You — the business, farm, nursery, shop, processor or retailer using GrowIQ to record information about other people. In this agreement, the Controller.
Us — SEVRA Group Limited (Co. No. 16573490), registered in England and Wales, trading as GrowIQ UK. In this agreement, the Processor.
This agreement is incorporated into, and forms part of, the GrowIQ Terms of Service. By using any GrowIQ feature to record personal data about another person, you accept it. Where it conflicts with the Terms, this agreement takes precedence for matters of data protection.
Article 28(3) UK GDPR requires this agreement to set out the subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subject. Here it is, plainly:
| Subject matter | Providing the GrowIQ platform to you — FarmIQ, ShopIQ, NetworkIQ and GrowIQ — so you can run your business. |
|---|---|
| Duration | For as long as you have an account with us, plus the deletion period in section 9. |
| Nature & purpose | Storing, organising, displaying, and making available to you the records you create. Sending notifications you configure. Nothing else. |
| Types of personal data | Names; job titles; email addresses; join PINs; clock-in and clock-out times; tasks assigned and completed; work, treatments, harvests and produce recorded against a person; till actions; photographs you upload. |
| Categories of data subject | Your workers, staff, team members and colleagues. Where you use NetworkIQ, staff of the organisations in your chain. |
| Special category data | None. GrowIQ has no field for health, biometric, racial, religious, political, trade union, sex life or sexual orientation data, and you must not put such data into free-text fields. |
We will:
And we will not: sell your data, use it to advertise to anyone, use it to train AI models, or use it for our own purposes at all. If we ever want to use aggregate, anonymised statistics to improve the product, we will do it in a way that cannot identify you, your business or any individual.
You are the controller, which means the law puts these on you, not us:
We take appropriate technical and organisational measures under Article 32, including:
No system is perfectly secure, and we do not claim otherwise. We keep these measures under review as the service changes.
You give us general authorisation to use the sub-processors below. We remain fully liable to you for what they do. We will give you reasonable notice before adding or replacing one, and if you object on reasonable data-protection grounds you may terminate the affected service without penalty.
| Who | What for | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (AWS) |
| Netlify | Hosting and serverless functions | EU / US |
| Stripe | Subscription payments (we never see card details) | EU / US |
| Resend | Sending email you ask us to send | EU / US |
| Anthropic | The AI behind GrowSense | US |
On the AI: GrowSense sends only what is needed to answer the question in front of you. Worker records, staff records and payroll-adjacent data are not sent to the AI. Our AI provider does not train models on data sent through the API.
If one of your workers or staff exercises a right — access, rectification, erasure, restriction, portability or objection — that request is yours to answer. GrowIQ gives you the tools to do it yourself: you can view, edit, export and delete the records you hold. Where the platform can't do it, ask us and we will help within a reasonable time and at no charge for a reasonable volume of requests.
If such a request reaches us directly, we will not answer it ourselves. We will tell the person to contact you, and let you know it happened.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay — and in any event promptly enough for you to meet your own 72-hour deadline to the ICO. We will tell you what we know: what happened, who is likely affected, what the likely consequences are, and what we are doing about it. Reporting to the ICO and to affected people is your call as controller; we will give you what you need to make it.
On termination, and at your choice, we will delete or return your data. Unless you tell us otherwise, we will delete it within 90 days of your account closing, except where the law requires us to keep it.
We will make available the information you reasonably need to demonstrate compliance with Article 28, and will allow and contribute to audits. In practice, we would ask you to start by asking us — most questions can be answered without an inspection. Audits should be at reasonable notice, no more than once a year unless there has been a breach or the ICO requires it, and must not compromise other customers' confidentiality.
Your data is primarily held in the EU. Where a sub-processor transfers data outside the UK or EEA, that transfer relies on an appropriate safeguard — an adequacy decision, or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. We will not transfer your data outside the UK/EEA without one.
Liability under this agreement is subject to the limitations in the Terms of Service Data Processing, except where the law does not allow that. Nothing here limits a data subject's rights or the ICO's powers.
If we change this agreement materially, we will tell you before it takes effect. If a change is required by law, it applies from the date the law requires.
Data protection questions, requests, audits or breach notifications: hello@growiq.co.uk.
SEVRA Group Limited, Company No. 16573490, registered in England and Wales.
Need this signed as a standalone document for your own records or your auditor? Email us and we'll sort it.