Cadra Platform Privacy Notice
Last updated: 24 August 2026
Who We Are
CADRA MARKETPLACE LTD (Company No. 17099285) provides the Cadra platform (the "Platform"). For the personal data described in this notice, Cadra is the controller.
- Registered address: 1 London Road, Ipswich, Suffolk, United Kingdom, IP1 2HA
- Privacy contact: Fernando Freitas, fernando@cadra.uk
In this notice, "Cadra", "we", "us" and "our" mean CADRA MARKETPLACE LTD.
What This Notice Covers
This notice explains how we handle the personal data of the people who access and use the Platform — our Authorised Users (for example, staff of our customers who log in to use Cadra) — and our business contacts. For this data, Cadra is the controller.
Data we process on behalf of our customers. Separately, our customers upload and generate workforce and survey information through the Platform (for example, information about learners and about staff of their own customers). For that information, Cadra acts as a processor on the customer's instructions and the customer is the controller. If you are one of those individuals and want to understand how your data is used or exercise your rights, please contact the organisation that invited you or provided the survey — they are the controller. We describe the safeguards we apply to that data in "Security" and "Who We Share Data With" below, and we assist our customers in responding to requests about it.
The Personal Data We Collect
When you use the Platform as an Authorised User, we may collect:
- your name and business email address
- your job title / role and employer, where provided
- account and authentication data (for example, a securely hashed password and sign-in/session information)
- records of your activity in the Platform, including audit logs of significant actions
- support and correspondence you send us
- technical information such as IP address and browser/device information, and error diagnostics, collected through our hosting and monitoring infrastructure for security and reliability
How We Use Your Personal Data
We use this personal data to:
- provide, operate and secure the Platform and your account
- authenticate you and keep the service available and reliable
- respond to your support requests
- maintain audit and security records
- improve the Platform using aggregated or anonymised data from which you cannot be identified
- comply with our legal obligations
We do not sell your personal data, and we do not share it with other companies for their own marketing purposes.
AI Features
The Platform uses artificial intelligence to help draft certain narratives (for example, business-case and survey-analysis summaries). Our AI provider is Anthropic (the Claude API). We minimise what is sent: prompts are built from organisational context and aggregated or anonymised information, and we do not deliberately include direct identifiers such as names or email addresses. Under our commercial terms with Anthropic, data sent to the API is not used to train Anthropic's models and is retained for a maximum of 30 days. All AI-generated content is a draft that a person reviews before it is relied upon, and no decision producing legal or similarly significant effects for an individual is made solely by automated means.
Our Lawful Bases
Depending on the context, our lawful bases for the data we control include:
- performance of a contract — to provide the Platform to you and the organisation you belong to
- legitimate interests — to secure, maintain and improve the Platform, and to keep audit and security records
- legal obligation — where we must process data to comply with the law
(Where we act as processor for customer-uploaded data, we process it on the customer's documented instructions under our contract with that customer.)
Who We Share Data With
We use trusted service providers ("sub-processors") to run the Platform. They process personal data on our behalf under data-processing agreements:
- Supabase — database, authentication and file storage (UK/EU-hosted, Ireland)
- Vercel — application hosting (EU region)
- Resend — transactional email delivery (e.g. invitations, notifications)
- Anthropic — AI-assisted drafting (see "AI Features")
- Sentry — error monitoring and alerting (EU region; direct identifiers are removed before transmission)
We keep our current sub-processor list under review and update it as needed.
International Transfers
Most personal data is processed in the UK/EU. Two providers process personal data in the United States — Resend (email delivery) and Anthropic (AI drafting). Where personal data is transferred outside the UK, we rely on appropriate safeguards, including Standard Contractual Clauses (and, for Resend, participation in the Data Privacy Framework), and we carry out transfer risk assessments. Details are available on request.
How Long We Keep Data
We keep personal data only for as long as needed for the purposes above. Our current retention periods are:
- account and profile data — for the life of the account and then 30 days after it is closed
- audit and security logs — 12 months
- support correspondence — 24 months
Data we process on behalf of a customer is retained and deleted in line with our agreement with that customer.
Cookies
The Platform uses essential session cookies to keep you logged in and to keep the service secure. These are necessary for the Platform to work. If we introduce optional cookies (for example, analytics) in future, we will ask for your consent first and you will be able to change your preference at any time. See our Cookie Notice for details.
Your Rights
Depending on applicable law, you may have the right to:
- request access to your personal data
- request correction of inaccurate data
- request deletion of your personal data
- object to, or request restriction of, certain processing
- withdraw consent where processing is based on consent
- complain to the Information Commissioner's Office (ICO)
To exercise your rights, contact fernando@cadra.uk. If your request concerns data we process on behalf of a customer, we will direct you to, or assist, the relevant controller.
Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access control, and monitored alerting. Cadra is Cyber Essentials certified. No internet transmission or storage can be guaranteed completely secure.
Changes To This Notice
We may update this notice from time to time. The version published in the Platform, with the "Last updated" date above, is the current one.
Contact
Questions or privacy requests can be sent to fernando@cadra.uk.