How Grovabe handles your personal data
This Policy explains how Grovabe Ltd collects and uses personal data when you visit, create an account, use the Service, contact us or receive communications from us. It should be read with the Cookie Policy and Terms and Conditions.
On this page
- Who we are
- Personal data we collect
- How we obtain data
- Purposes and lawful bases
- AI processing
- Location, photographs and regional insights
- Recipients and service providers
- International transfers
- Retention
- Security
- Your rights
- Marketing and notifications
- Children
- Cookies and similar technologies
- Changes and contact
1. Who we are
Grovabe Ltd (company number 17353027), of 66 Paul Street, London, EC2A 4NA, is the controller for the processing described in this Policy. ICO registration number: ZC207423. Contact: support@grovabe.com. Data protection lead: Nsama Chibulu, Director.
2. Personal data we collect
Account and identity data: name, email address, account identifiers, encrypted or hashed credentials, authentication and multi-factor authentication information.
Profile and growing data: farm or growing profile, town or village, approximate coordinates, Modules, fields, batches, varieties, planting and harvest information, livestock records, tasks, readings, vaccinations, treatments, expenses, sales and other operational records.
User Content and photographs: prompts, messages, feedback, support communications, photographs and associated metadata. Photographs may incidentally show people or identifying surroundings; users should avoid this where unnecessary.
AI interaction data: inputs, outputs, model and feature information for Farma, reports, identification and other AI Features.
Payment and subscription data: plan, billing status, payment reference, transaction and tax information. Payment providers normally retain full card or payment credentials.
Device, usage and security data: IP address, device and browser type, app version, identifiers, session and authentication data, logs, timestamps, diagnostics, security events and consent records.
Marketing and preference data: marketing/community choices, notification settings, unsubscribe records and communications preferences.
Third-party data supplied by Business Users: for example buyer or contact names recorded by a Business User. For this data, the Business User may be controller and Grovabe processor.
3. How we obtain data
We collect data directly from you; automatically from your device and use of the Service; generate it from your inputs; receive it from payment providers, app stores, authentication and technical providers; and obtain location, weather, mapping, disease-zone and similar information from public or third-party sources. If you provide another person's data, you must be entitled to do so and give them any required privacy information.
4. Purposes and lawful bases
| Purpose | Lawful basis | Main data |
|---|---|---|
| Provide accounts and the Service | Contract; legitimate interests where the user is acting for a business | Account, profile, operational, location, User Content, device data |
| Provide AI Features | Contract; legitimate interests in operating requested business features | Growing data, prompts, photographs, AI interactions |
| Payments, subscriptions and accounting | Contract; legal obligation; legitimate interests in debt and fraud prevention | Identity, payment, subscription, device data |
| Security, fraud prevention and service integrity | Legitimate interests; legal obligation where applicable | Account, IP, device, logs and security data |
| Support and service communications | Contract; legitimate interests | Identity, account, support and communications data |
| Improve, test and develop the Service | Legitimate interests, subject to balancing and safeguards; consent where required | Usage and diagnostics data; User Content only where separately justified and disclosed |
| Regional statistics and insights | Legitimate interests in providing aggregated insights | Approximate location and operational data; published only following contextual anonymisation assessment |
| Weather, mapping and official disease-zone checks | Contract; legitimate interests in supplying requested features and promoting safety | Approximate coordinates and relevant Module data |
| Marketing and community messages | Consent for electronic marketing where required; legitimate interests for permitted business marketing | Name, email, preferences and engagement data |
| Legal compliance and claims | Legal obligation; recognised or ordinary legitimate interests as applicable | Relevant records and communications |
Where we rely on legitimate interests, our interests include operating, securing, improving and protecting Grovabe and providing useful grower services. You may object, and we will consider your circumstances. We do not rely on "public interest" merely because a feature concerns animal disease; disclosures to public authorities will be assessed under the applicable lawful basis.
5. AI processing
Relevant prompts, growing records and photographs are sent to Anthropic through its Claude API to produce requested outputs. Anthropic processes this information in the United States. Grovabe does not develop or operate its own AI model and does not use your inputs or outputs to train an AI model. Anthropic's Commercial Terms state that it may not train models on customer content submitted through its commercial services. Anthropic's published information also states that API inputs and outputs are not used for model training by default, unless the customer expressly opts in or submits feedback. Grovabe will not submit User Content as feedback or opt it into model training. Anthropic's standard API retention is ordinarily up to 30 days, subject to stated exceptions for particular features, legal requirements and usage-policy enforcement. Further information is available at anthropic.com/legal/commercial-terms and privacy.claude.com. We do not use AI to make solely automated decisions about you producing legal or similarly significant effects.
6. Location, photographs and regional insights
We use a chosen town or village to derive approximate coordinates. We do not intend to collect precise real-time device location unless this Policy and the relevant permission screen are updated. One-off identification photographs are processed in memory and not stored. Weekly-report photographs are stored for 60 days. You should avoid including faces, vehicle registrations, addresses or other unnecessary identifiers.
Regional insights are produced from pooled data using suppression and aggregation controls. A minimum contributor threshold is one safeguard, not an automatic legal guarantee of anonymity. We assess the data, geography, rarity, available auxiliary information and likelihood of singling out before treating an output as anonymous. If an output remains reasonably identifiable, we continue to treat it as personal data.
7. Recipients and service providers
| Provider / category | Purpose | Location | Role / transfer position |
|---|---|---|---|
| Supabase (primary and marketing-site instances) | database, authentication, storage and opted-in marketing contacts | London, UK | processor; no restricted transfer; verify support-access terms |
| Railway | backend processing, AI calls, payment webhooks and scheduled tasks | Netherlands, EU | processor; UK adequacy regulations apply |
| Vercel | static frontend hosting and access logs | global edge network; provider based in US | processor for relevant logs; restricted-transfer terms to be verified |
| Anthropic (Claude API) | Farma, reports, plant identification and land-planning AI | United States | processor; DPA and valid UK transfer mechanism required; no model training on customer content under Commercial Terms |
| Stripe and any other payment gateway or app store used | billing, subscriptions, refunds and fraud prevention | varies by provider | independent controller and/or processor depending on activity; transfer safeguards as applicable |
| Resend | transactional and weekly-report email | United States | processor; valid UK transfer mechanism required |
| Open-Meteo | weather forecasts using approximate farm coordinates | Germany, EU | service provider/recipient; UK adequacy regulations apply; contractual role to be confirmed |
| OpenStreetMap / Nominatim | settlement geocoding using a typed place name | EU | service provider/recipient; UK adequacy regulations apply; contractual role to be confirmed |
| Esri ArcGIS (hosting Defra/APHA disease-zone data) | point-in-polygon disease-zone check using farm latitude and longitude | United States for location-query processing | service provider/recipient; valid UK transfer mechanism required; contractual role to be confirmed |
| Sentry | error and performance monitoring with request bodies removed and PII disabled | Germany (EU) | processor; valid UK transfer mechanism required before activation |
| OneSignal | device push notifications | United States | processor; DPA and valid UK transfer mechanism required before launch |
We may also disclose relevant data to professional advisers, insurers, auditors, regulators, law-enforcement bodies, courts, prospective purchasers or funders, and group companies, where lawful and necessary. We do not sell personal data.
8. International transfers
Our primary Supabase databases and storage are hosted in London. Railway processes data in the Netherlands, and Open-Meteo and OpenStreetMap/Nominatim operate in the EU; current UK adequacy regulations cover transfers to the EEA. Selected data is transferred to providers in the United States, including Anthropic, Stripe or another payment provider, Resend, Esri, and — if enabled — OneSignal (Sentry is hosted in the EU region, in Germany, so it is not a restricted US transfer). For restricted transfers, we use the applicable provider data-processing terms and a valid UK transfer mechanism, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, together with supplementary measures where required.
9. Retention
| Data | Indicative retention |
|---|---|
| Account and operational data | account life plus 90 days, unless longer retention is required |
| AI interaction records | 24 months |
| Cached AI answers | 30 days |
| Weekly-report photographs | 60 days |
| One-off identification photographs | not stored |
| Support communications | 24 months |
| Security and technical logs | 90 days |
| Marketing preferences and suppression records | until withdrawal, plus a minimal suppression record as necessary |
| Financial, tax and transaction records | normally six years from the end of the relevant accounting period, subject to legal requirements |
| Backups | rolling 7 days; isolated until overwritten |
We may retain limited information longer where necessary for legal obligations, fraud prevention, security or legal claims. Deletion from live systems may not immediately remove protected backups. Genuinely anonymous statistics may be retained indefinitely.
10. Security
We use risk-based technical and organisational measures which may include encryption in transit and at rest, access controls, row-level security, multi-factor authentication for privileged access, private storage, monitoring, rate limiting, secure secrets management, backup and incident response. No system is completely secure. Detailed internal controls may change as technology and risk evolve and are governed by our internal Data Protection and Security Policy.
11. Your rights
Depending on the circumstances, you may have rights to access, rectification, erasure, restriction, objection, portability, withdrawal of consent and safeguards relating to automated decision-making. Rights are not absolute and exemptions may apply. We may verify identity and will respond without undue delay and ordinarily within one month. A request for access requires only reasonable and proportionate searches under current UK law.
To exercise a right or make a data protection complaint, contact support@grovabe.com. We will acknowledge a data protection complaint within 30 days and respond without undue delay. You may complain to the Information Commissioner's Office at ico.org.uk or by using its published contact channels. We would appreciate the opportunity to address the concern first.
12. Marketing and notifications
We send marketing or community electronic messages to individuals where they have consented or another PECR rule permits it. Consent choices are separate and off by default. You can unsubscribe through the message or settings at any time. Service, security and billing messages are not marketing. Push notifications use device permissions and can be changed in device settings.
13. Children
The Service is for users aged 18 and over and is not directed at children. We do not knowingly collect children's data. If you believe a child has provided data, contact us. Grovabe should monitor whether actual use indicates that the Service is likely to be accessed by children and reassess age-assurance and design measures if necessary.
14. Cookies and similar technologies
Our Cookie Policy explains cookies, SDKs, local storage, pixels, scripts, device identifiers and similar technologies used on the website and applications, including which require consent or offer a right to object.
15. Changes and contact
We may update this Policy. We will publish the updated date and give appropriate notice of material changes.
Contact: Grovabe Ltd, 66 Paul Street, London, EC2A 4NA | support@grovabe.com | ICO ZC207423.