Privacy Policy

  1. Introduction and Scope

Cascade Software Systems (“Cascade”, “we”, “us”, or “our”) respects privacy and is committed to handling personal information responsibly. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with https://www.cascadegovsoftware.com/, our communications, demonstrations, sales and support activities, and the products and services described below.

Cascade develops and supports WinCAMS, a modular cost and project accounting system used by public works, road, fleet, facilities, utilities, engineering, and other government departments.

For public website and direct business relationship information, Cascade generally acts as a business/controller. For Customer Data processed solely to provide contracted services, Cascade generally acts as a service provider/processor to the Customer. For Customer-hosted or on-premise deployments, the Customer may control most operational data directly.

This Policy does not replace a customer contract, data processing addendum, business associate agreement, security addendum, records-retention schedule, or agency-specific privacy notice. If those documents conflict with this Policy concerning customer-controlled data, the applicable contract or customer instruction controls to the extent permitted by law.

This Policy also does not apply to information handled solely in an employment or job-applicant context, which may be covered by a separate workforce privacy notice.

  1. Key Definitions

Personal information / personal data: Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. It does not include information that is lawfully public, deidentified, or aggregated where excluded by applicable law.

Customer: A government agency, municipality, district, business, or other organization that purchases, licenses, or evaluates our products or services.

Customer Data: Information submitted to, stored in, or processed through a product or service by or for a Customer, including information relating to the Customer’s personnel, residents, ratepayers, vendors, assets, accounts, operations, or transactions.

Service provider / processor: An entity that processes personal information on behalf of another organization and under contractual restrictions.

Sensitive personal information: Information treated as sensitive under applicable law, such as account credentials, precise geolocation, government identifiers, financial account information, or certain demographic, biometric, health, or communications data.

  1. Personal Information We Collect

The categories below describe information we may collect. The exact information depends on the individual’s relationship with us, the Customer’s configuration, and whether a product is hosted by us, hosted by a Customer, or deployed on premises.

CategoryExamplesTypical sources
Contact and professional informationName, work email, phone number, organization, title, department, mailing address, and communication preferences.Directly from you, your employer or agency, referrals, public sources, events, and business partners.
Commercial and relationship informationProducts or services requested, demo activity, proposals, contracts, licenses, support entitlements, invoices, and account history.You, Customer representatives, our sales/support systems, and contracting records.
Online activity and device informationIP address, browser and device type, operating system, referring pages, pages viewed, timestamps, cookie identifiers, logs, and approximate location derived from IP address.Automatically through websites, hosting infrastructure, security tools, cookies, and similar technologies.
Communications and support informationEmails, form submissions, call notes, support tickets, screen shares, training records, troubleshooting files, and feedback.Directly from you or Customer personnel and through support channels.
Account and authentication informationUsername, organization, role, permissions, authentication events, and security logs. Passwords should be stored only in protected form.You, Customer administrators, identity providers, and our systems.
Payment and transaction informationBilling contact, purchase order, invoice, payment status, and limited payment metadata. Full card or bank details may be processed by a payment provider rather than stored by us.Customers and payment, banking, procurement, or accounting providers.
Security and compliance informationAudit logs, access records, incident information, vulnerability reports, and records needed to meet contractual or legal requirements.Our systems, Customers, security providers, and authorized investigators.
WinCAMS operational and government recordsDepending on modules and Customer configuration: employee or contractor identifiers, time and labor, equipment and vehicle records, inventory, purchasing, budgets, project and work-order data, service requests, facility or infrastructure data, addresses, meter or account references, and related notes or attachments.Government Customers, authorized users, configured integrations, imports, and Customer systems.
Demo and evaluation informationDemo credentials, evaluation activity, training attendance, and feedback.Prospective Customers and authorized evaluators.

We ask Customers and users not to submit personal information that is unnecessary for the requested purpose. Customers are responsible for configuring their use of our products and establishing lawful collection, access, retention, and disclosure practices for Customer Data.

  1. How We Use Personal Information

Provide, configure, host, maintain, support, secure, and improve our websites, products, and services.

Respond to inquiries, schedule demonstrations, prepare proposals, manage contracts, deliver training, and provide customer service.

Authenticate users, administer permissions, troubleshoot issues, maintain audit logs, prevent fraud and abuse, and protect systems and data.

Process transactions, invoices, renewals, procurement requirements, and related business records.

Communicate service notices, security alerts, product updates, and—where permitted—marketing communications.

Analyze website and service performance, understand usage, diagnose errors, and develop features, using aggregated or deidentified information when practical.

Comply with law, public-sector contracting obligations, court orders, audits, records requirements, and enforce our agreements and policies.

Establish, exercise, or defend legal claims; investigate incidents; and protect the rights, safety, property, and integrity of our company, Customers, users, and the public.

Carry out mergers, acquisitions, financing, restructuring, or other corporate transactions subject to appropriate confidentiality and legal safeguards.

Legal bases for EEA, UK, and similar jurisdictions

Where applicable, we rely on one or more of the following legal bases: performance of a contract; steps requested before entering a contract; compliance with legal obligations; legitimate interests such as operating and securing our business, supporting Customers, preventing fraud, and improving services; consent where required; and protection of vital interests or performance of tasks in the public interest where applicable. Individuals may withdraw consent at any time, without affecting earlier lawful processing.

  1. Artificial Intelligence and Automated Processing

We may use software-assisted tools, including artificial intelligence, to help with tasks such as support triage, documentation, coding, security analysis, search, or business analytics. We do not intend to use website visitor information or Customer Data to make decisions producing legal or similarly significant effects about individuals unless expressly disclosed, contractually authorized, and supported by required notices, assessments, consent, human review, and opt-out rights.

IT REVIEW: Confirm whether any generative-AI vendors receive personal information or Customer Data; whether vendor training is disabled; the applicable retention settings; and whether any product features perform profiling or consequential decision-making.

  1. Cookies and Similar Technologies

Our website may use cookies, pixels, local storage, server logs, and similar technologies. These technologies may be necessary for site operation and security, remember preferences, measure performance, or support analytics. Where required, we will obtain consent before placing nonessential cookies and provide a mechanism to manage preferences.

Our public contact form has used Google reCAPTCHA to reduce spam and abuse. reCAPTCHA may collect device and interaction information under Google’s terms and privacy policy. IT should confirm the current version, configuration, and whether additional notice or consent is required.

Browser settings may allow users to block or delete cookies. Blocking necessary cookies may affect functionality. Where legally required and technically applicable, we will recognize valid universal opt-out preference signals, such as Global Privacy Control, for sales, sharing, or targeted advertising.

IT REVIEW: Inventory all active cookies, tags, analytics, session replay, advertising pixels, consent-management tools, and embedded content before publication. Add a cookie list or separate Cookie Notice if nonessential technologies are used.

  1. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients, only as reasonably necessary and subject to appropriate safeguards:

Hosting, cloud, data center, content-delivery, backup, communications, customer-support, CRM, analytics, security, identity, accounting, payment, and professional-service providers.

Customers and their authorized administrators, personnel, contractors, auditors, or integration partners as directed by the Customer or needed to provide the services.

Government authorities, courts, regulators, law enforcement, or other parties when required by law or reasonably necessary to protect rights, safety, security, and integrity.

A successor, purchaser, investor, lender, or adviser involved in a proposed or completed merger, acquisition, financing, reorganization, bankruptcy, or transfer of assets, subject to confidentiality and legal requirements.

Other parties with the individual’s direction or consent.

WinCAMS may exchange information with systems selected by a Customer. Such integrations and disclosures are controlled by the Customer’s configuration and agreements.

No sale of personal information

We do not sell personal information for money. We also do not knowingly sell or share personal information of individuals under 16. Some privacy laws define “sale,” “sharing,” or “targeted advertising” broadly enough to include certain analytics or advertising technologies. Based on current intended practices, we do not use Customer Data for cross-context behavioral advertising. IT must verify whether any website tags could constitute sale, sharing, or targeted advertising and, if so, implement required opt-out links and disclosures.

  1. Customer Data and Public-Sector Systems

WinCAMS is designed for government cost accounting and operational management. Depending on the Customer and modules used, records may relate to personnel, contractors, vendors, assets, vehicles, facilities, roads, bridges, utilities, work orders, maintenance requests, budgets, labor, equipment, materials, inventory, projects, and service requests. Cascade does not determine the governmental purpose or public-records status of these records.

Customers determine what Customer Data is collected, the purposes for processing, user access, disclosure, retention, and responses to data-subject or public-records requests. We process Customer Data under Customer instructions and applicable contracts, except where law requires otherwise. Individuals seeking access to, correction of, or deletion of Customer Data should generally contact the relevant Customer or government agency first. We will assist the Customer as required by contract and law.

Customer Data may be subject to public-records, freedom-of-information, government retention, audit, litigation-hold, or other sector-specific requirements. Nothing in this Policy promises deletion where a Customer or law requires preservation.

  1. Data Security

We use administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include access controls, authentication, encryption where appropriate, logging, backups, vulnerability management, employee training, incident response, vendor oversight, and contractual safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

IT REVIEW: Confirm actual controls and avoid publishing unsupported certifications. Add verified statements regarding encryption, MFA, SOC reports, penetration testing, secure development, incident notification, and hosting regions only after validation.

  1. Retention and Disposal

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide services, comply with contracts and law, resolve disputes, maintain security and audit records, and enforce agreements. Retention depends on the type of information, sensitivity, risk, contractual requirements, Customer instructions, public-sector records schedules, legal limitation periods, and whether deletion is technically and legally feasible. We then delete, deidentify, aggregate, or securely dispose of information in accordance with applicable procedures.

IT REVIEW: Map each system and data category to an approved retention schedule. Consider separate periods for website leads, CRM records, support tickets, recordings, logs, backups, financial records, inactive accounts, and Customer Data.

  1. International Data Transfers

We are based in the United States, and personal information may be processed in the United States or other countries where we or our service providers operate. Those countries may have different data-protection laws. Where required, we use recognized safeguards for restricted transfers, such as adequacy decisions, standard contractual clauses, the UK International Data Transfer Addendum or Agreement, contractual and technical supplementary measures, or another lawful transfer mechanism.

  1. Privacy Rights

Depending on the individual’s location and applicable law, rights may include:

Confirm whether we process personal information and access or obtain a copy of it.

Correct inaccurate personal information.

Delete personal information, subject to exceptions.

Receive certain information in a portable format.

Object to or restrict certain processing.

Opt out of sale, sharing, targeted advertising, or qualifying profiling.

Limit certain uses or disclosures of sensitive personal information.

Withdraw consent where processing is based on consent.

Appeal a denial of a privacy request, where provided by law.

Receive equal service and pricing and not be discriminated against for exercising privacy rights.

Lodge a complaint with a data-protection authority or regulator.

How to submit a request

Submit a request using the contact information in Section 18. Please describe the right being exercised and the relationship to us. We may verify identity and authority using information proportionate to the request. Authorized agents may submit requests where permitted, but we may require proof of authorization and identity verification. We will respond within the time required by applicable law and explain any denial and available appeal process.

If the request concerns Customer Data, identify the relevant government agency or Customer. We may direct the request to that organization because it controls the data and can verify the requester’s relationship to the records.

California disclosures

For California residents, the categories in Section 3 also describe the categories of personal information collected during the preceding 12 months; Sections 4 and 7 describe business or commercial purposes and recipient categories. Subject to applicability and exceptions, California law may provide rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive nondiscriminatory treatment. We do not use or disclose sensitive personal information for purposes requiring a right to limit unless IT/legal determines otherwise. We will update this disclosure at least annually where required.

Other U.S. states

Residents of states with comprehensive privacy laws may have similar rights, subject to each law’s scope, exemptions, and effective dates. These laws may include Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states that enact comparable requirements. We will honor verified requests to the extent required by applicable law.

  1. Children’s Privacy

Our public website and business services are not directed to children under 13, and we do not knowingly collect personal information directly from children through the public website. Products used by government agencies may contain information about minors when a Customer lawfully collects and manages that information. In that context, the Customer is responsible for appropriate authority, notices, consents, access controls, retention, and compliance with laws protecting children and student or resident records. Contact us if you believe a child submitted personal information directly to us without appropriate authorization.

  1. Marketing Communications

Individuals may opt out of promotional email by using the unsubscribe mechanism or contacting us. We may still send nonpromotional messages, such as contract, service, security, billing, or support communications. We do not use Customer Data to market unrelated products directly to residents or ratepayers unless authorized by the Customer and permitted by law.

  1. Third-Party Sites and Integrations

Our websites and products may link to or integrate with third-party sites, payment processors, identity providers, mapping systems, financial systems, asset-management systems, or other applications. Those third parties have their own privacy practices. A link or integration does not mean that we control the third party’s handling of information. Customers should review and configure integrations appropriately.

  1. Do Not Track

Some browsers transmit “Do Not Track” signals. Because there is no single accepted standard governing all such signals, our website may not respond to traditional Do Not Track signals. We will process legally recognized universal opt-out signals where required and applicable.

  1. Changes to This Policy

We may update this Policy to reflect changes in technology, law, products, vendors, or practices. The effective date at the top indicates the latest revision. When required, we will provide additional notice of material changes. Prior versions should be archived according to our records practices.

  1. Contact Us

Questions, complaints, and privacy requests may be directed to:

OrganizationCascade Software Systems
Privacy emailsupport@cascadegovsoftware.com
Websitehttps://www.cascadegovsoftware.com/
Phone(541) 343-9160
Mailing address132 E Broadway, Suite 800, Eugene, OR 97401

    ARE YOU INTERESTED IN LEARNING MORE?

    Contact a Cascade Software Systems Expert today at (541) 343-9160

    Contact Us Now