Privacy Policy
Last updated: 29 July 2026
1. Who we are
Cadanz is management software for dance schools. It is currently operated on an individual basis by its founder; no legal entity has yet been incorporated for it. Until one is, the operator is the point of contact for everything in this policy and can be reached at privacy@cadanz.io. When a company is registered, this policy will be updated with its legal name, registered address and, if one is required, its data protection officer.
2. What data we collect
We collect only what the Service needs to work:
- Account data — your email address, whether it has been verified, and an authentication identifier. Passwords are handled by our authentication provider and are never stored by us or visible to us.
- Profile data — first and last name, and optionally a phone number, date of birth, profile photo and short biography. Only the name is required.
- School and membership data — which organisations and schools you belong to and in what role (owner, admin, instructor, student), your class enrolments, your timetable, and attendance marked by an instructor.
- Administrative records — where a school issues you a bill or assigns you a pass, the record of it: amounts, status, and any payment reference the school itself enters.
- Notification data — your notification preferences and, if you use a mobile app and allow it, a device token so push notifications can reach that device.
- Technical data — server logs containing IP address, request metadata and timestamps, kept for security and debugging.
We do not collect payment card data. The Service does not currently take payments — see section 5.
We do not use advertising cookies, we do not track you across other websites, and we do not sell personal data. Browser storage is used only to keep you signed in and to remember preferences such as language and light/dark theme.
3. How we use your data & legal basis
- To provide the Service — creating your account, authenticating you, showing your schedule and enrolments, and letting your school administer its activities. Legal basis: performance of a contract (GDPR Art. 6(1)(b)), or the school’s own basis where it is the controller (section 4).
- To send service messages — email verification, password resets, invitations, and notifications about your classes. Legal basis: contract, and our legitimate interest in operating the Service (Art. 6(1)(f)).
- To keep the Service secure and working — logging, rate limiting, abuse prevention and debugging. Legal basis: legitimate interest (Art. 6(1)(f)).
- To meet legal obligations — where the law requires records to be kept or requests to be answered. Legal basis: legal obligation (Art. 6(1)(c)).
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Controller / processor roles
Which role we play depends on the data:
- We are the controller for your own account — the email address and profile you create, your authentication, and the technical logs needed to run the Service.
- We are a processor for the data a school records about its members: enrolments, attendance, bills, announcements and similar. The school is the controller of that data. It decides what to collect and why; we process it on the school’s instructions to provide the Service.
If you are a member of a school and want data corrected or erased from its records, the quickest route is usually to ask the school directly. You can also contact us and we will act on the school’s instruction, or handle it ourselves where we are the controller.
5. Payments
The Service is free during early access and we do not process payments. We do not collect or store card details, and we do not hold funds. Where a school records a bill, a package or a payment in Cadanz, that is a bookkeeping entry the school maintains for itself; any money changes hands outside Cadanz, directly between the school and its member.
If online payment is introduced later, this policy will be updated before it is switched on, and the payment provider will be named here as a sub-processor.
6. Sub-processors
We keep the list short on purpose. The Service currently relies on:
- Scaleway SAS (France, EU) — hosting. The application, the database and uploaded files all run on servers in Paris. The database and file storage are self-hosted there rather than being third-party services.
- Google Ireland / Google LLC — Firebase Authentication — account sign-in and password handling.
- Google Ireland / Google LLC — Firebase Cloud Messaging — delivery of mobile push notifications, where you have enabled them.
- OVH SAS (France, EU) — outbound email (verification, password reset, invitations, notifications).
No analytics, advertising or session-recording provider is used. We will update this list before adding a sub-processor that handles personal data.
7. Data retention
We keep personal data for as long as your account is active, and then only as long as we have a reason to.
- Account and profile data — kept while the account exists. When erasure is requested, the account enters a grace period (30 days by default) before the data is permanently deleted or anonymised, so that an accidental or disputed request can be reversed.
- School records — retained by the school for as long as it needs them. When a school deletes a record it is soft-deleted first, so it can be restored if the deletion was a mistake, and purged afterwards.
- Technical logs — kept for a short period for security and debugging, then rotated out.
Records that must be kept for a fixed period by law — for example accounting records, once the Service handles them — are retained for that period regardless of an erasure request, and are then deleted.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting what was done before.
Cadanz provides self-service data export and erasure in the app. You can also write to privacy@cadanz.io and we will respond within one month. We may need to verify your identity first, so that we do not disclose someone else’s data to whoever asks.
If you believe your data has been handled improperly you may complain to the data protection supervisory authority of the EU or EEA country where you live, work, or where the issue occurred. A directory is maintained by the European Data Protection Board at edpb.europa.eu. Once an operating entity is registered, its lead supervisory authority will be named here.
9. International transfers
The Service is hosted in the European Union — application, database and uploaded files are on servers in Paris, France, and email is sent through a provider in France. Your data is not routinely moved outside the EEA.
The exception is the Google services in section 6 (authentication and push notifications), which may involve processing outside the EEA. Those transfers rely on the safeguards Google offers for them — Standard Contractual Clauses approved by the European Commission and, where applicable, the EU–US Data Privacy Framework. Push notifications are optional: if you do not enable them on a device, no token is created for it.
10. Changes to this policy
We will update this policy as the Service develops — and certainly when an operating entity is incorporated, if payments are introduced, or if a sub-processor is added. The date at the top shows the current version, and we will give notice through the Service or by email where a change materially affects you.
11. Contact
Questions about this policy or your data: privacy@cadanz.io. General enquiries: hello@cadanz.io or the contact form.