Data Processing Agreement
This agreement applies from 1 November 2026.
1. What this agreement is, and when it applies
This Data Processing Agreement ("DPA") is between you ("you", "the Customer") and AGRIVALE LIMITED, company number 824192, Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland ("AgriVale", "we", "us").
It forms part of the Terms of Service and applies automatically from the date you accept those terms. There is nothing to sign and nothing to request.
It applies in one situation only: where you keep, in your AgriVale account, personal data about other people, and you are the controller of that data. Then you are the controller and we are your processor, and Article 28 of the GDPR requires the terms below.
Examples of what this DPA covers:
- a farmer's account, where an employee, a family member, a contractor, a supplier or a customer is named — in a task, a note, a message, on a receipt or on a bank line;
- an advisor's account, where the advisor holds their client book: their clients' names, businesses, mobile numbers, email addresses, counties, herd numbers and the advisor's own notes about them, together with their tasks, notes, key dates, projects, time entries, invoices and documents for those clients.
2. What this agreement does not cover
This DPA does not apply to the personal data for which AgriVale is the controller. For that data we decide what is collected and why, this DPA's obligations do not fit, and the Privacy Policy governs instead. It includes:
- your own account, name, mobile number, email address and sign-in records;
- security, fraud prevention, abuse defence and our audit trails;
- support you ask us for;
- operating and improving AgriVale;
- billing, if and when we start charging.
We are not your processor for that data and we do not describe ourselves as one. Where this DPA and the Privacy Policy would apply to the same processing, this DPA governs our processor role only.
This DPA also does not make us a processor for an advisor's processing of a farmer's data. An advisor who uses AgriVale is an independent controller of their own client records, and is the Customer under this DPA for those records.
3. Words used here
| Term | Meaning |
|---|---|
| GDPR | Regulation (EU) 2016/679, and the Data Protection Act 2018 where it applies |
| Customer Personal Data | Personal data about other people that you put into, or generate in, your AgriVale account, and for which you are the controller |
| Data Subject | The person the Customer Personal Data is about |
| Sub-processor | A third party we engage to process Customer Personal Data on our behalf |
| Personal Data Breach, controller, processor, processing, supervisory authority | As defined in the GDPR |
4. Subject matter, duration, nature, purpose, data and data subjects
This section is the description Article 28(3) requires.
| Subject matter | Our provision of the AgriVale service to you under the Terms of Service |
| Duration | For as long as you hold an AgriVale account, and afterwards only as section 13 allows |
| Nature and purpose | Hosting, storing, organising, retrieving, transmitting, backing up, displaying, indexing and — where you use those features — extracting information from documents, transcribing audio, classifying transactions and generating summaries, all for the purpose of providing AgriVale to you |
| Types of personal data | Names; business names; mobile numbers; email addresses; addresses, counties and Eircodes; herd numbers; free-text notes; the content of documents, receipts, invoices and bank statements, including supplier and customer names and bank account-holder names; the content of messages and voice notes; photographs; calendar event titles, locations and times; dates, amounts and other transactional details |
| Categories of data subject | Your employees, family members and farm workers; your contractors, suppliers and customers; your advisor's clients and their representatives; anyone named in a document, message or note you hold |
| Special category data | AgriVale is not designed for special category personal data and you should not put it in. If you do, you remain responsible for having an Article 9 condition for it |
5. Our obligations, in outline
We will process Customer Personal Data only on your documented instructions, including for transfers outside the EEA, unless we are required to do otherwise by EU or Irish law — in which case we will tell you before processing, unless that law forbids it on important grounds of public interest.
Your instructions are: this DPA, the Terms of Service, and your use of AgriVale's features and settings. If we think an instruction breaches data protection law, we will tell you.
We will not sell Customer Personal Data, share it for anyone else's marketing, or use it for our own purposes beyond providing, securing, supporting and improving AgriVale as the Terms of Service describe.
We do not use Customer Personal Data to train artificial-intelligence models, and our AI sub-processor does not use content submitted through its API to train its models, under the terms and settings that apply to our account.
6. Confidentiality
We make sure that everyone authorised to process Customer Personal Data is under an appropriate duty of confidentiality, whether by contract or by law, and that access is limited to those who need it to do their job.
7. Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as Article 32 requires. Taking account of the state of the art and the risks involved, these include:
- encryption of personal data in transit and at rest;
- access controls that keep each farm's and each advisor's data separate from every other customer's;
- uploaded files held in private storage, reachable only through authenticated, time-limited links;
- one-time codes rather than passwords for farmer sign-in, and an additional verification step before submissions to the Department;
- logging of sensitive actions, so that access can be reconstructed;
- routine encrypted backups, so that availability and access can be restored after an incident;
- review of these measures as the service changes.
We do not publish the detail of our security configuration, because publishing it would weaken it. We will describe our measures to you in reasonable detail on request under section 14.
8. Sub-processors
You give us a general written authorisation to engage sub-processors.
The current list is published, and kept up to date, on the Subprocessors page. It names each sub-processor, its legal entity, what it does, what data it receives, where it processes and the transfer safeguard.
When we intend to add or replace a sub-processor, we will update that page and give at least 30 days' notice before the new sub-processor begins processing Customer Personal Data. You can subscribe to changes at info@agrivale.ie.
You may object on reasonable data-protection grounds within 30 days of that notice. If you do, we will work with you in good faith to find a resolution — a different provider, a change to the processing, or a way of using AgriVale that avoids the sub-processor. If we cannot resolve it, you may terminate the affected part of the service by giving us written notice, and stop using it, without penalty. Any charge already paid for a period after termination will be refunded proportionately.
Where we engage a sub-processor we impose data protection obligations on it that are no less protective than those in this DPA, and we remain fully liable to you for its performance.
9. Helping you answer people's requests
Taking account of the nature of the processing, we will help you meet your obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR — access, rectification, erasure, restriction, portability and objection.
Most of that help is in the product: you can search, view, correct, export and delete Customer Personal Data in your account yourself. Where the product cannot do it, email us at info@agrivale.ie and we will assist by appropriate technical and organisational measures, so far as is possible.
If a Data Subject contacts us directly about data you control, we will not respond substantively. We will tell them to contact you, and tell you promptly — unless we are prohibited from doing so.
10. Helping you with security, breaches and impact assessments
Taking account of the nature of the processing and the information available to us, we will help you comply with your obligations under Articles 32 to 36 of the GDPR — security, breach notification to the supervisory authority and to Data Subjects, data protection impact assessments, and prior consultation.
11. Personal data breaches
If we become aware of a Personal Data Breach affecting Customer Personal Data, we will notify you without undue delay.
The notification will describe, as far as we know it at the time: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures we have taken or propose to take, including to mitigate any adverse effects; and a contact point for more information. Where we cannot give all of it at once, we will give it in phases as it becomes available, without further undue delay.
You are responsible for deciding whether to notify your supervisory authority and the Data Subjects, and for making any notification you must make as controller.
12. Records
We keep a record of the categories of processing carried out on your behalf, as Article 30(2) requires, and will make it available to you on request.
13. Deletion and return at the end
Your choice at the end of the service. When you stop using AgriVale, you choose whether we delete Customer Personal Data or return it, and we will do as you choose, unless EU or Irish law requires us to keep it.
In practice:
- Export it first. AgriVale provides exports you can download or share — a receipts-and-documents ZIP, a money-out CSV, farm accounts as a PDF, a printable compliance report, a milk and weights CSV, and a Bord Bia audit report from the phone. Each covers what it says and no more; none is a complete copy of everything held. You can also ask us for a copy under section 9.
- Then delete. When you close a farm account, the farm and everything in it is deleted from our live systems straight away, and the uploaded files with it. It cannot be undone. When an advisor deletes their advisor account, the advisor's client book and working records are deleted with it.
- Backups. Our routine encrypted database backups are not edited record by record. Deleted data leaves them as they are overwritten, within 7 days. The files you upload are not held in those database backups at all — they are deleted from storage. While they exist, backups are protected to the same standard as live data.
- What we keep, and why. We retain a limited set of records where the GDPR permits it: a minimal record that a deletion happened, which holds no personal data in the clear; reduced security and audit records; the advisor authorisation trail; and records needed to establish, exercise or defend a legal claim, or to comply with a legal obligation. The Privacy Policy gives the periods.
- A farmer's request about an advisor's records. An advisor is an independent controller of their own client records. We will not delete them on a farmer's instruction. We will pass the request to the advisor and tell the farmer we have.
14. Information and audits
We will make available to you the information necessary to demonstrate our compliance with Article 28 and with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
So that this is workable for both of us:
- Information first. We will answer a reasonable written request with the information we hold — our security measures, our sub-processors, our records of processing, and any third-party certification or audit report our providers make available to us. In most cases this will satisfy the obligation.
- An audit may be requested where the information provided does not reasonably answer your question, where you have suffered a Personal Data Breach affecting your data, or where a supervisory authority or the law requires one.
- How an audit runs. Not more than once in any 12 months, except after a Personal Data Breach or where a supervisory authority requires it; on at least 30 days' written notice; during business hours; without unreasonable disruption to our business; subject to confidentiality; and not extending to another customer's data, to our other customers' systems, or to information whose disclosure would breach a duty we owe someone else.
- On-site inspection only where the law or a supervisory authority requires it, or where the steps above have not resolved a specific and substantiated concern.
- Cost. You bear your own costs and our reasonable costs of supporting an audit, except where the audit reveals a material breach of this DPA by us, in which case we bear our own.
15. International transfers
You instruct us to process and transfer Customer Personal Data as necessary to provide AgriVale, including to the sub-processors named on the Subprocessors page and to the countries stated there.
Your AgriVale database and uploaded files are hosted with Supabase on Amazon Web Services infrastructure in Ireland (AWS region eu-west-1). That does not mean nothing leaves the EEA: some providers, and some providers' support and sub-processors, are outside it.
Where Customer Personal Data is transferred outside the EEA to a country without an adequacy decision, the transfer is made under the Standard Contractual Clauses approved by the European Commission, with the module appropriate to the relationship, together with the additional measures those clauses require. Switzerland and the United Kingdom have adequacy decisions.
We will, on request, give you the information we have about the safeguards applying to a particular transfer, and help you carry out a transfer impact assessment so far as is possible.
16. Your responsibilities as controller
You are responsible for:
- having a lawful basis for the Customer Personal Data you put into AgriVale, and for telling the people concerned what you do with it;
- the accuracy, quality and legality of that data and of your instructions;
- configuring AgriVale appropriately — in particular, choosing what to share with an advisor, and with whom you share access to your farm;
- keeping your account secure, including who you allow to use it;
- responding to Data Subjects' requests about data you control;
- your own retention decisions while your account is open.
You confirm that your instructions comply with data protection law, and that you have given any notice and obtained any consent your own processing requires.
17. Liability, and how this fits with the rest
The limits and exclusions of liability in the Terms of Service apply to this DPA as well, to the extent the law allows, and the total cap there is a single combined cap across the Terms of Service and this DPA. Nothing here limits either party's liability to a Data Subject or to a supervisory authority, or any liability that cannot lawfully be limited.
If this DPA conflicts with the Terms of Service, this DPA governs for the processing it covers. If this DPA conflicts with the Standard Contractual Clauses, the Clauses govern.
18. Changes to this agreement
We may update this DPA — for example to reflect a change in the law, in guidance, or in how AgriVale works. We will publish the new version here with a new version number and effective date, and will give you reasonable notice of a change that materially affects your rights or our obligations. Where the change requires it, we will ask you to accept it.
19. Duration and termination
This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Personal Data for you. Sections 6, 11, 13, 14, 15 and 17 continue to apply after it ends, for as long as they are relevant.
20. Governing law
This DPA is governed by the law of Ireland, and the courts of Ireland have jurisdiction, on the same basis as section 29 of the Terms of Service.
21. Contact
AGRIVALE LIMITED Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland Company number 824192 info@agrivale.ie
Registered office: Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland
info@agrivale.ie
The rest of the shelf
