The EU value-chain cap has been in force since 3 July 2026. It limits what large customers can ask suppliers for.See what applies to you →

Privacy

What we collect, where it is stored, who processes it, how long we keep it, and how to make it stop. Written to be read rather than to be survived.

Last updated 2026-09-04

Who the controller is

EARTH AROGYAM INNOVATE, a sole proprietorship at Durgapur, West Bengal, India, Udyam registration UDYAM-WB-23-0081393, operating the CoreCanopy service. Write to support@corecanopy.earth for any request under this policy. A dedicated privacy mailbox is being created and will be published here.

Where your data lives

Customer data is stored and processed in Amazon Web Services eu-central-1, in Frankfurt. It is not replicated outside the European Union. Administration of the service is performed remotely from India by the operator, and we treat that access as a transfer for the purposes of Chapter V of the GDPR; the mechanism and its documentation are being finalised with counsel and this section will state the outcome precisely when it is.

What we collect

  • Account data: name, work email address, organisation, and authentication credentials in hashed form.
  • Inventory data: the activity records, readings, documents and figures you enter or import.
  • Operational logs: request metadata retained for seven days for reliability and abuse prevention.
  • Error traces carrying tenant, user and correlation identifiers, with personal data scrubbed at source before it leaves our systems.

What this website collects

This marketing site sets no tracking cookies and runs no third-party analytics. Fonts are served from this domain, not from a font CDN, so visiting a page here does not disclose your address to a third party. If you submit the working-session form we receive only what you type into it.

Payments

Payments are processed by Razorpay. No card data touches our systems: we receive a billing contact and payment metadata only. Payments are not yet live, and this section will be updated when they are.

Support access

Our staff cannot read your inventory data without your consent. Access is requested, you see the request before deciding, you may refuse it, and a refusal is recorded as an outcome rather than dismissed as a dialog. A granted session can be ended by you at any time, and every screen we opened is written to your own audit trail for you to read.

Your rights

Access, rectification, erasure, restriction, portability and objection, as the GDPR provides. Erasure and Article 15 access are implemented in the product and have been rehearsed rather than merely designed: an erasure returns a receipt naming what was retained and the legal basis for retaining it.

Retention

  • Inventory data: for the life of the account, then erased on request or on closure.
  • Filed reports and their audit entries: retained while the account exists, because they are the record the service exists to keep.
  • Operational logs: seven days.
  • Billing records: as tax law requires.

This policy is in review with counsel alongside our contract set. Where it is silent or imprecise, that is because we would rather leave a gap visible than fill it with language we cannot stand behind.