Privacy Policy
How Candor collects, uses, and protects personal data when you use the platform.
Candor is a platform for discovering online formations, reading and publishing reviews, participating in discussions, and managing a public contributor profile.
If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, this Privacy Policy is intended to provide the information required under the General Data Protection Regulation ("GDPR"), the UK GDPR, and similar privacy laws.
1. Who is responsible for your data+
Data controller: Candor
Operated from: Spain
Privacy contact: privacy@example.com
If you have questions about this Privacy Policy or want to exercise your privacy rights, you can contact us at privacy@example.com.
2. What data we collect+
We may collect the following categories of personal data:
- Account and profile information, such as your email address, account identifier, chosen username, chosen display name, and profile image or avatar.
- Content you submit, including reviews, comments, ratings, reports, and waitlist or creator inquiry information.
- Technical and usage information, such as IP address, browser and device information, cookie and session information, pages viewed, interactions with the Service, and security, diagnostic, and performance information.
3. How we collect data+
- directly from you
- when you sign in through Google
- when you create or update your profile
- when you publish reviews, comments, or reports
- through cookies and similar technologies
- through analytics, security, and anti-abuse tools used to operate the Service
4. How we use data+
- to provide and operate the Service
- to create and manage user accounts
- to authenticate users
- to publish and display reviews, comments, and public profiles
- to maintain trust, safety, and moderation systems
- to prevent abuse, spam, fraud, and misuse
- to improve the Service, product experience, and performance
- to communicate with users where necessary
- to comply with legal obligations
5. Legal bases for processing+
- Performance of a contract: where processing is necessary to provide the Service to you.
- Legitimate interests: where processing is necessary to operate, protect, and improve the Service.
- Consent: where required by law, including where certain optional technologies or features rely on consent.
- Legal obligation: where processing is necessary to comply with applicable laws or lawful requests.
6. Public profiles and pseudonymous publishing+
Candor is built around public, pseudonymous contributions.
When you create an account, you choose a public username and display name. Reviews, comments, and some profile-related activity may be shown publicly under those identifiers rather than your legal name.
This means:
- your reviews and comments may be visible to other users and to the public
- your public username and display name may appear alongside your contributions
- public content may be indexed by search engines
You are responsible for choosing public profile details you are comfortable sharing and for avoiding the inclusion of sensitive personal data in reviews, comments, or profile content.
8. Analytics and product improvement+
We may use analytics tools, including PostHog, to understand how the Service is used and to improve usability, reliability, and product quality.
These tools may collect limited usage, device, and interaction data. We use this information to understand product performance, improve features, and prioritize development.
9. Sharing of personal data+
We may share personal data with service providers that help us operate the Service, including providers for authentication, infrastructure and hosting, analytics, security, and abuse prevention.
These providers may include Supabase, Google, Upstash, PostHog, and other infrastructure providers used to run Candor.
We may also disclose personal data:
- where required by law
- to protect rights, safety, or security
- in connection with policy enforcement, abuse investigations, or legal claims
- as part of a merger, acquisition, restructuring, or similar business transaction
We do not sell personal data in the ordinary meaning of that term.
10. International transfers+
Candor and its service providers may process personal data outside your country, including outside the EEA, UK, or Switzerland.
Where required, we rely on appropriate safeguards for international transfers, such as adequacy decisions, contractual protections, or equivalent legal mechanisms.
You can contact us at privacy@example.com if you would like more information about international transfer safeguards.
11. Data retention+
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, maintain public content and community records, resolve disputes, enforce policies, comply with legal obligations, and prevent abuse and protect the platform.
Retention periods may vary depending on the type of data and the reason it was collected.
12. Your rights+
Depending on your location, you may have the right to access your personal data, correct inaccurate personal data, request deletion of your data, object to certain processing, request restriction of processing, request data portability, withdraw consent where processing is based on consent, and lodge a complaint with a supervisory authority.
If you are in the EEA, UK, or Switzerland, you may also complain to your local data protection authority.
13. How to exercise your rights+
To exercise your privacy rights, email us at privacy@example.com with the subject line `Privacy Request`.
Please describe your request clearly and provide enough information for us to understand and process it. We may ask for additional information where reasonably necessary to verify your identity.
We will respond within the timeframe required by applicable law.
14. Security+
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, misuse, loss, alteration, or disclosure.
However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Children+
Candor is not intended for children under 16, and we do not knowingly collect personal data from children under 16.
If you believe that a child has provided personal data to us, please contact us at privacy@example.com.
16. Third-party links+
Candor may contain links to external websites or third-party services. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy notices.
17. Changes to this Privacy Policy+
We may update this Privacy Policy from time to time. If we make material changes, we will update the 'Last updated' date and take additional steps where required by law.
18. Contact+
Candor
Operated from: Spain
Privacy contact: privacy@example.com
