Data Processing Agreement
Last updated: 26 August 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between International Awards Group Ltd (“Cadence”, “we”, “us” or “our”) and the customer (“you” or “Customer”). It governs the processing of personal data when you use the Cadence email campaign platform (“Service”).
1. Definitions
- Controller, Processor, Data Subject, Personal Data and Processing have the meanings given in the UK GDPR / EU GDPR and any equivalent data protection law.
- Customer Contacts means the contact records (names, email addresses, job titles, companies, phone numbers, locations and any custom fields) that you import, add or otherwise process through the Service.
- Account Data means personal data relating to you and your authorised users, such as names, email addresses, billing contacts and usage activity.
2. Controller and processor roles
Customer Contacts: You are the Controller and we are the Processor. You decide which contacts to upload, what campaigns to send, and the purposes and means of that processing. We process Customer Contacts only on your documented instructions and as described in this DPA and the Terms of Service.
Account Data: We act as Controller for Account Data, as described in our Privacy Policy. This DPA does not restrict our processing of Account Data where we are the Controller.
Where data protection law requires a written contract between Controller and Processor, this DPA satisfies that requirement.
3. Processing instructions
We will process Customer Contacts only for the purpose of providing, securing and improving the Service, including:
- storing, organising and deduplicating contact records;
- sending, scheduling and tracking email campaigns on your behalf;
- generating campaign content, segment suggestions and analytics using AI features;
- handling unsubscribes, bounces, complaints and suppression lists;
- complying with legal obligations, court orders or enforceable governmental requests.
We will not sell Customer Contacts, use them for our own marketing, or process them in any way that is inconsistent with your instructions, except where required by law.
4. Confidentiality
We treat Customer Contacts as confidential. Our personnel are subject to confidentiality obligations and are permitted to access personal data only on a need-to-know basis. We do not disclose Customer Contacts to third parties except as set out in this DPA, the Terms of Service or the Privacy Policy, or where required by law.
5. Security measures
We implement appropriate technical and organisational security measures to protect personal data, including:
- Encryption: data in transit over public networks is protected using TLS 1.2 or higher; data at rest is encrypted by our hosting provider.
- Access controls: role-based permissions, multi-factor authentication for administrative access, and row-level security policies in the database.
- Monitoring and logging: audit logs for access to personal data, anomaly detection and regular security reviews.
- Availability and resilience: regular backups, redundancy and business-continuity procedures.
- Vulnerability management: dependency scanning, security patches and penetration testing as appropriate.
You are responsible for maintaining the security of your account credentials and for configuring workspace permissions in line with your own security policies.
6. Subprocessors
We use the following categories of subprocessor to provide the Service. A current list of named subprocessors is set out below:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Cloud database, authentication and storage | United States / EU |
| Resend | Email delivery and transactional sending | United States |
| Paddle | Payment processing, tax and invoicing | United Kingdom / EU |
| Google Cloud / Gemini | AI generation, brand extraction and document parsing | United States |
| Cloudflare | Edge network, security and DNS | United States |
We may add or change subprocessors. We will notify you at least 30 days before any material change, and you may object to a new subprocessor by contacting us. If we cannot reasonably address your objection, you may terminate your subscription for the affected workspace.
7. Data-subject requests
Because you are the Controller of Customer Contacts, you are responsible for responding to requests from your contacts to access, correct, delete, restrict or port their personal data. We will assist you in fulfilling these requests to the extent the request relates to data processed by us on your behalf.
For requests relating to Account Data, where we are Controller, please contact us directly and we will respond within the timeframe required by applicable law.
8. Breach notification
If we become aware of any accidental, unlawful or unauthorised destruction, loss, alteration, disclosure of, or access to Customer Contacts, we will notify you without undue delay and, where feasible, no later than 24 hours after becoming aware. The notification will include, to the extent then available:
- the nature of the breach and the categories and approximate number of data subjects affected;
- the likely consequences and the measures taken or proposed to mitigate harm;
- contact details for more information.
We will cooperate with you and take reasonable steps to investigate, remediate and prevent recurrence.
9. International transfers
Customer Contacts may be transferred to, stored in, or processed from countries outside the UK, EEA or the jurisdiction in which you or your contacts are located. Where such transfers are not covered by an adequacy decision, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / EU Standard Contractual Clauses, supplemented by technical measures such as encryption in transit and at rest.
Subprocessors listed above may also process personal data internationally. We enter into data processing terms with subprocessors that require equivalent levels of protection.
10. Deletion and return of data
At any time during the subscription you can export Customer Contacts from the Service. On termination or expiry of your subscription for a workspace, we will delete or return Customer Contacts in accordance with your instructions, except where we are required to retain copies by law.
Unless otherwise instructed, we will delete Customer Contacts within 90 days of termination. Backups may be retained for a reasonable period thereafter but will be protected by the same security measures and deleted in accordance with our backup retention schedule.
11. Audit and assistance
On written request, and no more than once per calendar year, we will provide you with information reasonably necessary to demonstrate compliance with this DPA, such as a summary of our security measures or a copy of any relevant third-party security report (for example, SOC 2, where available). You may also submit a short written questionnaire, which we will answer within a reasonable time.
We will assist you, at your cost, with data protection impact assessments, prior consultations with supervisory authorities, and other compliance obligations that relate to our processing of Customer Contacts.
12. Liability
Each party is liable for breaches of this DPA caused by its own acts or omissions. Our liability is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party’s liability for fraud, death or personal injury where such limitation would be unlawful.
13. Duration and termination
This DPA is effective from the date you first use the Service and continues for as long as we process Customer Contacts on your behalf. The obligations in sections 4 (Confidentiality), 5 (Security), 8 (Breach notification), 9 (International transfers), 10 (Deletion and return of data), 11 (Audit and assistance) and 12 (Liability) survive termination.
14. Changes to this DPA
We may update this DPA to reflect changes in law, our subprocessors or the Service. Material changes will be notified by email or through the Service at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated DPA.
15. Contact
For questions about this DPA or to exercise any of the rights described above, please contact support@cadencetechnologies.app.