Privacy Policy
Effective Date: December 6, 2024
At Candu, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our educational platform.
1. Information We Collect
1.1 Information You Provide
When you create an account and use Candu, we collect:
- Account Information: Name, email address, password
- Profile Information: Province, school district, grade levels, subjects taught, teacher type
- Payment Information: Credit card details (processed securely through Stripe; we do not store full card numbers)
- Contact Information: Phone number (optional)
- Content You Create: Lesson plans, notes, customizations, and other materials you generate using our Service
1.2 Information Collected Automatically
When you use our Service, we automatically collect:
- Usage Data: Pages viewed, features used, time spent, actions taken
- Device Information: Browser type, operating system, device type
- Log Data: IP address, access times, error logs
- Cookies: Session cookies, preference cookies (see Section 5)
1.3 Information We Do NOT Collect
We do not collect:
- Student names or personally identifiable information about students
- Social insurance numbers or government IDs
- Sensitive personal data (health, religion, political opinions) unless you voluntarily provide it
2. How We Use Your Information
We use your information to:
2.1 Provide the Service
- Create and manage your account
- Generate personalized lesson plans and content
- Process payments and manage subscriptions
- Provide customer support
- Remember your preferences and settings
2.2 Improve the Service
- Analyze usage patterns to improve features
- Fix bugs and technical issues
- Develop new features and functionality
- Conduct research and analytics
2.3 Communicate With You
- Send service updates and announcements
- Respond to your inquiries and support requests
- Send billing and payment notifications
- Send marketing communications (only with your consent; you can opt out anytime)
2.4 Legal and Safety
- Comply with legal obligations
- Prevent fraud and abuse
- Enforce our Terms of Service
- Protect the rights and safety of our users
3. How We Share Your Information
We do NOT sell your personal information to third parties.
We may share your information in the following limited circumstances:
3.1 Service Providers
We share information with trusted third-party service providers who help us operate the Service:
- Stripe: Payment processing (credit card information)
- Amazon Web Services (AWS): Cloud hosting and data storage
- Email Service Providers: Transactional and marketing emails
- Analytics Providers: Usage analytics and performance monitoring
These providers are contractually obligated to protect your data and use it only for the services they provide to us.
3.2 Legal Requirements
We may disclose your information if required by law or if we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation (court order, subpoena)
- Protect our rights or property
- Prevent fraud or illegal activity
- Protect the safety of our users or the public
3.3 Business Transfers
If Candu is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
3.4 With Your Consent
We may share your information for other purposes with your explicit consent.
4. Data Security
We implement industry-standard security measures to protect your personal information:
- Encryption: All data transmitted to and from our servers is encrypted using SSL/TLS
- Secure Storage: Data at rest is encrypted using AES-256 encryption
- Access Controls: Strict access controls limit who can access your data
- Regular Audits: We conduct regular security audits and vulnerability assessments
- Password Protection: Passwords are hashed and salted using bcrypt
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
5. Cookies and Tracking Technologies
5.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. We use cookies to enhance your experience and improve our Service.
5.2 Types of Cookies We Use
- Essential Cookies: Required for the Service to function (e.g., authentication, session management)
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how you use the Service
- Marketing Cookies: Used to deliver relevant advertisements (only with your consent)
5.3 Managing Cookies
You can control cookies through your browser settings. However, disabling essential cookies may affect your ability to use certain features of the Service.
6. Your Privacy Rights
You have the following rights regarding your personal information:
6.1 Access
You have the right to access your personal information. You can view most of your data through your account settings.
6.2 Correction
You can update or correct your information at any time through your account settings.
6.3 Deletion
You can request deletion of your account and personal information by contacting support@can-du.com. We will delete your data within 30 days, except where we are required to retain it for legal purposes.
6.4 Data Portability
You can request a copy of your data in a machine-readable format by contacting support@can-du.com.
6.5 Opt-Out of Marketing
You can opt out of marketing emails by clicking the "unsubscribe" link in any marketing email or by updating your communication preferences in account settings.
6.6 Object to Processing
You have the right to object to certain types of processing of your data. Contact us to exercise this right.
7. Data Retention
We retain your personal information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:
- Active Accounts: Data is retained while your account is active
- Cancelled Accounts: Data is retained for 90 days after cancellation, then deleted
- Legal Obligations: Some data may be retained longer to comply with legal requirements (e.g., payment records for tax purposes)
- Backups: Data in backups is deleted as backups are rotated (typically within 60 days)
8. Children's Privacy
Candu is designed for use by teachers and educators who are at least 18 years old. We do not knowingly collect personal information from children under 13.
While teachers may reference their students in lesson planning, we require that teachers:
- Do NOT enter student names or personally identifiable information
- Use pseudonyms or codes if referencing individual students
- Comply with all applicable privacy laws regarding student data
If we become aware that we have collected personal information from a child under 13 without parental consent, we will delete it immediately.
9. International Data Transfers
Candu is based in Canada, and your information is processed and stored in Canada. If you are accessing the Service from outside Canada:
- Your information will be transferred to and processed in Canada
- Canada's privacy laws may differ from those in your jurisdiction
- By using the Service, you consent to this transfer
- We comply with applicable data protection laws for international transfers
10. Third-Party Links
Our Service may contain links to third-party websites or services (e.g., educational resources, YouTube videos). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will notify you via email at least 30 days before the changes take effect
- We will update the "Effective Date" at the top of this policy
- We will post a notice on our website
Your continued use of the Service after the changes take effect constitutes acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Candu Privacy Team
Email: privacy@can-du.com
Support: support@can-du.com
Website: https://can-du.com
We are committed to protecting your privacy and handling your data responsibly.