Legal

Privacy Policy

How Canopy collects, uses, and protects personal data, written plainly. Because Canopy is identity infrastructure, this policy draws a clear line between the data we control about our own customers and visitors, and the end-user identity data we process on our customers' behalf.

Controller & processorGDPR-alignedDPA on request
Last updated: June 26, 2026

Scope of this policy

Who this applies to and what it covers.

This Privacy Policy explains how Canopy Identity Inc. ("Canopy", "we", "us") handles personal data across our marketing website, documentation, applications, and API (together, the "Services").

It applies to two groups of people:

  • Our customers and visitors: the people who sign up for Canopy, administer an account, or browse this site. For their data, Canopy is the data controller.
  • Our customers' end users: the identities our customers create and manage inside Canopy. For that data, Canopy is a data processor acting on our customer's instructions.

The next section makes that distinction concrete, because it determines who you should contact about your data and which rights apply.

Our two roles: controller & processor

As identity infrastructure, Canopy handles personal data in two distinct capacities. This is the most important thing to understand on this page.

Canopy as controller
Data about our own customers & visitors
We decide

When you create a Canopy account, administer it, or browse our site, we determine why and how your data is used.

  • Account & billing contacts
  • Administrator profiles & settings
  • Site analytics & support requests
Canopy as processor
End-user data, on our customer's behalf
They decide

The identities our customers create live in Canopy, but our customer controls them. We process this data only on their documented instructions.

  • End-user identities & credentials
  • Roles, permissions & assignments
  • Authentication & audit records

If you are an end user of a service built on Canopy and want to access or delete your data, contact that service's operator (our customer): they are the controller. We will support their request. Our processing of end-user data is governed by our Data Processing Addendum.

What we collect

The categories of personal data we handle, and in which role.

  • Account & contact details (controller): name, work email, organization, and password when you register or are invited to a Canopy account.
  • Billing information (controller): plan, billing contact, and transaction records. Card details are handled by our payment processor; we don't store full card numbers.
  • Usage & device data (controller): log data, IP address, browser type, and product analytics that help us secure and improve the Services.
  • End-user identity data (processor): identities, credentials, roles, permissions, and audit events that our customers create and manage. We process these strictly on the customer's instructions.

How we use it

We use personal data only for the purposes below: never sold, never used for advertising.

  • Provide the Services: authenticate you, run our applications and API, and deliver the features you've signed up for.
  • Secure the platform: detect abuse, investigate incidents, and maintain the audit trail described on our Security page.
  • Support & communicate: respond to requests and send essential service notices about changes, outages, or security.
  • Billing & compliance: process payments and meet our legal and tax obligations.
  • Improve the product: understand usage in aggregate to make Canopy better.

We do not sell personal data, and we do not use end-user identity data for our own purposes.

Legal bases for processing

Where the GDPR or similar laws apply, we rely on these bases.

  • Contract: to provide the Services you or your organization have signed up for.
  • Legitimate interests: to secure, maintain, and improve the platform, balanced against your rights.
  • Legal obligation: to comply with tax, accounting, and other laws.
  • Consent: for optional cookies and any communications that require it; you can withdraw consent at any time.

For end-user identity data we process as a processor, our customer determines the legal basis as controller.

Sharing & subprocessors

Who we share data with, and why.

We share personal data only with:

  • Subprocessors: vetted vendors for hosting, database, cache, and object storage that help us run the platform. Each is bound by data-protection terms.
  • Payment & service providers: for billing, email delivery, and support.
  • Legal & safety: where required by law, or to protect the rights and safety of users and the public.

A current list of subprocessors is available on request, and customers on eligible plans can subscribe to advance notice of changes.

International data transfers

How data is protected when it moves across borders.

Canopy may process data in countries other than where you are located. Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms.

Data retention

How long we keep data.

We keep personal data only as long as needed for the purposes above. Account data is retained for the life of your account and a limited period afterward for legal and accounting needs. End-user identity data is retained per our customer's configuration and deleted on their instruction or on account closure, subject to short backup-rotation windows.

Audit records may be retained longer where required for security and compliance, consistent with the durability guarantees described on our Security page.

Your privacy rights

Depending on where you live, you may have the following rights.

  • Access & portability: request a copy of the personal data we hold about you in a portable format.
  • Correction: ask us to fix inaccurate or incomplete data.
  • Deletion: request erasure of your data, subject to legal retention requirements.
  • Objection & restriction: object to or restrict certain processing, and withdraw consent where we rely on it.
  • How to exercise them: contact us at the address below. If you're an end user of a service built on Canopy, contact that service's operator. We'll assist them as processor. You also have the right to lodge a complaint with your supervisory authority.

Cookies

What we store in your browser and why.

We use strictly necessary cookies to keep you signed in and protect against CSRF. These can't be turned off without breaking the Services. With your consent we also use limited analytics cookies to understand usage. We don't use advertising or cross-site tracking cookies. You can manage non-essential cookies through your browser or our cookie controls.

Changes to this policy

How we'll tell you when this changes.

We may update this policy as our Services and the law evolve. When we make material changes, we'll update the "Last updated" date above and, where appropriate, notify account admins by email or an in-product notice. Continued use of the Services after a change means you accept the updated policy.

Contact us

Reach our team, or request our DPA.

Questions about this policy, a data request, or a Data Processing Addendum? Reach our team through the Company page. Enterprise customers can request our DPA, subprocessor list, and security documentation under NDA.