), security events 1 year.
Availability and resilienceDaily full backup with SHA-256 checksums on a rotating schedule (daily 30 days, weekly 6 months, monthly 2 years); multiple application instances behind a load balancer; automated certificate renewal; monitoring and alerting.
Input and instruction controlThe controller’s instructions are given through the product interface and this DPA; administrative actions in the interface are logged and traceable.
Support for data subject rightsSelf-service data export (JSON or CSV), account deletion with a 7-day grace period, restriction of processing and objection from the interface, on every plan.
Organisational measuresConfidentiality obligations for everyone involved; least-privilege access; weekly dependency vulnerability scanning with critical CVEs patched within 24 hours; a documented incident response process with 24-hour controller notification.
Not yet in placeNo independent penetration test and no SOC 2 / ISO 27001 certification at present; a bug bounty programme is planned. We state this deliberately so procurement questionnaires need no later correction.

13. Signatures

This DPA becomes effective on registration, when you accept the Terms of Service — on every plan, with no signature needed. The signature block below exists only for controllers whose procurement process requires a countersigned copy:

Controller:

Name: __________________________

Address: __________________________

Date: __________________________

Signature: __________________________

Processor:

Name: Axeri Labs Bt. (CADENSA)

Address: 2120 Dunakeszi, Brassói utca 7., Hungary

Date: __________________________

Signature: __________________________

For a signed copy, please contact:

Related Documents:

Language of this document

This document is authored in English and Hungarian. On other language interfaces the English text is shown. In case of any discrepancy between the two versions, the English text prevails — except where the contracting party is a consumer resident in Hungary, in which case the Hungarian version applies. If you spot a discrepancy between the versions, please tell us at legal@cadensa.io and we will fix it.