Data & Security FAQs
Is my data secure?
Yes! Enterprise-grade security:
Encryption:
Data at rest: AES-256 encryption
Data in transit: TLS 1.3 (minimum TLS 1.2)
Database: Encrypted MongoDB
Backups: Encrypted S3 storage
File uploads: Encrypted (ENTERPRISE)
Infrastructure:
Hetzner hosting (Germany, EU region)
MongoDB Atlas (Frankfurt, EU — managed service)
CDN: Vercel (global, EU edge nodes)
Firewall protection
Regular security audits
Penetration testing (annual)
Access control:
Strong password requirements
Two-factor authentication (2FA) — backup codes stored as bcrypt hashes
Team invitation tokens: SHA-256 hashed before storage
Audit log user agents: captured only for security/auth events (GDPR data minimisation)
Admin access logs: operator email stored as SHA-256 hash only
Billing PII (contact name, email, phone, VAT/tax numbers) excluded from general queries (database-level select: false — only returned when explicitly requested by billing endpoints)
SSO/SAML (ENTERPRISE) (Coming Soon)
IP allowlisting (ENTERPRISE)
Session management
Automatic logout (configurable)
More details: Security Settings →
Where is my data stored?
Data centers:
Primary region: Europe (Germany)
Why Europe?
GDPR compliance
EU data residency (Hetzner)
Low latency for European users
Privacy-friendly jurisdiction
Infrastructure:
• Hosting: Hetzner Online GmbH (Germany) • Database: MongoDB Atlas (Frankfurt, EU — AWS eu-central-1) • CDN: Vercel (global with EU edge) • Email: Tarhely.eu (Hungary, EU)
All infrastructure:
Located in EU (data residency)
GDPR-compliant DPAs signed
Regular security audits
Backups:
Daily automated backups
30-day retention (PRO)
90-day retention (ENTERPRISE)
Geo-redundant storage (3 regions)
Encrypted at rest
Regular restore testing
Is CADENSA GDPR compliant?
Yes! Fully GDPR compliant:
Your rights:
Right to Access
→ Export your data anytime
→ Settings → Profile → Export Data
Right to Rectification
→ Edit your data in app
→ Update profile, time entries
Right to Erasure ("Right to be forgotten")
→ Delete account permanently
→ Settings → Profile → Delete Account
Right to Data Portability
→ Export in JSON/CSV formats
→ Take your data anywhere
Right to Object
→ Opt-out of marketing emails
→ Control notification preferences
Our commitments:
Data Processing Agreement (DPA) available
Privacy by design and default
Data minimization (collect only needed data)
Consent-based processing
Breach notification (within 72 hours)
EU data storage (Frankfurt)
Regular compliance audits
GDPR features:
Settings → Privacy:
• View data we collect
• Export all your data
• Delete your account
• Manage cookie preferences
• Review data processors
• Download DPA
Cookie management:
Granular cookie consent (Essential, Functional, Marketing)
Site analytics are cookie-free (Plausible — no consent required)
Easy opt-out anytime via Cookie Settings
Transparent cookie policy with full disclosure
Automatic deletion when categories disabled
- Cookie Preferences Documentation →
Request DPA: support@cadensa.io
What data do you collect?
Data we collect:
Account data:
Email address (required for login)
Name (first, last)
Password (encrypted, never stored in plain text)
Profile picture (optional)
Job title, department (optional)
Phone number (optional, for 2FA)
Usage data:
Time entries (date, project, duration, description)
Projects and tasks (names, budgets, settings)
Workspace settings
Reports generated
Login history (IP, device, location)
Billing information (payment method, invoices)
Technical data:
Browser type and version
Device type (desktop/mobile)
Operating system
IP address (for security)
Cookies (session, preferences)
Data we DON'T collect:
Browsing history outside CADENSA
Keystrokes or screenshots
Personal files on your device
Data from other apps
Unnecessary personal information
View your data:
Settings → Privacy → View Collected Data
• See exactly what we have
• Export anytime (JSON/CSV)
• Delete permanently