Draft: this text is still being reviewed by a lawyer.
Data processing agreement
This data processing agreement belongs to the agreement between the customer and legal name, trading as TimeInvest, KvK KvK number, address (TimeInvest or the processor), for the use of Cadence. The customer is the controller. The customer accepts this agreement when it creates its organisation or takes out a subscription; an administrator can do so on the customer’s behalf. Terms have the meaning given in the General Data Protection Regulation (GDPR). This is a translation of the Dutch version; if the two differ, the Dutch version prevails.
1. Subject
- TimeInvest processes personal data on the customer’s behalf, only to provide Cadence as described in the agreement and the terms of service. Annex 1 describes the processing: its purpose, the types of data and the data subjects.
- This agreement applies for as long as TimeInvest processes personal data for the customer.
2. The customer’s instructions
- TimeInvest processes the personal data only on the customer’s documented instructions. The customer’s use of Cadence, and the settings administrators choose, count as such instructions.
- If TimeInvest believes an instruction infringes the GDPR, it tells the customer immediately.
- If TimeInvest is legally required to process data, for example by court order, it tells the customer in advance, unless the law forbids that.
3. The customer’s responsibility
The customer decides what Cadence is used for and ensures a valid legal basis. The customer informs its staff, obtains the works council’s consent where needed, and carries out a data protection impact assessment (DPIA) where needed. Cadence provides the information for this, among other places on the Your data page and under Privacy and data location.
4. Confidentiality
TimeInvest ensures that everyone who has access to the personal data on its behalf is bound to confidentiality.
5. Security
- TimeInvest takes appropriate technical and organisational measures to secure the personal data. Annex 2 describes them.
- TimeInvest may change the measures, as long as the level of security does not decrease.
6. Sub-processors
- The customer gives TimeInvest general authorisation to engage sub-processors. The current list is in Annex 3 and on the Sub-processors page.
- If TimeInvest wants to add or replace a sub-processor, it tells the customer’s administrators at least 30 days in advance. The customer can object on reasonable grounds within that period. If the parties cannot agree, the customer can end the agreement before the change takes effect.
- TimeInvest imposes the same obligations on every sub-processor as in this agreement, and remains responsible to the customer for its sub-processors.
- Connections the customer switches on itself, such as Jira, Azure DevOps, Slack, Microsoft 365, Google Calendar or an AI provider, are not sub-processors of TimeInvest. The customer chooses those services and has its own agreement with them; TimeInvest only exchanges data with them on the customer’s instructions.
7. Transfers outside the EU
TimeInvest processes the personal data in the European Economic Area. Transfers outside it happen only where the GDPR allows them, for example on the basis of an adequacy decision or standard contractual clauses. Annex 3 states where that is the case.
8. Data subjects’ rights
- Cadence contains tools with which the customer can handle data subjects’ requests itself: seeing what is recorded about someone, exporting, correcting and erasing, with recorded evidence of how a request was handled.
- If a request reaches TimeInvest, it forwards it to the customer. Where needed, TimeInvest helps the customer answer within the legal deadline.
9. Personal data breaches
- TimeInvest notifies the customer of a personal data breach without undue delay, and where possible within 48 hours of discovering it. That way the customer can notify the supervisory authority within 72 hours, where needed.
- The notification contains what is known at that moment: the nature of the breach, the data and people concerned, the likely consequences and the measures taken. TimeInvest supplements the notification as more becomes known.
- Notifying the supervisory authority and data subjects is the customer’s responsibility. TimeInvest helps with it.
10. Assistance
TimeInvest reasonably assists the customer with a DPIA and with a prior consultation of the supervisory authority, with the information it has.
11. Audits
- TimeInvest makes available to the customer the information needed to demonstrate that it complies with this agreement.
- If that information is insufficient, the customer may have an audit carried out once a year by an independent expert bound to confidentiality, after at least 30 days’ notice. The audit disrupts operations as little as possible. The costs are the customer’s, unless the audit shows a material shortcoming.
12. End of the processing
- During the agreement, administrators can download all data of their organisation at any time.
- After the agreement ends, or earlier at the customer’s request, TimeInvest deletes the personal data. Deletion takes place 30 days after the request, so that the customer can still change its mind. Encrypted backups are overwritten automatically after at most 14 days.
- After deletion, TimeInvest keeps only a record of it: the organisation’s name, the dates and the number of deleted records, and no personal data of staff.
- A legal retention obligation may postpone the deletion of certain data; TimeInvest then uses that data for nothing else.
13. Liability
The parties’ liability is governed by the terms of service.
14. Final provisions
Where this agreement conflicts with other arrangements, this agreement prevails as regards the processing of personal data. This agreement is governed by Dutch law.
Annex 1: the processing
Purpose. Providing Cadence: teams rate their ceremonies, run pulse checks, follow up retrospectives, impediments and actions, and look at trends, all with privacy as the starting point.
Data subjects. The customer’s employees and contractors who use Cadence or appear in it, and external participants the customer invites, such as stakeholders giving review feedback.
Types of data.
- Identity and account: name, work email address, language, teams, role, rights, sign-in details (a link with the organisation’s own Microsoft or Google environment, or a hash of a password and two-step sign-in settings).
- Participation: that someone rated a ceremony or answered a pulse check. Scores are stored without a name and without a time, and only once at least 3 people have answered.
- Content users enter: notes, impediments, actions, working agreements, team canvases, postmortems, OKRs, personal notes of Scrum Masters and coaches.
- Planning: absence dates without a reason, ceremonies from the connected calendar.
- Delivery data from connected services, without titles, descriptions or comments.
- Optional, only if the customer switches it on: Meeting Persona Assessment results (visible only to the person themselves), and features of meeting transcripts in which every name has been replaced.
- An audit log of important actions.
Special categories of personal data are not knowingly processed; Cadence asks users to leave them out.
Retention periods. As described in the privacy statement, section 4. Cadence applies them automatically.
Location. Data centres in the European Union: Germany, with backups also at a second Hetzner location in the EU.
Annex 2: security measures
- Separation of customers: every organisation is shielded in the database with row-level security; the application cannot read another organisation’s data.
- Privacy by design: anonymous scores, minimum numbers for showing and storing results, no rankings of teams, optional functions off by default.
- Encryption: all connections over https (TLS); connection secrets and tokens stored encrypted; backups encrypted before they reach a disk.
- Signing in: through the customer’s own Microsoft or Google environment, or with a password stored only as a scrypt hash, with two-step sign-in; limits on sign-in attempts and a temporary lock after repeated failures.
- Access at TimeInvest: the admin console shows only settings and counts; server access only for a few administrators with a personal key.
- Accountability: an audit log the application can add to, but not change.
- Retention: applied automatically per data category.
- Operations: automatic security updates of the operating system, automated tests with every change, separate test and production environments, monitoring of availability and certificates, and error reporting with personal data removed.
- Continuity: daily encrypted backups, kept 14 days, also at a second location in the EU, and a monthly restore rehearsal.
Annex 3: sub-processors
| Sub-processor | What | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of servers, database and backups | Germany (EU); backups also at a second location in the EU |
| Scaleway SAS | Sending email: invitations, sign-in links, notices | France (EU) |
| Stripe Payments Europe, Ltd. | Payments and invoices; only data of the billing contact | Ireland (EU); possible transfer to Stripe, Inc. (US) on the basis of the EU-US Data Privacy Framework and standard contractual clauses |
Version 1.0 · effective date