This policy explains what personal data DeepLeaf handles, why, for how long, who else sees it, and how you can use your rights. It covers this website and the DeepLeaf Yield app.
Who is responsible
The controller of your personal data is DeepLeaf LLC, 6th Floor, TASMU Accelerator Hub, Ooredoo Main Building, Doha, Qatar. You can reach us at hello@deepleaf.io. Data protection officer: [DPO contact if any].
When a grower organization uses the app, it decides what its team records about its own farms. For that data DeepLeaf acts on the organization's behalf, as set out in the data processing agreement.
What we collect
When you request access
Organization name, contact name, email address, country, growing area, tomato type, an optional note, and the time you gave consent to be contacted.
When your organization uses the app
- the organization and its access keys (we store only a hash of each key, never the key itself);
- farms and greenhouses, including each greenhouse's location, rows and crop cycles;
- walks and their photos and videos, corrections, harvests, irrigation, climate readings, crop registration, crop plans, pick plans and forecasts;
- the billing account, invoices and usage.
Cookies and browser storage
DeepLeaf sets two cookies, both strictly necessary: deepleaf_key keeps you signed in (HttpOnly, SameSite=Strict, Secure over HTTPS, 30 days), and deepleaf_admin is used only by DeepLeaf operators for the operator console (8 hours). There are no analytics or third-party cookies, and our pages load nothing from other websites.
Your browser also keeps, on your device: your theme and language; an offline session (organization id, key name and role, never the key); the crop cycles you last opened, cleared when you sign out; walks waiting to upload; and a cache of the app's own files. See the cookie notice.
Logs
The app logs each request's method, path (without the query string), status, duration and a request id. It does not log headers, cookies, request bodies or IP addresses. The web server in front of the app keeps an access log that includes the client IP address, with key headers removed.
Why we use it, and on what legal basis
- To provide the service (accounts, walks, forecasts, plans, exports, billing): performance of our contract with your organization.
- To answer an access request and contact you about it: your consent, given on the form. You can withdraw it at any time.
- To keep the service secure and working (logs, backups, abuse prevention): our legitimate interest in running a reliable, safe service.
- To keep invoices and accounting records: legal obligation.
Forecast learning stays within each crop cycle unless the operator enables pooling. Your data is not used to train models for other customers unless [opt-in/agreement].
How long we keep it
- Access requests: the contact fields are erased 90 days after we decide on the request; the rest is removed with the organization.
- Organization data: for as long as the organization uses DeepLeaf, until it asks us to delete it.
- Backups: taken daily and kept 14 days on the server; off-server copies are kept for [Backup retention].
- Web server access log: rotated, at most 5 files of 20 MB each.
- Invoices: [Invoice retention period required by law].
Who receives it
We share personal data only with service providers that help us run DeepLeaf, each limited to what it needs:
- a cloud hosting provider, which runs our servers and stores the data and backups;
- a payment processor: card payments happen on its hosted payment page, so card details never reach DeepLeaf servers;
- a banking provider, for bank transfers;
- a weather data service, which receives only each greenhouse's latitude and longitude;
- an email provider, for messages we send you.
We do not sell personal data.
International transfers
Some of these providers may process data outside your country or the European Economic Area. Where that happens, we rely on [Transfer mechanism].
Your rights
You have the right to access your data, to receive it in a portable format, to have it corrected or erased, to restrict or object to its processing, and to withdraw consent. How to use them:
- Access and portability: an organization admin can download a zip export of the organization's data from the app, optionally including walk media.
- Rectification: most records can be corrected directly in the app; for anything else, write to us.
- Erasure: ask us to delete the organization. We first take a backup, then remove all its records, keys and media. We keep one audit record (organization id, counts, time) to show the deletion happened.
- Restriction, objection, withdrawing consent: write to us at the address below.
You may also complain to a data protection supervisory authority, in particular in the country where you live or work.
Security
All traffic uses HTTPS. Access keys are stored only as hashes. Each organization's data is kept separate from every other organization's. Data is backed up daily.
Children
DeepLeaf is a service for businesses and is not meant for anyone under 16.
Changes
When this policy changes, we update this page and the date below, and tell organizations of significant changes before they apply. Last updated: [Date].
Contact
Questions or requests about your data: hello@deepleaf.io.