Security Contact
Support Request
Feedback

Privacy Policy

Version: 2.7Effective: July 31, 2026
Last updated: July 31, 2026

1. Data Controller Information

Company Name: Axeri Labs Bt.

Registered Office: 2120 Dunakeszi, BrassΓ³i utca 7., Hungary

Company Registration Number: 13-06-060656

Tax Number: 22531300-2-13

EU VAT Number: HU22531300

Representative: MΓ‘rton LΓ‘szlΓ³ Attila, Managing Director

Email:

1.1. When we are a controller and when we are a processor

Two kinds of data occur in Cadensa, and a different role applies to each. This is not a formality: it determines who you turn to with your rights, and who decides what happens to your data.

DataOur roleWho decides
Account data (registration name, email), billing data, security logs, messages you send us, marketing subscriptionsControllerAxeri Labs Bt. β€” you exercise your rights directly with us
Workspace content data: time entries, projects, tasks, memberships, hourly rates, reportsProcessorYour employer / the organisation whose workspace you work in β€” we process it only on their instructions

If you use Cadensa as an employee and want your working-time data erased, corrected or handed over, start with your employer β€” they are the controller, and without their instruction we cannot delete or change workspace content data. You may of course send the request to us as well: we pass it on to the controller without delay and, under section 8 of the DPA, assist them in fulfilling it. For your own account data (registration, billing, security logs) we are the controller β€” bring those to us directly.

For employers we provide a staff privacy notice template to help them meet their own Article 13 information duty β€” available at the email address above.

2. Data We Collect

When you use CADENSA, we collect the following personal data:

2.1. Registration Data

  • Full name - for identification purposes
  • Email address - login and communication
  • Password - stored as bcrypt hash
  • Session token - JWT token, 7-day validity
  • Language preference - UI customization
  • Timezone - accurate time display

2.2. Usage Data

  • Time entries - start/stop times, description, project
  • Projects and workspaces - name, description, members
  • Settings - user preferences (theme, notifications)
  • Team memberships - roles, permissions

2.3. Data from Third Parties (GDPR Article 14)

In some cases, we may receive personal data about you from third parties:

  • Account migration/import from other time tracking tools
  • API integrations (with your consent)
  • Signing in with a Google account β€” if you choose it, we receive your name, email address and profile picture from Google. This is our only working SSO provider; SAML and Microsoft Entra ID are planned and not implemented today.

πŸ“‹ When we collect data from a third party, we will provide you this Privacy Notice within a reasonable time (typically within 1 month). You have the same rights as if you provided the data directly.

2.4. Technical Data

  • IP address - security purposes (audit log)
  • User-Agent - device and browser identification
  • Cookies - session management, preferences (details: Cookie Policy)

2.5. Feedback, Support and Security Reports

Three forms are available on our pages: feedback, support request and security report. They are served by Formbricks, on the provider’s cloud instance (app.formbricks.com). Formbricks GmbH is a German company storing in Germany, so it is an EU-based processor β€” and it appears on our sub-processor list.

  • What we collect: whatever you type into the form (the message and, if you give it, your email address), plus the time of submission and the page you sent it from. Name and email are optional; without an email we cannot reply.
  • Legal basis: legitimate interest (Article 6(1)(f)) β€” improving the product and answering reports. If you are a customer and the request concerns your subscription, contract performance (Article 6(1)(b)).
  • Retention: 24 months from closure, then deletion. For security reports we keep the reporter’s contact details until the fix ships; the technical description we keep longer, but no longer linked to the reporter.
  • What not to put in: passwords, your own clients’ data, or health information. If any arrives, we delete it.

3. Legal Basis (GDPR)

  • Contract performance (GDPR Article 6.1.b) - providing CADENSA service
  • Consent (GDPR Article 6.1.a) - marketing, non-essential cookies
  • Legal obligation (GDPR Article 6.1.c) - eight-year retention of our own subscription invoices under Β§169 of the Hungarian Accounting Act (Act C of 2000). Invoicing is handled by an external provider (Billingo).
  • Legitimate interest (GDPR Article 6.1.f) - security audit logging; error logging and performance monitoring; and usage-based emails β€” these are set out separately in section 3.1 below

Time entry data is not covered by the Accounting Act. Section 169 of the Accounting Act mandates eight-year retention for our accounting records β€” the invoices Axeri Labs issues and receives. Your staff’s time entries are not our accounting records: you control them, we are the processor for them, and at the end of the subscription we must delete or return them (Article 28(3)(g)). We do not hold them for eight years under any circumstances. The actual periods are in the table in section 4 below.

3.1. Emails Based on Your Usage

Some of our emails are not requested by you: the system sends them based on when you registered and how much you use the service. We say this openly because it can look like profiling β€” though the substance is simple: we look at dates and activity, and infer nothing about you as a person.

EmailWhat triggers itLegal basis
Welcome emailRegistrationContract performance (6(1)(b))
Onboarding sequenceDay 3, 7 and 14 after registrationLegitimate interest (6(1)(f))
NPS surveyDay 21 and 30 after registrationLegitimate interest (6(1)(f))
Weekly summary / reminderMondays; your previous week’s activity decides whether you get stats or a reminderLegitimate interest (6(1)(f))

How to stop them: in your account settings under email preferences, or via the unsubscribe link at the bottom of the message. Objection takes effect immediately and needs no justification (Article 21). It does not affect service emails β€” password reset, invoice notices, security alerts β€” which are part of performing the contract.

These emails involve no automated decision-making: they do not affect your price, your account status, or what you can access. We have carried out the legitimate interests assessment (LIA) and share it on request for procurement.

4. Data Retention Periods

Data TypeOur roleRetention PeriodLegal Basis
User accountsControllerUntil deletion + 7-day grace period
For dormant accounts: after 24 months of inactivity a warning email, then deletion 30 days later (being rolled out)
Article 6(1)(b) β€” contract; Article 5(1)(e) β€” storage limitation
Workspace content (time entries, projects, tasks, memberships)ProcessorAs instructed by the customer acting as controller
Default: deletion when the account ends. When an individual account is deleted, the identifier is detached from that person’s entries immediately.
The controller customer’s legal basis (typically an employment-law obligation or contract)
Our outgoing subscription invoicesController8 years
In a WORM Object Lock archive β€” technically not deletable before expiry. VAT invoices also remain with the external provider (Billingo).
Article 6(1)(c) β€” legal obligation (Hungarian Accounting Act Β§169)
Audit and security logsController30 days (FREE) / 90 days (PRO) / 1 year (ENTERPRISE)
Security events for 1 year on every plan, then deleted automatically
Article 6(1)(f) β€” legitimate interest (with a documented balancing test)
BackupsBoth rolesDaily: 30 days Β· Weekly: 6 months Β· Monthly: 2 years
Deleted data leaves the backups within 2 years at the latest; if a restore happens, the deletion is re-applied
Article 32 β€” security of processing
Marketing consentControllerUntil withdrawn; we keep a record of the withdrawal itself for accountabilityArticle 6(1)(a) β€” consent

πŸ“Œ This table is the single source of truth for retention periods. The GDPR page, the DPA and the security page all refer back to these values β€” if you spot a discrepancy anywhere, this table prevails.

5. Third-Party Data Processors

To securely store your data and operate the service, we use the following third-party processors. We have GDPR-compliant Data Processing Agreements (DPA) with all of them:

πŸ“‹ Data Processing Agreement (DPA) β€” GDPR Article 28

The Data Processing Agreement applies to every plan (FREE, PRO, ENTERPRISE) as an annex to the Terms, effective on registration β€” nothing to request, nothing to sign, no surcharge. Full text: Data Processing Agreement.

  • Why this way: Article 28(3) requires a written contract from the moment you invite your first colleague. β€œAvailable on request” does not satisfy that, and the omission falls on you as controller too.
  • Signed copy: if your procurement process needs a countersigned PDF, request one at privacy@cadensa.io β€” same content, different form.

βœ… Our DPA covers every sub-processor listed below. As both controller and processor are in the EU, the agreement follows GDPR Article 28 and the structure of the standard clauses in Commission Decision (EU) 2021/915 β€” Standard Contractual Clauses (SCCs) exist for third-country transfers, and the service performs none in its default state.

πŸ–₯️ Hetzner Online GmbH

Purpose: Server hosting

Location: Germany (EU)

DPA: Hetzner Data Privacy FAQ

πŸƒ OVH Hosting Limited

Purpose: Managed database service (MongoDB) β€” storage of all operational data

Location: Data center: Gravelines, France (EU) / Contracting entity: Dublin, Ireland (EU)

DPA: OVH Data Protection Agreement (IE)

πŸ—„οΈ Wasabi Technologies, LLC

Purpose: S3-compatible object storage with three separate buckets: (1) encrypted database backups on a rotating retention schedule, (2) invoice PDF archive under WORM Object Lock in COMPLIANCE mode, (3) profile pictures. The buckets never mix: the backup bucket has no Object Lock, so erasure requests remain executable. The profile picture bucket is publicly readable so the image can render in the interface β€” uploading one is optional and you can delete it at any time in your account settings.

Location: Germany – Frankfurt (eu-central-2 region, EU)

Data stored: AES-256-GCM encrypted archives (encrypted before upload β€” Wasabi cannot access the data)

Retention: Database backups: daily for 30 days, weekly for 6 months, monthly for 2 years (then automatically deleted). Invoice PDFs: 8 years (Hungarian Accounting Act Β§169)

DPA: Wasabi Privacy Policy & DPA

πŸ’³ Mollie B.V.

Purpose: Payment processing, subscription management

Location: Netherlands (EU) β€” Amsterdam

DPA: Automatic upon registration (GDPR Art. 28 β€” EU-based processor)

πŸ“§ Tarhely.eu (EZIT Kft.)

Purpose: SMTP email delivery (notifications, password reset)

Location: Hungary (EU)

DPA: Tarhely.eu ÁSZF (GDPR compliance declared)

🌐 Vercel Inc.

Purpose: Landing page hosting, CDN (static content)

Location: Global (with EU edge nodes)

DPA: Vercel DPA

🧾 Billingo Technologies Zrt.

Purpose: Electronic invoice issuance for subscriptions + mandatory NAV Online SzΓ‘mla 3.0 reporting

Location: Hungary (EU)

Data transferred: customer name, billing address, tax / EU VAT number, email, invoice line items and amounts

Retention: 8 years (mandatory under Hungarian Accounting Act Β§169)

DPA: Billingo Privacy & DPA

πŸ“Š Plausible Analytics OÜ

Purpose: Cookie-free website analytics (page views, traffic sources β€” no individual user identified)

Location: Estonia (EU) β€” Plausible OÜ

Legal basis: Article 6(1)(f) β€” legitimate interest (improving the service). No cookie consent is needed, because nothing is stored on or read from your device (ePrivacy Art. 5(3)).

What it processes: It processes your IP address and user agent transiently to compute a daily hash, but stores neither and builds no persistent identifier from them. That is still processing of personal data, however briefly β€” which is why we do not claim it is β€œnot personal data”.

DPA: plausible.io/dpa

πŸ“… Google LLC (Google Calendar)

Purpose: Optional Google Calendar integration β€” user-initiated only

Location: USA ⚠️ (transfer outside EU)

Role: Google is not our processor here: when you connect your own Google account via OAuth, Google acts as an independent controller for its own service. We only fetch the title and time of calendar events on your instruction (read-only scope).

Legal basis for the access: GDPR Article 6(1)(a) β€” explicit consent, given when you switch the integration on and revocable at any time.

Basis for the transfer: An adequacy decision under Article 45: the EU–US Data Privacy Framework, under which Google LLC maintains a certification. We do not rely on the Article 49(1)(a) derogation, which exists for occasional transfers β€” a continuously syncing integration is not occasional.

Google privacy terms: policies.google.com/privacy

⚠️ The Google Calendar integration is optional and off by default. Before activation we show a notice about the transfer to the US. You can revoke it at any time in Settings β†’ Integrations. An employer cannot make it mandatory: consent given in an employment relationship is of doubtful freedom (EDPB WP249).

6. Your Rights (Under GDPR)

Under GDPR, you have the following rights. You can exercise these rights in the CADENSA settings menu or via email:

6.1. Right to Access (GDPR Article 15)

Request a copy of all personal data we hold about you in machine-readable format.

πŸ“Š Export formats:

  • JSON: Machine-readable, complete data structure
  • CSV: Human-readable, Excel-compatible

βš™οΈ How to: Settings β†’ Privacy β†’ Export Data

πŸ•’ Instant download (no waiting time)

6.2. Right to Rectification (GDPR Article 16)

Correct inaccurate or incomplete personal data.

βš™οΈ How to: Settings β†’ Profile β†’ Edit

Or send email to:

6.3. Right to Erasure ("Right to be Forgotten") (GDPR Article 17)

Request immediate deletion of your data. After deletion request, there is a 7-day grace period during which you can cancel.

⏰ 7-day grace period:

  • You can cancel deletion within 7 days after request
  • You will receive email notification about deletion date
  • After 7 days, data is permanently deleted

⚠️ Exceptions (legal obligations):

  • Time entry data: when you delete your account we immediately detach the identifier from your entries, so they can no longer be linked to you. The entries themselves stay in the workspace, because they belong to the customer acting as controller (your employer) β€” they set the retention period under the employment rules that apply to them. This is not based on the Hungarian Accounting Act: that governs our own outgoing invoices, not your time entries.
  • Our outgoing subscription invoices: 8 years (Hungarian Accounting Act Β§169) β€” these are our own accounting records. VAT invoices also remain with the external provider (Billingo).
  • Security logs: 1 year (other audit logs: 30 days / 90 days / 1 year depending on plan)

βš™οΈ How to: Settings β†’ Danger Zone β†’ Delete Account

πŸ•’ Immediate effect, with 7-day cancellation option

6.4. Right to Restriction of Processing (GDPR Article 18)

Request restriction of processing in the following cases:

  • Contesting accuracy: You contest the accuracy of your data
  • Unlawful processing: Processing is unlawful but you oppose erasure
  • No longer needed: We no longer need data but you need it for legal claims
  • Objection pending: You objected to processing and we are verifying

πŸ“Œ What happens during restriction?

  • We store your data but do not actively process it
  • Your account remains active with limited functionality
  • You can still access and export your data
  • You can lift restriction at any time

βš™οΈ How to: Settings β†’ Privacy β†’ GDPR Rights β†’ Request Data Processing Restriction

πŸ•’ GDPR Article 18.3: We inform you before lifting restriction

6.5. Right to Data Portability (GDPR Article 20)

Export your data in machine-readable format to transfer to another service.

πŸ“¦ Exported data:

  • Profile data (name, email, settings)
  • Time tracking entries (start/stop, description)
  • Projects and workspaces
  • Invoices and payments
  • Email and notification preferences

βš™οΈ How to: Settings β†’ Privacy β†’ Export Data β†’ Select format (JSON/CSV)

6.6. Right to Object (GDPR Article 21)

Object to data processing based on different legal grounds:

6.6.1. Direct Marketing - Article 21(2)

πŸ›‘οΈ Absolute right - no justification needed. This is the strongest user right in GDPR.

βœ… What happens:

  • Marketing emails stop immediately
  • Transactional emails (invoices, alerts) continue

βš™οΈ How to: Settings β†’ Privacy β†’ GDPR Rights β†’ "Object to Direct Marketing"

πŸ•’ Immediate effect

6.6.2. Profiling (for Marketing) - Article 21(3)

Object to profiling for direct marketing purposes (e.g., behavior analysis for advertising).

βœ… What happens:

  • Marketing profiling stops
  • Service functionality analysis continues

βš™οΈ How to: Settings β†’ Privacy β†’ GDPR Rights β†’ "Object to Profiling"

πŸ•’ Immediate effect

6.6.3. Processing Based on Legitimate Interests - Article 21(1)

If processing is based on legitimate interests, you can object if you have grounds relating to your particular situation.

πŸ“ Justification required: You must provide reason for objection

βœ… What happens:

  • Your objection is reviewed within 30 days
  • Temporary restriction applied during review
  • If we have no compelling legitimate grounds, we stop processing

βš™οΈ How to: Settings β†’ Privacy β†’ GDPR Rights β†’ "Object to Data Processing" β†’ Provide reason

πŸ•’ 30-day response time

6.7. Withdraw Consent (GDPR Article 7.3)

Withdraw consent at any time without justification (cookies, marketing emails).

βš™οΈ How to:

  • Cookies: Settings β†’ Privacy β†’ Cookie Preferences
  • Marketing: Settings β†’ Privacy β†’ Email Preferences

πŸ•’ Immediate effect

6.8. Right to Lodge a Complaint (GDPR Article 77)

If you believe we have violated your data protection rights, you can lodge a complaint with the supervisory authority.

πŸ‡­πŸ‡Ί Hungary:

NAIH - National Authority for Data Protection and Freedom of Information

Address: 1055 Budapest, Falk Miksa utca 9-11.

Postal address: 1363 Budapest, Pf. 9.

Email: ugyfelszolgalat@naih.hu

Website: naih.hu

πŸ“§ How to exercise your rights?

Most GDPR rights can be exercised directly in CADENSA settings. If you need assistance:

Email:

πŸ•’ Response time: 30 days (GDPR Article 12.3). We will verify your identity for security purposes.

7. Data Security

We implement the following technical and organizational measures to protect your data:

  • Encryption: HTTPS/TLS for all data transmission, bcrypt password hashing
  • Access control: Role-based access control (RBAC), JWT tokens
  • Audit logging: All critical operations logged (login, data modification)
  • Regular backups: Daily automated backups, encrypted (Wasabi S3, EU data center)
  • Server hardening: Firewall, SSH key-based access, regular updates

8. International Data Transfers

Data is primarily stored within the European Union (Germany, France, Hungary). Transfers outside the EU only occur with GDPR-compliant safeguards:

  • Google LLC β€” Google Calendar (USA): The legal basis for the access is explicit consent under GDPR Article 6(1)(a); the basis for the transfer is an adequacy decision under Article 45 (EU–US Data Privacy Framework), under which Google LLC maintains a certification. In this relationship Google is an independent controller, not our processor. Only where the user activates the optional Google Calendar integration themselves.

US-incorporated providers with EU storage

Two of our sub-processors are US companies, even though they store the data in an EU region. For assessing transfers what counts is the contracting entity, not where the server physically sits β€” so we name them separately:

  • Vercel Inc. (USA): serving the static files of the public website and the application, in an EU edge region (fra1, Frankfurt). Data involved: IP address, user agent, request metadata. No time entries, projects or reports reach it β€” API calls go straight to the EU backend. Basis: Vercel DPA + SCCs.
  • Wasabi Technologies LLC (USA): object storage in Frankfurt (eu-central-2): encrypted database backups and the invoice PDF archive. Backups are encrypted with AES-256-GCM before upload and the key stays with us. Basis: Wasabi DPA + SCCs.

Every other sub-processor is an EU entity storing in the EU: Hetzner (DE), OVH Hosting Limited (contracting entity: IE, data centre: FR), Mollie (NL), Billingo (HU), Tarhely.eu (HU), Plausible (EE), Formbricks GmbH (DE). The complete, canonical list β€” with contracting entity, storage location and transfer basis β€” lives on the Sub-processors page; in case of any discrepancy, that page prevails.

9. Mobile Applications

The App Store and Google Play badges on the homepage are marked β€œcoming soon”: there is no released Cadensa app in either store at present. On mobile, the service is used through the browser, under exactly the same processing rules as on desktop.

When we release a native app, this section will be extended beforehand: we will describe how device identifiers, push notification tokens and any crash reporting are handled, and align both store disclosures (Apple Privacy Nutrition Label, Google Play Data Safety) with this policy. Our principle stays the same: no background location, no screen monitoring and no activity measurement in the mobile app either.

10. Automated Decision-Making and Profiling

Under GDPR Article 13(2)(f) we confirm that CADENSA does not carry out solely automated decision-making or profiling β€” including automated evaluation of employee performance β€” that produces legal effects concerning you or similarly significantly affects you. The reports and aggregations in the product are descriptive statistics: they make no decisions, produce no rankings, and trigger no automated action.

If we introduce such a feature in the future, we will announce it in advance and ship it together with the Article 22 safeguards (human intervention, right to contest).

11. Children's Privacy

CADENSA is not intended for children under 16 years of age. We do not knowingly collect data from individuals under 16.

How we enforce this: candidly: we do not verify age. We do not ask for a date of birth at sign-up and we use no age-estimation technology β€” for a time tracking tool that would be disproportionate data collection and would not add real protection. By accepting the Terms you declare that you are at least 16 and have legal capacity.

If we receive a report β€” from a parent, an employer, or through our own detection β€” that an account is used by someone under 16, we suspend the account, delete the personal data, and notify the reporter. Reports: privacy@cadensa.io. Where a young worker is invited by an employer, the employer is the controller and its own national age and labour law rules apply.

12. Changes to This Policy

We reserve the right to update this Privacy Policy from time to time. We will notify you of significant changes via email. The "Last updated" date indicates the most recent revision.

13. Contact Us

If you have questions about data privacy or want to exercise your GDPR rights:

Email:

Postal address:
Axeri Labs Bt.
2120 Dunakeszi, BrassΓ³i utca 7.
Hungary

πŸ•’ Response time: 30 days (as per GDPR Article 12.3)

βœ… GDPR Compliance

This Privacy Policy complies with the European Union General Data Protection Regulation (EU 2016/679) and the Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information.

Language of this document

This document is authored in English and Hungarian. On other language interfaces the English text is shown. In case of any discrepancy between the two versions, the English text prevails β€” except where the contracting party is a consumer resident in Hungary, in which case the Hungarian version applies. If you spot a discrepancy between the versions, please tell us at legal@cadensa.io and we will fix it.