// legal

Privacy Policy

Last updated: 2 August 2026

List Canopy is an AI automation agency. We design and build automation for our clients' internal operations and marketing. This policy explains what information we handle, both as a business in our own right and on behalf of clients whose systems we work inside, how we protect it, who we share it with, and the control you keep over it.

The short version: if you contact us, we hold your details to reply and nothing more. If you become a client, your business data stays in your systems under your accounts. We work with the least access needed to build and run what you asked for, we tell you which third-party AI services process what, we don't train models on your data, and your access can be revoked at any time.

1. Who we are

List Canopy is a trading name of FIREHOSE.AI LTD ("List Canopy", "we", "us"), a company registered in England and Wales. We provide AI automation consulting and build services covering internal operations, marketing, content generation and reporting.

For information about our own website visitors and enquirers, we are the data controller. For personal data inside a client's systems that we process while delivering an engagement, the client is the controller and we act as a processor on their documented instructions. You can reach us at hello@listcanopy.com.

2. Information we collect

Information you give us

  • Contact details. The email address you submit through the form on this site, and any name, company or role you choose to tell us.
  • Enquiry and engagement content. What you tell us about your business, your tools and where your team's time goes, including anything shared during a discovery or mapping session.
  • Correspondence. Emails, messages and call notes relating to your enquiry or engagement.

Client system data during an engagement

To build and run automations we need access to the systems the automation touches: for example a CRM, a shared inbox, a spreadsheet, a project tool or a reporting database. Depending on the workflow, that access may expose personal data belonging to your staff, customers or suppliers (such as names, work contact details, message content, or transaction records).

  • Access is granted by you, under your accounts, and is revocable by you at any time.
  • We request the narrowest scope a workflow actually needs.
  • Before a workflow goes live we document what it reads and what it writes.
  • We do not copy client data out of your systems except where a workflow genuinely requires it, and then only for as long as that workflow requires it.

Information collected automatically

  • Basic technical and usage data (such as server log data and browser or device type) needed to operate and secure this website.

3. How we use information

  • To respond to your enquiry and prepare an automation map or proposal.
  • To design, build, test, operate, monitor and support the automations you engage us for.
  • To contact you about your engagement, and about service or security matters affecting it.
  • To keep records required for accounting, tax and legal compliance.
  • To secure, maintain and improve our own systems and working methods.

We do not sell your personal information, and we do not share it for advertising.

4. AI services and your data

Automations we build often send content to third-party AI model providers to do their work, for example to draft copy, summarise a document, classify a message or extract a field. This is central to what we do, so we are explicit about it:

  • We tell you which AI providers a workflow uses before it goes live, and what is sent to them.
  • We use business or enterprise tiers where available, under terms that do not permit your content to be used to train the provider's models.
  • We minimise what is sent: a workflow should send the field it needs, not the whole record.
  • Where a workflow can achieve the same result without sending personal data, we build it that way.
  • AI output can be wrong. Anything customer-facing or financial is routed to a person for approval before it takes effect, and workflows log what they did so errors are visible and reversible.

5. Legal bases (UK / EU GDPR)

  • Legitimate interests. Responding to business enquiries, running and securing our business, and delivering engagements.
  • Contract. Performing the agreement we have with you as a client.
  • Consent. Where you opt in to receive something specific from us; you can withdraw it at any time.
  • Legal obligation. Accounting, tax and other statutory records.

6. How we store and protect it

  • Data is transmitted over encrypted connections (HTTPS / TLS).
  • Credentials, API keys and access tokens are stored in encrypted secret storage, never in plain text, never in shared documents or chat.
  • Access is limited to the people working on your engagement, and removed when it is no longer needed.
  • Access we hold to your systems can be revoked by you at any time, without our involvement.

7. Who we share it with

We share information only in these limited cases:

  • AI model providers. As described in section 4, and only as required by a workflow you have approved.
  • Infrastructure and service providers. Vetted providers (for example hosting, email, automation platforms and error monitoring) that process data on our behalf under confidentiality obligations.
  • Your own systems. Automations write back into the tools you nominate.
  • Professional advisers. Accountants and lawyers, where necessary.
  • Legal. Where required by law, or to establish, exercise or defend legal claims.

Where a client requires it, we will sign a data processing agreement setting out subprocessors and instructions in a binding form.

8. International transfers

Some providers we rely on, including AI model providers, operate outside the UK and EEA. Where personal data is transferred internationally we rely on an adequacy decision or on appropriate safeguards such as Standard Contractual Clauses or the UK Addendum.

9. Data retention

We keep enquiry correspondence for as long as needed to deal with the enquiry and for a reasonable period afterwards. Engagement records are kept for the life of the engagement and then for as long as needed for legal, accounting and dispute-resolution purposes. Any client system data held by us outside your own systems is deleted when the workflow that needed it ends, or on your instruction.

10. Your rights

  • Access, correct or delete. Email hello@listcanopy.com to request a copy of your data, a correction, or deletion.
  • Object or restrict. You can object to processing based on legitimate interests, or ask us to restrict it.
  • Portability. You can ask for the data you gave us in a portable format.
  • Withdraw consent. Where we rely on consent, you can withdraw it at any time.
  • Complain. You can complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

If your request concerns data we process on a client's behalf, we will refer it to that client as the controller and support them in answering it.

11. Cookies

This website uses only the cookies and similar technologies needed to load the page and run the contact form. We do not use advertising or cross-site tracking cookies.

12. Children

Our services are business-to-business and are not directed to anyone under 18. We do not knowingly collect data from children.

13. Changes to this policy

We may update this policy as our services evolve. We will change the "Last updated" date above and, for material changes affecting clients, give notice by email.

14. The List Canopy Etsy application

Separately from our agency services, FIREHOSE.AI LTD operates a listing tool for Etsy sellers at app.listcanopy.com. If you are a user of that application, the following also applies to you:

  • We access Etsy shop data only through Etsy's official OAuth, with the scopes you approve, and we never receive or store your Etsy password.
  • With those scopes we may access shop and account information, listing and inventory data, and (only where you grant it) order data, in each case to provide the features you use.
  • We do not scrape Etsy. All Etsy data is obtained through Etsy's official API with your authorisation, and we follow Etsy's API Terms of Use including its caching policy.
  • You can revoke the application's access at any time from your Etsy account settings, which immediately stops our access to that shop.
  • Sections 6 to 13 above apply equally to this data.

15. Contact

Questions about privacy or your data: hello@listcanopy.com.