Skip to content

Data Processing Agreement

Last updated: 18 June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between SaaS Life OÜ (registry code 16345451, registered at Sepapaja tn 6, 15551 Tallinn, Estonia) (“Processor”, “Cadence”) and the customer that has agreed to the Terms of Service or a corresponding order form (“Controller”, “Customer”). It governs the processing of personal data by Cadence on the Customer’s behalf under Article 28 of the EU General Data Protection Regulation (GDPR).

Where this DPA conflicts with the Terms of Service in respect of the processing of personal data, this DPA prevails. A countersigned copy is available to customers on request via [email protected].

1. Roles of the parties

For personal data contained in the Customer’s workspace, including coaching conversations and scenarios derived from call recordings and deal data the Customer connects (“Customer Personal Data”), the Customer is the controller and Cadence is the processor. Cadence processes Customer Personal Data only on documented instructions from the Customer, including those set out in the Terms, this DPA, and the configuration of the Service.

The subject matter, duration, nature, purpose of processing, the types of personal data, and the categories of data subjects are described in the Annex below.

2. Processor obligations

Cadence will:

  • process Customer Personal Data only on the Customer’s documented instructions, including for transfers, unless required to do otherwise by law (in which case it will inform the Customer, where legally permitted);
  • ensure that persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (see Section 4);
  • respect the conditions in Section 5 for engaging subprocessors;
  • assist the Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting its obligations regarding security, breach notification, data protection impact assessments, and prior consultation;
  • at the Customer’s choice, delete or return Customer Personal Data at the end of the provision of services (see Section 7); and
  • make available the information necessary to demonstrate compliance and allow for and contribute to audits as described in Section 8.

3. Customer obligations

The Customer is responsible for the lawfulness of the personal data it provides and of its processing instructions, including establishing a valid legal basis and providing any required notices or consents to its own personnel and the individuals on connected calls. The Customer must not instruct Cadence to process data in violation of applicable law.

4. Security measures

Cadence maintains technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS) and at rest, role-based access controls and least-privilege access, logical separation of customer data, and internal access restricted to personnel who need it to deliver and support the Service. Further detail is described on our Security page. Cadence does not use Customer Personal Data to train third-party foundation models and does not sell it.

5. Subprocessors

The Customer authorises Cadence to engage subprocessors to provide the Service. Cadence maintains a list of subprocessor categories on its subprocessors page, with a named list available to customers. Cadence imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains liable for their performance. Cadence will give the Customer reasonable prior notice of any intended addition or replacement of a subprocessor, giving the Customer the opportunity to object on reasonable data-protection grounds.

6. International transfers

Cadence offers a choice of hosting regions from major cloud providers so the Customer can determine where Customer Personal Data is hosted. Where personal data is transferred outside the European Economic Area, such transfers are made under an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses or an adequacy decision, together with any supplementary measures required.

7. Return and deletion of data

On termination or expiry of the services, and at the Customer’s choice, Cadence will return or delete Customer Personal Data within the period set out in the Terms or order form, and delete existing copies unless retention is required by law. The Customer may also export data during the term using the functionality of the Service.

8. Audits

Cadence will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. On reasonable prior notice, and no more than once per year unless required by a supervisory authority or following a personal-data breach, the Customer may audit Cadence’s compliance, subject to confidentiality and reasonable limits on disruption. Cadence may satisfy audit requests by providing relevant certifications or third-party reports where available.

9. Personal-data breaches

Cadence will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations.

10. Liability and term

This DPA is effective for as long as Cadence processes Customer Personal Data on the Customer’s behalf. Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service. This DPA is governed by the laws of the Republic of Estonia.

Annex: details of processing

  • Subject matter: provision of the Cadence AI sales coaching service.
  • Duration: the term of the Customer’s subscription and any agreed post-termination period.
  • Nature and purpose: hosting, processing, and analysis of Customer data to generate practice scenarios, deliver coaching in Slack and Microsoft Teams, and provide reporting to the Customer.
  • Types of personal data: names and business contact details of the Customer’s users; coaching interactions and progress; and personal data contained in the call recordings and deal data the Customer chooses to connect (which may include the Customer’s personnel and the individuals on those calls).
  • Categories of data subjects: the Customer’s employees and authorised users, and the customers, prospects, and other parties present in the connected source data.
  • Subprocessors: as listed on the subprocessors page.

Contact

To request a countersigned DPA or for data-protection questions, contact [email protected], or write to SaaS Life OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia.