Privacy Policy
1. Controller
The controller within the meaning of the GDPR for this website is:
[First Name Last Name]
[Street and House Number]
[Postal Code and City]
Email: engineering@candolab.de
2. What data we collect and why
2.1 When visiting the website (server logs)
When you access our website, our hosting provider Netlify automatically collects technical connection data (server log files):
- IP address (anonymised)
- Date and time of the request
- URL accessed
- Browser type and operating system
- HTTP status code
This data is processed solely for the technical provision of the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and uninterrupted operation of the website). We are unable to assign this data to specific individuals and do not attempt to do so.
2.2 Email sign-up (waiting list)
When you sign up to our waiting list, we collect your email address. We use it to notify you once about the launch of candolab.
- Data collected: Email address
- Purpose: One-time launch notification
- Legal basis: Art. 6(1)(a) GDPR (consent given by submitting the form)
- Retention period: Until withdrawal of consent or at the latest 12 months after sign-up if no launch has taken place
You may withdraw your consent at any time with future effect by sending an email to: engineering@candolab.de
3. Third-party processors — Netlify
This website is hosted by:
Netlify, Inc.
512 2nd Street, Suite 200
San Francisco, CA 94107, USA
Netlify processes technical connection data and form submission data (email address) as part of the hosting and form handling service. A Data Processing Agreement (DPA) pursuant to Art. 28 GDPR is in place with Netlify. Netlify uses EU Standard Contractual Clauses to ensure an adequate level of data protection for transfers to the USA.
Further information: netlify.com/gdpr-ccpa
Your data is not shared with any other third parties unless we are legally required to do so.
4. Cookies
This website does not use tracking cookies, analytics tools (e.g. Google Analytics), or social media plugins. Only technically necessary, short-lived session cookies are set, which are automatically deleted when you close your browser. No consent is required for these.
5. No external services
This website does not embed any external services such as Google Fonts, Google Maps, YouTube, Facebook Pixel, or similar services that would cause data to be transmitted to third parties. All resources are served locally from our own server.
6. Your rights
As a data subject you have the following rights under the GDPR:
- Right of access (Art. 15 GDPR): You may request information about the data we hold about you at any time.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your data, provided no retention obligation exists.
- Right to restriction (Art. 18 GDPR): You may request restriction of processing.
- Right to data portability (Art. 20 GDPR): You may request your data in a structured, machine-readable format.
- Right to object (Art. 21 GDPR): You may object to the processing of your data.
- Right to withdraw consent (Art. 7(3) GDPR): You may withdraw any consent given at any time with future effect.
To exercise these rights, please contact: engineering@candolab.de
7. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
[Name of the competent supervisory authority]
8. Updates to this Privacy Policy
This Privacy Policy was last updated in April 2026. As our website develops or due to changes in legal or regulatory requirements, it may be necessary to update this policy. The current version is always available on this page.