Back to Agrianta

Data Processing Addendum

Last updated 23 July 2026

1. Introduction and Scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Astraeus Technology Limited, a company registered in England and Wales under number 15162283 ("Agrianta", "we", "us", or the "Processor"), and the customer using the Services ("you" or the "Controller").

This DPA applies whenever we process personal data on your behalf to provide the Services. It is designed to meet Article 28 of the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR").

By agreeing to our Terms of Service or using the Services, you accept this DPA as a legally binding contract for the processing of personal data. No signature is needed for it to take effect, but a signed copy is available on request from privacy@agrianta.com.

2. Order of Precedence

If this DPA conflicts with the Terms of Service or any other agreement between the parties, this DPA prevails on matters relating to the processing of personal data. All other provisions of the Terms of Service remain in full force.

3. Definitions

Unless defined below, capitalised terms have the meaning given to them in the Terms of Service or, where relevant, in UK GDPR.

  • "Applicable Data Protection Laws" means UK GDPR, the Data Protection Act 2018, EU GDPR, the Privacy and Electronic Communications Regulations 2003, and any other data protection laws applying to Customer Personal Data.
  • "Customer Personal Data" means personal data that we process on your behalf in order to provide the Services.
  • "Data Subject", "personal data", "processing", "controller", and "processor" have the meanings given in UK GDPR.
  • "Sub-processor" means any third party engaged by us to process Customer Personal Data on our behalf in connection with the Services, as listed in our Sub-processors page.
  • "Personal Data Breach" has the meaning given to it in UK GDPR.

4. Role of the Parties

In providing the Services, you act as the Controller and we act as the Processor of Customer Personal Data. Where you use the Services on behalf of another controller (for example, a farm business you manage), you remain responsible for having authority to instruct us and for your use complying with Applicable Data Protection Laws.

Each party is independently responsible for its own compliance with Applicable Data Protection Laws.

5. Subject Matter, Duration, Nature and Purpose

Our processing of Customer Personal Data is as follows:

  • Subject matter: the provision of the Services described in our Terms of Service, including farm management, livestock monitoring, compliance reporting, alerting, data storage, and AI-powered insights.
  • Duration: for the term of your subscription plus the 30-day recovery window following account closure, subject to deletion or return under Section 13 below.
  • Nature and purpose: storing, organising, analysing, displaying, transmitting, and otherwise processing Customer Personal Data to deliver the Services, including transmission to Sub-processors for the purposes set out on our Sub-processors page.
  • Types of personal data: names, email addresses, phone numbers, organisational roles, login credentials, payment and billing details, farm location, livestock records, compliance records, device and sensor data, livestock images, audit logs, and user-generated content (for example, notes, task descriptions, and Scout AI prompts).
  • Categories of Data Subject: your personnel, team members and farm workers; veterinarians and agricultural advisors you share data with; suppliers and contractors; and other individuals whose personal data appears in farm records you upload.

6. Your Instructions

We will process Customer Personal Data only on your documented instructions, which are:

  • the Terms of Service and this DPA;
  • the instructions you give us through the configuration, administration, and use of the Services; and
  • any additional written instructions we agree in writing to act on.

We will promptly inform you if, in our opinion, an instruction infringes Applicable Data Protection Laws. Where we are required by law to process Customer Personal Data other than on your instructions, we will inform you of the legal requirement before processing, unless the law prohibits such notice.

7. Confidentiality

We will ensure that any person we authorise to process Customer Personal Data is subject to a duty of confidentiality, whether contractual or statutory, and is trained on their obligations under Applicable Data Protection Laws.

8. Security of Processing

We will implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures are set out in Annex III and are reviewed and updated from time to time. We will not materially reduce the overall level of protection during the term of your subscription.

9. Sub-processors

You grant us general authorisation to engage Sub-processors to process Customer Personal Data, subject to the conditions in this Section 9. The current list of Sub-processors is published at agrianta.com/subprocessors.

Before engaging a new Sub-processor or materially changing an existing one, we will update the Sub-processors page and, where required, give business customers at least 30 days' notice by email. If you reasonably object on data-protection grounds, notify us in writing within that notice period and we will work in good faith to address your concerns. If we cannot, you may terminate the affected part of your subscription in accordance with the Terms of Service.

We impose written obligations on each Sub-processor substantially the same as those in this DPA, including those on security, confidentiality, Data Subject rights, and international transfers. We remain responsible to you for our Sub-processors' acts and omissions in relation to Customer Personal Data.

10. Data Subject Rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection.

If we receive a request directly from a Data Subject that relates to Customer Personal Data, we will promptly forward it to you and will not respond ourselves unless you authorise us to or we are legally required to do so.

11. Personal Data Breach Notification

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. We will notify the primary administrator address on your account by email and will, so far as possible, include the information required by Article 33(3) UK GDPR:

  • the nature of the breach, including the categories and approximate number of Data Subjects and records affected;
  • the likely consequences of the breach and the measures we have taken or propose to take to address it and mitigate its possible adverse effects; and
  • the contact point for further information.

We aim to notify you within 48 hours of awareness so you can meet your own 72-hour obligation to the UK Information Commissioner's Office (ICO). Where information is not available at that point, we will provide it in stages as it becomes available.

12. Data Protection Impact Assessments and Consultation

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you carry out Data Protection Impact Assessments and, where required, prior consultations with the ICO or other supervisory authority.

13. Deletion and Return of Data

When your organisation account is closed (whether you initiate closure or your subscription terminates), Customer Personal Data is retained but made inaccessible for a 30-day recovery window, during which the organisation owner may cancel the closure. At the end of that window it is permanently deleted from our active systems, except where retention is required by law. Trial organisations that do not convert to a paid subscription are scheduled for closure about 30 days after the trial ends and are then deleted following the same recovery window.

At your choice, we will delete or return Customer Personal Data at the end of the provision of the Services. Where the organisation owner initiates closure, we email the owner an export of the organisation's records in a commonly used, machine-readable format; export download links remain valid for 7 days. You may also export Customer Personal Data using our standard export tools at any time before closure takes effect, or request an export from privacy@agrianta.com before deletion.

The following limited records are retained after deletion:

  • Billing and financial records are retained for approximately 6 years to meet legal (tax) obligations, in reliance on Article 17(3)(b) UK GDPR. These records are held primarily by our payment processor, Stripe; we retain a minimal closure record (organisation name, billing references, and timestamps).
  • Erasure receipts: where an individual user deletes their account, their name, email address, login credentials, sessions, and two-factor authentication data are erased or anonymised immediately, and we retain an append-only erasure receipt (user identifier and timestamp) as evidence that erasure was carried out. Organisation and farm records the user contributed to remain available to you as Controller.

Deleted data may persist in encrypted backups for up to approximately 30 days before being overwritten. Backups are not restored to live systems except for disaster recovery.

14. Audit Rights

We will make available to you all information reasonably necessary to demonstrate our compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an independent auditor mandated by you, subject to the following:

  • audits must be scheduled at a mutually agreed time with at least 30 days' written notice, must not occur more than once per calendar year (except following a Personal Data Breach or as required by a supervisory authority), and must not disrupt the Services;
  • the auditor must sign a confidentiality agreement with us in a form we reasonably require;
  • we may satisfy audit requests with copies of any independent third-party audit reports or certifications we hold; and
  • each party bears its own costs unless an audit reveals a material breach of this DPA by us, in which case we will bear the reasonable costs of the audit.

15. International Transfers

Where we transfer Customer Personal Data outside the United Kingdom or the European Economic Area, we will ensure an appropriate transfer mechanism is in place first. Depending on the Sub-processor and destination country, this will be one of:

  • a UK or EU adequacy decision covering the destination country;
  • the UK International Data Transfer Agreement (IDTA) issued by the ICO;
  • the European Commission's Standard Contractual Clauses (Decision 2021/914) supplemented by the UK Addendum; or
  • the EU-US Data Privacy Framework or UK Extension where the recipient is certified.

By agreeing to this DPA you enter into, and authorise us to enter into on your behalf with Sub-processors, the relevant transfer instrument on the standard terms published by the issuing authority. Transfers are made under the mechanism identified for each Sub-processor on our Sub-processors page. Further details are set out in Annex II.

16. Liability

Each party's liability arising under or in connection with this DPA, whether in contract, tort (including negligence) or otherwise, is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under Applicable Data Protection Laws or other applicable law.

17. Term and Changes

This DPA takes effect on the date you accept the Terms of Service (or first use the Services) and continues for as long as we process Customer Personal Data on your behalf. Obligations that by their nature survive termination (including Sections 11, 13, 14, 15, and 16) continue to apply.

We may update this DPA from time to time. Where changes are material, we will notify you in advance by email and post the updated version on this page. Your continued use of the Services after the effective date constitutes acceptance of the updated DPA.

18. Governing Law

This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of its courts, in each case as provided in the Terms of Service.


Annex I: Details of Processing

List of Sub-processors: the current list is maintained at agrianta.com/subprocessors and is incorporated into this DPA by reference.

Subject matter, duration, nature and purpose, types of personal data, and categories of Data Subject: as set out in Section 5 of this DPA.

Frequency of processing: continuous, for as long as you use the Services.

Annex II: Transfer Mechanisms

For each Sub-processor located outside the United Kingdom and the European Economic Area, the transfer mechanism relied upon is as follows:

  • Stripe (United States): EU-US Data Privacy Framework (including UK Extension) and/or Standard Contractual Clauses with UK Addendum.
  • Resend (United States): Standard Contractual Clauses with UK Addendum.
  • OpenAI (United States):Standard Contractual Clauses with UK Addendum, together with OpenAI's Data Processing Addendum.
  • Anthropic (United States):Standard Contractual Clauses with UK Addendum, together with Anthropic's Data Processing Addendum.
  • Google (United States): EU-US Data Privacy Framework (including UK Extension) and/or Standard Contractual Clauses with UK Addendum, under the Google Maps Platform terms. Google renders maps in our mobile apps and receives the device IP address and the map area requested.

Sub-processors located in the United Kingdom or European Economic Area (Sentry, PostHog, Neon, Railway) do not require a transfer mechanism under this Annex. Transfers to the UK Livestock Information Service take place within the United Kingdom.

Annex III: Technical and Organisational Security Measures

We maintain technical and organisational measures appropriate to the risks presented by our processing of Customer Personal Data, including:

  • Encryption: TLS 1.2 or higher for data in transit; industry-standard encryption for data at rest in databases and object storage.
  • Access control: role-based access control, principle of least privilege, multi-factor authentication for administrative access, optional two-factor authentication (authenticator app with one-time backup codes) for user accounts, granular permissions for customer team-member access.
  • Network and application security: segregated environments, hardened infrastructure, secure development lifecycle, code review, dependency vulnerability scanning.
  • Monitoring and logging: application and security logging, anomaly detection, privileged-access audit trails (including impersonation).
  • Business continuity: regular encrypted backups and tested restoration procedures.
  • Personnel: confidentiality obligations and data protection training.
  • Incident response: documented incident response plan covering detection, containment, investigation, and notification of Personal Data Breaches.
  • Sub-processor due diligence: risk assessment and contractual controls for all Sub-processors.

Contact

Astraeus Technology Limited

Company Number: 15162283

Data protection enquiries: privacy@agrianta.com