CadenceNederlands

Draft: this text is still being reviewed by a lawyer.

Privacy statement

Cadence helps teams rate and improve their ceremonies, with privacy as its starting point. This statement explains which data Cadence processes, why, for how long, and which rights you have. Cadence is provided by legal name, trading as TimeInvest, KvK KvK number, address (TimeInvest, we). This is a translation of the Dutch version; if the two differ, the Dutch version prevails.

1. Who is responsible?

That depends on the data.

2. How Cadence handles privacy

Cadence is built to need to know as little as possible about people.

On the Your data page in Cadence you see exactly what is recorded about you.

3. Which data Cadence processes

DataPurposeLegal basis
Name, work email address, language, teams and roleYour account, signing in, making your teams workLegitimate interest of your organisation; performance of the agreement
Sign-in details: the link with your Microsoft or Google account, or an encrypted hash of your password and your two-step sign-in settingsSigning in securelyAs above
That you rated a ceremony (without the score)Calculating the response rateLegitimate interest of your organisation
Notes, impediments, actions and their ownersFollowing up retrospectives and improvementsLegitimate interest of your organisation
Personal notes your Scrum Master or coach keeps about youCoachingLegitimate interest of your organisation; you can see them
Answers to pulse checks (anonymous by default)Gauging how the team is doingLegitimate interest of your organisation
Absence dates (never a reason)Planning the team’s capacityLegitimate interest of your organisation
Data from connected services, such as sprints and work items from Jira or Azure DevOps (no titles or descriptions)The team’s delivery figuresLegitimate interest of your organisation
An audit log of important actions, such as who viewed which team dataSecurity and accountabilityLegitimate interest; legal obligation
Optional: your Meeting Persona Assessment resultInsight into your own meeting style; only you see your resultYour choice to take part
Optional: features of meeting transcripts, without namesSummaries, decisions and suggested actionsLegitimate interest; only if your organisation switches it on, with the works council’s consent

For our own customer relationship we process the name, email address and billing details of the customer’s contact person (basis: performance of the agreement and the legal retention obligation), and the messages you send us (basis: legitimate interest, so that we can help you).

4. How long data is kept

Cadence deletes data automatically according to these periods. Your organisation can have data deleted earlier.

DataRetention
A score awaiting release (apart from your name)at most 2 days
Anonymous ratings of ceremonies5 years
Notes with ceremonies3 years
Personal and coaching notes1 year
Impediments and actions3 years
Response records (that you answered)3 years
Absence dates1 year
Delivery data from connected services3 years (raw synchronised data: 90 days)
Anonymous answers to pulse checks3 years
Named answers to pulse checks90 days
Meeting Persona Assessment result12 months
Team persona overviews (counts only)3 years
Features of meeting transcripts2 years (the transcript text itself: at most 4 hours)
Team memberships and the audit log7 years
Encrypted backups14 days
Invoices and billing details (TimeInvest)7 years, because of the tax retention obligation

When an organisation stops using Cadence, all its data is deleted 30 days after the request. After that, only a record of the deletion remains: the organisation’s name, the dates and the number of deleted records.

5. Who can see the data

We do not sell data, do not use it for advertising and do not train AI models with it.

6. Data outside the EU

Cadence itself runs in the EU. Two exceptions:

7. Security

Among other things, we protect data with encrypted connections (https), passwords stored only as a strong hash, two-step sign-in, strict separation of organisations in the database, encrypted backups also kept at a second location, automatic security updates, an audit log, and as few people with access as possible. More detail is in the annex to the data processing agreement.

8. Cookies and storage in your browser

Cadence uses only functional cookies: to keep you signed in, to protect forms against misuse, and temporarily while signing in. There are no cookies for statistics or advertising, and no trackers of others. That is why we do not ask for cookie consent.

In your browser, Cadence also keeps a few preferences, such as your theme and language, and the Your notes list, with which you follow your own anonymous notes. That list is only on your device. You receive push notifications only if you switch them on yourself.

9. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection. For your data in Cadence, you make a request to your own organisation, for example through Your data in Cadence. Your organisation answers within 30 days; we help with that. We cannot link ratings to you, not even on request: they were never stored linked to you.

For data TimeInvest itself is responsible for, contact us at email address.

If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the authority in your own country. We would like to hear it first, so that we can solve it.

10. Changes

We update this statement when Cadence or the law changes. For important changes, we tell the administrators of customer organisations in advance. The date of the latest version is at the bottom.

11. Contact

TimeInvest · address · email address · KvK KvK number

Version 1.0 · effective date