Last updated: September 04, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
This Privacy Policy explains how Candli processes Personal Data. Where data processing requires specific consent under applicable law, acceptance of this Privacy Policy alone does not constitute that consent.
We collect and process only the data needed to operate Candli, provide user accounts and user-created content, investigate technical problems, improve the Service, prevent abuse, fulfil contracts and comply with legal obligations.
We do not sell Personal Data. We do not use Personal Data for advertising or advertising profiling. We send newsletters or other direct marketing only where a user has explicitly subscribed, and the subscription can be withdrawn at any time.
When Candli is used by a school or another organisation and that organisation determines why Personal Data is processed, the organisation acts as Data Controller and Enlightware GmbH processes that data on its behalf. For processing that Enlightware performs for its own purposes, such as customer administration, billing, security and legal compliance, Enlightware may act as Data Controller.
The words of which the initial letter is capitalized have meanings defined under the following conditions.
The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
For the purposes of this Privacy Policy:
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Under GDPR (General Data Protection Regulation), You can be referred to as the Data Subject or as the User as you are the individual using the Service.
Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Enlightware GmbH, Rotbuchstrasse 60, 8037 Zürich.
Depending on the context, Enlightware GmbH may act either as Data Controller or as Data Processor. In particular, where a school or other organisation uses Candli and determines the purposes for which user data is processed, that organisation is generally the Data Controller and Enlightware GmbH acts as Data Processor for that data.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
For the purpose of the GDPR, Service Providers are considered Data Processors.
We collect and process Personal Data only as necessary to provide, operate, secure and improve Candli, fulfil contractual and legal obligations, and respond to users and customers. We do not use Personal Data for advertising or advertising profiling. We use contact information for newsletters or other direct marketing only where the relevant user has explicitly subscribed, and the subscription can be withdrawn at any time.
Depending on how Candli is used, We may process:
Asset Data is collected when users take or import pictures or record sounds through the use of the Service.
Asset Data is used as part of user-created games and projects. Some games and assets can be accessed without authentication through unique, difficult-to-guess identifiers. Anyone who obtains such an access link or identifier may be able to access the associated content.
Users and organisations using Candli are responsible for ensuring that they are authorised to upload and share Personal Data relating to other persons. In educational use, schools determine whether pupils may upload identifiable photographs, voice recordings or other Personal Data as part of a learning activity.
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages or features of our Service that You visit, the time and date of Your visit, the time spent on those pages or features, unique identifiers and other diagnostic data.
Candli uses a persistent authentication cookie to maintain Your authenticated session. The cookie may be stored for up to one year.
Candli also uses browser storage, including local storage and IndexedDB, for application functionality. This includes storing user preferences and anonymous workspaces, and temporarily retaining data that could not be transmitted because of a network failure. If You choose to have Candli remember Your login, authentication information may also be stored locally in Your browser.
Candli collects usage analytics to help Us understand how the Service is used, including acquisition, engagement and use of Candli features, identify problems and improve the Service. Analytics events are sent directly to servers operated by Us and are not provided to third-party advertising or analytics services.
Analytics collection can be disabled. Ordinary usage analytics data is retained for no longer than 100 days. Diagnostic and crash data may be retained for longer where reasonably necessary to investigate and prevent technical problems. Aggregated data that no longer identifies individual users or accounts may be retained for longer.
We do not use advertising cookies, third-party advertising trackers or cross-site tracking technologies.
You can configure Your browser to delete or restrict cookies and browser storage. However, doing so may prevent some parts of Candli from functioning correctly or may remove locally stored work.
AI-powered features are optional. Personal Data is sent to external AI service providers only when such a feature has been enabled and is used.
When You use AI-powered features in Candli, information necessary to provide the feature may be sent to external AI service providers. This may include prompts, relevant conversation history, generated responses, model and usage information, and a session identifier.
AI requests may be routed through an intermediary service to selected downstream AI model providers. The set of downstream providers may change as models, providers and processing arrangements evolve.
For Personal Data submitted to AI inference services, Enlightware restricts processing to providers and configurations that meet its applicable data-protection and security requirements, including zero retention of submitted inference data and appropriate safeguards for international transfers. Where EEA AI data processing is configured for an organisation, AI API payloads are processed only within the European Union or European Economic Area.
The current AI processing arrangements and downstream providers are listed on Our Subprocessors page.
Some Candli features may use speech recognition provided by Your web browser. When such a feature is used, audio may be processed by the browser or operating-system provider according to its own privacy practices. Candli receives the resulting transcription for use by the relevant feature.
The Company may use Personal Data for the following purposes:
We may share your personal information in the following situations:
The Company retains Personal Data only for as long as necessary for the purposes described in this Privacy Policy.
Analytics data is retained for no longer than 100 days. Diagnostic and crash data may be retained for longer where reasonably necessary to investigate and prevent technical problems.
Personal Data may be retained for longer where necessary to comply with legal obligations, resolve disputes, enforce agreements, or establish, exercise or defend legal claims.
Candli is operated by Enlightware GmbH in Switzerland. Our primary application infrastructure is located in Switzerland or the European Economic Area.
We also use global network infrastructure for content delivery and security. Requests may therefore be processed outside Switzerland or the European Economic Area, including technical data such as IP addresses.
Authenticated or session-specific content is not cached on this global network. Content that can be retrieved without an authenticated session, including game assets identified by unguessable identifiers, may be cached for content delivery.
Where Personal Data is processed or transferred to a country that does not provide an adequate level of data protection, We use the safeguards required by applicable data protection law.
If the Company is involved in a merger, acquisition, reorganisation or sale of all or part of its business, Personal Data may be transferred where necessary as part of that transaction and in accordance with applicable law.
Where Personal Data would become subject to materially different processing as a result of such a transaction, We will provide appropriate notice where reasonably possible.
Additional rights agreed with schools or other institutional customers, including termination or deletion rights, remain subject to the applicable agreement.
The Company may disclose Personal Data where required by law or in response to a valid request from a competent public authority.
We may also disclose Personal Data where reasonably necessary to establish, exercise or defend legal claims, protect the rights or security of the Company or its Users, or investigate unlawful activity or abuse of the Service.
We use appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, misuse, alteration or disclosure.
These measures include encrypted transmission, access controls, restricted administrative access, system maintenance and backups.
No Internet-connected service can guarantee absolute security.
Under Swiss data protection law, You may have the right to request information about the Personal Data We process about You, request correction or deletion of Personal Data, object to or request restriction of certain processing, and receive Personal Data in a portable format where applicable.
You may exercise these rights by contacting Us using the contact information below. We may request information reasonably necessary to identify You or the relevant account or data.
Where the GDPR applies and the Company acts as Data Controller, We may process Personal Data on the following legal bases:
Where Candli is used by a school or other organisation acting as Data Controller, that organisation determines the applicable legal basis and We process Personal Data on its behalf according to its documented instructions.
Where the GDPR applies, You may have the right to:
You may exercise Your rights by contacting Us using the contact information below. We may request information reasonably necessary to verify Your identity or identify the relevant account or data.
You also have the right to lodge a complaint with the competent data protection supervisory authority.
Candli does not currently respond differently to browser “Do Not Track” signals.
We do not use third-party advertising trackers or permit third parties to track users across unrelated websites or online services for advertising purposes.
Candli is an educational service that may be used by children, including children under the age of 13.
When Candli is used through a school or other educational organisation, the organisation may provide the authorisation required for the processing of pupil data where permitted by applicable law. We process such data only for the educational purposes for which Candli is provided and as otherwise described in this Privacy Policy.
When applicable law requires parental consent for a particular use of Candli outside such an educational context, the required consent must be obtained before the relevant Personal Data is collected or processed.
Parents, legal representatives and schools may contact Us to request access to, correction of, or deletion of Personal Data relating to a child where applicable. We may request information reasonably necessary to identify the relevant account or data.
We do not use children's Personal Data for advertising or advertising profiling. Newsletters or other direct marketing are sent only where the relevant user has explicitly subscribed.
California users under the age of 18 may request removal of content or information they have posted through Candli where applicable under California Business and Professions Code Section 22581.
Requests may be submitted using the contact information below. We may request information reasonably necessary to identify the relevant account or content.
Removal does not necessarily ensure complete or comprehensive deletion, for example where the information must be retained by law or has been copied or shared by another person.
Candli may contain links to websites or services that are not operated by Us. We are not responsible for the content, privacy practices or security of those third-party services.
We encourage You to review the privacy policies of any external services You visit.
We may update this Privacy Policy when Candli, Our processing activities or applicable legal requirements change.
The current version will always be published on this page together with its “Last updated” date.
For material changes that significantly affect how Personal Data is processed, We will provide reasonable advance notice through Candli and, where We have suitable contact information, by email or another appropriate communication channel.
Changes that must be implemented promptly for legal or security reasons may take effect sooner.
Additional notification rights agreed with schools or other institutional customers are governed by the applicable agreement.
If you have any questions about this Privacy Policy, You can contact us by email: .