This Data Processing Addendum (“DPA”) is incorporated into the Terms of Service between you (“Customer,” the controller) and Schwerd Capital Holdings LLC, doing business as Cadey.ai (“Cadey,” the processor) and applies where Cadey processes personal data on your behalf. If you need a countersigned copy for your records, email privacy@cadey.ai and we will provide one.
1Introduction and scope
This DPA reflects the parties' agreement on the processing of Customer Personal Data in connection with the Service. It applies to the extent Cadey processes Customer Personal Data that is subject to Data Protection Laws. In the event of a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA controls. The Standard Contractual Clauses referenced below, where they apply, control over this DPA.
2Definitions
- Data Protection Laws
- All laws and regulations applicable to the processing of personal data under the agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”).
- Customer Personal Data
- Personal data contained within Customer Data that Cadey processes on the Customer's behalf as a processor (or service provider) in providing the Service.
- Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach
- Have the meanings given in the GDPR (and equivalent terms in other Data Protection Laws).
- Standard Contractual Clauses (SCCs)
- The clauses approved by the European Commission in Decision 2021/914, and, for UK transfers, the UK International Data Transfer Addendum issued by the UK Information Commissioner.
- Subprocessor
- Any third party engaged by Cadey to process Customer Personal Data in connection with the Service.
3Roles and details of processing
The parties acknowledge that, with respect to Customer Personal Data, the Customer is the controller (or business), Cadey is the processor (or service provider), and Cadey engages Subprocessors as permitted below. Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that its instructions and actions, including appointing Cadey as a Subprocessor, are authorized by that controller. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex A.
4Processing on documented instructions
Cadey will process Customer Personal Data only on the Customer's documented instructions, including as set out in the Terms, this DPA, the configuration and features of the Service the Customer selects, and the Customer's use of the Service, and as necessary to comply with applicable law. The Terms and the Customer's use of the Service constitute the Customer's complete and final instructions. IfCadey is required by law to process Customer Personal Data otherwise, it will inform the Customer first unless the law prohibits it. Cadey will notify the Customer if, in its opinion, an instruction infringes Data Protection Laws.
5Confidentiality of processing
Cadey will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and are informed of the confidential nature of the data, and that access is limited to those who need it to provide the Service.
6Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Cadey will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. A description of these measures is set out in Annex B. Cadey may update its measures over time provided that the updates do not materially decrease the overall level of protection.
7Subprocessors
The Customer provides general authorization for Cadey to engage Subprocessors to process Customer Personal Data. Cadey maintains a current list of Subprocessors at cadey.ai/legal/subprocessors, which includes the name, processing activity and location of each. Cadey will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for each Subprocessor's performance.
Cadey will give notice of any intended addition or replacement of a Subprocessor (by updating the list and, on request, by a notification mechanism the Customer can subscribe to), giving the Customer the opportunity to object on reasonable data-protection grounds within the notice period. If the parties cannot resolve a reasonable objection, the Customer may, as its sole remedy, terminate the affected subscription.
8Data-subject requests and assistance
Taking into account the nature of the processing, Cadey will provide reasonable assistance, including through appropriate technical and organizational measures and the self-service features of the Service, to enable the Customer to respond to requests from data subjects to exercise their rights. If Cadey receives such a request directly relating to the Customer's data, it will, unless legally prohibited, promptly inform the Customer and direct the data subject to the Customer. Cadey will also provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, in each case relating to the Service and taking into account the information available to Cadey.
9Personal-data breaches
Cadey will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its breach-notification obligations. Notification will be sent to the contact associated with the Customer's account; keeping that contact current is the Customer's responsibility. Cadey will take reasonable steps to mitigate and remediate the breach. Cadey's notification is not an acknowledgment of fault or liability.
10International data transfers
The Customer authorizes Cadey to transfer Customer Personal Data to the United States and to other countries where Cadey or its Subprocessors operate. Where Cadey processes Customer Personal Data protected by EEA, UK or Swiss Data Protection Laws and transfers it to a country that has not received an adequacy decision, the SCCs are incorporated into this DPA by reference and apply to that transfer, with Cadey acting as “data importer” and the Customer as “data exporter.” The Module Two (controller-to-processor) clauses apply, or Module Three (processor-to-processor) where the Customer is itself a processor; the docking, audit and subprocessor options align with this DPA; the governing law and forum are those of the relevant EEA member state or, for UK transfers, England and Wales; and the annexes are completed by Annexes A, B and C of this DPA. For UK transfers, the UK Addendum applies; for Swiss transfers, references are read to include the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner.
11CCPA service-provider terms
To the extent Cadey processes personal information subject to the CCPA on the Customer's behalf, Cadey acts as a “service provider” and certifies that it: (a) will not sell or share that personal information; (b) will not retain, use, or disclose it except as necessary to perform the Service, for the business purposes specified in the agreement, or as otherwise permitted by the CCPA; (c) will not retain, use, or disclose it outside the direct business relationship between the parties; and (d) will not combine it with personal information from other sources except as permitted by the CCPA. Cadey will comply with applicable CCPA obligations and provide the same level of privacy protection required of service providers.
12Return and deletion of data
On termination or expiration of the Service, and on the Customer's request, Cadey will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage. As described in the Terms, Customer Data is available for export for 90 days after termination and is then deleted, with backup copies removed on Cadey's standard backup cycle.
13Audits and demonstrating compliance
Cadey will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports, certifications, and a security overview where available. To the extent the SCCs or Data Protection Laws grant an audit right that these materials do not satisfy, the Customer may, on reasonable prior written notice and no more than once per year (unless required by a supervisory authority or following a Personal Data Breach), conduct or mandate an audit, subject to confidentiality obligations, conducted during business hours, in a manner that does not disrupt Cadey's operations or compromise the security of other customers, and at the Customer's expense.
14Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort or any other theory, is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference in the Terms to the liability of a party means the aggregate liability of that party under the Terms and this DPA together.
AAnnex A — Details of processing
A.1 Parties
Data exporter / controller: the Customer identified in the account or order.
Data importer / processor: Schwerd Capital Holdings LLC, doing business as Cadey.ai, State of Florida, United States; contact privacy@cadey.ai.
A.2 Subject matter and duration
Subject matter: Cadey's provision of the Service to the Customer. Duration: the term of the agreement, plus the post-termination export and deletion period described in the Terms.
A.3 Nature and purpose of processing
Hosting, storage, transmission, retrieval, indexing and embedding, AI-assisted generation of responses, scheduling and booking, support-ticket handling, analytics, security, and related operations necessary to provide and support the Service on the Customer's instructions.
A.4 Categories of data subjects
The Customer's end users and website visitors; the Customer's prospects, leads and customers; the Customer's personnel, administrators and agents; and any other individuals whose personal data the Customer chooses to submit to the Service.
A.5 Types of personal data
Identifiers and contact details (such as name, email, phone); conversation and message content; meeting and scheduling details; support-ticket content; account and profile data; IP address and device or usage data; and any other personal data the Customer includes in Customer Data. The Service is not intended for special categories of data, and the Customer agrees not to submit them unless expressly agreed in writing with appropriate safeguards.
A.6 Frequency and competent authority
Frequency: continuous, for the duration of the agreement. Where the SCCs apply, the competent supervisory authority is that of the EEA member state in which the data exporter (or its EU representative) is established.
BAnnex B — Technical and organizational security measures
Cadey maintains measures that include, at a minimum:
- Encryption: TLS 1.2 or higher for data in transit and AES-256 for data at rest; secrets and encryption keys held in a managed key-management or vault service.
- Tenant isolation: row-level security enforced at the database keyed to tenant context, with the application connecting under a least-privilege, non-owner role, so one customer cannot access another customer's data.
- Access control: role-based access, least-privilege provisioning, unique accounts, and authentication through a managed identity provider, with administrative access logged.
- Network and application security: segmentation, firewalling, hardened configurations, and secure software-development practices including code review and dependency management.
- Logging and monitoring: security logging, monitoring and alerting designed to detect and respond to anomalous or unauthorized activity.
- Resilience and backup: encrypted backups and recovery procedures designed to restore availability after an incident.
- Vendor management: assessment of Subprocessors and contractual data-protection obligations flowed down to them.
- Personnel: confidentiality obligations, security awareness, and access tied to job role and revoked on termination.
- Incident response: a documented process to detect, investigate, mitigate and notify relevant parties of security incidents.
CAnnex C — Subprocessors
Cadey's current Subprocessors, including each Subprocessor's name, processing activity and location, are listed and kept up to date at cadey.ai/legal/subprocessors, which forms part of this Annex C.
Reach our privacy team at privacy@cadey.ai, or contact us here. We respond to every message from a real person.
Schwerd Capital Holdings LLC, doing business as Cadey.ai · organized in the State of Florida, United States.