Legal
Privacy notice
What we collect, why we collect it, how long we keep it, and the control you keep over your farm data.
Last updated 10 August 2026
This notice describes AgriRisk Limited's own practices. It is written to be read by a working farmer, not a lawyer. Where a term has a specific legal meaning under the UK GDPR and the Data Protection Act 2018, we use it in that sense.
01Who we are
AgriRisk Limited is a company registered in England and Wales and is the data controller for the personal data described in this notice. Written enquiries and data protection requests go to privacy@agririsk.co.uk.
02Data we collect
Account data — name, email address, account type (farmer or adviser), tier and authentication identifiers. Where you sign in with Google we receive your name, email address and account identifier from that provider; we never receive your Google password.
Farm business data — farm name, region, area, enterprises, opening balance and facility limits, risk register entries, expected receipts and payments, alerts and the decisions you record against risks.
Audit data — an immutable record of risk decisions (accept, defer, dismiss), the reason you gave, and the time it happened. This record exists so you can evidence your own governance to a lender, accountant or adviser.
Enquiry data — anything you submit through the discovery call form.
Technical data — operational logs needed to keep the service secure and available.
03Why we use it and our lawful basis
To provide the service you have asked for — risk monitoring, cash flow projection, alerts, health scoring and reporting — on the basis of performance of a contract.
To keep the platform secure, prevent abuse, and improve the accuracy of our models in aggregate, on the basis of our legitimate interests in running a safe and useful service, balanced against your interests.
To respond to enquiries and, where you have asked for them, to send you sector briefings, on the basis of your consent, which you may withdraw at any time.
To meet accounting, tax and regulatory record-keeping duties, on the basis of legal obligation.
04We do not sell your farm data
We do not sell, rent or licence identifiable farm data, and we do not share it with input suppliers, buyers, insurers or lenders. Where an adviser has access to your farm, it is because you or they created that link in the workspace, and either party can remove it.
05Processors and where data is held
We use a small number of processors to run the platform: cloud hosting and database, managed authentication, and email delivery. Each is bound by a written processing agreement, may only act on our instructions, and may not use your data for their own purposes.
Where a processor operates outside the UK, transfers are covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards.
06How long we keep it
Farm data is retained for the retention window attached to your tier while your account is active. If you close your account, you may export your risk register, audit trail, cash flow projection and health score history first; we then delete or irreversibly anonymise farm data within 90 days, except records we must keep for accounting or legal purposes.
Enquiry records are kept for 24 months from the last contact.
07Your rights
You have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent where consent is the basis. We respond to requests within one month.
We do not make decisions producing legal or similarly significant effects about you by automated means. Risk scores and suggested actions are decision-support only; every decision stays with you.
If you are unhappy with how we have handled your data, you may complain to the Information Commissioner's Office at ico.org.uk. We would rather you raised it with us first.
08Security
Access to farm data is enforced at the database level so a signed-in user can only reach farms they own or have been explicitly granted. Data is encrypted in transit and at rest by our hosting provider, access to production is limited to the people who need it, and audit records are insert-only.
Our security and trust page sets out the current posture and what is still in build.
09Changes
We will update this notice when the service changes. Material changes are notified by email or in the workspace before they take effect.