Last updated 9 Sept 2026Version 2026-09-draft-1
Status: draft for counsel. This is an Art. 28 GDPR template between the club (controller) and Canopy (processor) for personal data processed in the Canopy application. It is not a signed contract until both parties execute a counsel-approved version.
Processor (Canopy): [legal entity name, company number, registered address — pending counsel]
Controller (the Association): the organisation that holds a Canopy tenant and decides why member and staff data are processed in the shop.
DPO / privacy contact: [to be appointed] · privacy@canopy-os.com
Canopy provides multi-tenant software for membership, point of sale, inventory, and related club operations. Processing lasts for the subscription and a limited backup window afterwards, unless the controller instructs earlier deletion.
Hosting, storage, transmission, backup, support, and security of the controller’s data so staff and members can use Canopy. Canopy does not sell member data and does not use club member data to train general-purpose AI models for other customers.
Identity and contact data, government ID images and numbers, optional health notes, signatures, visit and purchase records, staff credentials and time records, IP addresses in audit logs, and media uploaded to the controller’s tenant.
Club members (patients/enrollments), staff users, and (for the global member account) individuals who register on the platform — the global account is described in the Privacy policy as joint control, outside pure processing, and will be covered in the final agreement.
Canopy shall:
Transfers outside the EEA (notably OpenAI in the United States for optional ID scan and other AI features, and Sentry as a US-headquartered error-monitoring vendor with EU Frankfurt storage) shall use a Chapter V GDPR mechanism (SCCs and/or adequacy). The controller is responsible for ensuring it has a lawful basis (including Art. 9 where relevant) before staff send ID images to OpenAI.
Encryption of identity fields with a tenant-scoped key, hashed passwords, optional staff TOTP, private object storage for ID documents, and IP allowlists for staff. Details may evolve; material reductions in security require notice.
The current list is published at the Subprocessors page and is incorporated by reference. Using Canopy after notice of a new subprocessor (other than an emergency replacement) constitutes the controller’s opportunity to object as set out in the commercial terms.
This template is intended to be governed by Spanish law, with the AEPD as the lead supervisory authority where the controller is established in Spain, unless the signed DPA says otherwise.
Signature blocks, annexes (TOMs, subprocessor list, instructions), and liability caps will be added by counsel.