Agririgo

Legal · version 1.1

Privacy Policy

Effective 21 July 2026 · read with the Terms of Use

The promise in one paragraph: we collect the minimum needed to run a professional platform, we tell you exactly what that is, your field imagery stays on your device unless you share it to your team, what you share is used to improve the Platform, you can download everything we hold about you with one click, and you can leave, with your data, whenever you wish. Data protection is not a page on this site; it is how the system is built.

1. Who we are

Ericolas Technologies Limited of Lusaka, Zambia ("Agririgo", "we") is the data controller for personal data processed on this Platform. We process personal data in accordance with the Data Protection Act No. 3 of 2021 of Zambia and, where it applies to you, the EU General Data Protection Regulation.

2. What we collect, and what we deliberately do not

Account and profile data: your name, email address, password (stored only as a cryptographic hash by our authentication provider; we can never read it), role, organisation, country and stated purpose of use, plus the timestamp and version of the terms you accepted.

Usage events: sign-ins, studio sessions, counts of images processed and exports made, and pages of the Platform used. These events record what happened and when, tied to your account.

Technical data: our hosting providers log IP addresses and request metadata for security and delivery; we do not build advertising profiles from them.

Team content, only if you opt in: images, labels and snapshots you explicitly upload to a Team Workspace are stored in our EU-hosted cloud and are visible to your team members only.

Crop passports (RigoTrace), only if you publish them: a passport is public by design, so include only what belongs on a printed label. You can delete a passport at any time and its page goes dark.

Community posts, only if you publish them: when you choose to make a post public, we store its title, description, a small set of summary statistics (such as percentage healthy canopy, not raw pixels), and your display name and role, plus any ratings and comments made on it. You choose public or private per post, and can switch or delete it at any time.

Crop Passport data, if you use RigoTrace: batch details, photos you upload, quality tests, chain-of-custody entries, your organisation profile, and any story content are stored so the public passport page can display them. Anyone who scans the passport's QR code or visits its page can see this content; publish only what belongs on a public label.

Passport scan analytics, about the buyers who scan your passports (not about you): for each scan we log an approximate country and city (from network geolocation, not GPS), a coarse device type, and a same-day salted one-way hash used only to estimate repeat visits. We never store the scanning visitor's name, exact location, or IP address, and this data is visible only to the passport's owner, never to us for any other purpose or to other users.

What we do not collect: images you process locally stay on your device and are never uploaded without your explicit action; we hold no payment card data; and we do not ask for or store government identity documents.

3. Why we process it

To provide the service: accounts, saved acceptance of terms, and the studio itself. Legal basis: performance of our contract with you.

To secure the Platform: detecting abuse, enforcing rate limits and investigating incidents. Legal basis: legitimate interest.

To improve the Platform: data you share with us, your profile and your usage events are analysed, usually in aggregate, to understand who the Platform serves and to make it better. This is stated plainly at sign-up and is a condition of use. Legal basis: consent and legitimate interest.

To communicate: service messages about your account or material changes to terms. We do not sell your data, and we do not send marketing without separate consent.

4. Where it lives and who touches it

Account data and events are stored with Supabase (database and authentication, hosted in the European Union, Frankfurt region) and the website is delivered by Vercel. Both act as processors under their own security and data-processing terms. Access within Agririgo is restricted to people who need it to operate the service.

We may publish aggregated, anonymised statistics (for example, "40% of studio users are agronomists") that can never identify you. We disclose personal data only if a law or court order compels it, or to protect the Platform and its users from serious harm.

5. Security, honestly stated

Data is encrypted in transit (TLS) and at rest. Database access is guarded by row-level security so each account can read only its own records. Passwords are hashed with industry-standard algorithms. No system is unbreakable; if a breach materially affects you, we will notify you and the Office of the Data Protection Commissioner as the law requires.

The strongest protection is architectural: by default your field imagery never leaves your device. Sharing to a team is a deliberate, per-image action, and shared content is fenced to that team by database-level row security.

6. Your data stays yours

Download everything: the "My data" button inside Rigo Studio exports your complete profile and usage history as JSON, anytime, no request form needed.

Keep results locally: analysis outputs, labels and datasets can be saved to your own device; labels also autosave to your browser's local storage so closing a tab never loses work.

Correct or delete: you can update profile fields in the studio, and you may request deletion of your account and personal data by emailing us; we complete verified requests within 30 days, subject to records we must keep by law.

Object or complain: you may object to specific processing, withdraw consent for the future, and lodge a complaint with the Office of the Data Protection Commissioner of Zambia or your local supervisory authority.

7. Retention

Profiles live as long as your account. Usage events are kept for up to 24 months, then deleted or anonymised. Backups roll off on our processors' standard schedules. Data tied to legal obligations is kept only as long as those obligations require.

8. Cookies and local storage

We use only what the service needs: an authentication session token, and local storage for your studio preferences and label autosave. There are no third-party advertising or tracking cookies on this Platform.

9. Children

The Platform is not directed at children under 16. If you believe a child has created an account without appropriate supervision, contact us and we will remove it.

10. Changes and contact

If this policy changes materially, we will tell you on the Platform and, for studio users, ask you to re-accept before continuing.

Data requests and questions: info@agririgo.com · Ericolas Technologies Limited, Lusaka, Zambia.