Candy Sonic

Privacy Policy

Sign in to Candy Sonic

Last updated: [Date]

THIS PRIVACY POLICY (the "Privacy Policy") describes how:

NADIRAOS LLC, a Wyoming limited liability company (the "Company"), collects, uses, discloses, and protects information in connection with its software-as-a-service platform (the "Service").

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, you must not access or use the Service.

This Privacy Policy is incorporated into and forms part of the Company's Terms and Conditions (the "Terms"), available at [Terms URL].

1. Definitions

1.1 "Personal Data"

Any information that relates to an identified or identifiable individual, as defined under applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1.2 "Account Data"

Personal Data collected and stored by the Company to create and manage your Account, including but not limited to your name, email address, business name, encrypted password, and security settings.

1.3 "Workspace Data"

All data, content, records, files, and information that you and your Workspace members create, upload, store, or process within your isolated Workspace through the Service. Workspace Data is stored within the multi-tenant architecture in a logically separated environment associated with your business.

1.4 "Technical Data"

Information automatically collected when you access or use the Service, including IP address, browser type and version, device information, and usage logs.

1.5 "Data Controller"

The entity that determines the purposes and means of processing Personal Data. With respect to Account Data and Technical Data, the Company acts as the Data Controller. With respect to Workspace Data, you (or your business) act as the Data Controller and the Company acts as the Data Processor.

1.6 "Data Processor"

The entity that processes Personal Data on behalf of and on the instructions of the Data Controller.

1.7 "Third-Party Services"

External services, applications, or platforms that the Company uses to operate the Service, including but not limited to payment processors, email delivery providers, and cloud infrastructure providers.

2. Information We Collect

2.1 Account Data

We collect and store the following information to create and manage your Account:

  • Your name
  • Your email address
  • Your business name
  • An encrypted password (hashed using bcrypt)
  • Security settings (e.g., two-factor authentication configuration)
  • Subscription and billing status

2.2 Workspace Data

Workspace Data is the content and information that you and your Workspace members create, upload, store, or process within your Workspace. This may include but is not limited to:

  • Business records and data
  • Documents and files
  • Contact information and CRM data
  • Financial records
  • Communications and messages
  • Configurations and settings within your Workspace

Your Workspace Data is stored in an isolated, business-scoped environment within the Service's multi-tenant architecture. The Company processes Workspace Data on your behalf as a Data Processor. The Company does not access, review, or use your Workspace Data except as necessary to operate, maintain, and secure the Service, or as required by law.

2.3 Technical Data

We automatically collect certain technical information when you access or use the Service:

  • IP address (for security and fraud prevention)
  • Browser type and version
  • Device type and operating system
  • Referring URLs
  • Access timestamps
  • Feature usage logs (which features were used, not the content entered)
  • Server response times and error logs

2.4 Information Collected via Third-Party Services

Certain Third-Party Services used by the Company may collect information on their own, subject to their own privacy policies. These may include:

  • Payment processors (e.g., Stripe) — billing information, payment method details
  • Email delivery providers (e.g., self-hosted email server) — email addresses for transactional email delivery
  • Cloud infrastructure providers — server hosting and data storage

The Company does not control the data collection practices of Third-Party Services and is not responsible for their privacy practices. You are encouraged to review the privacy policies of any Third-Party Services you interact with.

3. How We Use Your Information

3.1 Account Data

We use Account Data to:

  • Create and manage your Account
  • Authenticate your identity and provide secure access
  • Communicate with you regarding your Account, the Service, and important updates
  • Process payments and manage subscriptions
  • Provide customer support
  • Detect, prevent, and address fraud, security incidents, and abuse
  • Comply with legal obligations

3.2 Workspace Data

We process Workspace Data solely to:

  • Provide, operate, and maintain the Service for your Workspace
  • Store and display your Workspace Data to you and your authorized Workspace members
  • Provide features and tools that process your Workspace Data as directed by you
  • Secure and back up your Workspace Data
  • Comply with legal obligations where applicable

We do not use your Workspace Data to:

  • Sell to third parties
  • Train machine learning models or artificial intelligence systems
  • Market products or services to you based on your Workspace Data
  • Share with advertisers or advertising networks

3.3 Technical Data

We use Technical Data to:

  • Operate, secure, and maintain the Service
  • Monitor performance and diagnose technical issues
  • Detect and prevent fraud, security incidents, and unauthorized access
  • Improve the Service's performance, reliability, and user experience
  • Generate aggregated, de-identified analytics about Service usage

3.4 Legal Basis for Processing (GDPR)

For Users in the European Economic Area, United Kingdom, or Switzerland, the Company's legal bases for processing Personal Data are:

  • Performance of a contract — processing necessary to provide the Service under the Terms (Account Data, Workspace Data processing)
  • Legitimate interests — security, fraud prevention, service improvement, and analytics (Technical Data)
  • Compliance with legal obligations — responding to legal requests, tax record retention
  • Consent — for any optional processing where consent is sought (e.g., marketing communications)

You may withdraw consent at any time for processing based on consent. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

4.2 Sharing with Third-Party Services

We share information with Third-Party Services only as necessary to operate the Service:

  • Payment processors (e.g., Stripe) — billing information and payment method details to process subscription payments
  • Email delivery providers (e.g., self-hosted email server) — email addresses and message content necessary to deliver transactional and service-related emails
  • Cloud infrastructure providers — data storage and hosting to operate the Service

Each Third-Party Service processes data in accordance with its own privacy policy and applicable laws. The Company selects Third-Party Services that it believes maintain appropriate data protection standards.

4.3 Disclosure Required by Law

The Company may disclose Account Data, Technical Data, or Workspace Data if required to do so by law, court order, subpoena, or other valid legal process. The Company will use commercially reasonable efforts to notify you of such disclosure unless legally prohibited from doing so.

4.4 Disclosure for Safety and Security

The Company may disclose information if it believes in good faith that disclosure is necessary to:

  • Protect the rights, property, or safety of the Company, its Users, or others
  • Investigate or prevent fraud, security incidents, or violations of these Terms
  • Respond to emergencies or protect individuals from harm

4.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of the Company's assets, your data may be transferred to the acquiring or successor entity. You will be notified via email of any such transfer and of any changes to this Privacy Policy resulting from the transfer.

4.6 Aggregated and De-Identified Data

The Company may use, disclose, and share aggregated, de-identified data that cannot reasonably be used to identify any individual or business, including for analytics, research, and service improvement purposes.

5. Data Security

5.1 Security Measures

The Company implements commercially reasonable technical, administrative, and physical security measures to protect your data, including:

  • All connections to the Service use TLS/SSL encryption
  • Passwords are hashed using bcrypt (never stored in plaintext)
  • Two-factor authentication is available for Accounts
  • Database credentials are encrypted at rest
  • Access to systems and data is restricted on a need-to-know basis
  • Regular security reviews and monitoring

5.2 Multi-Tenant Data Isolation

The Service uses a multi-tenant architecture in which each Workspace's data is logically separated from other Workspaces. The Company employs technical controls to ensure that Workspace Data is accessible only to authorized members of the relevant Workspace.

5.3 No Absolute Security

No method of transmission over the internet or electronic storage is completely secure. While the Company strives to protect your data, the Company cannot guarantee absolute security. Unauthorized access, use, or disclosure of your data may occur despite the Company's efforts.

5.4 Security Incident Notification

In the event of a data breach that poses a risk to your rights or freedoms, the Company will notify you and the relevant supervisory authorities in accordance with applicable data protection laws, including GDPR Article 33 (notification to supervisory authorities within 72 hours) and applicable state breach notification laws.

6. Your Privacy Rights

6.1 GDPR Rights (European Economic Area, UK, Switzerland)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the GDPR:

  • (a) Right of Access — You may request a copy of the Personal Data the Company holds about you.
  • (b) Right to Rectification — You may request that the Company correct any inaccurate or incomplete Personal Data.
  • (c) Right to Erasure ("Right to Be Forgotten") — You may request that the Company delete your Personal Data, subject to certain exceptions (e.g., legal retention obligations).
  • (d) Right to Restriction of Processing — You may request that the Company restrict the processing of your Personal Data in certain circumstances.
  • (e) Right to Data Portability — You may request that the Company provide your Personal Data in a structured, machine-readable format and transmit it to another controller.
  • (f) Right to Object — You may object to the processing of your Personal Data based on legitimate interests or for direct marketing.
  • (g) Right to Withdraw Consent — Where processing is based on consent, you may withdraw consent at any time.
  • (h) Right to Lodge a Complaint — You have the right to lodge a complaint with your local data protection supervisory authority.

6.2 CCPA Rights (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • (a) Right to Know — You may request disclosure of the categories and specific pieces of Personal Data the Company collects, the purposes for collection, and the categories of third parties with whom data is shared.
  • (b) Right to Delete — You may request that the Company delete your Personal Data, subject to certain exceptions.
  • (c) Right to Opt Out of Sale — The Company does not sell your Personal Data. You have the right to opt out of any future sale of your Personal Data, but this right is not currently applicable.
  • (d) Right to Non-Discrimination — The Company will not discriminate against you for exercising your privacy rights.

6.3 Other Jurisdictions

If you are located in a jurisdiction with data protection laws that grant rights not listed above, you may exercise those rights in accordance with the applicable law.

6.4 How to Exercise Your Rights

To exercise any of your privacy rights, you may:

  • Use the self-service tools available within the Service's account settings
  • Contact the Company at [Contact Email]

The Company will respond to your request within the timeframe required by applicable law (generally within 30 days). The Company may verify your identity before processing your request to protect against unauthorized access to your data.

6.5 Authorized Agents

You may authorize an agent to submit requests on your behalf. The Company may require the agent to provide proof of authorization and may verify your identity directly.

7. Data Retention

7.1 Account Data

The Company retains Account Data for as long as your Account is active. Upon Account deletion, the Company will delete or anonymize your Account Data within a reasonable period, except where retention is required by law (e.g., tax records, legal hold).

7.2 Workspace Data

Workspace Data is retained for as long as your Workspace is active. Upon termination of your Account or Workspace, the Company may delete all associated Workspace Data after a grace period, the length of which may vary. You are responsible for exporting or backing up your Workspace Data before termination.

7.3 Technical Data and Logs

The Company retains Technical Data and server logs for up to ninety (90) days, after which they are automatically deleted or anonymized, except where retention is required for security investigations or legal compliance.

7.4 Backups

The Company may maintain encrypted backups of Account Data and Workspace Data for up to thirty (30) days after Account deletion for disaster recovery purposes. After this period, backups are permanently deleted.

7.5 Legal Holds

The Company may retain data beyond the periods stated above if required by law, court order, or ongoing legal investigation. Data subject to a legal hold will be deleted once the legal obligation no longer applies.

8. Cookies and Tracking Technologies

8.1 Essential Cookies

The Service uses essential cookies and similar technologies that are strictly necessary for the Service to function:

  • Session cookies — to authenticate you and maintain your logged-in session
  • CSRF tokens — to prevent cross-site request forgery attacks
  • Remember me tokens — to keep you logged in across sessions (optional, only if you enable it)
  • Trusted device tokens — to skip two-factor authentication on recognized devices
  • Cookie consent record — to record your cookie consent state

8.2 Functional Cookies

The Service uses a limited set of functional cookies that require your consent. These cookies are only set after you accept functional cookies via the cookie consent banner:

  • Language preference — to remember your selected language
  • Theme mode — to remember your light/dark mode preference
  • Affiliate referral — to store an affiliate referral code when you visit via an affiliate link, so that signup attribution can be completed if you register later. This cookie expires after 30 days and is only set with your consent.

8.3 No Tracking or Advertising Cookies

8.4 Cookie Management

You can grant or revoke consent for functional cookies at any time through the cookie consent banner or your account cookie settings. You may also clear cookies from your browser at any time. Note that clearing session cookies will log you out of the Service.

8.5 Browser Do-Not-Track Signals

The Company does not track Users across third-party websites and does not respond to browser Do-Not-Track (DNT) signals, as the Service does not engage in tracking activities that DNT signals are designed to address.

9. Children's Privacy

9.1 Age Restriction

The Service is not intended for or directed to individuals under the age of eighteen (18). The Company does not knowingly collect Personal Data from children under 18.

9.2 Removal of Children's Data

If the Company becomes aware that it has collected Personal Data from a child under 18, the Company will take steps to delete such data as soon as practicable. If you believe the Company has collected such data, please contact the Company at [Contact Email].

10. International Data Transfers

10.1 Server Location

The Company's servers and data storage infrastructure are located in the United States. By using the Service, you acknowledge that your Personal Data and Workspace Data will be processed and stored in the United States.

10.2 Cross-Border Transfers

If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States. The Company takes reasonable measures to ensure that such transfers comply with applicable data protection laws, including by using standard contractual clauses (SCCs) or other appropriate safeguards where required.

10.3 Acknowledgment

You acknowledge and agree that the data protection laws of the United States may differ from those of your jurisdiction. By using the Service, you consent to the transfer and processing of your data in the United States as described in this Privacy Policy.

11. Your Responsibilities as a Data Controller

11.1 Workspace Data

As a Workspace owner or member, you act as the Data Controller with respect to the Personal Data contained in your Workspace Data. The Company acts as the Data Processor on your behalf.

11.2 Your Obligations

You are responsible for:

  • Ensuring that you have the legal right and basis to collect, store, and process the Personal Data in your Workspace
  • Obtaining any necessary consents from individuals whose Personal Data is included in your Workspace Data
  • Complying with applicable data protection laws (e.g., GDPR, CCPA) with respect to your Workspace Data
  • Responding to requests from individuals whose data you have stored in your Workspace (e.g., access, deletion, correction requests)
  • Ensuring that your Workspace members are aware of and agree to applicable privacy policies and terms

11.3 Company's Role

The Company processes Workspace Data on your behalf and in accordance with your instructions as given through the Service's configuration options. The Company does not determine the purposes for which you collect or use Personal Data within your Workspace.

11.4 Data Processing Agreement

For Users subject to the GDPR or other laws requiring a Data Processing Agreement (DPA), the Company may provide a separate DPA upon request. The terms of this Privacy Policy, together with any applicable DPA, govern the Company's processing of Workspace Data.

12. Third-Party Links and Services

12.1 Third-Party Links

The Service may contain links to third-party websites, services, or applications that are not operated by the Company. The Company has no control over and is not responsible for the content, privacy practices, or policies of any third-party websites or services.

12.2 Your Responsibility

You are encouraged to review the privacy policies of any third-party websites or services you visit or use. The Company is not liable for the privacy practices or content of third-party websites or services.

13. Changes to This Privacy Policy

13.1 Right to Modify

The Company may modify this Privacy Policy at any time. The most current version will be posted at [Privacy Policy URL] with the "Last updated" date revised accordingly.

13.2 Notice of Material Changes

The Company will provide notice of material changes to this Privacy Policy by email to the address associated with your Account, or by in-app notification, at least thirty (30) days before the changes take effect.

13.3 Acceptance of Changes

Your continued access to or use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. If you do not agree to the revised Privacy Policy, you must stop using the Service and terminate your Account.

14. Contact Information

For any questions, concerns, requests, or notices regarding this Privacy Policy or your privacy rights, please contact the Company at:

NadiraOS LLC

State of Formation: Wyoming, United States of America

Email: hello@localhost

Website: https://candysonic.cloud

For GDPR-related inquiries or data protection requests, you may also contact the Company at the email address above. The Company will respond in accordance with applicable law.

This Privacy Policy, together with the Terms and Conditions, constitutes the complete privacy framework governing your use of the Service. By using the Service, you acknowledge that you have read and understood this Privacy Policy and agree to the practices described herein.