Data Processing Agreement

Alerts

All clear
Back to Dashboard

Legal

Data Processing Agreement

Effective date: 12 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between AgriOps Technologies Limited ("Processor") and the Customer ("Controller"), and governs the processing of personal data by AgriOps on behalf of the Customer.

This DPA applies where the Customer's use of the Platform involves the processing of personal data subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, the Nigeria Data Protection Act 2023, or any other applicable data protection law.

1. Definitions

  • Controller — the Customer, who determines the purposes and means of processing personal data;
  • Processor — AgriOps, who processes personal data on behalf of the Controller;
  • Personal Data — any information relating to an identified or identifiable natural person included in Customer Data;
  • Processing — any operation performed on personal data, including collection, storage, use, disclosure, or deletion;
  • Sub-processor — any third party engaged by AgriOps to process personal data on behalf of the Controller.

2. Subject Matter and Nature of Processing

AgriOps processes personal data as necessary to provide the Platform services described in the Terms of Service, including:

  • Storing and managing supply chain records containing personal data (farmer names, supplier contacts, employee accounts);
  • Generating compliance documents and traceability certificates;
  • Maintaining audit logs of user actions;
  • Providing access controls, authentication, and session management.

3. Categories of Personal Data and Data Subjects

Categories of personal data processed:

  • Identity data: names, job titles;
  • Contact data: email addresses, phone numbers, postal addresses;
  • Location data: GPS coordinates and farm polygon boundaries associated with named farmers;
  • Access and audit data: IP addresses, login timestamps, action logs.

Categories of data subjects:

  • Authorised Users (Customer employees and contractors);
  • Suppliers and their contact personnel;
  • Farmers and smallholder operators in the Customer's supply chain.

4. Duration

This DPA remains in effect for the duration of the Terms of Service. Upon termination, AgriOps will retain Customer Data for 30 days to enable export, then securely delete it in accordance with the Terms of Service and Section 9 of this DPA.

5. Controller Obligations

The Controller warrants and represents that:

  • It has a lawful basis for processing the personal data it uploads to the Platform;
  • It has provided all required notices and obtained all required consents from data subjects where applicable;
  • Its instructions to AgriOps comply with applicable data protection law;
  • It is responsible for the accuracy and legality of the personal data it submits.

6. Processor Obligations

AgriOps shall:

  • Process personal data only on documented instructions from the Controller (i.e. to provide the Platform services), unless required otherwise by applicable law;
  • Ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations;
  • Implement and maintain the technical and organisational security measures described in Section 7;
  • Notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data;
  • Assist the Controller in fulfilling data subject rights requests and data protection impact assessments, to the extent reasonably practicable;
  • Delete or return all personal data upon termination as specified in Section 9;
  • Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.

7. Technical and Organisational Security Measures

AgriOps maintains the following controls:

  • Encryption in transit — TLS for all data transmitted between the Platform and users;
  • Access controls — role-based permissions and organisation-scoped access rules designed to restrict Authorised Users to their own organisation's data;
  • Authentication — password hashing (PBKDF2), brute-force protection (account lockout after 5 failed attempts), TOTP for administrative access;
  • Session management — 8-hour session timeout, secure session cookies;
  • Audit logging — all create, update, and delete actions are logged with user identity, timestamp, and IP address, retained for 365 days;
  • Tenant isolation — core application data is scoped by organisation, with tenant-isolation controls reviewed and hardened as part of ongoing security work;
  • Vulnerability management — periodic security reviews; dependencies reviewed for known vulnerabilities.

8. Sub-processors

The Controller provides general authorisation for AgriOps to engage sub-processors to assist in providing the Platform services. AgriOps will:

  • Maintain a published list of current sub-processors at agriops.io/legal/subprocessors, available to the Controller at any time without request;
  • Notify the Controller of any intended changes to sub-processors (additions or replacements) with reasonable advance notice, and record each change in the change log on that page;
  • Impose data protection obligations on sub-processors equivalent to those in this DPA;
  • Remain liable to the Controller for the acts and omissions of its sub-processors.

9. Deletion and Return of Data

Upon termination of the Terms of Service, AgriOps will:

  • Make Customer Data available for export for 30 days following termination;
  • Securely delete all Customer Data from live systems within 60 days of termination;
  • Provide written confirmation of deletion upon request;
  • Retain data only where required by applicable law (e.g. audit logs required by a regulatory authority).

10. International Data Transfers

Where personal data originating from the EU/EEA or UK is transferred to and processed in Nigeria or another third country, AgriOps will ensure appropriate transfer safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission; or
  • Any other transfer mechanism recognised under applicable data protection law.

The Controller may request a copy of applicable transfer mechanisms by contacting privacy@agriops.io.

11. Audit Rights

AgriOps will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. The Controller may request an audit of AgriOps's data processing activities upon 30 days' written notice and at the Controller's expense. Audits must be conducted during normal business hours and must not unreasonably disrupt AgriOps's operations.

12. Data Breach Notification

AgriOps will notify the Controller without undue delay — and in any event within 72 hours of becoming aware — of any personal data breach affecting Customer Data. Notification will include, to the extent known at the time:

  • Nature of the breach and categories and approximate number of individuals affected;
  • Likely consequences of the breach;
  • Measures taken or proposed to address the breach.

13. Conflict

In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of personal data.

14. Contact

Data protection enquiries: privacy@agriops.io

15. Revision history

Effective Change
12 Aug 2026 Clause 8 amended. The sub-processor list is now published and available to the Controller at any time, rather than supplied on request, and each change is recorded in a change log on that page. No change to the Controller's rights — this strengthens the notice mechanism.
26 Mar 2026 Initial version.

Confirm Delete

This action cannot be undone.

Delete ?