Privacy Policy
Effective 25 July 2026 · Last updated 3 September 2026. The short version: we collect what the product needs to run your bookings and nothing more, we never sell your data, and every third-party service we share data with is listed on this page by name.
Who we are
This Privacy Policy explains how NYD&Co Pty Ltd(ACN 676 409 868, ABN 11 676 409 868), a company registered in Victoria, Australia (“Kadens”, “we”, “us”), collects, uses, discloses and protects personal information when you use the Kadens platform, websites and mobile apps (the “Service”), reachable at getkadens.com. Kadens is a booking, coordination and run-sheet platform for entertainment providers (DJs, MCs and bands), the people and businesses who book them, and the venues and clients involved in their events.
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, NYD&Co Pty Ltd is the data controller for the personal data described in this policy, except where we act as a processor on behalf of a business customer (see the controller and processor section below).
Contact: support@getkadens.com · PO Box 5793, Studfield, Victoria 3152, Australia.
Who this policy covers
The Service is used by several different groups, and we handle data about people who do not themselves hold an account:
- Performers — DJs, MCs, bands and their crew who hold Kadens accounts.
- Bookers — individuals and businesses (agencies, venues, promoters) who book or roster performers.
- Clients — couples, hosts or event buyers who interact with the Service through a secure link, usually without creating an account.
- Event crew and participants — people invited to an event, some of whom access it via a link without an account.
- Guests and third parties — people whose details are entered into the Service by a booker or client (for example in an event questionnaire), and people whose email addresses are submitted so they can be invited or referred.
If your personal information was provided to us by someone else (for example, a booker entered your details), we still handle it under this policy, and the rights described below still apply to you.
What we collect
Identity and contact information — name, email address, phone number (which may be verified by SMS), display name or performer handle, and profile photo or avatar.
Account and authentication data — your account identifier and, if you sign in with Google, Apple or Facebook, the identity and authentication tokens those providers return (stored encrypted). If you connect an Instagram professional account for booking capture, we also hold an Instagram access token, encrypted. Clients and some crew use a signed access link rather than an account.
Profile and public content — biography, electronic press kit, photos, share cards, and (where you use those features) your public page, ranking or listing.
Booking and event information — event dates, times, venues, gig types, fee notes, booking-request details, run sheets, scripts and schedules, plus the client details you enter to manage an event. For client and guest data you enter, you are the controller and we process it on your instructions.
Free-text event details you or others enter — including ceremony, cultural, dietary or accessibility notes. Some of this can reveal sensitive information (see the sensitive information section below).
Music information — song lists, do-not-play lists, and playlist data you import from music services.
Messages and user-generated content — booking requests, in-app messages, ratings and reviews, and contact-form and support enquiries.
Payment information — billing details and transaction identifiers needed to process payments and subscriptions. We do not collect or store full card numbers; card details are handled directly by Stripe.
Technical and device information — device identifiers and push-notification tokens, app version, platform, IP address, and information about how you use the Service, including for security and abuse prevention.
Calendar information — if you connect a calendar, the event information needed to sync it.
Referral information — referral codes and, where you invite someone, the email address you submit for them.
We do not knowingly collect information from anyone under 18 (see the children section).
Booking capture from shared messages
Kadens can capture a booking from content you share into it — a screenshot, a forwarded text, an email, or a DM. When you share content for capture, we process it solely to extract the booking details (who, when, where, what) and create the booking record you then review. The shared content can include messages written by a third party (the person who messaged you); we process it only on your instruction, only for that extraction, and we do not use it to build profiles of the sender, for advertising, or to train models. The original shared artefact is kept while the capture is waiting for your review, retained for up to 90 days after you confirm or dismiss it (so you can check what was captured against what was said), and then deleted — what remains is the structured booking you confirmed and an audit reference to when it was captured.
There are three ways content reaches capture, and they are the only three. You can forward an email to the private capture address we issue you. You can share or paste content into the mobile app from your phone — a screenshot, a copied message, a note — whatever messaging app it came from. And you can connect an Instagram professional account, so that direct messages sent to that account arrive in your capture queue.
The Instagram connection is capture-only.We ask Meta for permission to receive messages sent to your professional account; we do not send messages, reply, react, mark anything read, or post. For each direct message we receive the message text, the identifier Instagram uses for the sender, a message identifier and the time it was sent, and those become the draft booking you review. We do not store photos, videos or other attachments sent in a DM, and we do not receive your followers, your contacts or the sender’s profile. We hold a long-lived Instagram access token, encrypted; disconnecting deletes that token and stops any further capture, while the bookings you already confirmed remain yours.
Our use of data received from Meta’s APIs complies with Meta’s developer policies, is limited to providing the capture feature you connected, and is never sold or transferred except as needed to provide that feature.
Controller and processor
For most personal information (performer profiles, your own account, booking data you create), we are the controller. Where a booker or client uses the Service to manage their own event and enters information about other people (their crew, their guests), we generally act as a processor or service provider on that customer’s behalf for that data, and the customer is the controller. If you have a question about data a booker or client holds about you, contact them, or contact us and we will help direct your request.
Sensitive information
Some event details can reveal sensitive information as defined by the Australian Privacy Act (and special category data under the GDPR) — for example, information that reveals religious or cultural background (such as ceremony details), or health-related information (such as dietary or accessibility requirements). We collect this only where you or an event organiser choose to provide it so that the event can be run as intended. By entering such details, you consent to us handling them for that purpose. Please do not enter sensitive information that is not needed to run the event.
How we use it, and our legal bases
We use personal information to:
- create and administer accounts and authenticate users;
- provide the core Service — bookings, rostering, run sheets, scheduling and day-of coordination;
- process payments and subscriptions;
- send transactional messages by email and push (booking updates, reminders, notifications you asked for), and a one-time code by SMS when you verify a phone number;
- parse and structure inbound booking enquiries, including with automated / AI processing (see the next section);
- enable messaging, ratings and reviews, and public profiles or listings where you use those features;
- provide customer support;
- maintain security and prevent fraud, spam and abuse;
- comply with legal obligations; and
- with your consent where required, send marketing communications — opt in or out at any time from your preferences, or with one press on the unsubscribe link in any marketing email.
Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (providing the Service you sign up for); legitimate interests (securing and improving the Service, preventing fraud, and business operations, balanced against your rights); consent (marketing, and sensitive data); and legal obligation. You may withdraw consent at any time. We do not sell personal information, and we do not use your event data for advertising.
Automated processing and AI
We use a third-party AI service (Anthropic) to read and structure inbound booking enquiries you capture — for example, to turn a free-text email or message into a structured booking request — and to draft social captions when you ask for one. This processing extracts details such as names, contact details and event information from the content you share. You review every capture before it becomes a booking; this processing does not make legally significant decisions about you without human involvement. Personal information processed this way may be transferred overseas (see overseas disclosure below).
Children
The Service is intended for people aged 18 and over. You must be at least 18 to create an account, make a booking, or make a payment. We do not knowingly collect personal information from anyone under 18. If we learn we have collected such information, we will delete it. If you believe a minor has provided us information, contact us at support@getkadens.com.
How we collect information
We collect information: directly from you when you sign up, build a profile, create bookings or contact us; from bookers, clients or crew who enter information about you or invite you; from your device when you use the Service; from third-party sign-in and connected services you authorise (Google, Apple, Facebook, Instagram, calendar, music); and from our payment processor in relation to transactions.
Who we share it with (processors)
We share personal information with the service providers who help us run the Service. We do not sell your personal information. Named services, and what they hold:
- Supabase — our database, authentication, and file storage. Hosted in Sydney, Australia.
- Vercel — application hosting and delivery (Sydney region for compute; a global CDN for public pages). Every request to the Service passes through it.
- Stripe — payments, subscriptions, and tax. Stripe is a global processor and holds your card and billing details under its own certified controls.
- Zoho (CRM and Desk) — when you contact us through the website, submit a support request, or join a waitlist, your enquiry (name, email, what you wrote, and the routing details you chose) is transmitted to and stored in Zoho’s Australian data centre. We keep enquiry records in Zoho for as long as the conversation is active and up to 24 months after it closes, then delete them. Self-serve product signups are not synced to the CRM.
- ZeptoMail — transactional and lifecycle email: every email the product sends you. Holds your email address and the messages we send to it.
- Loops — our previous email provider. It is kept configured as a rollback only, so that we can switch back if ZeptoMail fails; no email is routed to it today. It still holds the email addresses and message history from the period it was in use.
- Mailgun — inbound email. When a booking enquiry is forwarded to your Kadens capture address, Mailgun receives that email — the sender’s address, the subject and the message body — and hands it to us. Nothing is sent through Mailgun.
- Twilio — the one-time code we send by SMS when you verify a phone number. Holds the number that code is sent to.
- Google — sign-in, venue and address lookup, and calendar sync and meeting links where you connect them.
- Apple — sign-in, and push notification delivery on Apple devices.
- Meta (Facebook and Instagram) — sign-in, and Instagram booking capture. When you sign in with Facebook, Meta gives us the permissions you approve there (your basic public profile and your email address), which means a Meta account identifier, your name, your profile picture and your email address; the Meta identity and its access token are held in our authentication system, and your email address on your Kadens account record. When you connect an Instagram professional account, Meta sends us the direct messages that account receives, and we hold an encrypted Instagram access token and the account identifier that tells us whose queue a message belongs in — see booking capture above for exactly what is kept. This is separate from the marketing measurement entry below.
- Spotify — song and playlist lookups when you or a client import a playlist.
- Expo, Apple (APNs) and Google (FCM) — push notification delivery to the mobile app. Hold your device push token.
- Pusher — realtime presence and broadcast on live events (Sydney region). Transient; holds connection metadata, not your content.
- Anthropic — AI parsing of booking enquiries and caption drafting (see the automated processing section above).
- Sanity — the content system behind our marketing pages. It publishes the words and images on those pages; we send it nothing about you.
- Google Analytics 4 and Meta (Pixel and Conversions API) — marketing measurement. Built in but not currently switched on, and if switched on they would cover signed-in pages as well as public ones; see the analytics section below for exactly what that means. The mobile app contains no analytics, advertising or tracking SDKs.
We may also disclose personal information: to a booker, client or crew member as needed to coordinate an event you are part of; to professional advisers; to authorities where required by law; and to a successor entity in the event of a business sale.
Overseas disclosure
Our core data stores (Supabase, Pusher and Zoho) are located in Australia. Several other providers above — including Vercel, Stripe, ZeptoMail, Mailgun, Loops, Twilio, Google, Apple, Meta, Expo and Anthropic — operate outside Australia, primarily in the United States, so some personal information is disclosed overseas. For individuals in the EU and UK, transfers outside the EEA/UK are made under appropriate safeguards, principally the Standard Contractual Clauses (or the UK equivalent) put in place by these providers. By using the Service you acknowledge these overseas disclosures.
Analytics, cookies, and consent
Google Analytics 4 and the Meta Pixel (with the server-side Conversions API) are built into this website, but they are not switched on. The account identifiers that activate them are not set in our production environment, so as at the last-updated date on this page, no analytics or advertising data is going to Google or Meta from any part of Kadens. We describe them here because the code is in place and we may enable it.
Neither one loads until you say so. When you first arrive, a banner asks whether you allow analytics and advertising cookies, and until you answer, the scripts are not placed on the page at all — so no request is made to Google or Meta, and nothing is collected to be sent later. This is the same for every visitor everywhere: there is no country where we switch tracking on for you by default, and declining takes exactly one press, the same as accepting.
You can change your answer at any time, in either direction, on our cookie preferences page, where the two categories are listed separately. Declining also stops the Meta Conversions API, which runs on our servers rather than in your browser — so a refusal reaches the part your browser’s own tracking protection cannot.
If you do allow them, this is how the code behaves, so you can judge it before it happens rather than after. They would load on every page of the website, including the pages you use once you are signed in — the signed-in product is not carved out, and the addresses of signed-in pages can contain event and booking identifiers. The one exception is magic-link pages — contract signing, client approval, invitations, rosters, payment and enquiry links — where analytics never loads at all, whatever you have chosen, so those links are never handed to a third party.
Cookies we do set today: your sign-in session; your light or dark theme; and, the first time you arrive from an external link carrying campaign tags, a first-party attribution cookie recording where you came from and the page you landed on, kept for 90 days. When you make a consent choice, that choice is stored for a year alongside a random identifier for your browser, so we have a record of what was chosen and when; neither is created before you choose.
How long we keep information
We keep personal information only as long as needed, then delete or de-identify it:
- Account and profile data — for the life of your account. If you delete your account, data is permanently deleted after the 30-day cancellation window described below.
- Booking and event content — while your account is active. Events you archive are permanently deleted 3 years after archiving.
- Captured message content — the original shared artefact is deleted 90 days after you confirm or dismiss a capture (see booking capture above).
- Financial and tax records — 7 years, as required by Australian tax and corporations law, de-identified where your account has been deleted.
- Support communications — as long as the conversation is active and up to 24 months after it closes.
- Marketing suppression (unsubscribe) records — kept indefinitely so we can honour your opt-out.
- Backups — overwritten on a rolling cycle of no more than 35 days.
Deleting your account
You can delete your account from inside the product (Settings → Account on the web, or Profile → Account in the mobile app), or — if you can’t sign in — from getkadens.com/delete-account, which emails you a confirmation link. Deletion starts a 30-day window during which nothing is hidden or locked and you can cancel at any time, restoring your account with no trace. After 30 days your account is permanently purged: events you own and their content are deleted, your files are removed, subscriptions are cancelled, and your email address is removed from our systems. Events owned by a booker survive with your assignment removed, and invoices are retained for 7 years in de-identified form as Australian tax law requires.
Your rights and choices
Depending on where you live, you may have the right to: access the personal information we hold about you; request correction; request deletion; request a copy of certain data in a portable format; object to or restrict certain processing; and withdraw consent. You can export much of your own data from within the Service. To make a request, contact support@getkadens.com. We will respond within the timeframe required by applicable law, and we may need to verify your identity first.
We handle requests under the Australian Privacy Principles; Australian individuals may complain to us first and then to the Office of the Australian Information Commissioner (OAIC). Where the GDPR or UK GDPR applies to you, you may lodge a complaint with your local data protection authority (in the UK, the Information Commissioner’s Office).
California privacy (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access and deletion, to correct inaccurate information, and to opt out of any “sale” or “sharing” of personal information. We do not sell your personal information and do not share it for cross-context behavioural advertising. We do not discriminate against you for exercising these rights. To make a request, contact support@getkadens.com.
Security
We take reasonable steps to protect personal information, including encryption in transit, access controls, encryption of sensitive tokens, and hosting with reputable providers. No system is completely secure; we cannot guarantee absolute security, but we work to protect your information and to notify you and the relevant regulator of any eligible data breach as required by law.
Changes
We’ll post changes here and bump the date at the top. Material changes get an email or in-product notice before they take effect.
Contact us
Questions, requests or complaints: NYD&Co Pty Ltd, PO Box 5793, Studfield, Victoria 3152, Australia · support@getkadens.com, or contact us. We aim to respond within 30 days.