Back to Agrianta

Privacy Policy

Last updated 23 July 2026

Introduction

Astraeus Technology Limited ("we", "us", "our", or "Agrianta"), registered in England and Wales under company number 15162283, is the data controller for personal data processed through our website at agrianta.com, our farm management web application, and our iOS and Android apps (together, the "Services"). This policy explains what we collect, why, who we share it with, and what rights you have.

Who This Policy Applies To

We process personal data about farm users (farmers, farm managers, and farm workers), veterinarians and advisors given access to farm data, website visitors, people who enquire about the Services, and our business partners and suppliers.

Information We Collect

Information you provide directly

  • Account information: name, email address, phone number, organisation name
  • Authentication data: a password if you choose password sign-in, and, if you enable two-factor authentication, the authenticator-app (TOTP) secret and one-time backup codes
  • Farm data: farm location, herd information, livestock records, compliance logs, drug records, and withdrawal dates
  • Sensor and device data from connected collars, tags, boluses, readers, cameras, and environmental monitors
  • Livestock photographs you upload for record-keeping or for ear-tag and passport recognition
  • Scout AI inputs: questions, prompts, and context you submit to our AI features
  • Communications you send us by contact form or email
  • Payment information: name, email, billing address, and invoice history. Card details go straight to our payment provider and never reach our servers.

Information collected automatically

  • Device information: browser type, operating system, device type, and for the mobile apps the app version, OS version, and crash reports
  • Usage data: pages visited, features used, time spent on pages
  • Session data: signing in sets a session cookie (Secure, SameSite=Lax) shared across *.agrianta.com subdomains to keep you signed in
  • IP addresses: your IP address is processed whenever you use the Services. We store it against sign-in sessions and privileged-access audit records, and our analytics and error-monitoring providers receive it with the events they collect. We use it to secure accounts, detect fraud, and derive a coarse country-level location. We do not use it to build advertising profiles, but it is shared with Meta and Google if you accept marketing cookies.
  • Analytics data collected via PostHog, hosted in the European Union

Information collected by our mobile apps

Our apps request only the permissions they need, and you can grant or revoke each one in your device settings: the camera, to scan ear tags and cattle passports and photograph records; your photo library, to attach existing photos; foreground location, to show your position on the farm map; Bluetooth, to connect to EID tag readers and weigh heads; and Face ID, Touch ID, or fingerprint to unlock the app, which your device handles and never sends to us. The apps do not use background location. Per-permission detail is also in our App Store and Google Play listings, which we keep current as the apps change.

The apps cache data on your device so you can keep working without a signal. Sign-in credentials are held in the device's secure store; the rest of the cache is ordinary app storage, protected by your device passcode and removed when you uninstall. We use Sentry for crash reporting and session replay, which masks text and images by default. Maps are rendered by Google Maps. The apps do not use cookies.

How We Use Your Data and Our Legal Basis

Under UK GDPR we process your personal data for these purposes, on these legal bases:

  • Providing the Services: running your account, your farm data, and our livestock, compliance, and AI insight features. Basis: performance of our contract with you.
  • Support and service messages: answering enquiries and sending service notices. Basis: contract, and our legitimate interest in running the Services.
  • Security and fraud prevention: detecting abuse, securing accounts, and keeping audit records. Basis: legitimate interests.
  • Improving the Services: understanding how features are used. Basis: consent where the law requires it for analytics, otherwise legitimate interests.
  • Legal and regulatory compliance: including tax and accounting records. Basis: legal obligation.
  • Marketing and advertising measurement: telling you about new features, and measuring whether our advertising leads to sign-ups. Basis: your consent.

AI-Powered Features

Some features of the Services are powered by third-party AI models:

  • Scout AIuses OpenAI's language models to answer questions about your farm. We send your prompt and relevant farm and livestock context to OpenAI (hosted in the United States) for inference. To make your records searchable, we also send selected records to OpenAI's embeddings endpoint; the resulting vectors are stored in our own database and OpenAI does not retain the original text.
  • Livestock image recognitionuses Anthropic's Claude Vision to read ear tags, passports, and similar documents from photographs. Images are transmitted to Anthropic (hosted in the United States) and are not retained after the result is returned.

We use API tiers with both OpenAI and Anthropic that do not permit your inputs, outputs, or livestock images to be used to train their foundation models. Both transfers to the United States rely on the safeguards described under "International Data Transfers" below.

AI output is a decision-support tool, not veterinary or professional advice; see section 8 of our Terms of Service.

Under Article 22 UK GDPR you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. The Services make no such decisions. AI insights and alerts are suggestions, and human judgement stays in the loop for every material decision about animal care, compliance, and farm management.

Cookies and Analytics

We use cookies on our website. You set your preferences in the consent banner shown on your first visit, and our Cookie Policy lists each cookie. Essential cookies keep you signed in and the site secure. Analytics cookies (PostHog) show us how the site is used. Marketing cookies (the Meta Pixel and the Google Ads tag) are set only if you accept them.

PostHog is hosted in the European Union. Where the law requires prior consent, such as in the EEA, nothing is measured until you accept. Elsewhere we measure basic, cookieless usage from your first visit, and session recording and surveys run only once you accept. The events we send carry no user names or email addresses, but they do carry your IP address, which PostHog uses to derive a country-level location.

With your consent we use the Meta Pixel and Meta's Conversions API, and the Google Ads tag, to see whether our advertising leads to sign-ups. Meta Platforms Ireland Limited receives a hashed (irreversibly encoded) version of your email address, a hashed account identifier, Meta's cookie identifiers, your IP address, and your browser type. Google receives its own cookie identifiers, your IP address, and your browser type. Neither receives farm data, animal records, or anything you do inside the product. If you do not accept marketing cookies, no advertising data is collected or shared.

Payment Processing

Card payments are handled by Stripe. Card details go straight from your browser to Stripe and never touch Agrianta's servers. We receive a token for the saved payment method plus invoice metadata (amount, description, date). See our Sub-processors page for details.

How We Share Your Information

We do not sell your personal data. We may share it with:

Sharing you control

  • Veterinarians and advisors: you can grant veterinary practices and agricultural advisors access to your farm data, which shares the contact details needed to connect. You can revoke access at any time in your account settings.
  • Team members: colleagues and farm workers you invite to your organisation see shared farm data according to the permissions you set.
  • UK Livestock Information Service (LIS): if you connect your LIS account, we transmit CPH number, animal IDs, and movement records to LIS on your behalf for statutory compliance reporting. Each transfer is authorised by the OAuth credentials you provide, which you can revoke at any time.

Sharing for service delivery

  • Sub-processors: third parties who help us operate the Services, covering cloud hosting, payment processing, transactional email, error monitoring, product analytics, and AI inference. The current list is at agrianta.com/subprocessors.
  • Professional advisers: lawyers, accountants, and auditors where necessary
  • Law enforcement: when required by law or to protect our legal rights
  • Business transfers: in connection with a merger, acquisition, or sale of assets

All sub-processors must protect your data and process it only on our instructions. Business customers processing personal data about others, such as staff or farm workers, are covered by our Data Processing Addendum.

Data Retention and Deletion

We keep personal data only as long as we need it:

  • Account, farm, and livestock data: while your account and your organisation are active
  • Product analytics (PostHog): up to 12 months
  • Error monitoring (Sentry): up to 90 days
  • Privileged-access audit logs, including IP addresses: up to 2 years
  • Billing and financial records: 6 years, to meet UK tax obligations, relying on the legal-obligation exemption in Article 17(3)(b) UK GDPR
  • Encrypted backups: deleted data may persist for up to 30 days before it is overwritten

You can delete your account yourself at any time from your account settings, which erases or anonymises your personal data immediately. We keep an append-only erasure receipt, your user ID and a timestamp, as proof that the erasure happened. Closing an organisation starts a 30-day recovery window, after which its data is permanently deleted; the owner is emailed an export first. The full mechanics, including what we keep after deletion, are set out in section 13 of our Data Processing Addendum.

Your Rights

Under UK GDPR you have the following rights over your personal data:

  • Access: request a copy of the personal data we hold about you
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your personal data in certain circumstances. We honour this through the self-service account-deletion and organisation-closure flows described above.
  • Restriction: request that we limit how we use your data
  • Portability: request your data in a machine-readable format. Owners closing an organisation are emailed an export of its records.
  • Objection: object to processing based on legitimate interests, or to direct marketing
  • Withdrawing consent: withdraw consent at any time where processing is based on consent
  • Automated decision-making:under Article 22 UK GDPR, not to be subject to solely automated decisions with legal or similarly significant effects (see "AI-Powered Features" above)

To exercise any of these rights, contact us at privacy@agrianta.com. We will respond within one month.

Data Security

We use technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, staff training on data protection, and incident response procedures.

Sign-in is handled first-party by Agrianta's own API; we do not use a third-party identity provider. Password sign-in requires a verified email address, passwords must be at least 12 characters, and changing your password signs you out of all other sessions. You can enable two-factor authentication using an authenticator app (TOTP) with one-time backup codes. Account emails, including verification, magic sign-in links, password resets, and data-export links, are sent through Resend and use short-lived links.

If we become aware of a personal data breach affecting you, we will notify you without undue delay, and, where we act as a processor for a business customer, in time for you to meet your own 72-hour obligation to the ICO. Further detail is in our Data Processing Addendum.

International Data Transfers

Your data is primarily stored and processed in the United Kingdom and European Economic Area. Some sub-processors, notably Stripe, Resend, OpenAI, and Anthropic, are in the United States.

Where we transfer data outside the UK or EEA we put appropriate safeguards in place, typically the UK International Data Transfer Agreement, Standard Contractual Clauses supplemented by the UK Addendum, or the EU-US Data Privacy Framework including the UK Extension. Our Sub-processors page lists each sub-processor and its location; our Data Processing Addendum sets out the transfer mechanism used for each.

Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

Changes to This Policy

We may update this policy from time to time. We will tell you about significant changes by posting a notice on our website or emailing you.

Complaints

If you are unhappy with how we have handled your personal data, you can lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by phone on 0303 123 1113. We would appreciate the opportunity to address your concerns first.

Contact Us

If you have questions about this policy, please contact us:

Astraeus Technology Limited

Company Number: 15162283

Email: privacy@agrianta.com

For general enquiries, visit our Contact page.