Privacy Policy
1. Data Controller Information
Company Name: Axeri Labs Bt.
Registered Office: 2120 Dunakeszi, BrassΓ³i utca 7., Hungary
Company Registration Number: 13-06-060656
Tax Number: 22531300-2-13
EU VAT Number: HU22531300
Representative: MΓ‘rton LΓ‘szlΓ³ Attila, Managing Director
Email:
1.1. When we are a controller and when we are a processor
Two kinds of data occur in Cadensa, and a different role applies to each. This is not a formality: it determines who you turn to with your rights, and who decides what happens to your data.
| Data | Our role | Who decides |
|---|---|---|
| Account data (registration name, email), billing data, security logs, messages you send us, marketing subscriptions | Controller | Axeri Labs Bt. β you exercise your rights directly with us |
| Workspace content data: time entries, projects, tasks, memberships, hourly rates, reports | Processor | Your employer / the organisation whose workspace you work in β we process it only on their instructions |
If you use Cadensa as an employee and want your working-time data erased, corrected or handed over, start with your employer β they are the controller, and without their instruction we cannot delete or change workspace content data. You may of course send the request to us as well: we pass it on to the controller without delay and, under section 8 of the DPA, assist them in fulfilling it. For your own account data (registration, billing, security logs) we are the controller β bring those to us directly.
For employers we provide a staff privacy notice template to help them meet their own Article 13 information duty β available at the email address above.
2. Data We Collect
When you use CADENSA, we collect the following personal data:
2.1. Registration Data
- Full name - for identification purposes
- Email address - login and communication
- Password - stored as bcrypt hash
- Session token - JWT token, 7-day validity
- Language preference - UI customization
- Timezone - accurate time display
2.2. Usage Data
- Time entries - start/stop times, description, project
- Projects and workspaces - name, description, members
- Settings - user preferences (theme, notifications)
- Team memberships - roles, permissions
2.3. Data from Third Parties (GDPR Article 14)
In some cases, we may receive personal data about you from third parties:
- Account migration/import from other time tracking tools
- API integrations (with your consent)
- Signing in with a Google account β if you choose it, we receive your name, email address and profile picture from Google. This is our only working SSO provider; SAML and Microsoft Entra ID are planned and not implemented today.
π When we collect data from a third party, we will provide you this Privacy Notice within a reasonable time (typically within 1 month). You have the same rights as if you provided the data directly.
2.4. Technical Data
- IP address - security purposes (audit log)
- User-Agent - device and browser identification
- Cookies - session management, preferences (details: Cookie Policy)
2.5. Feedback, Support and Security Reports
Three forms are available on our pages: feedback, support request and security report. They are served by Formbricks, on the providerβs cloud instance (app.formbricks.com). Formbricks GmbH is a German company storing in Germany, so it is an EU-based processor β and it appears on our sub-processor list.
- What we collect: whatever you type into the form (the message and, if you give it, your email address), plus the time of submission and the page you sent it from. Name and email are optional; without an email we cannot reply.
- Legal basis: legitimate interest (Article 6(1)(f)) β improving the product and answering reports. If you are a customer and the request concerns your subscription, contract performance (Article 6(1)(b)).
- Retention: 24 months from closure, then deletion. For security reports we keep the reporterβs contact details until the fix ships; the technical description we keep longer, but no longer linked to the reporter.
- What not to put in: passwords, your own clientsβ data, or health information. If any arrives, we delete it.
3. Legal Basis (GDPR)
- Contract performance (GDPR Article 6.1.b) - providing CADENSA service
- Consent (GDPR Article 6.1.a) - marketing, non-essential cookies
- Legal obligation (GDPR Article 6.1.c) - eight-year retention of our own subscription invoices under Β§169 of the Hungarian Accounting Act (Act C of 2000). Invoicing is handled by an external provider (Billingo).
- Legitimate interest (GDPR Article 6.1.f) - security audit logging; error logging and performance monitoring; and usage-based emails β these are set out separately in section 3.1 below
Time entry data is not covered by the Accounting Act. Section 169 of the Accounting Act mandates eight-year retention for our accounting records β the invoices Axeri Labs issues and receives. Your staffβs time entries are not our accounting records: you control them, we are the processor for them, and at the end of the subscription we must delete or return them (Article 28(3)(g)). We do not hold them for eight years under any circumstances. The actual periods are in the table in section 4 below.
3.1. Emails Based on Your Usage
Some of our emails are not requested by you: the system sends them based on when you registered and how much you use the service. We say this openly because it can look like profiling β though the substance is simple: we look at dates and activity, and infer nothing about you as a person.
| What triggers it | Legal basis | |
|---|---|---|
| Welcome email | Registration | Contract performance (6(1)(b)) |
| Onboarding sequence | Day 3, 7 and 14 after registration | Legitimate interest (6(1)(f)) |
| NPS survey | Day 21 and 30 after registration | Legitimate interest (6(1)(f)) |
| Weekly summary / reminder | Mondays; your previous weekβs activity decides whether you get stats or a reminder | Legitimate interest (6(1)(f)) |
How to stop them: in your account settings under email preferences, or via the unsubscribe link at the bottom of the message. Objection takes effect immediately and needs no justification (Article 21). It does not affect service emails β password reset, invoice notices, security alerts β which are part of performing the contract.
These emails involve no automated decision-making: they do not affect your price, your account status, or what you can access. We have carried out the legitimate interests assessment (LIA) and share it on request for procurement.
4. Data Retention Periods
| Data Type | Our role | Retention Period | Legal Basis |
|---|---|---|---|
| User accounts | Controller | Until deletion + 7-day grace period For dormant accounts: after 24 months of inactivity a warning email, then deletion 30 days later (being rolled out) | Article 6(1)(b) β contract; Article 5(1)(e) β storage limitation |
| Workspace content (time entries, projects, tasks, memberships) | Processor | As instructed by the customer acting as controller Default: deletion when the account ends. When an individual account is deleted, the identifier is detached from that personβs entries immediately. | The controller customerβs legal basis (typically an employment-law obligation or contract) |
| Our outgoing subscription invoices | Controller | 8 years In a WORM Object Lock archive β technically not deletable before expiry. VAT invoices also remain with the external provider (Billingo). | Article 6(1)(c) β legal obligation (Hungarian Accounting Act Β§169) |
| Audit and security logs | Controller | 30 days (FREE) / 90 days (PRO) / 1 year (ENTERPRISE) Security events for 1 year on every plan, then deleted automatically | Article 6(1)(f) β legitimate interest (with a documented balancing test) |
| Backups | Both roles | Daily: 30 days Β· Weekly: 6 months Β· Monthly: 2 years Deleted data leaves the backups within 2 years at the latest; if a restore happens, the deletion is re-applied | Article 32 β security of processing |
| Marketing consent | Controller | Until withdrawn; we keep a record of the withdrawal itself for accountability | Article 6(1)(a) β consent |
π This table is the single source of truth for retention periods. The GDPR page, the DPA and the security page all refer back to these values β if you spot a discrepancy anywhere, this table prevails.
5. Third-Party Data Processors
To securely store your data and operate the service, we use the following third-party processors. We have GDPR-compliant Data Processing Agreements (DPA) with all of them:
π Data Processing Agreement (DPA) β GDPR Article 28
The Data Processing Agreement applies to every plan (FREE, PRO, ENTERPRISE) as an annex to the Terms, effective on registration β nothing to request, nothing to sign, no surcharge. Full text: Data Processing Agreement.
- Why this way: Article 28(3) requires a written contract from the moment you invite your first colleague. βAvailable on requestβ does not satisfy that, and the omission falls on you as controller too.
- Signed copy: if your procurement process needs a countersigned PDF, request one at privacy@cadensa.io β same content, different form.
β Our DPA covers every sub-processor listed below. As both controller and processor are in the EU, the agreement follows GDPR Article 28 and the structure of the standard clauses in Commission Decision (EU) 2021/915 β Standard Contractual Clauses (SCCs) exist for third-country transfers, and the service performs none in its default state.
π₯οΈ Hetzner Online GmbH
Purpose: Server hosting
Location: Germany (EU)
π OVH Hosting Limited
Purpose: Managed database service (MongoDB) β storage of all operational data
Location: Data center: Gravelines, France (EU) / Contracting entity: Dublin, Ireland (EU)
ποΈ Wasabi Technologies, LLC
Purpose: S3-compatible object storage with three separate buckets: (1) encrypted database backups on a rotating retention schedule, (2) invoice PDF archive under WORM Object Lock in COMPLIANCE mode, (3) profile pictures. The buckets never mix: the backup bucket has no Object Lock, so erasure requests remain executable. The profile picture bucket is publicly readable so the image can render in the interface β uploading one is optional and you can delete it at any time in your account settings.
Location: Germany β Frankfurt (eu-central-2 region, EU)
Data stored: AES-256-GCM encrypted archives (encrypted before upload β Wasabi cannot access the data)
Retention: Database backups: daily for 30 days, weekly for 6 months, monthly for 2 years (then automatically deleted). Invoice PDFs: 8 years (Hungarian Accounting Act Β§169)
π³ Mollie B.V.
Purpose: Payment processing, subscription management
Location: Netherlands (EU) β Amsterdam
DPA: Automatic upon registration (GDPR Art. 28 β EU-based processor)
π§ Tarhely.eu (EZIT Kft.)
Purpose: SMTP email delivery (notifications, password reset)
Location: Hungary (EU)
DPA: Tarhely.eu ΓSZF (GDPR compliance declared)
π Vercel Inc.
Purpose: Landing page hosting, CDN (static content)
Location: Global (with EU edge nodes)
DPA: Vercel DPA
π§Ύ Billingo Technologies Zrt.
Purpose: Electronic invoice issuance for subscriptions + mandatory NAV Online SzΓ‘mla 3.0 reporting
Location: Hungary (EU)
Data transferred: customer name, billing address, tax / EU VAT number, email, invoice line items and amounts
Retention: 8 years (mandatory under Hungarian Accounting Act Β§169)
π Plausible Analytics OΓ
Purpose: Cookie-free website analytics (page views, traffic sources β no individual user identified)
Location: Estonia (EU) β Plausible OΓ
Legal basis: Article 6(1)(f) β legitimate interest (improving the service). No cookie consent is needed, because nothing is stored on or read from your device (ePrivacy Art. 5(3)).
What it processes: It processes your IP address and user agent transiently to compute a daily hash, but stores neither and builds no persistent identifier from them. That is still processing of personal data, however briefly β which is why we do not claim it is βnot personal dataβ.
DPA: plausible.io/dpa
π Google LLC (Google Calendar)
Purpose: Optional Google Calendar integration β user-initiated only
Location: USA β οΈ (transfer outside EU)
Role: Google is not our processor here: when you connect your own Google account via OAuth, Google acts as an independent controller for its own service. We only fetch the title and time of calendar events on your instruction (read-only scope).
Legal basis for the access: GDPR Article 6(1)(a) β explicit consent, given when you switch the integration on and revocable at any time.
Basis for the transfer: An adequacy decision under Article 45: the EUβUS Data Privacy Framework, under which Google LLC maintains a certification. We do not rely on the Article 49(1)(a) derogation, which exists for occasional transfers β a continuously syncing integration is not occasional.
Google privacy terms: policies.google.com/privacy
β οΈ The Google Calendar integration is optional and off by default. Before activation we show a notice about the transfer to the US. You can revoke it at any time in Settings β Integrations. An employer cannot make it mandatory: consent given in an employment relationship is of doubtful freedom (EDPB WP249).
6. Your Rights (Under GDPR)
Under GDPR, you have the following rights. You can exercise these rights in the CADENSA settings menu or via email:
6.1. Right to Access (GDPR Article 15)
Request a copy of all personal data we hold about you in machine-readable format.
π Export formats:
- JSON: Machine-readable, complete data structure
- CSV: Human-readable, Excel-compatible
βοΈ How to: Settings β Privacy β Export Data
π Instant download (no waiting time)
6.2. Right to Rectification (GDPR Article 16)
Correct inaccurate or incomplete personal data.
βοΈ How to: Settings β Profile β Edit
Or send email to:
6.3. Right to Erasure ("Right to be Forgotten") (GDPR Article 17)
Request immediate deletion of your data. After deletion request, there is a 7-day grace period during which you can cancel.
β° 7-day grace period:
- You can cancel deletion within 7 days after request
- You will receive email notification about deletion date
- After 7 days, data is permanently deleted
β οΈ Exceptions (legal obligations):
- Time entry data: when you delete your account we immediately detach the identifier from your entries, so they can no longer be linked to you. The entries themselves stay in the workspace, because they belong to the customer acting as controller (your employer) β they set the retention period under the employment rules that apply to them. This is not based on the Hungarian Accounting Act: that governs our own outgoing invoices, not your time entries.
- Our outgoing subscription invoices: 8 years (Hungarian Accounting Act Β§169) β these are our own accounting records. VAT invoices also remain with the external provider (Billingo).
- Security logs: 1 year (other audit logs: 30 days / 90 days / 1 year depending on plan)
βοΈ How to: Settings β Danger Zone β Delete Account
π Immediate effect, with 7-day cancellation option
6.4. Right to Restriction of Processing (GDPR Article 18)
Request restriction of processing in the following cases:
- Contesting accuracy: You contest the accuracy of your data
- Unlawful processing: Processing is unlawful but you oppose erasure
- No longer needed: We no longer need data but you need it for legal claims
- Objection pending: You objected to processing and we are verifying
π What happens during restriction?
- We store your data but do not actively process it
- Your account remains active with limited functionality
- You can still access and export your data
- You can lift restriction at any time
βοΈ How to: Settings β Privacy β GDPR Rights β Request Data Processing Restriction
π GDPR Article 18.3: We inform you before lifting restriction
6.5. Right to Data Portability (GDPR Article 20)
Export your data in machine-readable format to transfer to another service.
π¦ Exported data:
- Profile data (name, email, settings)
- Time tracking entries (start/stop, description)
- Projects and workspaces
- Invoices and payments
- Email and notification preferences
βοΈ How to: Settings β Privacy β Export Data β Select format (JSON/CSV)
6.6. Right to Object (GDPR Article 21)
Object to data processing based on different legal grounds:
6.6.1. Direct Marketing - Article 21(2)
π‘οΈ Absolute right - no justification needed. This is the strongest user right in GDPR.
β What happens:
- Marketing emails stop immediately
- Transactional emails (invoices, alerts) continue
βοΈ How to: Settings β Privacy β GDPR Rights β "Object to Direct Marketing"
π Immediate effect
6.6.2. Profiling (for Marketing) - Article 21(3)
Object to profiling for direct marketing purposes (e.g., behavior analysis for advertising).
β What happens:
- Marketing profiling stops
- Service functionality analysis continues
βοΈ How to: Settings β Privacy β GDPR Rights β "Object to Profiling"
π Immediate effect
6.6.3. Processing Based on Legitimate Interests - Article 21(1)
If processing is based on legitimate interests, you can object if you have grounds relating to your particular situation.
π Justification required: You must provide reason for objection
β What happens:
- Your objection is reviewed within 30 days
- Temporary restriction applied during review
- If we have no compelling legitimate grounds, we stop processing
βοΈ How to: Settings β Privacy β GDPR Rights β "Object to Data Processing" β Provide reason
π 30-day response time
6.7. Withdraw Consent (GDPR Article 7.3)
Withdraw consent at any time without justification (cookies, marketing emails).
βοΈ How to:
- Cookies: Settings β Privacy β Cookie Preferences
- Marketing: Settings β Privacy β Email Preferences
π Immediate effect
6.8. Right to Lodge a Complaint (GDPR Article 77)
If you believe we have violated your data protection rights, you can lodge a complaint with the supervisory authority.
ππΊ Hungary:
NAIH - National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu
Website: naih.hu
π§ How to exercise your rights?
Most GDPR rights can be exercised directly in CADENSA settings. If you need assistance:
Email:
π Response time: 30 days (GDPR Article 12.3). We will verify your identity for security purposes.
7. Data Security
We implement the following technical and organizational measures to protect your data:
- Encryption: HTTPS/TLS for all data transmission, bcrypt password hashing
- Access control: Role-based access control (RBAC), JWT tokens
- Audit logging: All critical operations logged (login, data modification)
- Regular backups: Daily automated backups, encrypted (Wasabi S3, EU data center)
- Server hardening: Firewall, SSH key-based access, regular updates
8. International Data Transfers
Data is primarily stored within the European Union (Germany, France, Hungary). Transfers outside the EU only occur with GDPR-compliant safeguards:
- Google LLC β Google Calendar (USA): The legal basis for the access is explicit consent under GDPR Article 6(1)(a); the basis for the transfer is an adequacy decision under Article 45 (EUβUS Data Privacy Framework), under which Google LLC maintains a certification. In this relationship Google is an independent controller, not our processor. Only where the user activates the optional Google Calendar integration themselves.
US-incorporated providers with EU storage
Two of our sub-processors are US companies, even though they store the data in an EU region. For assessing transfers what counts is the contracting entity, not where the server physically sits β so we name them separately:
- Vercel Inc. (USA): serving the static files of the public website and the application, in an EU edge region (fra1, Frankfurt). Data involved: IP address, user agent, request metadata. No time entries, projects or reports reach it β API calls go straight to the EU backend. Basis: Vercel DPA + SCCs.
- Wasabi Technologies LLC (USA): object storage in Frankfurt (eu-central-2): encrypted database backups and the invoice PDF archive. Backups are encrypted with AES-256-GCM before upload and the key stays with us. Basis: Wasabi DPA + SCCs.
Every other sub-processor is an EU entity storing in the EU: Hetzner (DE), OVH Hosting Limited (contracting entity: IE, data centre: FR), Mollie (NL), Billingo (HU), Tarhely.eu (HU), Plausible (EE), Formbricks GmbH (DE). The complete, canonical list β with contracting entity, storage location and transfer basis β lives on the Sub-processors page; in case of any discrepancy, that page prevails.
9. Mobile Applications
The App Store and Google Play badges on the homepage are marked βcoming soonβ: there is no released Cadensa app in either store at present. On mobile, the service is used through the browser, under exactly the same processing rules as on desktop.
When we release a native app, this section will be extended beforehand: we will describe how device identifiers, push notification tokens and any crash reporting are handled, and align both store disclosures (Apple Privacy Nutrition Label, Google Play Data Safety) with this policy. Our principle stays the same: no background location, no screen monitoring and no activity measurement in the mobile app either.
10. Automated Decision-Making and Profiling
Under GDPR Article 13(2)(f) we confirm that CADENSA does not carry out solely automated decision-making or profiling β including automated evaluation of employee performance β that produces legal effects concerning you or similarly significantly affects you. The reports and aggregations in the product are descriptive statistics: they make no decisions, produce no rankings, and trigger no automated action.
If we introduce such a feature in the future, we will announce it in advance and ship it together with the Article 22 safeguards (human intervention, right to contest).
11. Children's Privacy
CADENSA is not intended for children under 16 years of age. We do not knowingly collect data from individuals under 16.
How we enforce this: candidly: we do not verify age. We do not ask for a date of birth at sign-up and we use no age-estimation technology β for a time tracking tool that would be disproportionate data collection and would not add real protection. By accepting the Terms you declare that you are at least 16 and have legal capacity.
If we receive a report β from a parent, an employer, or through our own detection β that an account is used by someone under 16, we suspend the account, delete the personal data, and notify the reporter. Reports: privacy@cadensa.io. Where a young worker is invited by an employer, the employer is the controller and its own national age and labour law rules apply.
12. Changes to This Policy
We reserve the right to update this Privacy Policy from time to time. We will notify you of significant changes via email. The "Last updated" date indicates the most recent revision.
13. Contact Us
If you have questions about data privacy or want to exercise your GDPR rights:
Email:
Postal address:
Axeri Labs Bt.
2120 Dunakeszi, BrassΓ³i utca 7.
Hungary
π Response time: 30 days (as per GDPR Article 12.3)
β GDPR Compliance
This Privacy Policy complies with the European Union General Data Protection Regulation (EU 2016/679) and the Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
Language of this document
This document is authored in English and Hungarian. On other language interfaces the English text is shown. In case of any discrepancy between the two versions, the English text prevails β except where the contracting party is a consumer resident in Hungary, in which case the Hungarian version applies. If you spot a discrepancy between the versions, please tell us at legal@cadensa.io and we will fix it.