Skip to content
Canopy Observe

Privacy Policy

Effective date: 20 June 2026

1. Who We Are

CANOPY.INC(“we”, “us”, “our”) operates Canopy Observe, an enterprise drone-inspection and AI observability platform. We are the data controller of personal data collected through the Service.

Northern Edge Software, Queensland, Australia

Data Protection contact: [email protected]

2. Data We Collect

We collect the following categories of personal data:

  • Account data — name, email address, hashed password, role, and organisation details provided at registration.
  • Operational data — drone telemetry, GPS tracks, inspection job metadata, AI detection results, and associated images or video frames you upload or stream through the Service.
  • Usage data — log entries, API call records, session tokens, browser/device type, and IP addresses, collected automatically when you use the platform.
  • Communication data — content of support requests, feedback forms, or emails you send us.

3. How We Use Your Data

We process personal data for the following purposes:

PurposeLegal basis (GDPR / UK GDPR)
Providing and operating the ServicePerformance of a contract (Art. 6(1)(b))
Authentication and access controlContract / Legitimate interest (Art. 6(1)(b)(f))
Security monitoring and fraud preventionLegitimate interests (Art. 6(1)(f))
Billing and payment processingContract / Legal obligation (Art. 6(1)(b)(c))
Product improvement and analyticsLegitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Sending service and security noticesContract / Legitimate interests (Art. 6(1)(b)(f))

4. Data Sharing and Sub-processors

We do not sell personal data. We may share data with trusted sub-processors that help us deliver the Service, including cloud infrastructure providers (e.g., AWS, Cloudflare), database providers (e.g., Neon), and email delivery services. All sub-processors are bound by appropriate data-processing agreements.

We may disclose personal data where required by applicable law, court order, or regulatory authority, or to protect the rights, property, or safety of CANOPY.INC, our users, or the public.

5. International Data Transfers

Our infrastructure is hosted in AWS regions including Australia (ap-southeast-2), Europe (eu-west-1/2/3), and the United States (us-east-1). Transfers of personal data outside the UK or EEA are subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) or equivalent mechanisms recognised under UK GDPR.

6. Data Retention

We retain personal data for as long as your account is active or as necessary to provide the Service. Account data is deleted within 90 days of account closure. Aggregated, anonymised analytics data may be retained indefinitely. We retain logs for security purposes for up to 12 months. Customer-uploaded operational data (telemetry, images, detection results) follows the retention settings configured by your organisation administrator.

7. Security

We implement industry-standard technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. These include encryption in transit (TLS 1.2+) and at rest, role-based access controls, JWT-based authentication, and audit logging. However, no system is completely secure and we cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, in accordance with applicable law.

8. Cookies and Similar Technologies

Canopy Observe uses session storage and local storage to maintain authentication tokens. We do not use third-party tracking cookies for advertising. Where we use analytics tooling, it is configured to anonymise IP addresses and avoid cross-site tracking.

9. Your Rights (GDPR / UK GDPR)

If you are located in the European Economic Area or United Kingdom, you have the following rights in relation to your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure— request deletion of your personal data (“right to be forgotten”), subject to legal obligations.
  • Restriction — request that we restrict processing of your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdrawal of consent — where processing relies on consent, withdraw it at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK, or your national DPA in the EU).

10. Children's Privacy

The Service is intended for enterprise professional use only and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect. The effective date at the top of this page will always reflect the most recent revision.

12. Contact Us

For privacy-related queries, requests, or complaints, please contact:

CANOPY.INC — Privacy Team

Northern Edge Software, Queensland, Australia

Email: [email protected]

© 2026 CANOPY.INC. All rights reserved.
Terms of Service