Cadey
Platform
AI chatbotAnswers, books meetings, and takes over liveCRMContacts, leads, companies & deals, yours or syncedSupport TicketsAI resolves first; tickets arrive with contextKnowledge BaseA help center that writes itselfLanding PagesLaunch on-brand pages that capture and book
IntegrationsPricingDocs
Talk to salesSign inGet started
LEGAL & TRUST CENTER

Data Processing Addendum

This addendum sets out how Cadey processes personal data on your behalf when you use the Service, and our commitments under the GDPR, UK GDPR and U.S. state privacy laws. It forms part of our agreement with you.

EffectiveJune 20, 2026Last updatedJune 20, 2026

Legal documents

OverviewTerms of ServicePrivacy PolicyAcceptable UseData Processing AddendumSubprocessorsCookie Policy
Questions?Email privacy@cadey.ai and a human will get back to you.
On this page
  1. Introduction and scope
  2. Definitions
  3. Roles and processing
  4. Processing on instructions
  5. Confidentiality
  6. Security measures
  7. Subprocessors
  8. Data-subject requests and assistance
  9. Personal-data breaches
  10. International transfers
  11. CCPA service-provider terms
  12. Return and deletion
  13. Audits
  14. Liability
  15. Annex A — Details of processing
  16. Annex B — Security measures
  17. Annex C — Subprocessors
How this works

This Data Processing Addendum (“DPA”) is incorporated into the Terms of Service between you (“Customer,” the controller) and Schwerd Capital Holdings LLC, doing business as Cadey.ai (“Cadey,” the processor) and applies where Cadey processes personal data on your behalf. If you need a countersigned copy for your records, email privacy@cadey.ai and we will provide one.

1Introduction and scope

This DPA reflects the parties' agreement on the processing of Customer Personal Data in connection with the Service. It applies to the extent Cadey processes Customer Personal Data that is subject to Data Protection Laws. In the event of a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA controls. The Standard Contractual Clauses referenced below, where they apply, control over this DPA.

2Definitions

Data Protection Laws
All laws and regulations applicable to the processing of personal data under the agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”).
Customer Personal Data
Personal data contained within Customer Data that Cadey processes on the Customer's behalf as a processor (or service provider) in providing the Service.
Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach
Have the meanings given in the GDPR (and equivalent terms in other Data Protection Laws).
Standard Contractual Clauses (SCCs)
The clauses approved by the European Commission in Decision 2021/914, and, for UK transfers, the UK International Data Transfer Addendum issued by the UK Information Commissioner.
Subprocessor
Any third party engaged by Cadey to process Customer Personal Data in connection with the Service.

3Roles and details of processing

The parties acknowledge that, with respect to Customer Personal Data, the Customer is the controller (or business), Cadey is the processor (or service provider), and Cadey engages Subprocessors as permitted below. Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that its instructions and actions, including appointing Cadey as a Subprocessor, are authorized by that controller. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex A.

4Processing on documented instructions

Cadey will process Customer Personal Data only on the Customer's documented instructions, including as set out in the Terms, this DPA, the configuration and features of the Service the Customer selects, and the Customer's use of the Service, and as necessary to comply with applicable law. The Terms and the Customer's use of the Service constitute the Customer's complete and final instructions. IfCadey is required by law to process Customer Personal Data otherwise, it will inform the Customer first unless the law prohibits it. Cadey will notify the Customer if, in its opinion, an instruction infringes Data Protection Laws.

5Confidentiality of processing

Cadey will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and are informed of the confidential nature of the data, and that access is limited to those who need it to provide the Service.

6Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Cadey will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. A description of these measures is set out in Annex B. Cadey may update its measures over time provided that the updates do not materially decrease the overall level of protection.

7Subprocessors

The Customer provides general authorization for Cadey to engage Subprocessors to process Customer Personal Data. Cadey maintains a current list of Subprocessors at cadey.ai/legal/subprocessors, which includes the name, processing activity and location of each. Cadey will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for each Subprocessor's performance.

Cadey will give notice of any intended addition or replacement of a Subprocessor (by updating the list and, on request, by a notification mechanism the Customer can subscribe to), giving the Customer the opportunity to object on reasonable data-protection grounds within the notice period. If the parties cannot resolve a reasonable objection, the Customer may, as its sole remedy, terminate the affected subscription.

8Data-subject requests and assistance

Taking into account the nature of the processing, Cadey will provide reasonable assistance, including through appropriate technical and organizational measures and the self-service features of the Service, to enable the Customer to respond to requests from data subjects to exercise their rights. If Cadey receives such a request directly relating to the Customer's data, it will, unless legally prohibited, promptly inform the Customer and direct the data subject to the Customer. Cadey will also provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, in each case relating to the Service and taking into account the information available to Cadey.

9Personal-data breaches

Cadey will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its breach-notification obligations. Notification will be sent to the contact associated with the Customer's account; keeping that contact current is the Customer's responsibility. Cadey will take reasonable steps to mitigate and remediate the breach. Cadey's notification is not an acknowledgment of fault or liability.

10International data transfers

The Customer authorizes Cadey to transfer Customer Personal Data to the United States and to other countries where Cadey or its Subprocessors operate. Where Cadey processes Customer Personal Data protected by EEA, UK or Swiss Data Protection Laws and transfers it to a country that has not received an adequacy decision, the SCCs are incorporated into this DPA by reference and apply to that transfer, with Cadey acting as “data importer” and the Customer as “data exporter.” The Module Two (controller-to-processor) clauses apply, or Module Three (processor-to-processor) where the Customer is itself a processor; the docking, audit and subprocessor options align with this DPA; the governing law and forum are those of the relevant EEA member state or, for UK transfers, England and Wales; and the annexes are completed by Annexes A, B and C of this DPA. For UK transfers, the UK Addendum applies; for Swiss transfers, references are read to include the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner.

11CCPA service-provider terms

To the extent Cadey processes personal information subject to the CCPA on the Customer's behalf, Cadey acts as a “service provider” and certifies that it: (a) will not sell or share that personal information; (b) will not retain, use, or disclose it except as necessary to perform the Service, for the business purposes specified in the agreement, or as otherwise permitted by the CCPA; (c) will not retain, use, or disclose it outside the direct business relationship between the parties; and (d) will not combine it with personal information from other sources except as permitted by the CCPA. Cadey will comply with applicable CCPA obligations and provide the same level of privacy protection required of service providers.

12Return and deletion of data

On termination or expiration of the Service, and on the Customer's request, Cadey will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage. As described in the Terms, Customer Data is available for export for 90 days after termination and is then deleted, with backup copies removed on Cadey's standard backup cycle.

13Audits and demonstrating compliance

Cadey will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports, certifications, and a security overview where available. To the extent the SCCs or Data Protection Laws grant an audit right that these materials do not satisfy, the Customer may, on reasonable prior written notice and no more than once per year (unless required by a supervisory authority or following a Personal Data Breach), conduct or mandate an audit, subject to confidentiality obligations, conducted during business hours, in a manner that does not disrupt Cadey's operations or compromise the security of other customers, and at the Customer's expense.

14Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort or any other theory, is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference in the Terms to the liability of a party means the aggregate liability of that party under the Terms and this DPA together.


AAnnex A — Details of processing

A.1 Parties

Data exporter / controller: the Customer identified in the account or order.
Data importer / processor: Schwerd Capital Holdings LLC, doing business as Cadey.ai, State of Florida, United States; contact privacy@cadey.ai.

A.2 Subject matter and duration

Subject matter: Cadey's provision of the Service to the Customer. Duration: the term of the agreement, plus the post-termination export and deletion period described in the Terms.

A.3 Nature and purpose of processing

Hosting, storage, transmission, retrieval, indexing and embedding, AI-assisted generation of responses, scheduling and booking, support-ticket handling, analytics, security, and related operations necessary to provide and support the Service on the Customer's instructions.

A.4 Categories of data subjects

The Customer's end users and website visitors; the Customer's prospects, leads and customers; the Customer's personnel, administrators and agents; and any other individuals whose personal data the Customer chooses to submit to the Service.

A.5 Types of personal data

Identifiers and contact details (such as name, email, phone); conversation and message content; meeting and scheduling details; support-ticket content; account and profile data; IP address and device or usage data; and any other personal data the Customer includes in Customer Data. The Service is not intended for special categories of data, and the Customer agrees not to submit them unless expressly agreed in writing with appropriate safeguards.

A.6 Frequency and competent authority

Frequency: continuous, for the duration of the agreement. Where the SCCs apply, the competent supervisory authority is that of the EEA member state in which the data exporter (or its EU representative) is established.

BAnnex B — Technical and organizational security measures

Cadey maintains measures that include, at a minimum:

  • Encryption: TLS 1.2 or higher for data in transit and AES-256 for data at rest; secrets and encryption keys held in a managed key-management or vault service.
  • Tenant isolation: row-level security enforced at the database keyed to tenant context, with the application connecting under a least-privilege, non-owner role, so one customer cannot access another customer's data.
  • Access control: role-based access, least-privilege provisioning, unique accounts, and authentication through a managed identity provider, with administrative access logged.
  • Network and application security: segmentation, firewalling, hardened configurations, and secure software-development practices including code review and dependency management.
  • Logging and monitoring: security logging, monitoring and alerting designed to detect and respond to anomalous or unauthorized activity.
  • Resilience and backup: encrypted backups and recovery procedures designed to restore availability after an incident.
  • Vendor management: assessment of Subprocessors and contractual data-protection obligations flowed down to them.
  • Personnel: confidentiality obligations, security awareness, and access tied to job role and revoked on termination.
  • Incident response: a documented process to detect, investigate, mitigate and notify relevant parties of security incidents.

CAnnex C — Subprocessors

Cadey's current Subprocessors, including each Subprocessor's name, processing activity and location, are listed and kept up to date at cadey.ai/legal/subprocessors, which forms part of this Annex C.

Questions about this document?

Reach our privacy team at privacy@cadey.ai, or contact us here. We respond to every message from a real person.

Schwerd Capital Holdings LLC, doing business as Cadey.ai · organized in the State of Florida, United States.

Back to the Legal & Trust Center

CadeyThe fully customizable AI chatbot that closes leads and handles support.
PlatformAI chatbotCRMSupport TicketsKnowledge BaseLanding pages
ConnectIntegrationsREST APIWebhooksZapier
DocsHelp CenterAPI referenceGuidesChangelog
CompanyPricingTalk to salesContact usSecurityLegal & Trust Center
© 2026 Schwerd Capital Holdings LLC · dba Cadey.ai. All rights reserved.
TermsPrivacyCookiesDPAAcceptable UseSubprocessors