Privacy Policy

1. INTRODUCTION

Cadenya, Inc. ("Cadenya," "we," "us," or "our") is committed to protecting the privacy of the businesses and individuals who use our agent runtime platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information in connection with the Service. This Policy applies to: (a) businesses and organizations ("Customers") that subscribe to the Service; (b) individuals who access the Service on behalf of Customers ("Authorized Users"); and (c) visitors to our website at www.cadenya.com. By accessing or using the Service, you agree to the practices described in this Privacy Policy.

2. ABOUT THE SERVICE

Cadenya is an Agent runtime platform that enables businesses to build and run automated AI-powered workflows. The Service consists of three aspects: Tool Sets (and their tools), Agents (and their variants) and Memory Layers (and their entries). These combine to support assignments to Agents ("Objectives"). Cadenya handles running your Agent’s loop, responds to your tool calls by making a request to the known endpoint, and analytics via its API. The Memory Layer provides for message persistence in the Agent's conversation.

When Customers use the Service, they configure AI Agents that:

  • Connect to Customer-owned APIs, databases, and third-party services ("Customer Systems");
  • Send prompts and context to service providers ("Service Providers"); and
  • Execute automated tasks — such as data retrieval, content generation, API calls, and workflow actions — on the Customer's behalf, where data flows in and out of Cadenya's systems as part of agent execution loops.

Customer Systems may include Cadenya OpenAI, Claude, and Gemini keys.

Each Service Provider is an independent controller or processor of data it receives. Cadenya does not control how Service Providers use, store, or process data after transmission. Cadenya processes data both as a data controller (for account and platform data) and as a data processor (for Customer Data processed through the Service).

3. INFORMATION WE COLLECT

3.1 Account and Subscription Information

When a Customer creates an account or executes an Order Form, we collect:

  • Business name, billing address, and contact information;
  • Email addresses of Authorized Users;
  • Payment and billing information (processed by our third-party payment processor; we do not store full payment card numbers); and
  • Subscription tier and related commercial agreement details.

3.2 Configuration Data

To operate agents, Customers provide configuration data, including:

  • API credentials, tokens, and authentication materials for Customer Systems (encrypted at rest using AES-256);
  • Agent workflow definitions, including target systems, permitted actions, and operational parameters;
  • System prompts and agent instructions; and
  • Metadata about Customer Systems (e.g., endpoint URLs, schema definitions).

3.3 Agent Execution Data

During Agent execution, we generate and retain for 14 days:

  • Execution Logs: records of actions taken (e.g. data created/given to AI Agents configured in Cadenya), inputs provided to Service Providers, and outputs received;
  • Intermediate context passed within the agent execution loop (e.g., tool call results, memory states);
  • Error logs and exception data; and
  • Timestamps, session identifiers, and execution metadata.

Agent Execution Data may contain Customer Data — including data retrieved from Customer Systems, data submitted as context, and data generated by Service Providers — depending on how Customer has configured its agents. Cadenya is a processor of such data.

3.4 Telemetry Data

We automatically collect:

  • Service usage metrics (API call volumes, agent execution counts, latency data);
  • Feature utilization patterns;
  • Error rates and performance data; and
  • IP addresses and device/browser information for security and fraud prevention purposes.

We use Telemetry Data in aggregated and anonymized form for our internal business purposes, including product improvement and capacity planning. Telemetry Data does not contain any personally identifiable information.

3.5 Communications

If you contact us for support or inquiries, we collect the content of those communications and associated metadata. Cadenya is a processor of such data.

3.6 Sensitive Personal Information

We do not intentionally collect Sensitive Personal Information (as defined under the CPRA, including Social Security numbers, financial account details, health data, precise geolocation, and similar categories) through the Service platform itself and Customers may not configure agents that process Sensitive Personal Information within Customer Data.

4. HOW WE USE INFORMATION

We use the information described above for the following purposes:

Purpose

Details and Legal Basis

Service Delivery

Authenticating users, processing agent executions, routing Service Provider calls, and delivering outputs. Legal basis: contract performance.

Security and Fraud Prevention

Monitoring for unauthorized access, detecting misuse, and protecting Customer credentials. Legal basis: legitimate interests.

Service Improvement

Analyzing aggregated, anonymized usage data to improve performance, reliability, and features. Legal basis: legitimate interests.

Billing and Account Management

Processing payments, managing subscriptions, and sending billing communications. Legal basis: contract performance.

Customer Support

Responding to support requests and resolving technical issues. Cadenya personnel may access Execution Logs for debugging with appropriate access controls. Legal basis: contract performance.

Legal Compliance

Complying with applicable laws, responding to legal process, and enforcing our agreements. Legal basis: legal obligation / legitimate interests.

Communications

Sending service notices, security alerts, and (with appropriate consent) product updates and marketing. Legal basis: consent or legitimate interests.

We do not use Customer Data to train proprietary AI/ML models and we do not sell, rent, or trade Customer Data or personal data to third parties for their own marketing or commercial purposes.

5. OTHER DISCLOSURES OF INFORMATION

We may share information with third parties in the following circumstances:

5.1 Service Providers

We share information with third-party vendors that provide infrastructure, security, analytics, customer support, and payment processing services on our behalf. These vendors are bound by contractual data protection obligations and may only process data for the purposes we specify.

5.2 Business Transfers

If Cadenya is involved in a merger, acquisition, or sale of assets, Customer Data may be transferred to the acquirer as part of the transaction. We will notify affected Customers of any such transfer and the resulting changes to this Privacy Policy.

5.3 Legal Requirements

We may disclose information if we believe disclosure is required by applicable law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Cadenya, our Customers, or others.

5.4 Consent

We may share information for any other purpose with your prior written consent.

6. DATA RETENTION

We retain different categories of data for different periods, depending on purpose and legal obligations:

Data Category

Retention Period

Notes

Agent Execution Logs

14 days from creation

Automatically and permanently deleted upon expiration. Shorter periods can be configured. No export after deletion.

API Credentials

Duration of account + 30 days post-termination

Account & Configuration Data

Duration of subscription + 30 days

Billing Records

7 years (or as required by law)

Retained for tax and financial compliance obligations.

Usage / Telemetry Data (anonymized)

Indefinite

Aggregated, anonymized data that cannot reasonably identify Customer or individuals.

Support Communications

Up to 1 year from resolution

Retained for quality assurance and legal compliance.

7. SECURITY

We implement technical and organizational security measures designed to protect information against unauthorized access, disclosure, alteration, or loss. Our measures include:

  • Encryption of data at rest (AES-256) and in transit (TLS 1.2 or higher);
  • Role-based access controls and multi-factor authentication for Cadenya personnel;
  • Isolated, encrypted storage of Customer API credentials;
  • Regular penetration testing and vulnerability assessments;
  • Security logging, monitoring, and incident response procedures; and
  • Employee security training and background checks for personnel with data access.

Despite these measures, no security system is impenetrable. We will notify affected Customers within seventy-two (72) hours of confirming a security breach that materially affects their data, as required by applicable law.

Customers are responsible for securing their own accounts, API credentials, and access to the Service configuration interface. Customers should immediately notify us at security@cadenya.com if they suspect unauthorized access.

8. INTERNATIONAL DATA TRANSFERS

Cadenya operates in the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

9. PRIVACY RIGHTS

9.1 GDPR Rights (EEA, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have the following rights with respect to personal data we process about you (as a controller):

  • Access: request a copy of the personal data we hold about you;
  • Rectification: request correction of inaccurate or incomplete data;
  • Erasure: request deletion of your personal data in certain circumstances;
  • Restriction: request that we restrict processing in certain circumstances;
  • Portability: receive your personal data in a structured, machine-readable format;
  • Objection: object to processing based on legitimate interests; and
  • Withdrawal of consent: where processing is based on consent, withdraw consent at any time.

9.2 California Rights (CCPA/CPRA)

California residents have the following rights:

  • Know: request information about the categories and specific pieces of personal information we collect, use, and disclose;
  • Delete: request deletion of personal information we have collected (subject to exceptions);
  • Correct: request correction of inaccurate personal information;
  • Opt-Out of Sale or Sharing: we do not sell or share personal information for cross-context behavioral advertising; and
  • Non-Discrimination: we will not discriminate against you for exercising your privacy rights.

To submit a CCPA request, contact us at [privacy@cadenya.ai] with "California Privacy Request" in the subject line.

10. COOKIES AND TRACKING TECHNOLOGIES

Our website and Service interface use cookies and similar technologies for:

  • Authentication and session management (strictly necessary);
  • Security and fraud prevention (strictly necessary); and
  • Analytics and performance monitoring (functional/analytics)

.

We do not use third-party advertising cookies or tracking technologies for behavioral advertising. You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies may impair Service functionality.

11. CHILDREN'S PRIVACY

The Service is not directed to, and we do not knowingly collect personal information from, individuals under the age of 16. If we become aware that we have collected personal information from a minor, we will delete it promptly. Please contact us at privacy@cadenya.ai if you have questions or concerns.

12. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. For material changes, we will provide notice via email to the Customer's account address and/or a prominent notice in the Service interface at least thirty (30) days before the changes take effect. Non-material changes take effect upon posting. Continued use of the Service after the effective date of any changes constitutes acceptance of the updated Policy.

13. CONTACT INFORMATION

For privacy questions, requests, or complaints, please contact:

Privacy Contact

privacy@cadenya.ai

Security Issues

security@cadenya.ai

Mailing Address

Cadenya, Inc., 169 Madison Ave STE 15482

New York, NY 10016

If you are located in the EEA and have a complaint about our data practices, you have the right to lodge a complaint with your local data protection authority.