Skip to main content

Candor Data Platform – Privacy Policy

Version 1.1.0  |  Effective Date: June 1, 2026  |  Last Updated: June 1, 2026

This Privacy Policy ("Policy") explains how Proden Technologies, Inc., a company registered in Wyoming, USA, located at 30 N Gould St, Sheridan, Wyoming 82801 ("Candor," "we," "us," or "our"), collects, uses, discloses, and protects information when you ("User") access or use the Candor Data Platform and its associated AI features.

By installing, accessing, or using the platform, you consent to the practices described in this Policy.

1. Information We Collect

1.1 User-Provided Information

We may collect information you directly provide, including:

  • Account details (name, email, business information)
  • Login credentials (securely hashed)
  • Configuration settings, project files, workflows, and ETL definitions
  • Support inquiries and communication logs

1.2 AI Input Data

To operate AI-assisted features, we may collect:

  • Prompts, queries, instructions, or messages submitted by the User
  • Code fragments, schema definitions, or workflow rules provided for processing
  • System usage metadata (e.g., tool selected, interface interactions)

Users must not input confidential, personal, regulated, or sensitive data into AI prompts.

1.3 Automatically Collected Data

We automatically collect technical information, including:

  • Device information, IP address, browser type
  • Usage statistics, event logs, and performance indicators
  • Platform interaction data for reliability and optimization
  • Authentication metadata and license validation signals

1.4 Third-Party AI Providers

When you use AI features, prompts and processed data may be transmitted to:

  • AWS Bedrock
  • Groq
  • Anthropic
  • Google Gemini
  • Other integrated AI processors

These providers may have separate privacy practices. Candor does not control external LLM data handling.

2. How We Use Your Information

We use collected information to:

  • Provide platform functionality and authenticated services
  • Generate AI-assisted outputs (ETL scripts, code, workflow suggestions)
  • Improve AI accuracy, system performance, and platform security
  • Maintain operational logs, detect misuse, and enforce licensing
  • Communicate updates, alerts, and system notifications
  • Conduct anonymized analytics to enhance product development

We do not sell User data.

3. Data Sharing and Disclosure

We may share information under the following conditions:

3.1 With Authorized Third-Party Providers

To operate AI features, payment processing, cloud infrastructure, and analytics.

3.2 Compliance and Legal Obligations

Information may be disclosed to:

  • Law enforcement, if required
  • Regulatory authorities, where applicable
  • To enforce EULA terms or protect platform integrity

3.3 Business Transfers

If Candor undergoes a merger, acquisition, or restructuring, user data may be transferred under proper confidentiality safeguards.

4. AI Data Handling and Privacy

4.1 Processing of AI Inputs

AI input data (prompts, configuration data, scripts) may be processed on third-party cloud servers operated by trusted AI providers (AWS Bedrock, Groq, Anthropic, Gemini). Candor implements industry-standard security measures including encryption in transit (TLS), access controls, and secure transmission protocols. However, data processed through third-party AI services is subject to those providers' security practices and privacy policies. We strongly recommend that users avoid submitting highly sensitive, confidential, or regulated data (such as personal health information, financial data, or proprietary trade secrets) to AI features unless such submission is permitted under applicable law and your organization's policies.

4.2 Data Minimization

We encourage entering only non-sensitive, non-regulated information.

4.3 Output Ownership

Users retain ownership of AI-generated outputs, subject to the AI-EULA's restrictions.

4.4 Anonymized Model Improvement

Aggregated and anonymized usage data may be used to:

  • Train internal improvements
  • Enhance performance, accuracy, and reliability

No personal information is used for model training.

4.5 Automated Decision-Making & AI-Assisted Outputs

Certain features of the Candor Data Platform involve automated processing of your inputs (prompts, schema definitions, workflow configurations) to generate ETL scripts, code suggestions, pipeline recommendations, and data transformation outputs. These outputs are AI-assisted tools intended to support your decisions — they do not constitute fully automated decisions with legal or similarly significant effects on you as defined under GDPR Article 22.

You retain full control and are solely responsible for reviewing, validating, and applying any AI-generated output. Candor does not make automated decisions about individuals without human oversight. If this changes, we will update this Policy and provide appropriate opt-out mechanisms.

5. User Responsibilities

Users agree NOT to:

  • Input personal, confidential, or regulated data into AI modules
  • Use the platform to process sensitive personal information
  • Breach export control laws, privacy regulations, or data protection standards
  • Circumvent subscription, licensing, or security controls

Users are solely responsible for the legality and appropriateness of the data they submit.

6. Cookies and Tracking Technologies

The Candor Data Platform website and associated web services may use the following types of cookies and tracking technologies:

  • Essential Cookies: Session cookies and authentication tokens required for login, security, and core platform functionality. These cannot be disabled without impairing platform use.
  • Performance & Analytics Cookies: Persistent cookies and usage analytics scripts (such as Google Analytics or similar tools) that help us understand how the platform is used, identify errors, and improve reliability. These are non-essential and require your consent.
  • Functional Cookies: Cookies that remember your preferences and settings to provide a personalized experience.

6.1 Cookie Consent & Opt-Out

When you first visit our website, you will be presented with a cookie consent notice allowing you to accept or decline non-essential cookies. You may change your cookie preferences at any time through your browser settings or by contacting us at privacy@candorsys.com.

Most browsers allow you to block or delete cookies. Visit www.allaboutcookies.org for guidance on managing cookies across different browsers.

6.2 Global Privacy Control (GPC)

We recognize and honor the Global Privacy Control (GPC) signal, a browser-level opt-out mechanism for the sale and sharing of personal data for cross-context behavioral advertising, as required by the California Consumer Privacy Act (CCPA 2023). If your browser transmits a GPC signal, we will treat this as a request to opt out of the sale or sharing of your personal data for targeted advertising purposes.

7. Data Security

Candor employs industry-standard security measures, including:

  • Encryption in transit (TLS)
  • Access-control and authentication layers
  • Regular audits and monitoring
  • Intrusion and anomaly detection
  • Secure cloud infrastructure

However, no system is 100% secure. Users assume responsibility for verifying AI outputs and safeguarding their environments.

8. International Data Transfers

Candor Data Platform's infrastructure, AI processing, and third-party service providers may operate across multiple regions, including the United States and international data centers (including within the EEA, UK, and other jurisdictions).

Where personal data is transferred outside of the European Economic Area (EEA) or the United Kingdom, Candor relies on the following lawful transfer mechanisms as required under GDPR Chapter V:

  • Standard Contractual Clauses (SCCs): We use the European Commission's approved Standard Contractual Clauses (2021/914/EU) with our third-party processors and sub-processors located outside the EEA, including AI providers (AWS Bedrock, Groq, Anthropic, Google) and cloud infrastructure partners.
  • Adequacy Decisions: Where the European Commission has issued an adequacy decision for a destination country, we may rely on that decision as a transfer mechanism.
  • UK IDTA: For transfers to and from the United Kingdom, we use the UK International Data Transfer Agreement (IDTA) as the applicable transfer mechanism.

For a copy of the Standard Contractual Clauses applicable to your data transfers, or for more information about our transfer safeguards, please contact us at privacy@candorsys.com.

9. Payment Processing & Billing Information

All payment transactions for Candor Data Platform subscriptions are processed by Paddle.com Market Ltd. (and its affiliates, "Paddle"), which acts as the Merchant of Record for all purchases. As Merchant of Record, Paddle is responsible for payment processing, tax collection, invoicing, and handling payment-related customer service and refund requests. Paddle's privacy policy governs how Paddle collects and processes your payment data: paddle.com/legal/privacy.

Candor does not store, access, or process your credit card or bank account details. All payment-related inquiries should be directed to Paddle's customer support or to us at sales@candorsys.com.

9.1 Paddle Buyer Data — What Candor Receives

When you complete a purchase through Paddle, Paddle shares the following limited order information with Candor solely for the purposes described below:

  • Data received from Paddle: Your name, email address, country, order ID, subscription plan, and subscription status.
  • Purpose of use: Candor uses this data exclusively for: (a) provisioning and managing your Candor account and subscription; (b) providing customer support; and (c) sending transactional notifications (e.g., subscription renewals, payment confirmations).
  • Marketing restriction: Candor does not use Paddle buyer data for marketing or promotional communications unless you have explicitly opted in to such communications through a separate consent mechanism.
  • Lawful basis: Processing of Paddle buyer data is based on Contract Performance (GDPR Art. 6(1)(b)) — it is necessary to fulfill your subscription and deliver the services you have purchased.

9.2 Refunds, Tax Handling, and Payment Validation

  • Subscription Cancellation: You may cancel your subscription at any time through your account settings or by contacting Paddle's customer support. For monthly subscriptions, you will be charged for the full month. Cancellation takes effect at the end of your current billing cycle, and you retain access until that date. No charges apply for subsequent months after cancellation. For Pay-as-you-Go plans, you will be charged only for usage actually consumed during your active subscription period.
  • 30-Days Money-Back Guarantee: If you are not satisfied due to technical issues, service unavailability, or failure to deliver advertised features, you may request a full refund with 30 days of your initial purchase. Submit refund requests to Paddle's customer support or to sales@candorsys.com.
  • Tax Handling: VAT, GST, and applicable sales taxes are automatically calculated and collected by Paddle in accordance with local tax laws.
  • Failed Transactions: Failed or reversed transactions may result in account suspension pending resolution.

10. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. The following table provides indicative retention periods per data category:

Data Category Retention Period Basis
Account & registration data Duration of subscription + 3 years after termination Contract, Legal obligation
Billing & transaction records 7 years (tax/financial law compliance) Legal obligation
AI prompt & input data Processed transiently; not stored beyond session unless required for diagnostics (≤30 days) Legitimate interest, minimization
Platform usage & event logs 90 days (rolling) Legitimate interest (security & reliability)
Security & audit logs 1 year Legal obligation, security
Support & correspondence records 3 years from last interaction Legitimate interest (dispute resolution)
Marketing & consent records Until consent withdrawn + 3 years Consent, legal obligation

After the applicable retention period, personal data is securely deleted or anonymized. Users may request early deletion of non-essential stored data by contacting privacy@candorsys.com, subject to legal and operational constraints.

11. Lawful Basis for Processing (GDPR)

We process personal data based on the following lawful bases under GDPR:

  • Contract Performance: To provide the Software and services you have purchased or subscribed to
  • Legitimate Interests: To improve our services, prevent fraud, ensure security, and analyze usage patterns
  • Consent: For marketing communications and optional features (you may withdraw consent at any time)
  • Legal Obligations: To comply with applicable laws, tax requirements, and regulatory obligations

Paddle Buyer Data: When you purchase through Paddle.com, we receive order and billing information solely for order fulfillment, account management, and support. We do not use Paddle buyer data for marketing purposes unless you have explicitly opted in. Paddle acts as the Merchant of Record and handles payment processing, tax compliance, and related customer service inquiries.

12. User Rights (GDPR, CCPA, and Other Jurisdictions)

Depending on your jurisdiction, you may have the following rights:

  • Right of Access: Request a copy of your personal data we hold
  • Right to Rectification: Request correction of inaccurate or incomplete information
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal and operational constraints
  • Right to Restrict Processing: Request limitation of how we process your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Withdraw Consent: Withdraw previously given consent at any time
  • Right to Non-Discrimination (CCPA): Exercise your privacy rights without discrimination
  • Right to Opt-Out of Sale (CCPA): We do not sell personal data to third parties.
  • Right to Opt-Out of Sharing (CCPA 2023 – SB 362): We do not share personal data for cross-context behavioral advertising. If you use a browser or device that transmits a Global Privacy Control (GPC) signal, we will honor it as a valid opt-out of sale and sharing of your personal information, as required by California law.
  • Right to Correct (CCPA 2023): Request correction of inaccurate personal information we hold about you.

12.1 How to Exercise Your Rights

To exercise any of these rights, please submit a request by:

  • Privacy Email: privacy@candorsys.com — include "Privacy Request – [Your Name]" in the subject line. This is the primary channel for all GDPR/CCPA rights requests, data deletion, and consent withdrawal.
  • Mail: Proden Technologies, Inc., 30 N Gould St, Sheridan, Wyoming 82801, USA

Response Time: We will respond to your request within 30 days (or as required by applicable law). We may request identity verification to protect your privacy.

Appeals: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (e.g., ICO in the UK, CNIL in France, or your state's Attorney General for CCPA).

13. Children's Privacy

The platform is not intended for children under 16.

We do not knowingly collect or process information from minors.

14. Changes to This Policy

We may update this Privacy Policy periodically.

Revisions will be communicated via:

  • Email notifications
  • In-app alerts
  • Updated documentation

Your continued use signifies acceptance of updated terms.

15. Contact Information

For questions, privacy requests, data subject rights, or compliance matters, please use the following contacts:

  • Privacy & Data Protection Requests: privacy@candorsys.com — use subject line: "Privacy Request – [Your Name]"
    Use this email for GDPR/CCPA rights requests, data deletion, consent withdrawal, or international transfer queries.
  • General & Sales Inquiries: sales@candorsys.com
  • Payment & Billing (via Paddle): Contact Paddle Support directly for invoice, payment, or refund queries.

Proden Technologies, Inc.
30 N Gould St, Sheridan, Wyoming 82801, USA
www.prodentechnologies.net

Right to Lodge a Complaint: If you are not satisfied with how we handle your privacy request, you have the right to lodge a complaint with your local data protection authority — for example, the ICO (UK), CNIL (France), BfDI (Germany), or your state's Attorney General (CCPA – California). We encourage you to contact us first so we can address your concern directly.