Privacy Policy
Version 1.0 · effective from 2026-08-13
1. Data controller
The controller of personal data of Candy Lab platform users is [registration details to be completed], contact: hello@candylab.io.
This policy describes what data we process in connection with the platform, for what purpose and on what legal basis.
2. What data we process
Account data: email address, name, credentials stored as an irreversible hash.
Integration data: git account credentials and AI provider keys — stored encrypted and never returned to the browser.
Usage data: technical logs, IP addresses, pipeline events, agent conversation history and Project content.
3. Purposes and legal bases
Delivering the service and billing — Art. 6(1)(b) GDPR (performance of a contract).
Security, diagnostics and abuse prevention — Art. 6(1)(f) GDPR (legitimate interest).
Accounting and tax obligations — Art. 6(1)(c) GDPR.
Analytics and marketing beyond what is necessary — Art. 6(1)(a) GDPR (consent, which can be withdrawn).
4. Processors
We use the following providers, to whom we entrust data processing:
Anthropic — language-model provider; processes Project and conversation content as needed to carry out an agent task.
GitLab — hosting for code repositories, including company repositories and backup copies.
DigitalOcean — server infrastructure running the platform and its databases.
The current list is available on request at hello@candylab.io.
5. Data inside Client repositories and Projects
If the Client places personal data in a Project (for example in a test database, an import file or the code), the Client remains its controller and the Provider processes it solely on the Client's instructions, as a processor.
Such processing requires a separate data processing agreement (Art. 28 GDPR). We conclude one at the Client's request — contact: hello@candylab.io.
6. Retention
Account data — for the duration of the agreement and until claims become time-barred.
Technical logs — up to 12 months.
Repository backup copies — until the Client disables the copy or the Project is deleted.
Billing documents — for the period required by tax law.
7. Your rights
You have the right to access your data, rectify it, erase it, restrict processing, port it and object to processing based on legitimate interest. You may withdraw consent at any time.
You also have the right to lodge a complaint with the supervisory authority.
8. Transfers outside the EEA
Some providers process data outside the European Economic Area. Transfers rely on standard contractual clauses or another mechanism provided for in Chapter V GDPR.
10. Contact
For matters concerning personal data: hello@candylab.io.
Version identifier: privacy@1.0