Last updated: August 21, 2026
This Privacy Policy explains how Cdaeris Agency (“Cdaeris”, “we”, “us”) handles personal information across everything we run:
- the cdaeris.com website, including our store and booking forms;
- our consulting and advisory services;
- Cadence — our meetings, tasks, time and business-reporting application at cadence.cdaeris.com;
- Ascend — our learning platform and client portal at ascend.cdaeris.com.
1. Two different roles — please read this first
Not all data we touch is the same kind of data, and the difference matters to your rights and to our obligations.
- Data we control (Part A). Information about you that we collect and decide how to use — website enquiries, marketing contacts, account records, billing, and how our products are used. For this data Cdaeris is the controller (in some laws, “business”).
- Customer Data we process for you (Part B). Business records that a customer organisation puts into, or connects to, Cadence or Ascend — their tickets, invoices, tasks, meeting notes, employee time, contact lists, applicant records and similar. We handle that data only on that organisation’s instructions, for the purpose of running the product for them. For this data Cdaeris is a processor (in some laws, “service provider”), and the customer organisation is the controller.
If your employer or a company you deal with gave your information to Cadence or Ascend, that organisation — not Cdaeris — decides what happens to it. We will help you reach them, and Part B explains what we do and do not do with it.
Part C applies to both.
Part A — Data we control
2. Website visitors, enquiries and customers
We collect what you give us through forms, bookings, checkout and correspondence. Typically:
- name, email address, phone number and company name;
- appointment and booking details;
- the content of your enquiry or message;
- order and purchase details if you buy through our store;
- newsletter and event sign-ups.
Our website runs on WordPress with WooCommerce. Standard server, cache and security logs — including IP address, browser user agent and request time — are generated automatically and used to keep the site running and defended.
3. Account holders in Cadence and Ascend
To give you an account we hold identity and access records: your name, email address, the organisation you belong to, your role and permission level, your preferences, and authentication records held by our identity providers. Sign-in is handled by Clerk and, for Cdaeris staff and some client accounts, by Microsoft Entra ID. We do not store your password.
In Ascend we also hold your learning record: enrolments, lesson and course progress, quiz results, completions and any certificate issued to you.
4. Billing
Subscription and purchase payments are processed by Stripe, and website store orders may also be processed by PayPal. Those providers handle your card or account details directly. Cdaeris never receives or stores full payment card numbers. We keep the records we need to run the account and meet our tax and accounting obligations: what was bought, when, the amount, tax, and the status of the payment.
5. Cookies, analytics and tracking on cdaeris.com
Our website uses cookies and similar technologies for the following purposes:
- Necessary — session, checkout and shopping-cart cookies set by WordPress and WooCommerce; caching cookies set by LiteSpeed Cache; security cookies set by Wordfence.
- Analytics — Google Analytics 4 (measurement ID
G-HG2TX1VNEY), loaded client-side, to understand which pages are used and how visitors move through the site. We also use Rank Math connected to Google Search Console, which reports aggregate search queries and positions rather than individual people. - Functional — Jetpack, for site features and statistics.
You can refuse or delete cookies in your browser settings, and you can opt out of Google Analytics using Google’s browser add-on. Blocking necessary cookies will break checkout and sign-in.
Cadence and Ascend do not run advertising or cross-site tracking cookies. They set only the cookies needed to keep you signed in and to remember your interface preferences.
6. Product usage analytics inside Cadence
So that we can see which parts of the product are actually used, support customers, and prioritise development, Cadence records a usage event for each signed-in page view and for a small set of key actions (for example completing a task, concluding a meeting, logging time). Each event stores your email address, your display name, whether you are Cdaeris staff or a client user, the area and page path, the action, and the time. This is first-party product telemetry — not advertising, and not shared with any analytics vendor.
7. How we use Part A data, and why we are allowed to
- To provide what you asked for — answer enquiries, manage bookings, deliver consulting, run your account, deliver courses, issue certificates. Basis: performance of a contract, or your request.
- To bill and keep records — invoicing, tax, accounting, dispute resolution. Basis: contract and legal obligation.
- To operate, secure and improve our products — diagnostics, abuse prevention, capacity planning, product decisions. Basis: our legitimate business interests.
- To send marketing — newsletters, offers and event invitations. Basis: your consent, or an existing business relationship where the law allows it. Every marketing message carries an unsubscribe link, and unsubscribing does not affect service messages about your account.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Part B — Customer Data we process for you
8. What this covers
When an organisation subscribes to Cadence or Ascend, it puts its own business records into the product and may authorise the product to read records out of systems it already uses. Cdaeris processes all of that only to provide the product to that organisation, on its instructions.
In Cadence, Customer Data typically includes:
- Created in the product: tasks and task notes, meetings, agendas, issues, headlines, goals and milestones, scorecard metrics and measurements, dashboards, business plans, time entries, client and contact records, and any file or image attached to them.
- Read from systems the customer connects, at the customer’s direction: ConnectWise Manage and Datto Autotask (tickets, agreements, time entries, contacts, companies); QuickBooks Online and QuickBooks Desktop (invoices, billing items, accounts, financial reports); IT Glue and SharePoint (documentation); JazzHR (job applicants and hiring stages); Google Analytics 4 (aggregate website reporting); Microsoft 365 via Microsoft Graph (mail, calendar, Planner tasks, Teams messages, SharePoint documents); and LinkedIn (organisation and personal posting and analytics).
Connections are made by an administrator of the customer organisation, using that organisation’s own credentials, and can be revoked by that administrator at any time. Access is read-only except where a feature plainly requires otherwise, which brings us to the next point.
9. Two things worth calling out plainly
Sending email as you. Cadence’s client-conversation feature sends email through Microsoft 365 using delegated permission for the signed-in user. Messages therefore leave from that user’s own mailbox and appear in their Sent Items. Cadence does not send mail from a user’s mailbox except when that user, or a workflow they configured, asks it to.
Meeting summaries and transcripts. If a customer connects Granola, Cadence retrieves the summary and the full transcript of matching meetings and stores them against the meeting record. When a meeting is concluded, its content is frozen into a snapshot for the historical record. Recording or transcribing a conversation carries legal obligations that vary by province and state, and consent is sometimes required from every participant. Responsibility for obtaining that consent rests with the customer organisation running the meeting, not with Cdaeris.
10. Ascend organisations and learner visibility
Where an organisation buys Ascend for its people, an organisation administrator can see the membership and learning progress of the learners in that organisation — enrolments, completion status and certificates. If your employer pays for your Ascend access, assume your progress is visible to them.
11. Artificial intelligence features
Some features send Customer Data to an AI provider to generate a result. We use Anthropic (Claude) for task prioritisation scoring, generating metric and report definitions, importing business-plan documents, and drafting social and advocacy content. Draft social content may additionally be sent to WalterWrites, an AI text-rewriting service, to produce an alternative version alongside the original.
- Only the content needed for the request is sent.
- Cdaeris does not train any model on Customer Data, and we use these providers under terms that do not permit them to train their models on data we submit through their APIs.
- AI output can be wrong. It is presented as a draft or a suggestion for a person to review, and it is not used to make any decision about an individual that has legal or similarly significant effect.
12. Our commitments on Customer Data
- We process it only to provide and support the product, and only on the customer’s instructions.
- We do not sell it, rent it, or use it for advertising.
- We do not use it for our own commercial purposes, including product development, other than aggregated and de-identified operational statistics that cannot identify any person or organisation.
- We keep each customer’s data logically separated and access-controlled within the product.
- Cdaeris staff access it only as needed for support, troubleshooting or as the customer instructs. Administrators can use a support impersonation feature to view the application as another user in order to reproduce a problem; use of it is recorded and visibly indicated in the interface.
- We use subprocessors only as listed in section 13, and hold them to equivalent obligations.
- We will tell the customer without undue delay if we become aware of a personal data breach affecting their Customer Data, and assist them in meeting their own notification duties.
- If an individual asks us directly to access, correct or delete Customer Data, we will refer them to the customer organisation and support that organisation’s response rather than acting unilaterally.
- On termination we return or delete Customer Data as set out in section 16.
Customers who need these commitments in a signed contract, with the detail their own regulator or auditor expects, can request a Data Processing Agreement from us at growth@cdaeris.com.
Part C — Applies to everything
13. Service providers and subprocessors
We rely on the following providers. This list is current as at the date at the top of this policy, and we will update it here when it changes.
| Provider | What it does for us | Where |
|---|---|---|
| Vercel | Application hosting for Cadence and Ascend | United States |
| Neon | Managed PostgreSQL database | United States |
| Clerk | Authentication, organisations and memberships | United States |
| Microsoft | Entra ID sign-in; Microsoft 365 and Graph; transactional email | Canada / United States |
| Anthropic | AI features (see section 11) | United States |
| WalterWrites | AI rewriting of draft social content | United States |
| Liveblocks | Real-time collaborative editing of meeting and agenda content | United States |
| Trigger.dev | Scheduled and background job processing | United States |
| Granola | Meeting summaries and transcripts, where connected | United States |
| Cloudflare | DRM-protected course video delivery for Ascend | Global edge network |
| Stripe | Subscription and purchase payment processing | United States |
| PayPal | Website store payment processing | United States |
| ActiveCampaign | Email marketing and contact management | United States |
| Zapier | Automated transfers between our tools | United States |
| Calendar for bookings; Analytics and Search Console for site measurement | United States | |
| Automattic (Jetpack), LiteSpeed, Wordfence | Website features, caching and security | United States |
Systems that a customer connects to Cadence — such as ConnectWise, Autotask, QuickBooks, IT Glue, JazzHR or LinkedIn — are that customer’s own vendors, not our subprocessors. We read from them under the customer’s own credentials and authorisation.
We may also disclose information where we are legally required to, to enforce our terms, or in connection with a merger or sale of the business — in which case we will require the recipient to honour this policy.
14. Where your data is held, and transfers
Cdaeris is based in British Columbia, Canada. Our products are hosted with providers operating primarily in the United States, and the providers listed above may process data there or in other countries. Data held outside Canada is subject to the laws of the country it is held in, including lawful access requests by that country’s authorities. Where we transfer personal data out of the UK, EEA or Switzerland we rely on the applicable transfer mechanism, including Standard Contractual Clauses.
15. Security
We take reasonable technical and organisational measures to protect information, including:
- encryption in transit (HTTPS/TLS) for all our web properties;
- encryption at rest by our database and storage providers;
- additional application-level AES-256-GCM encryption for the most sensitive values we hold — the credentials and OAuth refresh tokens customers use to connect their own systems;
- role-based access control and per-customer access gating inside the products;
- single sign-on with multi-factor authentication available for staff and client accounts;
- DRM and signed, expiring URLs for Ascend course video.
No system can be guaranteed completely secure. Keep your credentials confidential and tell us promptly if you believe an account has been compromised.
16. How long we keep things
- Enquiries and marketing contacts — until you unsubscribe or ask us to delete them, and then removed from active use.
- Account records — for as long as the account is active.
- Billing and tax records — for the period Canadian tax law requires, currently six years.
- Product usage analytics — retained as an operational log; we do not use it after it stops being useful for support and product decisions.
- Customer Data — for as long as the subscription is active. After termination we keep it for 30 days so the customer can export it, then delete it from live systems. Residual copies in encrypted backups age out within 90 days.
We may keep information longer where we must for legal, tax or dispute-resolution reasons.
17. Your rights
Subject to the law that applies to you, you can ask us to:
- confirm what personal information we hold about you and give you access to it;
- correct information that is wrong or incomplete;
- delete information we no longer need to keep;
- stop sending you marketing;
- withdraw a consent you previously gave;
- provide your information in a portable form, or explain how we handled it.
Write to growth@cdaeris.com. We will respond within the time the applicable law allows — 30 days under Canada’s PIPEDA and British Columbia’s PIPA. We may need to verify who you are first, and we will not discriminate against you for exercising a right.
If your request concerns Customer Data — data your employer or a company you deal with placed in Cadence or Ascend — we will pass your request to that organisation and support their response. They, not we, decide the outcome.
If you are unhappy with how we handled a privacy matter you may complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner for British Columbia. Individuals in the UK or EEA may complain to their own supervisory authority.
18. Google API data
Where a customer connects Google Analytics, Cdaeris’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only Google Analytics scopes, retrieve only aggregate report data and the list of properties the connected account can see, never request write access, never use Google user data for advertising, and never transfer it to a third party except as needed to provide the reporting the customer asked for. A connection can be revoked at any time from inside Cadence or from the Google account’s own third-party access settings.
19. Children
Our website, products and services are intended for business use by people aged 18 or over. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.
20. Third-party websites
Our website and products link to services we do not control. We are not responsible for their privacy practices — review their policies separately.
21. Changes to this policy
We may update this policy. The revision date at the top always shows the current version, and the provider list in section 13 is maintained here. If a change materially reduces the protection given to Customer Data, we will notify affected subscribing organisations by email at least 30 days before it takes effect.
22. Contact us
Cdaeris Agency
Privacy enquiries and rights requests: growth@cdaeris.com
British Columbia, Canada
Website: cdaeris.com
Related document: Terms of Service.
