Last updated 9 Sept 2026Version 2026-09-draft-1
This notice describes how Canopy (the operator of canopy-os.com) and the cannabis associations (“clubs”) that use Canopy process personal data. It is written for people in the European Economic Area, with Spain (GDPR and LOPDGDD; supervisory authority: Agencia Española de Protección de Datos, AEPD) as the primary reference.
Until counsel confirms the legal entity name, DPO (if appointed), and registered address, treat the operator as “Canopy, canopy-os.com”. Contact: privacy@canopy-os.com.
Depending on how you use Canopy, we (or the club, through Canopy) may process:
Names and phone digits are also stored in a search index so staff can find members at the counter. Encrypted copies of identity fields are stored separately.
Clubs typically process member data to run the association (membership contract, Art. 6(1)(b)), to keep legally required records, and — for health notes and identity documents — under a suitable Art. 9 GDPR condition (often explicit consent, which later product phases will capture). Canopy processes club data as a processor and the global account as a joint controller for authentication, support, and platform security (Art. 6(1)(b) and (f)).
This draft does not replace the club’s own membership privacy information. Ask your club as well as Canopy.
OpenAI (United States) may receive a photo of a government ID when staff use ID scan to prefill a form, and may receive other content if staff use optional AI features (product suggestions, in-app assistant, CSV column mapping). Those transfers rely on OpenAI’s data processing terms and Standard Contractual Clauses (or equivalent). Staff see a notice about this transfer before scanning and must tell you first; your acknowledgement is recorded with your enrollment.
Sentry (Functional Software, Inc., United States) processes stack traces, request paths, and anonymous staff/member IDs for reliability. Event storage is configured in the EU (Frankfurt). Transfers rely on Sentry’s DPA and Standard Contractual Clauses (or equivalent). Names, emails, and request bodies are stripped before events are sent.
AWS and Railway process data in the EEA for the services above; they are US-headquartered vendors. Canopy will document SCCs / Data Privacy Framework coverage in the signed DPA.
Clubs decide how long membership and accounting records are kept, subject to law. Global accounts remain until you delete them in the member portal or a club asks us to erase what we hold as processor. Database backups (including point-in-time recovery) can retain a copy for a limited window after erasure. ID images and audit IPs should not be kept longer than needed; specific periods will be set with counsel.
You may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent where processing is based on consent, without affecting prior lawful processing. You may complain to the AEPD (https://www.aepd.es) or your local EEA supervisory authority.
The member portal can delete the global account and anonymize enrollments (sales stay in the shop’s books without your name). A structured download of your data will follow in a later product phase; until then, email privacy@canopy-os.com or ask the club.
See the Cookie policy. We currently use only what we consider strictly necessary for login, language, and display preferences. There is no advertising tracker.
We will update this page and the version stamp when the text changes. Material changes after this draft is approved may require a new acknowledgement.