Data Processing Agreement (DPA)
Last updated: 2026
This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between the Customer (“Controller”) and AgriProof (“Processor”). It sets out the terms under which AgriProof processes personal data on behalf of the Controller in accordance with UK GDPR and the Data Protection Act 2018.
1. Purpose
AgriProof processes personal data solely for the purpose of providing satellite‑based verification services requested by the Controller or its clients.
2. Roles
- The Customer is the Data Controller.
- AgriProof is the Data Processor.
3. Types of Data Processed
AgriProof may process the following categories of personal data:
- Contact details (name, email address, phone number)
- Farm or land information provided by the Controller
- Any information submitted when requesting a report
AgriProof does not intentionally process special category data unless explicitly provided by the Controller.
4. Processor Obligations
AgriProof shall:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorised to process personal data are bound by confidentiality
- Implement appropriate technical and organisational security measures
- Assist the Controller in fulfilling its obligations under UK GDPR
- Delete or return personal data upon request or at the end of the engagement, unless retention is required by law
5. Sub‑Processors
AgriProof may engage sub‑processors such as:
- Hosting providers
- Email and communication service providers
- Analytics providers
All sub‑processors are bound by data protection obligations no less protective than those in this Agreement.
6. International Transfers
AgriProof does not transfer personal data outside the UK unless adequate safeguards are in place and such transfers comply with UK GDPR.
7. Data Retention
Personal data is retained only for as long as necessary to provide services, maintain records, or comply with legal obligations.
8. Security Measures
AgriProof implements appropriate technical and organisational measures to protect personal data, including secure hosting, access controls, and encryption in transit where appropriate.
9. Assistance with Data Subject Rights
AgriProof will assist the Controller, where reasonably possible, in responding to requests from data subjects exercising their rights under UK GDPR.
10. Data Breach Notification
In the event of a personal data breach, AgriProof will notify the Controller without undue delay after becoming aware of the breach and provide relevant information to support any required notifications.
11. Governing Law
This Agreement is governed by the laws of England and Wales and interpreted in line with UK GDPR.
12. Contact
For questions about this Agreement, contact: hello@agriproof.co.uk
© 2026 AgriProof. All rights reserved.
