Your data, your business.
Last updated: 25 June 2026
1. Who we are
Cadence is a product of DarkMatter Creative Communications, a digital agency based in South Africa. When this policy says “we”, “us”, or “Cadence”, it means DarkMatter Creative Communications operating the Cadence service at cadencetime.co.
2. What we collect
We collect the minimum data needed to run the service:
- Account information: your name and email address. Authentication is email and password only.
- Organisation data: organisation name, team membership, and roles you create or are assigned within Cadence.
- Time tracking data: time entries, activity records, and project/client labels generated by the desktop application or entered manually.
- Integration tokens: if you connect external services (such as Google Calendar), we store encrypted OAuth tokens to maintain the connection. We never store your passwords for those services.
- Usage and diagnostics: basic request logs (IP address, browser/OS, timestamp) for security and reliability. We do not use third-party analytics trackers.
3. What we do not collect
- We do not take screenshots of your screen.
- We do not record keystrokes.
- We do not monitor the content of your files or messages.
- The desktop application records which application is in the foreground and its window title to build activity summaries. This data stays within your organisation and is never shared externally.
4. How we use your data
We use the data described above to:
- Provide and maintain the Cadence service.
- Authenticate you and enforce organisation-level access control.
- Generate time reports and exports you request.
- Process billing and subscriptions.
- Send transactional emails (account verification, billing receipts, critical service notices).
- Investigate and prevent abuse or security incidents.
We do not sell, rent, or share your personal data with third-party advertisers. We do not use your data to train machine-learning models.
5. Data storage and security
Your data is stored in Supabase-managed PostgreSQL databases hosted on AWS infrastructure. Every organisation's data is isolated at the row level using database security policies: one tenant can never query another's data.
Integration tokens are encrypted at rest using AES-256-GCM with per-organisation keys. All connections to our servers use TLS.
6. Third-party services
We use the following services to operate Cadence:
- Supabase: database, authentication, and file storage.
- Vercel: web application hosting.
- Paystack: payment processing (South Africa). We do not store your card details; Paystack handles payment data under their own PCI-DSS compliance.
- Cloudflare Turnstile: bot protection on sign-up forms. No personal data is shared beyond the challenge token.
- Google (Calendar): optional calendar integration. With your authorisation, Cadence connects to Google Calendar via OAuth to show your meetings as read-only context alongside your time entries. We store encrypted OAuth tokens to maintain the connection. We do not receive or store your Google password.
7. Data retention
We retain your account and time-tracking data for as long as your account is active. If you or your organisation administrator deletes your account, we remove your personal data within 30 days, except where we are required by law to retain it.
8. Your rights
Under the Protection of Personal Information Act (POPIA) and, where applicable, the GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to processing of your data.
- Export your data in a portable format (CSV/XLSX export is built into the product).
To exercise any of these rights, contact us at the address below.
9. Cookies
Cadence uses only essential cookies required for authentication and session management. We do not use advertising or tracking cookies.
10. Children
Cadence is a workplace tool and is not directed at anyone under the age of 18. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through the service. The “last updated” date at the top of this page reflects the most recent revision.
12. Contact
If you have questions about this policy or your data, contact us at Cadence:
Email: privacy@cadencetime.co