Privacy Policy
Last updated: 2026
This Privacy Policy (“Policy”) describes how CANN2, Inc. (“CANNII,” “we,” “us,” or “our”) processes personal data when you visit cannii.biz, use our contact forms, contract draft generator, or otherwise interact with our website and related services (collectively, the “Services”).
1. Data Controller
The data controller responsible for your personal data is:
- CANN2, Inc. (Delaware C-Corporation, USA)
- Registered office: 651 N Broad St, Suite 206, Middletown, Delaware 19709, United States
- Operating address: Jeddah, Kingdom of Saudi Arabia
- Website: cannii.biz
- Privacy contact: [email protected]
Where required by law, we will appoint or designate a representative or data protection contact and update this Policy accordingly following legal review.
2. Scope
This Policy applies to personal data collected through our public website and web-based tools. It does not govern:
- Executed service agreements or statements of work (governed by those contracts);
- Third-party websites, app stores, or services linked from our site;
- Employee or vendor data processed under separate policies.
3. Categories of Personal Data We Collect
Depending on how you use the Services, we may collect:
- Identity & contact data: name, email address, phone number (if provided), company name, job title, country.
- Communication data: messages submitted via contact forms, preferred language, inquiry subject.
- Contract & project data: project titles, descriptions, requirements, deliverables, timelines, payment preferences, reference images uploaded in the contract generator, and draft contract summaries submitted for review.
- Technical & usage data: IP address, browser type and version, device information, operating system, referring URLs, pages viewed, date/time stamps, and language preference (including cookie-stored language selection).
- Cookie & analytics data: as described in Section 8.
We do not intentionally collect special categories of personal data (e.g., health, biometric, political opinions) through the website. Please do not submit such data unless necessary and lawful to do so.
4. Sources of Data
We collect personal data:
- Directly from you when you complete forms or submit contract drafts;
- Automatically through cookies, logs, and similar technologies;
- From analytics or security providers acting on our behalf.
5. Purposes and Legal Bases for Processing
We process personal data for the purposes below. Where GDPR or UK GDPR applies, we rely on the legal bases indicated.
| Purpose | Legal Basis (GDPR) |
|---|---|
| Respond to inquiries and provide customer support | Contract performance; legitimate interests; consent where required |
| Review and respond to contract draft submissions | Pre-contractual steps; legitimate interests; consent where required |
| Operate, secure, and improve the website | Legitimate interests |
| Store language preference and essential session data | Legitimate interests; consent for non-essential cookies |
| Analytics and performance measurement | Consent where required; legitimate interests where permitted |
| Comply with legal obligations and enforce our terms | Legal obligation; legitimate interests |
| Establish, exercise, or defend legal claims | Legitimate interests; legal obligation |
6. How We Use Personal Data
We use personal data to:
- Communicate with prospective and existing clients;
- Prepare, review, and respond to contract drafts and project scoping information;
- Maintain website functionality, security, and user experience;
- Monitor aggregated usage trends and diagnose technical issues;
- Protect against fraud, abuse, and unauthorized access;
- Comply with applicable laws and respond to lawful requests.
We do not sell your personal data. We do not use contact form or contract data for unrelated third-party marketing without your consent where consent is required.
7. Disclosure of Personal Data
We may share personal data with:
- Service providers / processors: hosting providers, email delivery (SMTP), analytics, security, backup, and IT support vendors that process data on our instructions;
- Professional advisers: lawyers, accountants, or insurers where necessary;
- Affiliates: entities under common control with CANN2, Inc., subject to this Policy;
- Legal and regulatory authorities: when required by law, court order, or to protect rights and safety;
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards.
We require processors to implement appropriate security measures and process data only per our instructions and applicable law.
8. Cookies and Similar Technologies
We use cookies and similar technologies to:
- Remember your language preference (
cannii_lang); - Maintain security and basic site functionality;
- Measure site traffic and performance (e.g., via analytics plugins such as Google Analytics / MonsterInsights, if enabled).
Essential cookies are necessary for the site to function. Non-essential cookies (e.g., analytics) should be used only with valid consent where required by EU/UK/ePrivacy rules. We will implement or update a cookie consent mechanism following legal review.
You can control cookies through your browser settings. Disabling cookies may affect site functionality.
9. International Data Transfers
CANN2, Inc. is based in the United States and serves clients in Saudi Arabia, the GCC, Europe, and elsewhere. Personal data may be transferred to and processed in countries other than your own, including the United States, which may have different data protection laws.
Where required, we implement appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission or UK authorities;
- Other lawful transfer mechanisms under GDPR, UK GDPR, or Saudi PDPL;
- Contractual protections with processors.
Details of specific transfer mechanisms will be documented following legal review and made available upon request where required.
10. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law. Indicative periods (subject to legal review):
- Contact inquiries: up to 3 years from last communication, unless a client relationship continues;
- Contract drafts & project submissions: up to 7 years for business, tax, and legal record-keeping;
- Server logs & security records: typically 12–90 days unless needed for incident investigation;
- Analytics data: per provider settings or anonymized sooner where feasible.
When data is no longer needed, we delete or anonymize it using reasonable measures.
11. Security
We implement administrative, technical, and organizational measures designed to protect personal data, including access controls, encryption in transit (HTTPS/TLS) where configured, and vendor due diligence. No method of transmission or storage is 100% secure. You use the Services at your own risk.
Notify us promptly at [email protected] if you believe your data has been compromised through our Services.
12. Your Rights — EEA, UK, and Switzerland (GDPR / UK GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, you may have the right to:
- Access your personal data and obtain a copy;
- Rectify inaccurate or incomplete data;
- Erase data in certain circumstances (“right to be forgotten”);
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests or for direct marketing;
- Data portability for data you provided, where processing is automated and based on consent or contract;
- Withdraw consent at any time where processing is consent-based (without affecting prior lawful processing);
- Lodge a complaint with your local supervisory authority.
To exercise these rights, contact [email protected]. We may need to verify your identity. We will respond within applicable statutory timeframes (typically one month under GDPR).
13. Your Rights — United States
Depending on your U.S. state of residence (including California, Virginia, Colorado, Connecticut, Utah, and others with comprehensive privacy laws), you may have rights to:
- Know/access personal information collected about you;
- Correct inaccurate personal information;
- Delete personal information subject to exceptions;
- Opt out of certain processing such as “sale” or “sharing” for cross-context behavioral advertising (we do not sell personal data);
- Limit use of sensitive personal information where applicable;
- Non-discrimination for exercising privacy rights.
Submit requests to [email protected]. We will verify requests as required by law. Authorized agents may submit requests where permitted.
14. Saudi Arabia — Personal Data Protection Law (PDPL)
If you are in the Kingdom of Saudi Arabia, your personal data may be processed in accordance with the Personal Data Protection Law (Royal Decree M/19) and implementing regulations, as amended.
Subject to PDPL and applicable exceptions, you may have rights to:
- Be informed about the collection and processing of your personal data;
- Access and obtain a copy of your personal data;
- Request correction, completion, or updating of your data;
- Request destruction of your data when no longer needed or when processing is unlawful;
- Withdraw consent where processing is consent-based, without prejudice to prior lawful processing.
Requests and complaints may be submitted to [email protected]. You may also have the right to lodge a complaint with the Saudi Data & Artificial Intelligence Authority (SDAIA) where applicable.
Cross-border transfers from Saudi Arabia will be conducted in compliance with PDPL requirements, including adequacy decisions, assessments, or appropriate safeguards as required following legal review.
15. Other GCC and International Users
Users in the UAE, Qatar, Bahrain, Kuwait, Oman, and other jurisdictions may have additional rights under local data protection or consumer laws. We will honor applicable mandatory rights. Contact us to exercise them.
16. Children’s Privacy
The Services are not directed to children under 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us and we will take steps to delete it.
17. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects solely through the website. Contract pricing estimates are indicative tools requiring human review and are not binding automated decisions.
18. Marketing Communications
If we send marketing emails, you may opt out at any time using the unsubscribe link or by emailing [email protected]. Transactional and service-related communications may still be sent where necessary.
19. Changes to This Policy
We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be communicated via the website or email where required by law. Continued use after changes constitutes acknowledgment of the updated Policy where permitted.
20. Contact Us
For privacy questions, rights requests, or complaints:
- Email: [email protected]
- Mail: CANN2, Inc., 651 N Broad St, Suite 206, Middletown, DE 19709, USA