Skip to content

Privacy Program

This document describes how Cadence OneFive identifies and meets requirements for the preservation of privacy and protection of personally identifiable information (PII), in accordance with ISO 27001:2022 control A.5.34 and applicable laws and regulations.

This document covers all PII processed by Cadence OneFive, whether collected directly from data subjects or received through customer engagements.

Categories of Data Subjects and PII Processed

Section titled “Categories of Data Subjects and PII Processed”
Data Subject PII Collected Purpose Storage Location
Customers (building owners, managers, utility contacts) Name, email, phone, organization, billing information Service delivery, account management, communications Hubspot (CRM), Momentum platform (Fly.io/AWS S3), Google Workspace
Building occupants Limited to building-level data; no individual occupant PII collected Energy modeling, retrofit planning Momentum platform
Employees Name, email, address, tax ID, banking details, emergency contacts Employment administration, payroll, benefits Justworks (PEO), Google Workspace
Contractors Name, email, tax ID, banking details Contractor payments, access provisioning Ramp, Justworks, Wise, Google Workspace (contracts)
Website visitors IP address, browser metadata, form submissions Marketing, lead generation, analytics Hubspot, Cloudflare (logs), PostHog
Data subjects → Momentum platform / Hubspot / Google Workspace
Fly.io (application DB) / AWS S3 (file storage)
Backups (Fly.io snapshots, S3 versioning)

Employee and contractor PII is processed primarily by Justworks as an independent PEO, outside the ISMS scope (see ISMS Manual §4.3).

Regulation Applicability Key Requirements
CCPA / CPRA (California) Applicable — customers and employees may be California residents Right to know, delete, and opt-out; disclosure of data practices; reasonable security
State privacy laws (Colorado, Connecticut, Virginia, etc.) May apply depending on customer locations Similar rights frameworks; data protection assessments for high-risk processing
GDPR Applicable — some contractors are EU residents; customers may also be EU residents Lawful basis for processing; data subject rights; data protection by design; breach notification
CAN-SPAM Applicable to marketing emails Opt-out mechanism; accurate sender information

Customer contracts may include data protection terms. Where customers require specific privacy commitments (e.g., data processing agreements), these are reviewed and approved by the CISO.

Processing Activity Legal Basis
Customer data for service delivery Contractual necessity
Employee/contractor data for employment administration Contractual necessity and legal obligation
Marketing communications Consent (opt-in)
Security logging and monitoring Legitimate interest (security of systems and data)
Analytics and product improvement Legitimate interest

Privacy is implemented through the existing policy suite:

Protection Implementing Policy
PII classified as Confidential by default Data Classification Policy
Encryption at rest and in transit Data Security Policy, Encryption Key Management
Access restricted by least privilege GitHub Access Policy, Data Security Policy
Retention and disposal procedures Data Disposal Policy
Vendor due diligence for PII processors Vendor Management Policy
Logging of access to systems containing PII Log Management Policy

Cadence OneFive supports the following rights where required by applicable law:

  • Right to know — Data subjects may request what PII is held about them
  • Right to correction — Data subjects may request correction of inaccurate PII
  • Right to deletion — Data subjects may request deletion of their PII, subject to legal retention obligations (see Data Disposal Policy)
  • Right to opt-out — Data subjects may opt out of marketing communications

Requests may be received by any team member and are fulfilled within 30 days, or within the timeframe required by applicable law, under the Head of Platform’s accountability — see the Erasure Request Procedure below.

Erasure Request Procedure (GDPR Article 17 / CCPA Right to Delete)

Section titled “Erasure Request Procedure (GDPR Article 17 / CCPA Right to Delete)”

This procedure exists to make the 30-day commitment above auditable, not just aspirational.

  1. Intake. A deletion/erasure request can arrive through any channel — support, sales, customer success, or a direct email to the Head of Platform. Whoever receives it logs it the same day as a Data Subject Request issue in this repo, recording the date received — this issue is the system of record for the SLA, not an inbox or a private note.
  2. Identity verification. Verification does not require the Head of Platform specifically — whoever received the request (support, sales, customer success, etc.) may perform it and record how on the tracking issue:
    • If the request comes from the email address already on file for the account, that is sufficient verification.
    • If it comes from a different address for a matched account, confirm by replying to the account’s on-file email — not the address the request arrived from — and require an affirmative response before proceeding. Where possible, this confirmation should come from whoever already has the relationship with that account (their usual sales, support, or customer success contact), not an unfamiliar name — a familiar sender is more likely to get a response.
    • If the account can’t be matched directly at all (e.g., a former employee whose email is no longer active or known), verify through that organization’s designated Momentum account admin instead — there’s no on-file email to confirm through in this case.
    • The 30-day clock (step 3) starts once identity is confirmed, not at intake — per GDPR Art. 12(6), requesting reasonable additional verification doesn’t count against the response deadline.
  3. SLA tracking. The tracking issue’s target date is verified-date + 30 days (GDPR Art. 12(3)). Regardless of who handled intake and verification, the Head of Platform is accountable for the deadline. Open Data Subject Request issues are reviewed weekly as a standing item in the recurring DevOps/security team meeting, not left to a single person to remember — so the review doesn’t lapse if any one attendee is out. If a request can’t be completed in 30 days, the requester is notified within that first month, told why, and given a revised date up to two further months out — silence past 30 days is not an option under GDPR.
  4. Fulfillment. For a Momentum platform account, this means anonymizing the user’s PII per the erasure mechanism tracked in CadenceOneFive/momentum#18649 — until that mechanism ships, fulfillment is a manual, engineer-assisted anonymization coordinated with the Head of Platform, following the same intent (irreversible, no residual plaintext PII). For PII held in other systems listed in the PII Inventory above, deletion follows that system’s own procedure (e.g., the Data Disposal Policy for S3/Fly.io, Justworks’s own process for employee/contractor data). Third-party processors that may independently retain the same person’s data (Sentry, PostHog, Resend) are being audited separately (CadenceOneFive/momentum#18704) — until that’s resolved, treat those systems as out of this procedure’s guaranteed scope, not silently covered by it.
  5. Confirmation and closure. The Head of Platform records the completion date on the tracking issue and confirms fulfillment to the requester. The issue is then closed, not deleted — it’s retained as the audit record of the erasure (it references the account/request, not the erased PII itself, so retaining it doesn’t undermine the erasure).

In the event of a data breach involving PII, notification obligations are assessed based on applicable law:

  • CCPA/CPRA: Notification to affected California residents without unreasonable delay
  • State breach notification laws: Notification per state-specific requirements
  • GDPR (if applicable): Supervisory authority within 72 hours; affected individuals without undue delay if high risk

Breach response follows the Business Continuity and Disaster Recovery Plan.

Role Responsibility
Head of Platform Accountable for privacy program; approves data processing agreements; accountable for data subject requests meeting their SLA (see Erasure Request Procedure — verification itself may be performed by whoever receives the request)
CISO Maintains PII inventory; assesses privacy risks as part of risk assessment; monitors regulatory changes
All Personnel Handle PII in accordance with the Data Classification Policy; report suspected privacy incidents; may receive and verify a data subject request per the Erasure Request Procedure

Users of the Momentum platform agree to the Privacy Policy, which they are required to accept during each login. This user-facing policy should be kept consistent with the data practices described in this document.

  • This document will be reviewed annually and updated as necessary to reflect changes in PII processing activities, applicable regulations, or contractual requirements.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.