How Canopy collects, uses, and protects personal data, written plainly. Because Canopy is identity infrastructure, this policy draws a clear line between the data we control about our own customers and visitors, and the end-user identity data we process on our customers' behalf.
Who this applies to and what it covers.
This Privacy Policy explains how Canopy Identity Inc. ("Canopy", "we", "us") handles personal data across our marketing website, documentation, applications, and API (together, the "Services").
It applies to two groups of people:
The next section makes that distinction concrete, because it determines who you should contact about your data and which rights apply.
As identity infrastructure, Canopy handles personal data in two distinct capacities. This is the most important thing to understand on this page.
When you create a Canopy account, administer it, or browse our site, we determine why and how your data is used.
The identities our customers create live in Canopy, but our customer controls them. We process this data only on their documented instructions.
If you are an end user of a service built on Canopy and want to access or delete your data, contact that service's operator (our customer): they are the controller. We will support their request. Our processing of end-user data is governed by our Data Processing Addendum.
The categories of personal data we handle, and in which role.
We use personal data only for the purposes below: never sold, never used for advertising.
We do not sell personal data, and we do not use end-user identity data for our own purposes.
Where the GDPR or similar laws apply, we rely on these bases.
For end-user identity data we process as a processor, our customer determines the legal basis as controller.
Who we share data with, and why.
We share personal data only with:
A current list of subprocessors is available on request, and customers on eligible plans can subscribe to advance notice of changes.
How data is protected when it moves across borders.
Canopy may process data in countries other than where you are located. Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms.
How long we keep data.
We keep personal data only as long as needed for the purposes above. Account data is retained for the life of your account and a limited period afterward for legal and accounting needs. End-user identity data is retained per our customer's configuration and deleted on their instruction or on account closure, subject to short backup-rotation windows.
Audit records may be retained longer where required for security and compliance, consistent with the durability guarantees described on our Security page.
Depending on where you live, you may have the following rights.
What we store in your browser and why.
We use strictly necessary cookies to keep you signed in and protect against CSRF. These can't be turned off without breaking the Services. With your consent we also use limited analytics cookies to understand usage. We don't use advertising or cross-site tracking cookies. You can manage non-essential cookies through your browser or our cookie controls.
How we'll tell you when this changes.
We may update this policy as our Services and the law evolve. When we make material changes, we'll update the "Last updated" date above and, where appropriate, notify account admins by email or an in-product notice. Continued use of the Services after a change means you accept the updated policy.
Reach our team, or request our DPA.
Questions about this policy, a data request, or a Data Processing Addendum? Reach our team through the Company page. Enterprise customers can request our DPA, subprocessor list, and security documentation under NDA.