Privacy
Last updated: 19.03.2026
Privacy Policy
Introduction
DGE Concept SàRL, publisher of the CandleSafe.ch platform, is committed to protecting the privacy and personal data of its users. This Privacy Policy transparently describes what data is collected, why, how it is used, stored and protected, and what your rights are.
This policy applies to all services of the CandleSafe.ch platform, accessible at https://candlesafe.ch, as well as to all email communications related to your account.
Art. 1 Data Controller
| Entity | DGE Concept SàRL |
| Activity | SaaS Publisher — CLP/REACH regulatory document generation |
| Registered office | Rue du Village 8b, 1273 Arzier-Le Muids (Vaud), Switzerland |
| Contact email | contact@candlesafe.ch |
| Contact form | https://candlesafe.ch/contact |
Art. 2 Data collected and purposes
2.1 — Overview
| Data category | Purpose | Legal basis |
|---|---|---|
| Email address | Account creation, authentication, notifications, support | Contract performance (art. 6.1.b RGPD) |
| Company / workshop name | Identification, personalization | Contract performance (art. 6.1.b RGPD) |
| Chosen language and currency | Personalized display | Contract performance (art. 6.1.b RGPD) |
| Entered formulations & concentrations | SDS and CLP labels generation | Contract performance (art. 6.1.b RGPD) |
| Uploaded supplier SDS | CLP data extraction for regulatory calculation | Contract performance (art. 6.1.b RGPD) |
| Generated documents (SDS, CLP) | Storage and provision | Contract performance (art. 6.1.b RGPD) |
| Subscription history | Commercial management, billing, quotas | Legal obligation + Contract (art. 6.1.b/c RGPD) |
| IP address, connection logs | Security, fraud detection, debugging | Legitimate interests (art. 6.1.f RGPD) |
| Browser, operating system | Technical compatibility, service improvement | Legitimate interests (art. 6.1.f RGPD) |
| Email opens / clicks (if applicable) | Communication effectiveness measurement | Consent (art. 6.1.a RGPD) |
2.2 — Data NOT collected
- Credit card numbers or payment data (processing delegated to payment provider)
- Health data or sensitive data as defined in Article 9 of RGPD
- Precise location data (GPS)
- Data from social networks without explicit consent
- Data relating to minors (the platform is reserved for professional adults)
Art. 3 Confidentiality of artisanal formulations
Product formulations (scented compositions, concentrations, artisanal recipes) entered on CandleSafe.ch constitute trade secrets of the User. DGE Concept SàRL formally commits to:
- never share this data with third parties, competitors or business partners;
- never use it for market analysis, benchmarking or any commercial use other than providing the service;
- never resell, transfer or exploit it in any form whatsoever.
This data is processed exclusively to generate the regulatory documents requested by the User.
Art. 4 Data sharing and recipients
4.1 — General principle: no data sale
DGE Concept SàRL never sells, rents or transfers the personal data of its Users to third parties for commercial purposes.
4.2 — Technical subcontractors
Within the strict framework of service provision, certain technical providers may access part of the data as data processors within the meaning of RGPD. These subcontractors are contractually bound to the same confidentiality and security obligations:
- Hosting and server infrastructure (Europe / Switzerland)
- Payment provider (secure transaction processing — no access to formulations)
- Transactional email service (notifications, confirmations)
- API / Artificial Intelligence provider (used for data extraction from supplier SDS in non-standard format, document translation and regulatory guides — data processed on an ad-hoc basis and not retained by the provider beyond immediate processing)
4.3 — Transfers outside EU/Switzerland
If data were to be transferred to third countries that do not have a recognized adequate level of protection, the Publisher undertakes to implement appropriate safeguards (European Commission standard contractual clauses, adequacy decision, etc.).
4.4 — Legal authorities
The Publisher may be required to disclose personal data to competent authorities upon legally founded judicial or administrative requisition. In such case, the Publisher will inform the User to the extent permitted by law.
Art. 5 Retention period
| Data category | Retention period |
|---|---|
| Account data (email, company) | Duration of active subscription + 12 months after account closure |
| Formulations and generated documents | 74 days per document (Terms of Service Art. 5 lifecycle) |
| Uploaded supplier SDS | Time necessary for generation, then automatic deletion |
| Billing data and subscription history | 10 years (Swiss accounting obligations — CO art. 958f) |
| Connection logs and technical data | 12 rolling months |
| Support emails | 3 years from last interaction |
Upon expiration of these periods, data is permanently deleted or irreversibly anonymized.
Art. 6 Data security
6.1 — Technical measures
- Encryption of communications in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- Secure authentication with password hashing (bcrypt)
- Data access restricted to authorized personnel (principle of least privilege)
- Regular and secure backups
- Access monitoring and anomaly detection
6.2 — Organizational measures
- Production data access limited to strictly necessary developers
- Confidentiality commitment from any provider accessing data
- Regular review of access rights
6.3 — In case of data breach
In case of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, the Publisher undertakes to notify the competent supervisory authority within 72 hours (art. 33 RGPD) and to inform affected Users as soon as possible (art. 34 RGPD).
Art. 7 Cookies and trackers
7.1 — Strictly necessary cookies
The platform uses cookies strictly necessary for service operation (authentication session, language and currency preferences, CSRF security token). These cookies do not require prior consent.
7.2 — Analytics cookies
Audience measurement cookies will only be activated with the prior and explicit consent of the User, via the consent banner. The User can withdraw their consent at any time.
7.3 — No advertising cookies
CandleSafe.ch does not use any advertising cookies, behavioral tracking or third-party marketing targeting. For complete details of cookies used, see our Cookie Policy.
Art. 8 Automatic emails and communications
As part of the service, the Publisher sends the following automatic communications:
- Account and subscription confirmation emails
- Document lifecycle notifications (D+60: 14 days before deletion; D+71: 3 days before deletion)
- Reminders before subscription expiration
- Support emails in response to User requests
- Notifications of substantial updates to the Terms of Use / Privacy Policy
Transactional emails related to contract execution cannot be unsubscribed from, as they are necessary for the proper functioning of the service.
Art. 9 Rights of data subjects
9.1 — Your rights
In accordance with RGPD (EU) 2016/679 and Swiss nLPD, you have the following rights:
| Right | Description | Reference |
|---|---|---|
| Access | Obtain confirmation that data concerning you is being processed and receive a copy | Art. 15 RGPD / Art. 25 nLPD |
| Rectification | Have inaccurate or incomplete data corrected | Art. 16 RGPD |
| Erasure | Request deletion of your data under certain conditions | Art. 17 RGPD / Art. 32 nLPD |
| Portability | Receive your data in a structured, machine-readable format | Art. 20 RGPD |
| Objection | Object to processing based on legitimate interests | Art. 21 RGPD |
| Restriction | Request temporary suspension of processing | Art. 18 RGPD |
| Withdrawal of consent | At any time, without affecting the lawfulness of prior processing | — |
9.2 — How to exercise your rights
Address your request to contact@candlesafe.ch or via the contact form. The Publisher commits to responding within a maximum period of one (1) month (which may be extended to three months for complex requests, with prior notification).
9.3 — Right to lodge a complaint with the supervisory authority
- Switzerland: Federal Data Protection and Information Commissioner (PFPDT) — www.edoeb.admin.ch
- European Union: the competent supervisory authority in your country of residence (e.g.: CNIL for France, BfDI for Germany)
Art. 10 Applicable law
This Privacy Policy is governed by Swiss law (nLPD) and European law (RGPD) to the extent applicable. In case of conflict between these two regulations, the rule that is most protective for the User shall prevail.
Art. 11 Policy modifications
The Publisher reserves the right to modify this Privacy Policy at any time to reflect legal, regulatory or technical developments. In case of substantial modification, the User will be informed by email with thirty (30) days' notice. The current version is always accessible at https://candlesafe.ch/confidentialite.
Other legal pages: