Security Contact
Support Request
Feedback

GDPR Compliance

Version: 1.7Effective: August 1, 2026
Last updated: August 1, 2026

Under the European Union General Data Protection Regulation (GDPR) 2016/679, your personal data is protected. This page summarizes your rights and how to exercise them on the CADENSA platform.

1. Your Rights Under GDPR

The GDPR grants you the following rights regarding your personal data:

πŸ“„ Right to Access (GDPR Article 15)

You can request a copy of the personal data we hold about you.

How: Profile β†’ Settings β†’ Privacy β†’ Export Data (JSON or CSV format).

✏️ Right to Rectification (GDPR Article 16)

You can request correction of inaccurate or incomplete data.

How: Profile β†’ Edit, or contact us:

πŸ—‘οΈ Right to Erasure (GDPR Article 17)

You can request deletion of your personal data ("right to be forgotten").

How: Settings β†’ Delete Account. Note: All data is removed from Cadensa systems. VAT invoices remain with external providers (e.g. Billingo).

⏸️ Right to Restriction (GDPR Article 18)

You can request restriction of processing under certain conditions.

How: Settings β†’ Privacy β†’ GDPR Rights β†’ β€œRequest Data Processing Restriction” β€” from the interface, stating a reason. You can also request it by email:

πŸ“¦ Right to Data Portability (GDPR Article 20)

You can request your data in a machine-readable format.

Format: JSON or CSV (Profile β†’ Export Data)

πŸ›‘ Right to Object (GDPR Article 21)

You can object to data processing (e.g., direct marketing).

How: Settings β†’ Privacy β†’ GDPR Rights β†’ β€œObject” β€” separately against direct marketing, profiling, and processing based on legitimate interests. For marketing, the unsubscribe link in the emails is enough. By email:

↩️ Right to Withdraw Consent (GDPR Article 7)

You can withdraw consent at any time (e.g., cookies, marketing).

How: Cookie Settings (footer), or Settings β†’ Privacy

βš–οΈ Right to Lodge a Complaint (GDPR Article 77)

You can file a complaint with a supervisory authority if you believe your data protection rights have been violated.

Hungarian supervisory authority:
Nemzeti AdatvΓ©delmi Γ©s InformΓ‘ciΓ³szabadsΓ‘g HatΓ³sΓ‘g (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu
Web: https://naih.hu

2. Data Retention Periods

Detailed information about data retention periods is available in our Privacy Policy:

  • User accounts: Retained until user-initiated deletion
  • Time entries and other workspace content: as instructed by the customer acting as controller β€” they set the retention period under the employment rules that apply to them. Default: deletion when the account ends. When you delete your account, the link between you and your entries is severed immediately.
  • Billing records: Removed from Cadensa systems on account deletion; VAT invoices remain with external providers
  • Audit logs: 30 days (FREE), 90 days (PRO), 1 year (ENTERPRISE); security events for 1 year on every plan
  • Marketing consent: until withdrawn

For more details: Privacy Policy

3. Data Export Guide

Under the right to data portability, you can export all your personal data in JSON or CSV format:

  1. Sign in to your CADENSA account
  2. Navigate to Settings β†’ Privacy
  3. Click "Export Data" button
  4. Choose the format (JSON or CSV) and the file with all your personal data is downloaded
πŸ’‘ Exported data includes:
  • β€’ Profile information
  • β€’ Time entries
  • β€’ Projects and tasks
  • β€’ Settings and preferences
  • β€’ Billing history

4. Account Deletion (Right to be Forgotten)

Under GDPR Article 17, you can request deletion of your account and personal data:

Deletion Process:

  1. Settings β†’ Delete Account
  2. Confirm deletion intent (irreversible)
  3. 7-day grace period: you can export your data or cancel the deletion
  4. All personal data will be deleted (except legal obligations)

⚠️ Important Notes:

  • Billing records: Removed from Cadensa systems. VAT invoices remain with external providers (e.g. Billingo) β€” their retention obligations apply.
  • Audit logs: Depending on plan: 30 days / 90 days / 1 year; security events 1 year (anonymized)
  • Backups: Deleted from the live system immediately. Backups expire on a rotating schedule (daily: 30 days, weekly: 6 months, monthly: 2 years), so data disappears from backups within 2 years at the latest β€” if a restore ever happens, the deletion is re-applied.

5. Third-Party Data Processors

CADENSA uses the following GDPR-compliant third-party processors. The complete, canonical list β€” with contracting entity, storage location and transfer basis β€” lives on the Sub-processors page; in case of any discrepancy that page prevails.

Hetzner Online GmbH

Server hosting (Germany, EU)

DPA: hetzner.com/legal/data-privacy-faq

OVH Hosting Limited

Managed database service (MongoDB) β€” storage of all operational data (Data center: Gravelines, France, EU / Contracting entity: Dublin, Ireland, EU)

DPA: OVH Data Protection Agreement (IE)

Mollie B.V.

Payment processing, subscription management (Netherlands, EU β€” Amsterdam)

DPA: Automatic upon registration (GDPR Art. 28 β€” EU-based processor)

Tarhely.eu / EZIT Kft.

Email delivery (Hungary, EU)

ÁSZF: tarhely.eu/aszf

Vercel Inc.

Landing hosting (Global, EU edge servers)

DPA: vercel.com/legal/dpa

Wasabi Technologies, LLC

Object storage (eu-central-2 / Frankfurt, EU) with three separate buckets. (1) Encrypted database backups: rotating retention (daily 30 days, weekly 6 months, monthly 2 years) with no Object Lock β€” so erasure requests remain executable. (2) Invoice PDF archive: WORM Object Lock in COMPLIANCE mode, 8-year immutable retention per Β§169 of the Hungarian Accounting Act. (3) Profile pictures: a publicly readable bucket so the image can render in the interface β€” uploading one is optional and it can be deleted at any time. The buckets never mix.

DPA: wasabi.com/legal/data-processing-addendum

Billingo Technologies Zrt.

Electronic invoicing + NAV Online SzΓ‘mla 3.0 reporting (Hungary, EU). Data transferred: customer name, billing address, tax/EU VAT number, email, invoice line items.

DPA: billingo.hu/adatvedelem

Plausible Analytics OÜ

Cookie-free website analytics (Estonia, EU) β€” no personal data collected, no consent required

DPA: Not required (not personal data under GDPR)

Google LLC (Google Calendar)

Optional Google Calendar integration (USA) β€” user-initiated only, with explicit consent (Article 6(1)(a)); the transfer relies on the Article 45 adequacy decision (EU–US Data Privacy Framework). Google acts as an independent controller here, not as Cadensa’s processor.

DPA: cloud.google.com/terms/data-processing-addendum

6. Contact and Questions

If you have questions about your GDPR rights or wish to exercise any of them:

Privacy Contact:

  • Email:
  • Response time: Within 30 days
  • Service Provider: Axeri Labs Bt.
  • Address: 2120 Dunakeszi, BrassΓ³i utca 7., Hungary

Related Documents:

Language of this document

This document is authored in English and Hungarian. On other language interfaces the English text is shown. In case of any discrepancy between the two versions, the English text prevails β€” except where the contracting party is a consumer resident in Hungary, in which case the Hungarian version applies. If you spot a discrepancy between the versions, please tell us at legal@cadensa.io and we will fix it.