Cadence Subprocessor List
Last updated: September 1, 2026
Cadence uses the service providers below to operate and secure the Service. They process personal information only as needed to provide their services to Cadence. We will provide at least 30 days’ advance notice by email or through the Service before adding or replacing a subprocessor that materially affects Studio Personal Information, except when a change is legally required or needed to address an urgent security risk.
| Provider | Service and purpose | Information processed | Processing location |
|---|---|---|---|
| Stripe, Inc. | Payment processing and, where enabled, Stripe Connect payouts | Parent and studio identity, payment tokens held by Stripe, transaction data, and application-fee records | United States |
| DigitalOcean, LLC | Application hosting, managed PostgreSQL database, and encrypted backups | Service data | United States |
| Cloudflare, Inc. (R2) | Object storage and controlled-access delivery | Practice recordings, uploaded files, chat attachments, and invoice PDFs | Cloudflare’s network; storage configuration is managed by Cadence |
| Resend, Inc. | Transactional email delivery | Names, email addresses, and message content | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | Error events and limited request metadata | United States |
| Google LLC (Calendar API) | Optional calendar sync for staff who connect an account | Connected calendar event details and OAuth tokens | United States |
| Cloudflare, Inc. (Turnstile) | Bot protection for public signup and lead forms | IP address and browser signals on public forms | Cloudflare global network |
| Twilio Inc. | SMS delivery for studio-enabled text notifications | Recipient phone number and message content | United States |
Twilio is live integration code today, but it is dark for every studio: SMS
sending is gated per organization by Organization.smsEnabled, which defaults
to false and is turned on only by a direct data change per studio, not by a
self-service toggle. Twilio does not process any studio’s data until that
studio is individually enabled.
No transcription subprocessor
Lesson transcription runs entirely on infrastructure we operate. Audio is not sent to a third-party transcription, speech-to-text, or AI service. If that changes, we will update this list and provide the notice required by the DPA before the new provider processes audio or transcript content.