AcreAtlas Precision Ag

Data Processing Agreement

Our GDPR Article 28 processor terms. Incorporated by reference into the General Terms & Conditions.

Version
1.3
Effective
6 August 2026

The PDF is the authoritative version of this document. The text below is the same content, published for easier reading.

This Data Processing Agreement ("DPA") is entered into between AcreAtlas (as Processor) and the Customer named below (as Controller). It forms part of and is incorporated into the AcreAtlas General Terms & Conditions.

Parties

ProcessorAcreAtlas / AkkerAtlas (sole proprietorship), registered with the Dutch Chamber of Commerce under number 99197081. Contact: info@acreatlas.eu. (Note: the contracting party will be replaced by Acreatlas B.V. once incorporated and the relevant transfer formalities are completed.)
ControllerCompany name: ____________________________ KvK / registration number: ____________________________ Address: ____________________________ Contact person: ____________________________ | Email: ____________________________

1. Definitions

In this DPA, the following terms have the meanings assigned to them in the GDPR: 'personal data', 'processing', 'controller', 'processor', 'data subject', 'personal data breach', and 'supervisory authority'. Additionally:

  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • "AVG" means the Dutch implementation of the GDPR (Algemene verordening gegevensbescherming) and the Uitvoeringswet AVG.
  • "Platform" means the AcreAtlas software platform as described in the General Terms & Conditions.
  • "Field Data" means all personal data included in or derived from the Controller's field boundary coordinates, GPS data, drone imagery, crop records, spray records, and compliance documentation uploaded to or processed by the Platform.
  • "Sub-processor" means any third party engaged by AcreAtlas to process personal data on the Controller's behalf as part of providing the Platform.

2. Subject Matter and Duration

2.1 AcreAtlas processes personal data on behalf of the Controller solely for the purpose of providing the Platform services described in the General Terms & Conditions, including generating Spray Maps, processing drone imagery, and producing compliance reports.

This DPA applies only to processing of personal data by AcreAtlas as processor on behalf of the Controller. Processing carried out by AcreAtlas as an independent controller — including account administration, invoicing, platform security, service analytics, and legally required administration — is governed by AcreAtlas’s Privacy Policy and falls outside the scope of this DPA.

2.2 This DPA applies for as long as AcreAtlas processes personal data on behalf of the Controller. It continues in effect until all personal data has been returned or deleted in accordance with Section 9, even if the General Terms & Conditions have otherwise terminated.

3. Processing Details (Schedule A)

The following table describes the nature, purpose, and scope of processing under this DPA:

Nature of processingCollection, storage, organisation, analysis, and structuring of Field Data; generating Spray Maps and Prescription Files; producing compliance reports; displaying and exporting data to the Controller.
Purpose of processingTo provide the AcreAtlas Platform services to the Controller under the General Terms & Conditions. No other purpose.
Categories of personal dataField boundary GPS coordinates and identifiers, drone imagery metadata, crop type and growth stage records, spray application records, user account identifiers linked to field data.
Categories of data subjectsThe Controller (where Controller is an individual farmer); employees or agents of the Controller with access to the Platform; and to a limited extent, persons whose personal data may be incidentally included in field imagery (e.g., persons visible in aerial images).
Retention periodSee Section 9. Personal data deleted or returned within 30 days of written request after account termination, unless longer retention is required by law. AcreAtlas may use aggregated and anonymised data for service improvement and model training only after such data has been rendered anonymous in a manner that it no longer relates to an identified or identifiable natural person. To the extent any personal data is processed for analytics, service improvement, or model development outside the Controller’s documented instructions, AcreAtlas acts as an independent controller and such processing is governed by the Privacy Policy, not this DPA.

4. AcreAtlas's Obligations as Processor

AcreAtlas agrees to:

  • Process personal data only on documented instructions from the Controller — which are set out in this DPA and the General Terms & Conditions — and not for any other purpose, unless required to do so by EU or Dutch law (in which case AcreAtlas will inform the Controller before processing, unless prohibited by law).
  • Ensure that all personnel authorised to process personal data under this DPA are bound by appropriate confidentiality obligations.
  • Implement and maintain appropriate technical and organisational security measures as required by GDPR Art. 32, taking into account the state of the art, the nature of the data, and the risks involved (see Section 5).
  • Not engage any Sub-processor without prior written authorisation from the Controller, except as set out in Schedule B (Section 8). AcreAtlas will inform the Controller of any intended changes to its list of Sub-processors, giving the Controller an opportunity to object.
  • Assist the Controller in responding to data subject requests under Chapter III of the GDPR (access, rectification, erasure, portability, restriction, objection), to the extent technically possible and at the Controller's reasonable cost.
  • Assist the Controller in meeting its obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and information available to AcreAtlas.
  • At the Controller's choice, delete or return all personal data to the Controller upon termination of the DPA, and delete existing copies unless EU or Dutch law requires otherwise (see Section 9).
  • Make available to the Controller all information necessary to demonstrate compliance with this Article 28 GDPR obligation, and allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality obligations.

Audits shall be limited to once per calendar year, during normal business hours, subject to at least thirty (30) days’ prior written notice, and shall be conducted in a manner that does not unreasonably disrupt AcreAtlas’s business operations. The Controller shall bear its own audit costs and reimburse AcreAtlas for reasonable costs incurred in connection with audits, unless the audit reveals a material breach attributable to AcreAtlas. This limitation does not diminish the Controller’s mandatory rights under Article 28 GDPR.

5. Security Measures

AcreAtlas implements the following technical and organisational measures to protect personal data:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Access controls and role-based authentication limiting data access to authorised personnel
  • Regular security reviews and vulnerability assessments
  • Secure, access-controlled hosting infrastructure with data stored in the EEA (where applicable)
  • Incident response procedures for detecting and responding to personal data breaches

Hosting and storage. Production data is hosted with Microsoft Azure (Microsoft Ireland Operations Ltd) in the Germany West Central region within the European Economic Area. Data at rest on customer-facing systems is encrypted using AES-256 (or equivalent) provided by the hosting layer. No customer Field Data is stored outside the EEA without prior written agreement with the Controller and appropriate transfer safeguards.

Encryption in transit. All Platform traffic between the User and the Platform, and between Platform components and AcreAtlas’s hosting infrastructure, uses TLS 1.2 or higher.

Authentication and access control. End users authenticate through Firebase Authentication (Google LLC) using a Google account, a Microsoft (Entra) account, or a one-time code sent to their email address; no end-user passwords are stored by AcreAtlas. Optional two-factor authentication delivers a verification code by SMS to a phone number supplied by the user. Administrative access to production infrastructure is limited to named members of the AcreAtlas engineering team on a need-to-know basis, secured by individual accounts and multi-factor authentication where supported by the underlying provider.

Confidentiality. All AcreAtlas personnel with access to personal data are subject to written confidentiality obligations and process personal data only on documented instructions.

Backup and resilience. Production data is backed up on a regular schedule by the hosting layer. Backup data is held in the EEA and subject to the same access controls as production data.

Logging and monitoring. Access to personal data and material configuration changes are logged. Logs are retained for a period proportional to incident-response and audit-trail needs.

Vulnerability management. AcreAtlas applies dependency and platform security updates on a regular basis and monitors public advisories affecting components used by the Platform.

Incident response. AcreAtlas maintains an internal Data Breach Procedure aligned with GDPR Articles 33 and 34, including triage criteria, the 48-hour notification commitment to the Controller under Section 6 of this DPA, and post-incident review.

Data minimisation. Personal data is collected and retained only to the extent necessary to provide the Platform, in line with the AcreAtlas Privacy Policy.

Sub-processor due diligence. Sub-processors are selected based on their published security and certification posture (e.g. ISO 27001, ISO 27018, SOC 2) and bound by contractual obligations equivalent to those in this DPA.

6. Personal Data Breach Notification

AcreAtlas shall notify the Controller without undue delay and, where feasible, within 48 hours after becoming aware of a personal data breach affecting the Controller’s personal data. AcreAtlas shall provide information reasonably available to it to enable the Controller to assess whether notification to the supervisory authority or affected data subjects is required. The notification will include, to the extent available:

  • A description of the nature of the breach, including categories and approximate number of data subjects and records affected;
  • The name and contact details of AcreAtlas's data protection contact;
  • A description of the likely consequences of the breach;
  • A description of measures taken or proposed to address the breach and mitigate its effects.

The Controller is responsible for notifying the Autoriteit Persoonsgegevens and affected data subjects as required by GDPR Articles 33–34, using the information provided by AcreAtlas.

7. Controller's Obligations

The Controller confirms that:

  • It has a lawful basis under GDPR Art. 6 for the processing of personal data described in Schedule A, and that all personal data provided to AcreAtlas for processing has been collected in compliance with Applicable Law.
  • It will ensure that data subjects have been informed of the processing described in this DPA (e.g., through the Controller's own privacy policy), to the extent required by GDPR Articles 13–14.
  • It will inform AcreAtlas promptly of any data subject requests or supervisory authority inquiries relating to personal data processed under this DPA.
  • It will not instruct AcreAtlas to process personal data in a manner that would violate GDPR or Applicable Law.

8. Sub-processors (Schedule B)

The Controller provides general authorisation for AcreAtlas to engage the Sub-processors listed below. AcreAtlas will impose data protection obligations on each Sub-processor equivalent to those set out in this DPA. AcreAtlas remains fully liable for the acts and omissions of its Sub-processors.

Sub-processorService / purposeLocation / safeguards
Microsoft Azure (Microsoft Ireland Operations Ltd) — cloud hosting and data processingStorage of Field Data, drone imagery, processing pipeline outputsGermany (EEA); data at rest and processing within the EEA

AcreAtlas will notify the Controller at least 30 days before engaging a new Sub-processor or replacing an existing one. The Controller may object in writing within 14 days. If the parties cannot resolve the objection, the Controller may terminate the DPA on 30 days' written notice.

In addition to the sub-processor listed above, AcreAtlas uses Firebase Authentication (Google LLC) as its identity layer. You can sign in with a Google account, with a Microsoft (Entra) account, or with a one-time code sent to your email address. The identity layer receives only the minimum identifiers required to authenticate you (email address and profile identifier) and does not receive Field Data. If you enable two-factor authentication, your mobile phone number is processed to deliver the SMS verification code. The Controller acknowledges that signing in with a Google or Microsoft account involves a transfer of authentication metadata to the United States under the EU–US Data Privacy Framework. Payments are handled manually (no payment processor). The Platform also offers optional integrations with DJI Cloud (drone mission planning) and John Deere Operations Center (prescription map delivery to compatible tractors); these are third-party integrations activated only when the Controller configures them, are governed by the Controller’s own agreements with those providers, and AcreAtlas transmits only the data strictly necessary for the requested integration.

9. Return and Deletion of Data

Upon termination of the DPA or the General Terms & Conditions, AcreAtlas will, at the Controller's written request and choice:

  • Return all personal data to the Controller in standard, machine-readable formats appropriate to the data type, including PNG or GeoTIFF for imagery, ISOXML or ESRI Shapefile (.SHP) for prescription maps, KML for field boundaries, and CSV for tabular records, within 30 days; or
  • Securely delete all personal data within 30 days and provide written confirmation of deletion.

The deletion or return obligation applies to personal data processed by AcreAtlas as processor on behalf of the Controller. AcreAtlas may retain personal data where and to the extent it acts as an independent controller and retention is required by applicable law or necessary for legitimate dispute resolution, subject to the Privacy Policy.

AcreAtlas may retain personal data beyond this period only where required by applicable EU or Dutch law (e.g., statutory bookkeeping obligations), in which case the data will be kept only for as long as legally required and will not be processed for any other purpose.

10. Liability

Any liability arising out of or in connection with this DPA, whether in contract, tort or otherwise, is strictly subject to the limitation of liability set out in the AcreAtlas General Terms & Conditions, to the fullest extent permitted by applicable law. Nothing in this DPA limits any rights of data subjects or supervisory authorities under the GDPR.

11. Governing Law

This DPA is governed by the laws of the the Netherlands. Disputes arising from or in connection with this DPA are subject to the exclusive jurisdiction of the competent courts in Amsterdam, the Netherlands.

12. Signatures

By signing below, both parties agree to be bound by this Data Processing Agreement.

AcreAtlas — Processor _________________________ Name: Title: Date:Customer — Controller _________________________ Name: Title: Date:

This DPA is entered into as of the date of the last signature above and forms part of the General Terms & Conditions between the parties.