Data Processing Addendum (DPA)
Last updated: 11 June 2026 · Effective: 11 June 2026
This Data Processing Addendum ("DPA") forms part of the agreement between GTW Scaling Solutions S.R.L. ("Cadenus", the "Processor") and the customer workspace owner (the "Controller") for the use of the Cadenus service, and reflects the parties' obligations under Regulation (EU) 2016/679 ("GDPR").
1. Subject matter and duration
Cadenus processes personal data on the Controller's behalf to provide the agency operations service (production pipeline, client approvals, publishing, finance, collaboration) for the duration of the subscription, until deletion of the workspace in accordance with the agreement.
2. Nature and purpose of processing
Storage, organization, display, transmission and deletion of data the Controller and its users enter into the service — solely to provide, secure and support the service. Cadenus does not sell personal data and does not use Controller content for advertising.
3. Categories of data and data subjects
- Data subjects: the Controller's team members, clients and client contacts, and leads.
- Data categories: names, email addresses, account identifiers, work content (briefs, media, comments, approvals), scheduling and financial records the Controller chooses to store.
4. Processor obligations
- Process personal data only on documented instructions from the Controller, including with regard to international transfers.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational measures (tenant isolation with row-level security, encrypted credentials at rest, HttpOnly sessions, role-based access, audit logging, daily offsite backups — see the Security page).
- Assist the Controller in responding to data-subject requests (the service provides self-serve export and deletion).
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the provision of services, except where law requires retention.
- Make available information necessary to demonstrate compliance and allow audits as required by Art. 28(3)(h) GDPR.
5. Subprocessors
The Controller provides general authorization for the subprocessors Cadenus uses to deliver the service (hosting, database, content delivery and streaming, payments, transactional email, AI processing and error monitoring). The current list is available on request at contact@cadenus.io; Cadenus will inform the Controller of intended changes, and the Controller may object on reasonable data-protection grounds.
6. International transfers
Primary hosting and the database are in the EU. Where a subprocessor processes data outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
7. Contact
To execute this DPA or ask questions: contact@cadenus.io.