DPA at a glance
Cendaro acts as a service provider or processor for workspace customer data, follows documented customer instructions, uses approved subprocessors, supports privacy workflows, and applies security and audit controls appropriate for launch-readiness review.
1. Scope and role of the parties
This Addendum applies when a workspace customer uses Cendaro to process personal information in leads, customer profiles, messages, bookings, quotes, privacy workflows, exports, and related operational records. In that context, the workspace customer controls the purposes of processing and Cendaro acts as a service provider or processor for the limited purposes described in the main service agreement and public privacy documentation.
2. Processing instructions
Cendaro processes customer personal information to host the platform, authenticate users, route lead and booking workflows, support customer communications, store operational records, generate permitted exports, provide approved AI-assisted features, and support privacy, audit, billing, and security operations. Cendaro does not process customer data for unrelated advertising or data-sale purposes.
3. Categories of data
The platform may process customer and prospect names, phone numbers, email addresses, preferred language, service-request details, customer message history, booking details, quote details, consent evidence, call or voicemail metadata if enabled, internal ownership and follow-up fields, privacy request records, and related audit or workflow evidence generated through the service.
4. Subprocessors and infrastructure
Cendaro uses a controlled set of service providers to operate the service, including Supabase for core database and authentication services, Vercel for hosting and runtime execution, Stripe for billing, Resend for transactional email, Telnyx for phone and SMS services, and OpenAI for AI-assisted features when enabled. These subprocessors are further described on the public Subprocessors page and in internal launch review records.
5. Security and confidentiality
Cendaro applies administrative, technical, and organizational safeguards designed to protect customer personal information against unauthorized access, misuse, disclosure, alteration, or loss. These safeguards include role-based access controls, protected environment secrets, audit logging, scoped admin access, privacy workflow gating for destructive actions, and documented restore and retention review controls.
6. Cross-border processing
Cendaro and its subprocessors may process personal information in Canada, the United States, or other jurisdictions where supporting infrastructure operates. Customers should review the Privacy Policy, Subprocessors page, and customer-facing notices to understand that service-provider processing may occur outside their home jurisdiction.
7. Privacy assistance and incident support
Cendaro provides product workflows for privacy request intake, status tracking, secure export delivery, approved destructive execution, legal retention signoff, and restore-readiness review. If a privacy or security incident affects customer data, Cendaro will assess the incident, preserve relevant evidence, and support customer notification or response steps as required by law or contract.
8. Return, deletion, and retention
Customer data remains subject to documented retention, deletion, export, and redaction controls. Some records may be preserved for legal, billing, fraud, security, support, or audit reasons even after account closure or deletion review. Cendaro's public Privacy Policy and internal retention-signoff workflow describe how operational records are reviewed before irreversible deletion or redaction changes are made.
Contact
For questions about this Addendum, vendor processing, privacy workflows, or customer-data handling, contact Cendaro's privacy contact.