Cadence SM
Features For families Pricing Security About
Request early access
Features For families Pricing Security About Request early access

Legal

Cadence Data Processing Addendum

Effective date: September 1, 2026

Privacy and security contact: [email protected]

1. Scope and priority

This DPA forms part of the agreement between a studio customer (“Studio” or “Controller”) and Cadence for the Service (the “Agreement”). It applies when Cadence Processes Personal Information on the Studio’s behalf. If this DPA conflicts with the Agreement concerning that Processing, this DPA controls to the extent of the conflict. The Agreement’s liability limits, disclaimers, governing-law, and dispute terms apply to this DPA.

2. Definitions

“Applicable Privacy Law” means U.S. privacy, data-protection, and children’s privacy law applicable to the Processing, including the California Consumer Privacy Act, as amended (“CCPA”), where applicable. “Personal Information” has the meaning given under Applicable Privacy Law. “Process” means any operation on Personal Information, including collection, storage, use, disclosure, transmission, or deletion.

“Security Incident” means a confirmed unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Personal Information Processed by Cadence for the Studio. It does not include unsuccessful attempts or activity that does not compromise the confidentiality, integrity, or availability of Personal Information, such as blocked scans or denial-of-service attempts.

3. Roles and instructions

For Personal Information submitted to or created in the Service by or for the Studio (“Studio Personal Information”), the Studio is the Controller or Business and Cadence is the Processor or Service Provider. Cadence will Process Studio Personal Information only on the Studio’s documented instructions in this DPA, the Agreement, and the Studio’s Service configuration, unless Applicable Privacy Law requires otherwise.

The Studio instructs Cadence to Process Studio Personal Information to provide, secure, maintain, and support the Service; prevent fraud, abuse, and security incidents; comply with law; and create aggregated or de-identified information where permitted by law. Cadence will notify the Studio if it believes an instruction violates Applicable Privacy Law, unless prohibited by law.

Cadence acts as an independent Controller/Business—not a Processor—for its own relationship with the Studio, including Studio-account administration, Cadence billing and taxes, security and audit logs, fraud/abuse prevention, legal claims and compliance, and aggregated or de-identified information. The Privacy Policy governs that independent Processing.

4. Studio responsibilities and children’s information

The Studio represents that it has provided required notices and obtained all rights, permissions, and lawful bases necessary for Cadence to Process Studio Personal Information under this DPA. The Studio is responsible for the accuracy, quality, and legality of Studio Personal Information and its instructions to Cadence.

The Service may be used with information about children. The Studio must assess and meet its own obligations concerning children, including parental notice, consent, access, correction, and deletion rights. Cadence provides a parent-facing, scope-specific consent flow for student PIN access, practice logging and gamification; practice-recording uploads; student-initiated messaging; and lesson transcription. An authenticated parent’s grant records the notice version, typed signature, date and time, IP address, browser information, and a server-side verification basis. Online grants are accepted from the authenticated primary parent account after the parent reviews the notice and chooses the relevant scope; Cadence does not use a saved payment method as a consent-verification method.

These controls are designed to support the Studio’s consent process and are not a determination that a particular deployment satisfies every legal requirement. They do not relieve either party of obligations that Applicable Privacy Law imposes directly on that party. The Studio remains responsible for its own family notices and for the lawfulness of its instructions and offline-consent practices.

5. Service-provider commitments

For Studio Personal Information subject to the CCPA, Cadence certifies that it understands and will comply with this section. Cadence will not:

  • sell or share Studio Personal Information;
  • retain, use, or disclose it for a purpose other than the specific business purposes in this DPA and Agreement, except as CCPA permits a service provider to do;
  • retain, use, or disclose it outside the direct business relationship between Cadence and the Studio, except as CCPA permits; or
  • combine it with Personal Information received from another person or Cadence’s own interactions, except as CCPA permits a service provider to do.

Cadence will provide the level of privacy protection required of a service provider by Applicable Privacy Law and notify the Studio if it determines it can no longer meet these commitments. The Studio may take reasonable and appropriate steps to help ensure compliant use and stop or remediate unauthorized use, including requesting relevant information and, where appropriate, terminating affected Processing.

6. Confidentiality and security

Cadence ensures that personnel authorized to Process Studio Personal Information are bound by appropriate confidentiality obligations and access information only as needed to perform their duties. Cadence maintains reasonable administrative, technical, and organizational measures designed to protect Studio Personal Information. These measures are listed in Annex II and may be updated so long as the update does not materially reduce the Service’s overall security.

7. Subprocessors

The Studio grants Cadence general written authorization to use Subprocessors, provided Cadence places written obligations on them that are materially consistent with relevant obligations in this DPA. Current Subprocessors appear in Annex III.

Cadence will give at least 30 days’ advance notice by email or through the Service before adding or replacing a Subprocessor that materially affects Studio Personal Information. The Studio may object in writing on reasonable data-protection grounds within that period. The parties will work in good faith on a reasonable solution. If none is available, the Studio may terminate the affected Service before the new Subprocessor begins Processing its Studio Personal Information; Cadence will refund prepaid fees for the unused affected Service period, unless the change is legally required or needed to address an urgent security risk.

8. Individual-rights assistance

The Studio remains responsible for receiving, evaluating, and responding to individual privacy requests. Taking account of the nature of Processing and information available to Cadence, Cadence will provide reasonable assistance with valid requests for access, correction, deletion, portability, restriction, or opt-out rights.

If Cadence receives a request directly relating to Studio Personal Information, it will, where practicable and permitted by law, refer the requester to the Studio or notify the Studio within five business days. Cadence will not respond except on the Studio’s instructions or as Applicable Privacy Law requires.

9. Security Incidents

Cadence will investigate a suspected Security Incident promptly and notify the Studio without undue delay and no later than 72 hours after confirming a Security Incident affecting the Studio’s Personal Information. Cadence will provide reasonably available information about the incident’s nature, affected information, measures taken or planned, and a contact for further information, and will reasonably cooperate with the Studio’s investigation and response.

Cadence’s notice is not an admission of fault or a determination that the event is reportable. The Studio remains responsible for deciding whether notice to individuals, regulators, or others is required, except where Applicable Privacy Law imposes a non-waivable obligation directly on Cadence.

10. Deletion and retention

On expiration or termination of the Agreement, Cadence will delete or anonymize Studio Personal Information within 60 days, except where retention is required by law, needed to resolve a dispute, or permitted under the Privacy Policy and Agreement. Cadence does not provide a general data-export service; the Studio is responsible for maintaining independent records it needs before termination.

Financial and tax records are retained for seven years from the applicable transaction or invoice date. Information deleted from active systems may remain in encrypted database backups and point-in-time-recovery records for up to seven days. If a backup is restored, completed deletion requests are re-applied before the restored system returns to service. On written request, Cadence will confirm deletion, subject to these stated exceptions.

11. Information and audits

No more than once in a 12-month period, the Studio may submit reasonable written questions about Cadence’s security measures and this DPA. Cadence will provide a current security summary or reasonable responses, subject to confidentiality, security, and third-party obligations.

If that information is insufficient to demonstrate compliance, the Studio may request a further audit by an independent auditor. Any audit must occur during normal business hours, on at least 30 days’ notice, no more than annually, without unreasonably disrupting Cadence or exposing other customers’ information. The Studio bears its own audit costs and Cadence’s reasonable cooperation costs, unless the audit identifies a material breach by Cadence.

12. Processing locations and notices

Cadence offers the Service to U.S. studios, and its primary application and database infrastructure are hosted in the United States. Limited Processing by Cadence’s Subprocessors may occur through their global networks or in locations determined by their service configuration. Current providers and location information appear in the published subprocessor list.

If a planned service expansion or Processing activity requires an international-transfer mechanism or additional privacy terms, the parties will execute an appropriate addendum before that activity begins.

Cadence’s privacy and Security Incident contact is [email protected]. The Studio must keep its authorized privacy contact current in the Service. Notices under this DPA may be sent by email to the account contact unless law requires another method.


Annex I — Processing details

ItemDetails
Subject matterCadence’s music-studio administration, scheduling, billing, learning, practice, communication, and support services.
DurationThe Agreement’s term, plus the limited deletion and retention periods in Section 10.
Nature and purposeHosting, storing, organizing, transmitting, displaying, securing, supporting, and deleting Studio Personal Information as needed to provide the Service and follow the Studio’s instructions.
IndividualsStudio owners, staff and teachers; parents/guardians and family contacts; students, including minors; and people communicating with the Studio through the Service.
InformationContact and account information; roles and credentials; student profile, scheduling, attendance, assignment, practice, and gamification information; billing and payment-related identifiers; messages and attachments; practice recordings; lesson transcript text; consent status; and service, audit, and security information.

Annex II — Security measures

  • PostgreSQL tenant isolation using row-level security;
  • role-based access control and least-privilege database credentials for application and background-job access;
  • TLS encryption in transit and encryption at rest for hosted data;
  • one-way Argon2id password and student-PIN hashing;
  • TOTP multi-factor authentication, available for enrollment on staff and parent accounts and enforced for platform-administrator access;
  • AES-256-GCM encryption for calendar OAuth tokens;
  • signed, time-limited links for authorized access to stored media;
  • audit logging for sensitive administrative actions;
  • encrypted database backups and point-in-time-recovery records with a seven-day maximum retention period;
  • local-only lesson-transcription audio processing, with source audio deleted after processing; and
  • confidentiality obligations and need-to-know access controls for authorized personnel.

Annex III — Authorized Subprocessors

SubprocessorProcessing purpose
DigitalOceanApplication hosting and managed PostgreSQL database
CloudflareFile storage, static-site hosting, network, and TLS services
StripePayment processing and, where enabled, Stripe Connect payouts
ResendTransactional email delivery
GoogleOptional studio-enabled calendar sync
SentryError monitoring and diagnostics
Cloudflare (Turnstile)Bot protection on public signup and lead forms

The authoritative register is the published subprocessor list (source: SUBPROCESSORS.md). Cadence provides notice of changes to it under Section 7.

Cadence SM

Studio management with a musician's sense of time.
Built inside a working music studio.

Product

Features For families Pricing Security

Company

About Contact Terms Privacy Children's Privacy Data Processing Addendum Subprocessors
© 2026 Cadence SM. No trackers in the product — and this site lists exactly what it loads.