Legal
Privacy Policy.
Last updated
This policy explains what information canopyassociates.com collects, how we use it, and the choices you have. The short version: we collect the business contact details you give us, we never sell them, and this website holds no patient data.
The Plain-English Summary
- We collect what you type into our forms — business contact details — and standard website usage data. Nothing more.
- We never sell your personal information, and we never give it to anyone for their own marketing.
- This is a marketing website. It runs no patient surveys and holds no patient data — please never submit patient information here.
- We may identify the organization a visit comes from (a hospital's network identifies itself); we do not identify anonymous individual visitors.
- Analytics run with IP anonymization, and you can decline non-essential cookies. We honor Global Privacy Control signals.
- Email at any time to see, correct, or delete what we hold about you.
The rest of this policy is the full version of those promises.
Table of Contents
- 1. Who We Are and What This Policy Covers
- 2. Information You Provide to Us
- 3. Information Collected Automatically
- 4. No Patient Information (PHI)
- 5. How We Use Information
- 6. Business Visitor Identification
- 7. Cookies, Analytics, and Tracking
- 8. How We Share Information
- 9. Email Communications
- 10. Data Retention
- 11. Security
- 12. Your Choices and Rights
- 13. Children's Privacy
- 14. Visitors From Outside the United States
- 15. Third-Party Websites
- 16. California Residents
- 17. Changes to This Policy
- 18. Contact Us
1. Who We Are and What This Policy Covers
We are AdCo Advertising Agency, Inc., doing business as Canopy Associates ("Company," "we," "us," or "our"), a company registered in Illinois, United States, at 1302 W Pioneer Pkwy, Peoria, IL 61615. You can reach us by phone at 309-692-7880 or by email at .
This Privacy Policy covers canopyassociates.com (the "Site") and the related services that link to it (together, the "Services"), and it is incorporated into our Terms of Use.
This policy covers our marketing website only. Our products — patient experience surveys, quality reporting, and related software — operate on separate systems under separate written agreements with client organizations, including, where applicable, business associate agreements. The data those products handle is governed by those agreements, not this policy, and is never combined with data from this website.
2. Information You Provide to Us
We collect the information you choose to give us:
- Demo, quote, and contact forms: your name, organization, work email address, phone number (optional), your message (optional), and — for demo requests — the products and capabilities you tell us you want the demo to cover.
- Newsletter signup: your email address, your name (optional), and the topic streams you choose to receive.
- Consent records: when you check the "I accept the Terms of Use and Privacy Policy" box on a form, we record when you checked it, which version of the wording you accepted, and the IP address and browser it was submitted from — our proof that consent was given.
- Anything you email us at our published addresses.
If we add features that require registration — for example webinars or client training — we will collect the information those forms request, and we will update this policy if the collection is materially different from what is described here.
3. Information Collected Automatically
Like nearly every website, we automatically receive some technical data:
- Server logs: your IP address, browser type (user agent), the pages you request, and timestamps — used for security, troubleshooting, and the organization-level visitor identification described in section 6.
- How you arrived: on your first page view we note the referring website, the page you landed on, and any campaign tags (UTM parameters) in the link you followed. If you later submit a form, that arrival information is stored with your submission so we know which of our marketing efforts actually work.
- Analytics and cookies: described in section 7.
4. No Patient Information (PHI)
This website is a marketing and informational site. It runs no patient surveys, connects to no electronic health records, and holds no patient data. Our forms ask for business contact information only.
Do not submit protected health information (PHI), patient records, or any other individually identifiable health information through this website. If a form submission contains patient details, we delete it.
Visit data from this website is never merged with data from our survey and reporting products: a hospital employee browsing our marketing site is business contact data, not patient data, and we keep it that way.
5. How We Use Information
We use the information described above to:
- respond to your demo requests, quote inquiries, and messages;
- send you the newsletter you signed up for, matched to the topics you chose;
- follow up on sales inquiries, including tracking demo requests in our customer relationship management (CRM) system;
- understand which pages and marketing channels bring visitors, so we can improve the Site;
- identify the organizations researching our products (section 6);
- protect the Site against spam, abuse, and security threats; and
- keep records of the consent you gave us and comply with legal obligations.
We do not use your information for advertising networks, and we do not build advertising profiles of you.
6. Business Visitor Identification
We serve hospitals and healthcare organizations, and their networks usually identify themselves: a visit from a hospital's connection resolves to that hospital. We may use visitors' IP addresses to identify the organization a visit comes from, and we may keep organization-level records of which pages that organization's visitors viewed and when, so our sales team knows which organizations are researching our products. If someone from an identified organization submits a form, we may link that submission to the organization's record.
This identifies organizations, not people. We do not use identity-graph or visitor "de-anonymization" services that put names to anonymous individual visitors, and we do not display or share the IP addresses of visitors whose network does not resolve to an organization. If we ever decide to adopt person-level visitor identification, we will update this policy with the required disclosures and provide an opt-out before enabling it.
We honor Global Privacy Control (GPC) browser signals as an opt-out. Raw request logs are kept for 90 days; organization-level visit summaries are kept for 12 months, then purged.
9. Email Communications
We send two kinds of email:
- Transactional email — responses to your inquiries, a welcome message when you subscribe, and confirmations when you change your preferences.
- The newsletter — sent only to addresses that signed up for it, matched to the topic streams you chose.
Every newsletter includes an unsubscribe link, including one-click unsubscribe supported by major mail clients. Unsubscribing takes effect immediately, and an unsubscribed address stays unsubscribed — even if our lists are later re-imported. You can also change your topic preferences at any time through the secure preference link included in every newsletter. Addresses that bounce or mark our email as spam are automatically removed from the list.
10. Data Retention
- Form submissions and leads: kept for as long as they are relevant to an actual or prospective business relationship, or until you ask us to delete them (section 12).
- Newsletter subscriptions: kept while your subscription is active. Unsubscribed addresses are retained on a suppression list — the record that keeps us from ever emailing you again.
- Consent records: kept for as long as the record they evidence.
- Raw server logs: 90 days.
- Organization-level visit summaries: 12 months.
11. Security
The Site is served over HTTPS, sits behind Cloudflare's security layer, and follows current web security practices. Access to submitted information is limited to authorized staff and protected by multi-factor authentication. We collect no payment information through the Site at all.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security — but we deliberately collect little, which is the best protection there is.
12. Your Choices and Rights
Email to:
- ask what personal information we hold about you;
- correct information that is wrong or outdated;
- ask us to delete your information; or
- ask questions about this policy.
We honor these requests for everyone, regardless of which state's privacy law — if any — applies to us. We may need to verify that a request comes from the person it concerns, and we may retain what the law requires us to keep (for example, the suppression record that enforces an unsubscribe).
You can also unsubscribe from the newsletter at any time (section 9), decline analytics cookies (section 7), and send a Global Privacy Control signal (section 6) — each works without contacting us.
13. Children's Privacy
The Services are business services intended for users who are at least 18 years old. They are not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we will delete it.
14. Visitors From Outside the United States
We are a United States company serving United States healthcare organizations, and the Services are hosted and processed in the United States. If you access the Services from another region with different data protection laws, you are transferring your information to the United States, and by using the Services you consent to that transfer and to processing under this policy and United States law.
15. Third-Party Websites
The Site links to other websites — for example, our product sign-in portals and industry resources. This policy stops at our door: once you leave the Site, the destination's own privacy policy governs. We encourage you to read it.
16. California Residents
In the categories used by California law, we collect: identifiers and professional information (the contact details you submit through our forms) and internet activity (the usage data in sections 3, 6, and 7). We collect them from you directly and from your use of the Site, for the purposes in section 5, and we share them only with the service providers in section 8.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as the California Consumer Privacy Act defines those terms. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We do not disclose personal information to third parties for their own direct marketing (California Civil Code § 1798.83, "Shine the Light"). We honor Global Privacy Control signals; for the older "Do Not Track" setting, see section 7.
California residents may exercise the choices in section 12, and we will not discriminate against you for doing so.
17. Changes to This Policy
When we change this policy, we will post the revised version here and update the "Last updated" date above. If a change materially expands what we collect or how we share it, we will make the change conspicuous on the Site — and where this policy promises a specific step first (section 6), we will take that step before the change takes effect. Your continued use of the Services after a revised policy is posted means you accept it.
18. Contact Us
Questions, requests, or complaints about privacy on this Site — we answer them directly:
AdCo Advertising Agency, Inc., d/b/a Canopy Associates
Attn: Privacy
1302 W Pioneer Pkwy
Peoria, IL 61615
United States
Phone: 309-692-7880