Privacy Policy
Last updated: July 24, 2026
This policy describes how Cadence (operated by PRNet Consulting) collects and uses information. Cadence serves real-estate businesses (“customers”); most of the personal information we process belongs to our customers’ leads and is processed on the customer’s behalf and instructions.
1. Information we collect
- Customer account data: name, email, business details you provide at sign-up and onboarding; billing details are handled by Stripe (we never store card numbers).
- Lead data (processed for customers): names, phone numbers, emails, and inquiry details submitted through forms, embeds, or forwarded emails; call recordings, transcripts, and AI-generated call summaries.
- Calendar data: with your consent, free/busy availability and the events Cadence creates on your connected Google Calendar. Google user data is used only to check availability and book consults, and is never sold or used for advertising, in accordance with the Google API Services User Data Policy (including Limited Use).
- Usage and telemetry: product events, call outcomes, and diagnostic logs used to operate and improve the service. Our website uses Google Analytics to understand aggregate visitor behavior; IP-based location is coarse and we do not use it for advertising personalization.
2. How we use it
To deliver the service: place and manage calls, book consultations, generate summaries, send notifications, bill subscriptions, prevent abuse, and improve reliability. We do not sell personal information. We do not use lead data to train foundation models.
3. Service providers (subprocessors)
Data is shared with providers only as needed to run the service:
- Google Cloud (hosting, database), Stripe (payments), Brevo (email)
- VAPI, ElevenLabs, Deepgram (voice calls, speech synthesis, transcription)
- AI inference providers for parsing and summarization; where third-party PII is processed for extraction, we default to end-to-end-encrypted, attested execution environments so intermediaries cannot read the content
- Google Calendar (booking, with your explicit OAuth consent)
4. Communications consent and timing
Leads who submit a Cadence-hosted form expressly invite an immediate callback — at any time, including outside customary calling hours — about the inquiry they submitted, including via an AI voice assistant. We record the exact consent language shown, a timestamp, and the submitting IP address with each lead so the invitation is verifiable. Follow-up attempts after the immediate callback are made within customary calling hours (8 a.m.–9 p.m. local time). Opt-out is honored immediately on any channel.
5. AI processing and Google user data (Limited Use)
The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
Cadence’s Google Calendar access is narrow by design. Free/busy intervals are read on our own servers, held in memory only long enough to compute open appointment slots, and never stored or shared with any third party. Event access is write-only: Cadence creates consult bookings on your calendar and never reads your events. The connected account’s email address is used only to show you which account is connected and to prefill your notification settings.
The only calendar-derived information the AI voice assistant ever handles is the list of open appointment times our servers computed — provided during a call solely so the assistant can offer and book consult times, a core user-facing feature of Cadence. We never use Google user data to create, train, or improve machine-learning models, and we never transfer Google user data to any third party for that purpose. Our AI subprocessors do not receive raw Google user data, and their terms prohibit sharing customer content with third parties for independent model training.
Where third-party personal information (such as forwarded lead emails) is processed for text extraction, we default to end-to-end-encrypted, hardware-attested execution environments: the content is sealed on our servers, only the attested enclave can decrypt it, and it is never readable by — or available for training to — the model provider or any intermediary.
6. Call recording
Calls may be recorded and transcribed so customers can review conversations with their leads. Customers are responsible for ensuring recording is lawful in the jurisdictions they call and for any required notices.
7. Retention and deletion
Account and lead data are retained while the customer’s account is active. Leads can opt out at any time (saying “stop calling” on a call, or replying STOP to an email) and are added to a do-not-call list. Customers may request deletion of their organization’s data (including their leads’ data) at any time; we delete within 30 days except where law requires retention.
8. Your rights
Depending on where you live, you may have rights to access, correct, or delete personal information. Leads should direct requests to the real-estate business that contacted them (the data controller); we assist our customers in honoring such requests. You may also contact us directly and we will route your request.
9. Security
Data is encrypted in transit and at rest; OAuth tokens are additionally encrypted at the application layer; access is limited and audited. No system is perfectly secure — report concerns to the contact below.
10. Changes and contact
We will post updates here and notify customers of material changes. Contact: PRNet Consulting · team@callcadence.ai