Data Processing Agreement (DPA)

Last updated: 2026

This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between the Customer (“Controller”) and AgriProof (“Processor”). It sets out the terms under which AgriProof processes personal data on behalf of the Controller in accordance with UK GDPR and the Data Protection Act 2018.

1. Purpose

AgriProof processes personal data solely for the purpose of providing satellite‑based verification services requested by the Controller or its clients.

2. Roles

  • The Customer is the Data Controller.
  • AgriProof is the Data Processor.

3. Types of Data Processed

AgriProof may process the following categories of personal data:

  • Contact details (name, email address, phone number)
  • Farm or land information provided by the Controller
  • Any information submitted when requesting a report

AgriProof does not intentionally process special category data unless explicitly provided by the Controller.

4. Processor Obligations

AgriProof shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure that persons authorised to process personal data are bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Assist the Controller in fulfilling its obligations under UK GDPR
  • Delete or return personal data upon request or at the end of the engagement, unless retention is required by law

5. Sub‑Processors

AgriProof may engage sub‑processors such as:

  • Hosting providers
  • Email and communication service providers
  • Analytics providers

All sub‑processors are bound by data protection obligations no less protective than those in this Agreement.

6. International Transfers

AgriProof does not transfer personal data outside the UK unless adequate safeguards are in place and such transfers comply with UK GDPR.

7. Data Retention

Personal data is retained only for as long as necessary to provide services, maintain records, or comply with legal obligations.

8. Security Measures

AgriProof implements appropriate technical and organisational measures to protect personal data, including secure hosting, access controls, and encryption in transit where appropriate.

9. Assistance with Data Subject Rights

AgriProof will assist the Controller, where reasonably possible, in responding to requests from data subjects exercising their rights under UK GDPR.

10. Data Breach Notification

In the event of a personal data breach, AgriProof will notify the Controller without undue delay after becoming aware of the breach and provide relevant information to support any required notifications.

11. Governing Law

This Agreement is governed by the laws of England and Wales and interpreted in line with UK GDPR.

12. Contact

For questions about this Agreement, contact: hello@agriproof.co.uk

© 2026 AgriProof. All rights reserved.

Scroll to Top