Cadivra

Data Processing Addendum

Last updated: August 2026

1. Parties and Scope

This Data Processing Addendum ("DPA") is entered into between Cadivra Limited ("Processor", "we", "us") and you, the customer ("Controller", "you").

This DPA forms part of and is incorporated into the Cadivra Terms of Service. In the event of any conflict between this DPA and the Terms of Service on data processing matters, this DPA shall prevail.

This DPA applies to the processing of personal data that Cadivra carries out on your behalf in connection with the Platform, as described in Section 4 below.

2. Definitions

"Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Personal Data Breach" have the meanings given in the UK GDPR (as retained by the European Union (Withdrawal) Act 2018, and as amended by the Data Protection Act 2018) and, where applicable, the EU General Data Protection Regulation (EU 2016/679).

"Customer Data" means any personal data you upload, import, or otherwise provide to Cadivra in connection with the service, including contact names, email addresses, job titles, company names, engagement data (opens, clicks, replies), and any other information about third-party individuals. It also includes, where you connect a mailbox, the subject, headers and body text of replies and delivery notices that Cadivra retrieves from that mailbox on your instruction.

"Approved Sub-Processor" means a third-party processor engaged by Cadivra to process Customer Data in accordance with Section 7.

3. Roles of the Parties

3.1 You are the Data Controller in respect of Customer Data. You determine the purposes and means of processing (for example, conducting outreach campaigns to your contacts).

3.2 Cadivra is the Data Processor. We process Customer Data only on your documented instructions and solely for the purpose of providing the Platform.

3.3 Dual-role acknowledgement. Separately from its role as Processor for Customer Data, Cadivra acts as an independent Data Controller in respect of: account registration and administration data; billing and payment information; support and communications data; security, fraud prevention, and abuse detection data; aggregated and anonymised usage statistics; and any data processed to comply with Cadivra's own legal obligations. Cadivra's processing as a controller is described in its Privacy Policy and is not subject to this DPA.

3.4 Services you connect to Cadivra (such as your email provider - e.g. Microsoft 365, Google Workspace - and your CRM - e.g. HubSpot) are independent services selected and controlled by you. They are not Cadivra sub-processors under this DPA. Where you connect such a service, Cadivra reads from and writes to it on your instruction (for example, syncing contacts and writing back engagement, meeting, and outcome data). Your use of those services is subject to your own agreements with the relevant provider.

4. Details of Processing (Article 28(3))

5. Controller Obligations

You warrant and represent that:

6. Processor Obligations

Cadivra shall:

7. Sub-Processors

7.1 You grant general authorisation for Cadivra to engage sub-processors for the processing of Customer Data. The current list of sub-processors is set out below and is maintained at:

https://cadivra.com/sub-processors

7.2 We will notify you of any intended changes to sub-processors by updating the sub-processor list and sending email notification at least 14 days before the new sub-processor begins processing. You may object to a new sub-processor within 14 days of notification. If we cannot reasonably accommodate your objection, either party may terminate the affected service upon 30 days' written notice.

7.3 We impose data protection obligations equivalent to those set out in this DPA on each sub-processor by way of a written contract. Cadivra remains liable to you for the performance of each sub-processor's obligations in respect of Customer Data.

8. International Transfers

Customer Data is hosted within the European Union (Railway, Netherlands). Some sub-processors (such as Anthropic and Cloudflare) are based in or route data through the United States. The full, current list is at cadivra.com/sub-processors. Where Customer Data is transferred outside the UK or EEA to a country not covered by an adequacy decision, we ensure appropriate safeguards are in place, including:

Copies of the applicable transfer mechanism are available upon request.

9. Security Measures

We implement and maintain appropriate technical and organisational measures to protect Customer Data, including:

A fuller description of these measures, including the specific protections applied to content retrieved from a connected mailbox, is set out in section 7 of our Privacy Policy.

10. Data Retention and Deletion

11. Audits

We will make available to you all information reasonably necessary to demonstrate compliance with this DPA. Upon at least 30 days' written notice, and no more than once per year (unless required by a supervisory authority), you or a qualified independent auditor may conduct an audit, subject to reasonable scope, timing, confidentiality obligations, and minimal disruption to our operations. Audit costs are borne by you unless the audit reveals a material breach by us.

12. Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service.

13. Governing Law

This DPA is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

14. Contact

Cadivra Limited. Email: [email protected]

Email: [email protected]

← Back to home