1. What this addendum covers
This addendum (the “DPA”) applies when Cadex Systems (“Cadex”) processes personal data on behalf of an organization that uses Cadex Core (“Core”). It forms part of the Terms of Service and takes effect when your organization starts using Core to process personal data that data protection law covers.
It sets out what Cadex does with that data, which other companies process it, how it is secured and what happens when it crosses a border. The Privacy Policy describes the same handling in plainer terms and also covers the information Cadex holds for its own purposes.
If your organization has signed a separate data processing agreement with Cadex, that agreement governs and this one does not apply. Where this addendum and the Terms of Service differ on the handling of personal data, this addendum governs.
To have a countersigned copy, email discovery@cadexhq.com with your organization’s legal name, address and the contact for Annex I.
2. Words used here
“Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Business”, “service provider”, “sell” and “share” have the meanings given in the California Consumer Privacy Act.
- Data protection law is the law on the protection of personal data that applies to a party’s processing under this addendum, including the GDPR, the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws such as the California Consumer Privacy Act.
- GDPR is Regulation (EU) 2016/679.
- Customer personal data is the personal data within your data, as the Terms of Service define your data, that Cadex processes on your organization’s behalf.
- Standard Contractual Clauses or SCCs are the clauses annexed to Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
- UK Addendum is the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, version B1.0.
- Subprocessor is a company Cadex engages to process customer personal data.
Other defined terms have the meaning given to them in the Terms of Service.
3. Who is the controller and who is the processor
Your organization is the controller of customer personal data and Cadex is its processor. Where your organization is itself a processor, handling that data for someone else, Cadex is a subprocessor and this addendum applies as though your organization were the controller.
Cadex is the controller of the information it holds for its own purposes: account and sign-in records, waitlist signups, the messages your people send Cadex, security and service logs, and information about how the service is used. The Privacy Policy covers that information.
Each party meets the obligations that data protection law places on it in the role it holds.
4. Cadex’s instructions
Cadex processes customer personal data to provide, secure and support Core, and on your organization’s documented instructions. The instructions are the Terms of Service, this addendum, the Privacy Policy and the use your organization makes of Core: connecting a tool, setting a connection’s scope, uploading a file, adding a website, asking a question, running an AI agent and directing an agent to act in another tool.
Cadex does not sell or share customer personal data, does not use it to target advertising and does not use it to train or improve AI models. It does not process customer personal data for its own purposes beyond providing, securing and supporting the service.
If the law requires Cadex to process customer personal data for another purpose, Cadex tells your organization before it does so, unless that law forbids the notice.
If Cadex considers an instruction to breach data protection law, it tells your organization, and it may hold that instruction until the question is settled.
5. Confidentiality
Access to customer personal data at Cadex is limited to the people who need it to provide, support or secure the service. Their contracts bind them to confidentiality, and that duty continues after their work for Cadex ends.
People at Cadex read the content in a workspace when your organization asks them to look at specific items, when it is needed to investigate a bug, abuse or another security matter, when the law requires it, or once the content has been aggregated and anonymized for internal operations.
6. Security
Cadex keeps technical and organizational measures appropriate to the risk, as Article 32 of the GDPR requires. Annex II sets out the measures in place.
Those measures change as the service develops. Cadex does not make a change that puts the protection of customer personal data below what Annex II describes.
7. Subprocessors
Your organization gives Cadex general authorization to engage subprocessors. Annex III names the ones engaged today.
Cadex has a written contract with each subprocessor that places obligations on it equivalent to the ones in this addendum, and Cadex stays responsible to your organization for what its subprocessors do.
Before a new subprocessor starts processing customer personal data, Cadex gives at least 30 days’ notice by email to your organization’s administrators and by updating Annex III. Within those 30 days your organization can object on reasonable grounds related to data protection. The parties then look for a change that meets the objection, such as a different configuration or another provider. If none is found, your organization can stop using the part of the service that relies on that subprocessor, or end its use of the service under the Terms of Service, and any order form governs what happens to fees already paid.
8. Requests from people whose data Core holds
Core gives administrators the means to find, export, correct and delete content in a workspace, which is how most requests get answered.
If a request under data protection law reaches Cadex directly, Cadex does not answer it beyond acknowledging receipt and pointing the person to your organization, unless the law requires a different response or your organization asks Cadex to answer. Cadex passes the request on without undue delay.
Cadex helps your organization answer a request it cannot answer with the tools in Core, taking into account the nature of the processing and the information available to Cadex.
9. Impact assessments and prior consultation
Cadex helps your organization with data protection impact assessments and with consulting a supervisory authority, taking into account the nature of the processing and the information available to Cadex. This addendum, the Privacy Policy and Annex II are written to supply most of what an assessment needs. Email discovery@cadexhq.com for anything further.
10. Personal data breaches
Cadex notifies your organization’s administrators without undue delay after becoming aware of a personal data breach affecting customer personal data.
The notice describes what Cadex knows at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned where those are known, the likely consequences, and the measures taken or proposed. Where the facts arrive over time, Cadex sends them in stages as the investigation produces them.
Cadex helps your organization meet its own duty to notify a supervisory authority or the people affected. Sending a notice is not an admission of fault or liability.
11. Returning and deleting data
While the account is open, administrators can delete content in Core, and your organization can ask Cadex to delete data as the Privacy Policy describes. Disconnecting a tool stops its syncing and deletes the content described there.
When your organization’s account closes, Cadex deletes the workspace and its data within 30 days. Copies in backups go as those backups expire on the schedules of the providers in Annex III.
Export what your organization needs before the account closes. Cadex keeps a copy after that only where the law requires it, and then for that purpose and for as long as the law requires.
12. Audits and information
Cadex makes available the information needed to show that it meets Article 28 of the GDPR: this addendum, the Privacy Policy, Annex II, the certifications and reports its providers publish, and a written answer to a reasonable security questionnaire once in a 12-month period.
Where that leaves open a question data protection law or a supervisory authority requires your organization to answer, your organization can audit Cadex’s processing, or appoint an auditor who is not a competitor of Cadex, on 30 days’ written notice. An audit runs during business hours, once in a 12-month period, under a confidentiality agreement, and without access to another customer’s data or to material Cadex is not free to disclose. Your organization bears the cost. A supervisory authority requiring an audit, or a personal data breach, allows a further audit inside the same period.
13. International transfers
Cadex is based in the United States and processes customer personal data there. Annex III names each subprocessor, and the regions each one processes in are in the information Cadex supplies on request under that annex.
European Economic Area
Where the GDPR governs a transfer of customer personal data to Cadex, the SCCs apply and are incorporated into this addendum:
- Module Two (controller to processor) applies where your organization is a controller, and Module Three (processor to processor) where your organization is a processor.
- Your organization is the data exporter and Cadex is the data importer.
- Clause 7, the docking clause, applies.
- In Clause 9, Option 2 applies, with the 30 days’ notice set out in Subprocessors above.
- In Clause 11, the optional independent dispute resolution wording does not apply.
- In Clause 17, Option 1 applies and the law of Ireland governs the clauses. Under Clause 18(b), disputes go to the courts of Ireland. That choice covers the clauses; the Terms of Service govern everything else.
- Annexes I, II and III of this addendum are Annexes I, II and III of the SCCs.
United Kingdom
Where the UK GDPR governs the transfer, the UK Addendum applies to the SCCs above. In its Table 1 the parties are the ones in Annex I; Table 2 refers to the SCCs as set out in this section; Table 3 refers to Annexes I, II and III of this addendum; and in Table 4 neither party may end the UK Addendum when the Information Commissioner revises it.
Switzerland
Where the Swiss Federal Act on Data Protection governs the transfer, the SCCs apply with these changes: references to the GDPR are read as references to that act, the Federal Data Protection and Information Commissioner is the supervisory authority, and “personal data” covers data about legal entities for as long as Swiss law protects it.
If a transfer mechanism stops working
If a court or a regulator sets one of these mechanisms aside, the parties will put a valid alternative in place for the affected transfers. Until that is done, your organization can suspend the affected transfers or end its use of the service under the Terms of Service.
14. United States state privacy laws
Where the California Consumer Privacy Act applies, your organization is the business and Cadex is its service provider for customer personal data. Cadex is prohibited from selling or sharing that data, from retaining, using or disclosing it outside the direct business relationship or for any purpose other than the ones in this addendum, and from combining it with personal information from another source except where that act permits a service provider to do so. Cadex understands these restrictions and will comply with them.
Your organization can take reasonable and appropriate steps to confirm that Cadex uses customer personal data consistently with its obligations, using the information and the audit right in Audits and information above, and to stop and remediate an unauthorized use.
Where another United States state privacy law applies and uses different words for the same roles, this addendum is read as carrying the terms that law requires of a processor or service provider.
15. What your organization is responsible for
Your organization decides which tools to connect, what each connection can read, whether a connection stays private to the member who made it or is shared with the organization, who its members are, and what those members can see in the source tools. Core applies those decisions rather than making them.
Your organization is responsible for having the rights, permissions, notices and consents its instructions need, including for information about people who do not use Core, such as the sender of an email or a contact in a CRM record.
Core is built for business content. It is not built for personal data that carries specific legal requirements, such as health records, payment card numbers or government identity numbers, and Cadex asks that your organization not connect a source whose purpose is to hold them.
Your organization is responsible for the accounts its members use and for removing a member’s access when they leave.
16. Connected tools
When your organization connects a tool, Cadex accesses it within the permissions the connecting member grants and on your organization’s instruction. The company behind that tool is your organization’s provider rather than a subprocessor of Cadex, and its own terms and privacy notice cover what it does. Sending content to a connected tool, such as posting a message or creating a task, happens on your organization’s instruction.
Cadex Core’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The Privacy Policy sets out what that means for Google Drive, Gmail and Google Calendar, and a separate section covers data from Meta Ads.
17. Limitation of liability
Each party’s liability under this addendum is subject to the limits in the Terms of Service. Claims under this addendum, the Terms of Service and the End User License Agreement count against one limit together rather than a separate limit for each.
Nothing in this section limits liability that the law does not allow to be limited, and nothing in it affects the rights the SCCs give a data subject, including the right to compensation.
18. Changes to this addendum
Cadex may update this addendum to reflect a change in the law, in the service or in its subprocessors. The date at the top of the page shows when it last changed, and Cadex tells administrators by email or in Core before a change that materially lowers the protection of customer personal data takes effect. A countersigned copy changes only by written agreement between the parties.
19. Contact
Send questions about this addendum, requests for a countersigned copy and security questionnaires to:
Cadex Systems3301 N University Drive, Suite 100
Coral Springs, FL 33065
discovery@cadexhq.com
20. Annex I: the processing
A. The parties
Data exporter. The organization that holds the Core account, acting as the controller of customer personal data, or as a processor where it handles that data for someone else. Its name, address and contact are the ones in its Core account or in the agreement it signed with Cadex. Its activity relevant to the transfer is its use of Core, described in section B.
Data importer. Cadex Systems, acting as a processor, at the address in Contact above. Its activity relevant to the transfer is providing, securing and supporting Core.
B. What is processed
Categories of data subjects. The members of your organization who use Core; its other employees and contractors who appear in connected content; and the people who appear in the tools your organization connects, such as the senders and recipients of email, the participants in meetings, the contacts, leads and customers in CRM records, the people named in tasks, documents and messages, and the people named in accounting records.
Categories of personal data.
- Account data: name, email address, the organizations a member belongs to, their role in each, and the device, browser and IP address of each sign-in.
- Content from connected tools: documents, email, chat messages, calendar events, tasks and projects, CRM records, accounting records and advertising results, along with the settings that say who can see each item in the source tool.
- Files members upload, and pages fetched from the websites your organization adds.
- The questions members ask, the answers and sources Core returns, and the record of what AI agents do.
- For a member who uses Core in Slack or Telegram, the messages they send Core there and their account identifier in that app.
- Any other personal data the people in your organization put into the content above.
Special categories of personal data. Core does not ask for them and is not built to process them, as What your organization is responsible for says. Content in a workspace can still contain them, because the person who wrote it put them there. Where that happens the measures in Annex II apply to that content as they do to the rest of the workspace, and no further restriction applies unless the parties agree one in writing.
Frequency. Continuous. Core reads a connected Gmail mailbox every 30 minutes and the other connections hourly, and it processes questions and agent runs as they happen.
Nature and purpose of the processing. Collecting content from the tools your organization connects, storing it in that organization’s workspace, indexing it for search, organizing it into a knowledge graph, retrieving the passages that match a question, sending those passages and the question to an AI model that writes the answer, running AI agents on a schedule or on request, and delivering the output to the member who asked or to the tool your organization chose. The purpose is to provide, secure and support Core for your organization.
Duration. For as long as your organization’s account is open, and then for the period in Returning and deleting data above.
Processing by subprocessors. The subprocessors in Annex III process customer personal data for the purpose named against each of them, for as long as they are engaged and the account is open.
C. Supervisory authority
Where the SCCs apply, the supervisory authority is the one Clause 13 identifies: the authority of the member state in which the data exporter is established, or in which its representative is established, or, where the exporter is not established in the European Economic Area, the authority of the member state in which the data subjects are located.
21. Annex II: security measures
Encryption and stored data
- Connections to the site and to Core use TLS.
- The hosting, database, file storage and knowledge graph providers in Annex III encrypt stored data at rest under their published service descriptions.
- The access tokens for connected tools are held by Nango rather than in Core’s database.
Separation and access control
- Each organization has its own workspace, with its own connections and indexes.
- Sign-in and account management run through Clerk, with membership and a role recorded per organization.
- A connection is private to the member who made it until an administrator shares it with the organization, and results are filtered by the access Core records from the source tool.
- Access to production systems is limited to the people at Cadex who need it.
Logging
- Core records the questions members ask, the runs of AI agents, file uploads and downloads, and administrative actions such as disconnecting a tool or deleting a file. Administrators can review that record.
- Entries for questions and agent runs are deleted after 180 days and entries for routine events after 30 days. Records of administrative actions are kept while the account is open.
Availability and recovery
- Core runs on managed platforms that provide redundancy and backups as part of their service.
- Restoring data uses those providers’ restore paths.
Testing and change management
- Changes to Core are reviewed and run against an automated test suite before release.
- Cadex reviews these measures as the service changes.
Data minimization
- Core reads what the permissions granted at connection allow, and a member connects only the sources they choose.
- Answering a question sends the model the passages that match it, drawn from content the person asking can see, rather than the whole workspace.
- Customer personal data is not used to train or improve AI models.
Subprocessors
- Each subprocessor is engaged under a written contract carrying obligations equivalent to this addendum, as Subprocessors describes.
22. Annex III: subprocessors
These companies process customer personal data for Cadex:
- Vercel. Hosting and delivery of Core and this site.
- Supabase. The database and file storage behind each workspace.
- Neo4j Aura. The knowledge graph built from each organization’s content.
- Clerk. Sign-in and account management.
- Nango. Connections to other tools. It holds their access tokens, and some of Core’s requests to those tools pass through it.
- xAI and Anthropic. The AI models that write answers and run agents. Core sends a given request to one of them, and both are named here because either may be in use. Under the API terms each provider publishes, neither trains its models on what Core sends.
- Voyage AI. The embeddings Core uses to find related passages.
- Tavily. Web searches, when a question needs current information from the web.
- Slack. Cadex’s internal alerts, which can carry error details.
Each one is engaged for the purpose named against it, under the contract described in Subprocessors above. For each provider’s legal entity and the regions it processes in, email discovery@cadexhq.com. Cadex updates this annex when a subprocessor changes and gives the notice described in that section before a new one starts.