Skip to main content

Canopy legal

Data Processing Addendum

This DPA governs Canopy's processing of guest, staff, and booking personal information on an operator's behalf.

Effective July 28, 2026

DPA version: 2026-07-28. This Data Processing Addendum is incorporated into the Canopy Terms of Service between Canopy and Customer. Capitalized terms not defined here have the meaning given in the Terms.

1. Roles and applicable law

Customer is the controller, or organization responsible for the personal information it places in or collects through the service. Canopy is Customer's processor or service provider. Each party will comply with privacy law applicable to its role, including PIPEDA where applicable. Canopy processes Customer Personal Data only to provide, secure, and support the service and as Customer otherwise lawfully instructs.

2. Processing details

Duration. The subscription term plus the return and deletion period.

Purpose and operations. Hosting, organizing, retrieving, displaying, transmitting, backing up, and deleting data for websites, booking, guest portals, payments, messaging, support, property operations, integrations, security, and optional AI-assisted features.

AI suggestions, if enabled, are processed by Anthropic as described in the Subprocessor Register.

Data subjects may include:

  • guests, prospective guests, purchasers, attendees, and companions;
  • Customer's owners, employees, contractors, vendors, and authorized users; and
  • people who submit inquiries, reviews, support requests, or marketing preferences.

Personal data may include:

  • names, contact details, addresses, and account identifiers;
  • booking, stay, event, purchase, preference, access, and itinerary details;
  • messages, support content, reviews, signatures, and uploaded files;
  • staff roles, assignments, schedules, device, and access-code records;
  • payment status, amount, currency, and Stripe identifiers, but not full card numbers or CVC intentionally stored by Canopy; and
  • IP address, device/browser information, security events, and service-usage records.

3. Customer instructions

The Terms, Customer's configuration, and documented support requests are Customer's instructions. Canopy will notify Customer if an instruction appears to violate applicable privacy law and may pause it while the parties resolve the issue. Canopy may process data where law requires it, after notifying Customer unless law prohibits notice.

4. Confidentiality and access

Canopy will limit access to people and providers who need it for the service. Personnel authorized to process Customer Personal Data are subject to confidentiality obligations. Customer controls its users and roles and must promptly remove access no longer required.

5. Security measures

Canopy maintains the measures in the Security Schedule below and may replace a measure with one that does not materially reduce overall protection. No system is perfectly secure, and the measures do not create a guarantee against every incident.

6. Subprocessors

Customer gives general authorization for the subprocessors in the maintained Subprocessor Register. Canopy will impose data-protection obligations appropriate to each provider's work and remains responsible for its subprocessors' processing under this DPA.

Canopy will give at least 30 days' notice before a material new subprocessor begins processing Customer Personal Data, except an urgent replacement needed for security or continuity. Customer may object on reasonable data-protection grounds within 15 days.

7. Individual rights

Taking into account the nature of processing, Canopy will provide reasonable assistance for access, correction, deletion, consent-withdrawal, and complaint requests that Customer cannot complete using available tools. If Canopy receives a request about Customer Data directly, it will direct the requester to Customer unless Customer instructs it or law requires otherwise.

8. Security incidents

Canopy will notify Customer without undue delay after confirming unauthorized access, use, disclosure, alteration, loss, or destruction of Customer Personal Data. Canopy will provide known facts reasonably needed for Customer's assessment and reasonable containment and investigation assistance, with enough detail for Customer's notification, recordkeeping, and risk-assessment obligations under PIPEDA and applicable provincial law, including Quebec Law 25. Customer is responsible for notices to individuals and regulators unless law assigns that duty to Canopy.

9. Return, deletion, and retention

During the term, Customer may use available export functions. On written request made before termination or within 30 days afterward, Canopy will provide reasonable assistance with the then-available machine-readable export. By default, booking and guest data is retained for 6 years after the stay ends to support CRA tax-record requirements, and dispute data is retained as needed for chargebacks. Canopy may then delete or de-identify Customer Personal Data from active systems unless law, tax, security, fraud prevention, or a dispute requires longer retention. Residual copies remain protected until overwritten through ordinary provider backup cycles.

10. Processing outside Canada

Customer authorizes processing in the locations described in the Subprocessor Register. Providers may operate from or permit support access in Canada, the United States, and other countries, where information may be subject to local law and lawful government access. Canopy will use contractual and organizational safeguards appropriate to the transfer.

11. Information and audit cooperation

On reasonable written request, Canopy will provide information needed to demonstrate compliance with this DPA. If that material is insufficient, Customer may request one audit per 12-month period by an independent auditor bound to confidentiality, during business hours and without accessing another customer's data. Customer pays its audit costs and Canopy's reasonable costs for extraordinary assistance, unless the audit finds a material breach by Canopy.

12. Security Schedule

  • Tenant separation: application queries are scoped by organization. Postgres row-level-security policies and a restricted application role provide a database backstop when the deployment uses the restricted connection.
  • Transmission: public web traffic uses HTTPS/TLS, and non-local database and provider connections are TLS-configured.
  • Access controls: authenticated sessions, organization membership, roles, and permission checks restrict administrative functions.
  • Logging: defined administrative, authentication, billing, booking, configuration, and device actions are recorded in audit or activity logs. Canopy does not claim that every read of every record is logged.
  • Service continuity: Canopy uses managed infrastructure recovery capabilities and maintains procedures for restoring service after material failures.
  • Data minimization: diagnostic and analytics integrations are configured to limit direct identifiers where supported.

13. Contact and precedence

Privacy and DPA notices may be sent to hello@hostwithcanopy.com. If this DPA conflicts with the Terms on Customer Personal Data, this DPA controls.

Data Processing Addendum — Canopy