Privacy Policy

    Version 1.0 · effective from 2026-08-13

    This document is a working draft awaiting legal review. Until that review is complete it does not constitute binding terms of service.

    1. Data controller

    The controller of personal data of Candy Lab platform users is [registration details to be completed], contact: hello@candylab.io.

    This policy describes what data we process in connection with the platform, for what purpose and on what legal basis.

    2. What data we process

    Account data: email address, name, credentials stored as an irreversible hash.

    Integration data: git account credentials and AI provider keys — stored encrypted and never returned to the browser.

    Usage data: technical logs, IP addresses, pipeline events, agent conversation history and Project content.

    3. Purposes and legal bases

    Delivering the service and billing — Art. 6(1)(b) GDPR (performance of a contract).

    Security, diagnostics and abuse prevention — Art. 6(1)(f) GDPR (legitimate interest).

    Accounting and tax obligations — Art. 6(1)(c) GDPR.

    Analytics and marketing beyond what is necessary — Art. 6(1)(a) GDPR (consent, which can be withdrawn).

    4. Processors

    We use the following providers, to whom we entrust data processing:

    Anthropic — language-model provider; processes Project and conversation content as needed to carry out an agent task.

    GitLab — hosting for code repositories, including company repositories and backup copies.

    DigitalOcean — server infrastructure running the platform and its databases.

    The current list is available on request at hello@candylab.io.

    5. Data inside Client repositories and Projects

    If the Client places personal data in a Project (for example in a test database, an import file or the code), the Client remains its controller and the Provider processes it solely on the Client's instructions, as a processor.

    Such processing requires a separate data processing agreement (Art. 28 GDPR). We conclude one at the Client's request — contact: hello@candylab.io.

    6. Retention

    Account data — for the duration of the agreement and until claims become time-barred.

    Technical logs — up to 12 months.

    Repository backup copies — until the Client disables the copy or the Project is deleted.

    Billing documents — for the period required by tax law.

    7. Your rights

    You have the right to access your data, rectify it, erase it, restrict processing, port it and object to processing based on legitimate interest. You may withdraw consent at any time.

    You also have the right to lodge a complaint with the supervisory authority.

    8. Transfers outside the EEA

    Some providers process data outside the European Economic Area. Transfers rely on standard contractual clauses or another mechanism provided for in Chapter V GDPR.

    9. Cookies and analytics

    We use cookies necessary for the site to work and — subject to consent — analytics cookies. You manage consent in the cookie banner and in your browser settings.

    10. Contact

    For matters concerning personal data: hello@candylab.io.

    Version identifier: privacy@1.0