DeepLeaf Yield DeepLeaf Yield
Legal

Data processing agreement

This page summarizes the Data Processing Addendum (DPA) between your organization and DeepLeaf. It explains who is responsible for which data, how DeepLeaf protects it, and what happens when the service ends. The signed DPA is the binding text; this summary does not replace it.

Roles

  • Your organization is the controller of the farm data you put into DeepLeaf: greenhouses, crop cycles, walks (videos, images and counts), harvest and climate records. DeepLeaf is your processor for that data.
  • DeepLeaf is the controller of the account and billing data it needs to run your subscription: the organization's name, billing contact, plan, invoices and payments.

Subject matter, duration, nature and purpose

  • Subject matter: providing the DeepLeaf Yield service: scoring greenhouse walks, counting fruit, and forecasting harvests.
  • Duration: for as long as your organization uses the service, then until deletion as described below.
  • Nature: storing, analysing, displaying and exporting the data, and keeping backups of it.
  • Purpose: only to provide the service to your organization, and to support and secure it.

Data and the people it concerns

  • Mostly farm operational data: greenhouse layout and location, crop cycles, walk videos and images of plants, fruit counts, harvest weights, and climate readings.
  • A little personal data: the names and work email addresses of your staff, given in access requests and attached to access keys.
  • Data subjects: your staff and other people you authorize to use DeepLeaf.

DeepLeaf is not designed for sensitive categories of personal data. Please do not upload them.

Instructions and confidentiality

  • DeepLeaf processes your data only on your documented instructions: the agreement, this DPA, and what you do in the app. If an instruction seems to break data protection law, DeepLeaf will tell you.
  • Everyone at DeepLeaf who can access your data is bound by confidentiality and accesses it only when needed to run or support the service.

Security measures

  • All traffic uses HTTPS.
  • Access keys are stored only as hashes. DeepLeaf cannot read your key back.
  • Every request is checked against your organization: one organization can never see or change another's data.
  • Requests that change data are protected against cross-site requests from other websites.
  • Request logs leave out keys, cookies, request bodies and IP addresses.
  • Backups are taken daily and kept for 14 days.
  • The model files that score walks are checked against checksums before use.
  • Upload sizes are limited.

Sub-processors

DeepLeaf uses a small number of sub-processors, by category: hosting, payment processing, banking, and weather data (which receives only your greenhouse's coordinates). Each is bound by data protection terms at least as protective as this DPA.

DeepLeaf will give you notice [Notice period] before adding or replacing a sub-processor. You may object on reasonable data protection grounds; if we cannot resolve the objection, you may end the affected service.

Your requests and your people's rights

  • Your organization's admin can export all its data from the app at any time.
  • DeepLeaf deletes data on request, and helps you answer requests from your staff to access, correct or delete their data.

Personal data breaches

If DeepLeaf becomes aware of a personal data breach affecting your data, it will tell you without undue delay, and within [Hours] hours, with what it knows and what it is doing about it.

End of service

When the service ends, you can export your data first. DeepLeaf then deletes your organization's data, including walk videos and images. Copies in backups age out within 14 days, plus [Off-site backup retention] for off-site backup copies.

Audits and transfers

  • Audits: [Audit terms].
  • International transfers: if data leaves your region, DeepLeaf relies on [Transfer mechanism].

Signing the full DPA

To receive and sign the full DPA, write to hello@deepleaf.io.