Skip to main content
Cadence

Privacy policy

This policy has not been drafted yet.

Cadence has not launched. Rather than publish placeholder legal text that reads like a commitment, this page says plainly that the policy is with counsel. It will be replaced before the product is available to buy, and it is excluded from search engines until then.

If you need our privacy position before that, email privacy@cadencedental.com.au and you will get a straight answer from a person.

What the product actually does today

Engineering facts, not legal undertakings. They are what the policy will be drafted against.

  • · Data residency: Australian region only. Patient health information does not leave the country.
  • · Retention: 7 years from last service; where the patient was under 18, until they turn 25 — whichever is later. Configured per record type and per country.
  • · Breach process: a suspected breach opens a register entry and starts a 30-day assessment clock (Privacy Act Part IIIC s26WH(2)), surfaced as a task.
  • · Access logging: every read of a patient record is written to an append-only audit log with no delete path.
  • · Vendor access: support cannot read clinical data by default; it requires a time-boxed grant with a written reason that the customer can see.
  • · Marketing consent: explicit opt-in only, captured separately from any other action, with opt-out honoured on receipt.
  • · Sub-processors: to be listed once hosting, email and SMS providers are contracted.