Skip to main content

Data & Security FAQs

Single source of truth

For the processor chain, storage locations and third-country transfers, the authoritative document is the Sub-processors page. If anything on this page ever conflicts with it, that page prevails and this one is wrong — please tell us at privacy@cadensa.io.

Is my data secure?

Yes! Enterprise-grade security:

Encryption:

Data at rest: AES-256 encryption Data in transit: TLS 1.3 (minimum TLS 1.2) Database: Encrypted MongoDB Backups: AES-256-GCM encrypted before upload — the key stays with us File uploads: Encrypted (ENTERPRISE)

Infrastructure:

Hetzner hosting (Falkenstein / Nuremberg, Germany) OVHcloud Managed MongoDB (Gravelines, France, EU region) Static delivery: Vercel (EU edge region, fra1 / Frankfurt) Firewall protection

What we do not claim

We do not run annual penetration tests and we have no penetration test report to hand out — see "Can I request a security audit report?" below. Where this page lists a security measure, it is one that is actually in place today.

Access control:

Strong password requirements Two-factor authentication (2FA) — backup codes stored as bcrypt hashes Team invitation tokens: SHA-256 hashed before storage Audit log user agents: captured only for security/auth events (GDPR data minimisation) Admin access logs: operator email stored as SHA-256 hash only Billing PII (contact name, email, phone, VAT/tax numbers) excluded from general queries (database-level select: false — only returned when explicitly requested by billing endpoints) SSO/SAML (ENTERPRISE) (Coming Soon) IP allowlisting (ENTERPRISE) Session management Automatic logout (configurable)

More details: Security Settings →


Where is my data stored?

Data centers:

Primary region: Europe (Germany & France)

Why Europe? GDPR compliance EU data residency (Hetzner, OVHcloud) Low latency for European users Privacy-friendly jurisdiction

Infrastructure:

• Hosting: Hetzner Online GmbH (Falkenstein / Nuremberg, Germany) • Database: OVHcloud Managed MongoDB (Gravelines, France, EU) • Static delivery: Vercel (EU edge region, fra1 / Frankfurt) • Backups & invoice archive: Wasabi (eu-central-2, Frankfurt, Germany) • Email: Tarhely.eu (Hungary, EU)

All data is stored in the EU. Three of our sub-processors — Vercel, Wasabi and Sentry — are US-incorporated companies that store in an EU region; the transfer safeguards are set out on the Sub-processors page.

Where the data actually sits

Time entries, projects and reports live in the OVHcloud database (France) and the Hetzner cluster (Germany). Backups go to a single Wasabi region in Frankfurt — not three regions, and not geo-replicated. A monthly copy is kept for two years, so full erasure from every backup takes that long. If you need multi-region redundancy, tell us before you buy; today we do not offer it.

Backups:

Daily database backup at 02:00 UTC Daily copies kept 30 days Weekly copies (Sundays) kept 180 days Monthly copies (1st of the month) kept 2 years Single EU region: Wasabi eu-central-2 (Frankfurt, Germany) AES-256-GCM encrypted before upload — Wasabi cannot read them


Is CADENSA GDPR compliant?

Yes! Fully GDPR compliant:

Your rights:

Right to Access → Export your data anytime → Settings → Profile → Export Data

Right to Rectification → Edit your data in app → Update profile, time entries

Right to Erasure ("Right to be forgotten") → Delete account permanently → Settings → Profile → Delete Account

Right to Data Portability → Export in JSON/CSV formats → Take your data anywhere

Right to Object → Opt-out of marketing emails → Control notification preferences

Our commitments:

Data Processing Agreement (DPA) available Privacy by design and default Data minimization (collect only needed data) Consent-based processing Breach notification (within 72 hours) EU data storage (Germany & France) Published sub-processor list with 30 days' advance notice of changes

GDPR compliance is a legal obligation we meet, not a certificate anyone issues. Nobody has audited or certified it — if you see a "GDPR certified" badge for Cadensa anywhere, it is wrong and we want to know about it.

GDPR features:

Settings → Privacy:
• View data we collect
• Export all your data
• Delete your account
• Manage cookie preferences
• Review data processors
• Download DPA

Cookie management:

  • Granular cookie consent (Essential, Functional, Marketing)
  • Site analytics are cookie-free (Plausible — no consent required)
  • Easy opt-out anytime via Cookie Settings
  • Transparent cookie policy with full disclosure
  • Automatic deletion when categories disabled
  • Cookie Preferences Documentation →

Request a DPA: privacy@cadensa.io — available on every plan, including FREE.


What data do you collect?

Data we collect:

Account data:

Email address (required for login) Name (first, last) Password (encrypted, never stored in plain text) Profile picture (optional) Job title, department (optional) Phone number (optional, for 2FA)

Usage data:

Time entries (date, project, duration, description) Projects and tasks (names, budgets, settings) Workspace settings Reports generated Login history (IP address, browser/device string) Billing information (payment method, invoices)

We do not derive your location. No geolocation library runs in the backend, and the browser location permission is blocked at the HTTP header level (Permissions-Policy: geolocation=()). The IP address is stored for security purposes and cleared automatically — see the retention section below.

Technical data:

Browser type and version Device type (desktop/mobile) Operating system IP address (for security) Cookies (session, preferences)

Data we DON'T collect:

Browsing history outside CADENSA Keystrokes or screenshots Personal files on your device Data from other apps Unnecessary personal information

View your data:

Settings → Privacy → View Collected Data
• See exactly what we have
• Export anytime (JSON/CSV)
• Delete permanently

Can I delete my account and data?

Yes! Permanent deletion available:

Account deletion process:

1. Settings → Profile → Delete Account
2. Export your data first (recommended)
3. Enter password to confirm
4. Type "DELETE" to confirm
5. Click "Permanently Delete Account"
6. 7-day grace period begins

Grace period (7 days):

Days 1-6:
• Account deactivated (can't login)
• Data preserved
• Can cancel deletion
• Email sent with reactivation link

Day 7:
• Permanent deletion
• All data removed from production
• Irreversible

After day 7, your data survives only in backups, on this
schedule:
• Daily copies: up to 30 days
• Weekly copies: up to 180 days
• Monthly copies: up to 2 years

Backups are not searchable or editable — they are only
restored wholesale after an infrastructure failure. Nothing
from them re-enters production without a full restore.

What gets deleted:

Your account and profile All time entries Personal projects Workspace memberships Settings and preferences Login history Uploaded files

What's retained (legal requirement):

Kept for 8 years — Hungarian Accounting Act §169:
• Invoice history
• Payment records
These survive account deletion. We cannot delete them
on request; the retention obligation overrides erasure
(GDPR Art. 17(3)(b)).

Audit logs — 30 days (FREE), 90 days (PRO), 1 year (ENTERPRISE);
security events 1 year on every plan

After those periods: deleted.

The invoice archive sits under a WORM Object Lock at Wasabi: for the 8 years the Accounting Act requires, those PDFs cannot be altered or deleted by anyone — including us. That is the point of the lock, and it is also the reason an erasure request cannot reach them.

Workspace ownership:

If you own a workspace:
1. Must transfer ownership first
→ Settings → Workspace → Transfer
2. Or delete workspace entirely
3. Then can delete personal account

Who can access my data?

Access control:

Your team (within workspace):

Role-based access:

Admin: Full access to all data Can see all time entries Can edit workspace settings Can manage users

Manager: See team time entries Manage assigned projects Generate team reports Can't see billing

Member: See own time entries See assigned projects Can't see others' entries

Viewer: Read-only access See assigned projects Can't track time

On our side:

Cadensa is operated by a small team, and operator access is tied to a single named person. We are not going to claim a separation of duties we do not have:

Production access is limited to that one operator Every access is written to the audit trail The log covering your unit is available on request Support looks at your data only to resolve a ticket you opened Admin operator emails are stored as SHA-256 hashes only

Third parties:

We never sell your data No advertising partners No data mining No Google Analytics, no advertising or social media pixel

The full list, with contracting entity, storage location and transfer basis for each: cadensa.io/en/subprocessors

Data sharing (ENTERPRISE):

Client portal feature (Coming Soon):
• Share specific project reports
• Clients see only their project
• Controlled by you
• Can revoke anytime

What certifications do you have?

Security certifications:

SOC 2 Type II (not yet certified):

Not yet certified No audit currently in progress On our compliance roadmap for ENTERPRISE customers

Questions: support@cadensa.io

GDPR Compliance:

EU data residency Data Processing Agreement (DPA) Privacy by design Right to erasure Data portability Breach notification process

ISO 27001 (in progress):

Status: Not certified. Preparation is under way, with no fixed
completion date and no external assessment booked yet.
Do not treat this as a certification in a vendor questionnaire —
if you need ISO 27001 today, we do not have it.

HIPAA (not currently supported):

CADENSA does not currently offer a Business Associate Agreement (BAA)
or HIPAA-specific controls. Not recommended for storing PHI at this time.

If HIPAA support is a requirement for your organization, contact us —
we track demand for this on our roadmap:

Contact: support@cadensa.io

PCI DSS compliance (via Mollie):

Mollie B.V. payment processing (PCI DSS Level 1 certified) No card data stored by CADENSA Secure redirect-based checkout (card details never enter CADENSA servers) EU-based processor (Netherlands) — no US data transfer for payments


What happens if there's a data breach?

Breach response plan:

Detection:

• Automated error and performance alerting (Sentry, EU region)
• Infrastructure and uptime monitoring, with a public
status page at status.cadensa.io
• Application audit logs for security and auth events

We do not run an intrusion detection system, automated anomaly detection, or a staffed 24/7 security operations centre. Alerts reach a single on-call operator.

Response:

1. Isolate affected systems
2. Assess scope of breach
3. Contain and remediate
4. Preserve evidence for investigation

We aim to begin containment as soon as the alert is seen. We do not promise a one-hour response time, because with a team this size we cannot guarantee it.

Notification:

Within 72 hours (GDPR requirement):

Email to affected users:
• What data was accessed
• When breach occurred
• What we're doing about it
• Steps you should take

Email includes:
• Breach details
• Affected accounts
• Recommended actions
• Support contact

Where the breach is likely to result in a high risk to your rights, we notify you directly (GDPR Art. 34); the supervisory authority (NAIH) is notified within 72 hours under Art. 33.

Remediation:

1. Fix vulnerability
2. Enhanced monitoring
3. Password reset (if needed)
4. 2FA enforcement
5. Security audit
6. Public disclosure (if required)

To date:

We have had no reportable data breach. Cadensa is a young product in beta, so that says less about our track record than it may sound like — take it as a statement of fact, not as a security guarantee. Any future incident meeting the Art. 33 threshold will be reported here and to the affected customers.


How long do you keep my data?

Data retention:

Active accounts:

FREE plan:
• Last 30 days: Full access
• Older data: Read-only
• Forever: Not deleted unless you request

PRO plan:
• Last 1 year: Full access
• Older data: Read-only
• Forever: Not deleted unless you request

ENTERPRISE:
• All data: Forever (unless deleted)
• Custom retention policies available

IP addresses (GDPR Art. 5(1)(e) — storage limitation):

Last login IP address:
• Retained for up to 90 days after last login
• Cleared automatically by weekly cleanup job

Terms acceptance IP & user agent:
• Retained for up to 12 months after acceptance
• Cleared automatically by weekly cleanup job

Account deletion request IP:
• Retained for up to 2 years (audit trail)
• Cleared automatically by weekly cleanup job

Deleted accounts:

Day 0: Account deleted
• 7-day grace period
• Data preserved
• Can reactivate

Day 7: Permanent deletion
• Production data deleted
• Appears in backups for 30 days

Day 37: Full purge
• All backups purged
• Completely unrecoverable

Billing data:

Kept for legal compliance:
• Invoices: 8 years (Hungarian Accounting Act §169)
• Payment records: 8 years (Hungarian Accounting Act §169)

Even after account deletion

Retention periods for accounting records are set by national law, not by an EU-wide rule. As a Hungarian-established company we apply the Accounting Act's 8 years to every customer. If your own jurisdiction requires longer, that obligation is yours, not ours — export your invoices before you leave.

VIES validation snapshots (GDPR Art. 5(1)(e)):

EU VAT validation results (company name, address from VIES):
• Cleared after 180 days from validation date
• Cleared automatically by weekly cleanup job
• validatedAt date and valid flag are retained (no PII)

Audit logs:

• FREE: 30 days
• PRO: 90 days
• ENTERPRISE: 1 year
• Security events: 1 year on every plan

Backups:

• Daily copies: 30 days
• Weekly copies: 180 days (Sundays)
• Monthly copies: 2 years (1st of the month)
• One region: Wasabi eu-central-2 (Frankfurt, Germany)
• Same schedule on every plan — backup retention is not a tier feature

Can I request a security audit report?

Available for ENTERPRISE customers:

Available reports:

Security Questionnaire Responses • Standard vendor assessment • Customizable to your needs

Data Processing Agreement (DPA) • GDPR compliant • Available to all customers

ISO 27001 Certificate (once certified — no fixed date yet) • Once certified • Public document

Not yet available: SOC 2 Type II report, formal penetration test report. We're happy to answer specific security questions directly in the meantime.

How to request:

1. Email: <a data-action="security" href="#">security@cadensa.io</a>
2. Include:
• Company name
• Your role
• Document needed
• Purpose (vendor assessment, audit, etc.)
3. Receive within 2-3 business days

Do you use third-party services?

Yes, trusted partners only:

Infrastructure:

Hetzner Online GmbH • Purpose: Server hosting • Region: EU (Germany) • DPA: Yes • Certification: ISO 27001, TÜV-audited DPA

Vercel Inc. • Purpose: Serving static files for the website and app (hosting + CDN) • Contracting entity: ⚠️ United States (Delaware) • Region: EU edge region (fra1, Frankfurt) • Transfer: Vercel DPA + SCCs. Serving happens in the EU, but US engineers can access the system remotely for support — under the GDPR that access is a transfer even though the data stays in Frankfurt. Data involved: IP address, user agent, request metadata. • DPA: Yes (vercel.com/legal/dpa)

OVH Hosting Limited • Purpose: Managed database service (OVHcloud Public Cloud Databases for MongoDB) • Region: Data center — Gravelines, France (EU); Contracting entity — Dublin, Ireland (EU) • DPA: Yes • Certification: ISO/IEC 27001 (OVHcloud's own certification for its Cloud Databases product — not CADENSA's, see "What certifications do you have?" above)

Object storage (backups, invoices, profile pictures):

Wasabi Technologies LLC • Contracting entity: ⚠️ United States (Massachusetts) • Region: Germany (eu-central-2, Frankfurt) — one region, no geo-replication • Three separate buckets:

  1. Encrypted database backups, 30-day rolling retention AES-256-GCM encrypted before upload; the key stays with us, so Wasabi cannot read them
  2. Invoice PDF archive under WORM Object Lock COMPLIANCE 8-year immutable retention (Hungarian Accounting Act §169)
  3. Profile pictures — this bucket is publicly readable so the image can render in the interface. Do not upload anything there you would not put in public. Profile pictures are optional and can be deleted at any time. • Transfer: Wasabi DPA + SCCs (data stays in the EU, entity is US-based) • DPA: Yes (wasabi.com/legal/data-processing-addendum)

Invoicing & tax reporting:

Billingo Technologies Zrt. • Purpose: Electronic invoice issuance + NAV Online Számla 3.0 reporting • Region: EU (Hungary) • DPA: Yes (billingo.hu/adatvedelem) • Data transferred: customer name, billing address, tax/EU VAT number, email, invoice line items and amounts • Retention: 8 years (mandatory under Hungarian Accounting Act §169) • Sub-processors: NAV (Hungarian Tax Authority — mandatory legal reporting)

Payments:

Mollie B.V. • Purpose: Payment processing, subscription management • Region: Netherlands (EU) — Amsterdam • Security: PCI DSS Level 1 certified • DPA: Automatic upon registration (GDPR Art. 28 — EU processor) • Data: Payment mandate reference only (card details never touch CADENSA servers) • No US data transfer for payments

Communications:

Tarhely.eu (EZIT Kft.) • Purpose: SMTP email delivery • Region: EU (Hungary) • DPA: Yes (GDPR compliant) • Data: Email addresses only

Google services (independent controller, not our sub-processor):

Google LLC — Google Calendar integration Google LLC — Sign in with Google

Google is not our sub-processor, because it does not act on our instructions. When you connect your own Google account via OAuth, Google is an independent controller for its own service.

• Both are optional and off by default • Calendar runs with read-only scope, revocable in Settings → Integrations • Sign-in is never required — email and password always works • Transfer basis: GDPR Art. 45 adequacy decision (EU–US Data Privacy Framework) • Data we receive from sign-in: name, email address, profile picture • Data we store for calendar: OAuth token (AES-256 encrypted)

Analytics & Feedback:

Plausible Insights OÜ • Purpose: Cookie-free, identifier-free website analytics • Entity: Estonia (Tallinn) · Region: EU (Germany) • Legal basis: No consent required — no cookies, no personal data • DPA: Yes (plausible.io/dpa)

Formbricks GmbH • Purpose: Feedback, support and security report forms, NPS surveys • Entity: Germany (Kiel) · Region: Germany (EU) • Runs on the provider's cloud (app.formbricks.com) — not self-hosted • Whatever you type into one of those forms goes to them • Loaded only after consent to the functional cookie category • DPA: Yes (formbricks.com/dpa)

Monitoring:

Functional Software, Inc. (Sentry) • Purpose: Error logging and performance monitoring in the web app • Contracting entity: ⚠️ United States (San Francisco) • Region: EU data region (de.sentry.io, Germany) • Session replay is switched off — no screen content is captured • The production backend sends nothing to Sentry • Authorization and Cookie headers and the query string are stripped before an event is sent • Transfer: Sentry DPA + SCCs • DPA: Yes (sentry.io/legal/dpa)

All partners:

Art. 28 data processing agreement with every sub-processor EU storage region in every case SCCs where the contracting entity is US-based (Vercel, Wasabi, Sentry) 30 days' advance notice before a new sub-processor is added, with a right to object — subscribe at cadensa.io/en/subprocessors


Next Steps


Privacy Questions?

Response time: without undue delay, and within one month of receiving your request (GDPR Art. 12(3)). In practice most requests are answered in a few days, but one month is what we commit to.

We have not appointed a Data Protection Officer. Under Art. 37 we are not required to — we do not carry out large-scale systematic monitoring and we do not process special categories of data at scale. Data protection questions go to privacy@cadensa.io and are handled by the controller directly. You always have the right to lodge a complaint with the Hungarian supervisory authority (NAIH, naih.hu).