Skip to content

Privacy policy

Effective September 7, 2026 · Technologies Vestax (“Cadanse”, “we”)

Cadanse is a management platform for dance studios. We take the protection of personal information seriously and comply with Québec's Law 25 (An Act to modernize legislative provisions as regards the protection of personal information). This policy explains what information we collect, why, how we protect it, and your rights. It is provided in English for convenience; the French version prevails.

1. Personal information protection officer

The person in charge of the protection of personal information at Technologies Vestax is Jonathan Coll. For any question, access request or complaint regarding your personal information, write to support@cadanse.app.

2. Information we collect

Depending on your relationship with Cadanse, we may collect:

  • Studios (customers): studio name, contact details, billing and subscription information.
  • Parents and responsible adults: name, email, phone, address, emergency contact, payment history and receipts.
  • Students, including minors: name, date of birth, classes taken, attendance, costume measurements, and — only if the studio enters them — medical notes (sensitive information).
  • Studio staff: name, email, role, and a log of the actions performed in the Service — who created, changed or deleted what, and when. Exactly one read is logged too: access to a student's medical note, which goes through a button that says so before the click and writes a single entry per person, per student, per day. That log is kept for 12 months, then destroyed (§7). The studio that employs you can read it. For this information, Cadanse is the controller, not a processor: the asymmetry with the entry above is deliberate, and §4 explains it.
  • Payment data: processed by our payment providers (see §6). Your card number is entered in a field served by the provider itself and goes straight to it: it never transits through our servers, and we have access to it at no point. We do not store card numbers; we keep a transaction identifier and status.
  • Technical data: sign-in information (authenticated sessions) and logs needed for operation and security.
  • Referral origin: when a studio circulates a campaign link (an ad, a newsletter, a QR code), the labels that link carries — the source, the medium and the campaign name — are kept with the record created on that occasion, so the studio knows what brings families to it. Those labels describe the link, never the person: they are neither an identifier nor a profile (see §10).

3. Purposes of collection

We use this information to:

  • provide the service (registrations, classes, attendance, payments, receipts, recital);
  • communicate with you (confirmations, reminders, notices);
  • produce tax receipts and, where applicable, required statements;
  • ensure security, prevent fraud and meet our legal obligations.

We do not use your information for automated decisions producing a legal effect, nor for advertising profiling. We never sell your personal information.

4. Consent (and minors)

Collection is based on your consent and on the need to perform the service. Where required, consent is clear, free and informed, and given for specific purposes. The studio acts as the controller of its families' information; Cadanse processes it on the studio's behalf, according to its instructions and these terms. For a child under 14, consent is given by the holder of parental authority. You may withdraw your consent at any time (see §8), subject to information we must retain by legal obligation.

One exception, and it is a real one: the log of studio staff actions (§2) is not processed on the studio's behalf. Cadanse keeps it to meet its own security and traceability obligations, and is therefore its controller. The studio has access to it because it answers for how its team uses its families' information; informing the people concerned is the studio's responsibility, and Cadanse also tells them at their first sign-in.

5. Hosting and security

Data is hosted in Canada (region ca-central-1). Sensitive information — medical notes, social insurance number (Relevé 24), payment tokens — is encrypted at rest (AES-256-GCM). Access is protected by authentication, per-studio isolation and logging of sensitive actions. Communications are encrypted in transit (TLS).

6. Disclosure to third parties (providers)

We rely on providers that process certain information solely to deliver the service, bound by contract:

  • Amazon Web Services (AWS) — hosting and database, Montréal region (Canada).
  • Stripe and Square — payment processing.
  • SendGrid — sending of transactional emails.
  • Twilio — sending of text messages, when that channel is used.
  • Sentry — technical error diagnostics (scrubbed traces, no personal content).
  • Plausible Analytics — aggregate audience measurement of the public site (see §10).
  • Meta (Facebook, Instagram) — advertising conversion reporting, only at studios that have turned it on and only with your consent (see §10); United States.

Some providers may process data outside Québec. We carry out a privacy impact assessment before any disclosure outside Québec, as required by Law 25.

7. Retention

We keep information for as long as necessary for the purposes above and to meet our legal and tax obligations (for example, keeping receipts). When no longer needed, it is securely destroyed or anonymized.

One duration is fixed and announced: the log of studio staff actions (§2) is kept for 12 months, then destroyed.

8. Your rights

In accordance with Law 25, you may:

  • access your information and obtain a copy;
  • have it corrected if it is inaccurate or incomplete;
  • withdraw your consent or request deletion, subject to the law;
  • request the portability of your computerized information;
  • request de-indexing or the cessation of dissemination of information whose dissemination causes you harm, in the cases provided by Law 25.

To exercise a right, write to support@cadanse.app. We respond within the time limits set by law (generally 30 days). If our response does not satisfy you, you may file a complaint with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

A studio staff member may ask to consult the log of their own actions (§2), or contest an entry in it, by writing to that same address — without going through their employer, since Cadanse is its controller.

9. Privacy incidents

In the event of an incident presenting a risk of serious harm, we take reasonable measures to contain it, notify the individuals concerned and the Commission d'accès à l'information, and record the incident in a register, as required by Law 25.

10. Cookies and tracking technologies

A cookie is a small file placed on your device. We use only cookies that are strictly necessary to operate the Service:

  • Authentication session — securely keeps you signed in once you have authenticated. Without this cookie, you could not access your account.
  • Language preference (NEXT_LOCALE) — remembers your French, English or Spanish choice to display the Service in your language.
  • Theme preference (NEXT_THEME) — remembers your light or dark appearance choice. No personal data, no tracking.

These cookies are essential: they serve only to provide the Service and require no separate consent. We use no advertising cookies and no profiling or cross-site tracking technology: no page of the Service loads an advertising script, and we run no targeted advertising for our own account.

Conversion reporting at a studio's request. A studio that buys advertising may ask us to report to its ad platform — today Meta (Facebook, Instagram) — that an enquiry, a trial or a registration has just taken place, so that it knows which of its ads led to it. This happens only at studios that have turned it on and only if you have consented: without your consent nothing leaves, and refusal is the default state. No cookie is placed and no advertising script is loaded — the send comes from our servers, not from your browser.

What leaves is a fingerprint of your email address and, where applicable, of your phone number: a computed code (SHA-256) that cannot be read directly. We do not present it as anonymity — the ad platform can match it against the addresses it already knows, and that is precisely what it is for. What never leaves: your name, your child's name, their date of birth, the course chosen, or any note. The studio may also ask that the amount paid be attached; that setting is off by default. This information is processed in the United States (see §6). You may withdraw your consent at any time from your account, without this changing anything about your registration. Sends then stop, with one nuance we would rather write down: an event already prepared before your withdrawal may still leave within the hour. Those already made cannot be recalled.

Public-site audience measurement. On the public pages of cadanse.app — never inside your account — we measure traffic with Plausible Analytics, a cookie-free tool: it stores nothing on your device and uses no persistent identifier. The measurements are aggregated (page viewed, referring page, country, device type, and two anonymous milestones — « Essai réservé » (trial booked) and « Inscription publique » (public registration)) and are tied to no individual. Those two milestones are counters with no content: they record that a trial or a registration just went through on a public page — never who, which course, or what amount. Your IP address is neither logged nor retained: it is used only, for the duration of the request, to compute an anonymous daily counter. The script is served from our own domain, so your browser contacts no third-party server; the aggregated measurements are, however, transmitted to our processor Plausible, in the European Union (see §6).

Which pages, exactly. The public pages of cadanse.app are our own site and each studio's public pages: its course catalogue, its team, its ticketing, its shop. Three families of pages are excluded, and that exclusion depends on no setting at our processor — it keeps the script from existing on the page at all. Pages you can only reach through a private link — an invoice, a ticket order, a shop order — are never measured, because their address contains the token that opens them. Neither is the widget a studio embeds in its own site. And the inside of your account never is, as stated above.

In accordance with Law 25, where a technology allows a person to be identified, located or profiled, its settings must offer the highest level of privacy by default. The audience measurement described above allows none of those three things: with no cookie and no identifier, no visit is tied to a person, so there is nothing for you to turn off. If your browser or an extension blocks that script, the Service works exactly the same. You may also block or delete cookies in your browser, but blocking the session cookie will prevent you from using your account.

Campaign label. When you reach a studio's public page through a campaign link, your browser keeps the labels that link carries (source, medium, campaign name) in the tab's session storage — not in a cookie. Nothing is transmitted while you browse: the label leaves your browser only if you fill in and submit one of the studio's forms yourself, and it is then kept with the record created on that occasion, once, at first contact. It contains no identifier, does not follow you from site to site, is never shared from one studio to another, and disappears as soon as you close the tab.

11. Studios established outside Québec

Cadanse is a Québec supplier, and applies the Law 25 standard to all the information it processes, wherever the studio is established. A studio established elsewhere in Canada remains, for its part, the responsible organization under the law that applies to it — the federal Personal Information Protection and Electronic Documents Act (PIPEDA), or the provincial law deemed substantially similar where one exists. It is the studio, not Cadanse, that determines which one applies to its situation.

In that relationship, Cadanse acts as a service provider: it processes families' information on the studio's behalf and according to its instructions (§4), hosts it in Canada (§5), and notifies it without delay of any privacy incident affecting its data (§9), so that it can meet its own reporting obligations.

The General Data Protection Regulation (GDPR) is not claimed. Cadanse does not offer its services in the European Union and monitors no one's behaviour there. Sending aggregated measurements to a European processor (§10) does not make us subject to it, and writing otherwise would amount to declaring ourselves bound by a regime we have not complied with.

12. Changes

We may update this policy. The effective date at the top of the page indicates the current version; significant changes will be flagged.