Data processing agreement

Data Processing Agreement

Version 1.0 — September 2026

This Data Processing Agreement (“DPA“) forms part of, and is incorporated by reference into, the agreement between the organization using the Agromigo Workforce platform (the “Controller“, “Organization“, or “Customer“) and Agromigo B.V., a private limited liability company (besloten vennootschap) incorporated under Dutch law, with statutory seat in Rotterdam and registered address at Maashaven N.z. 797, 3072 AE Rotterdam, the Netherlands, registered with the Dutch Chamber of Commerce under number 42155329, RSIN 869958136, and VAT number NL869958136B01 (the “Processor” or “Agromigo“), as referenced in the Agromigo Terms and Conditions (together, the “Agreement”). This DPA applies wherever Agromigo processes personal data on the Customer’s behalf as a processor within the meaning of Article 4(8) of Regulation (EU) 2016/679 (the “GDPR”), as described in the Agromigo Application Privacy Policy. Terms capitalized in this DPA but not defined here have the meaning given to them in the Terms and Conditions or the Application Privacy Policy.

1. Definitions

  • “Applicable Data Protection Law” means the GDPR, the Dutch Implementation Act on the GDPR (Uitvoeringswet AVG), and any other data protection law applicable to the processing of Employee Data under this DPA.
  • “Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” have the meanings given to them in Article 4 GDPR.
  • “Employee Data” means the personal data of Employees and Contacts, as those terms are defined in the Application Privacy Policy, processed by Agromigo on the Customer’s behalf under this DPA.
  • “Services” has the meaning given to it in the Terms and Conditions.

2. Roles and Instructions

The Customer is the Controller of Employee Data it submits or generates through the Services, determines the purposes and means of that processing, and is responsible for the lawfulness of the personal data it provides to Agromigo, including that Employees have been given the notices required under Applicable Data Protection Law. Agromigo is the Processor of Employee Data and, separately, the Controller of Platform User account data, as described in Section 1 of the Application Privacy Policy.

Agromigo will process Employee Data only on the Customer’s documented instructions, including regarding transfers of personal data to a third country, unless required to do otherwise by Union or Member State law to which Agromigo is subject — in which case Agromigo will inform the Customer of that legal requirement before processing, unless that law prohibits this on important grounds of public interest. Configuring, using, and administering the Services in the manner they are designed to operate, as described in the Agreement, constitutes a documented instruction. Agromigo will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

3. Subject Matter, Duration, and Scope of Processing

The subject matter of the processing is Agromigo’s provision of the Services to the Customer, to the extent that provision involves processing Employee Data. Processing takes place for the duration of the Agreement, and thereafter for the retention period described in Article 12.

The nature and purpose of the processing, the categories of data subjects, and the categories of personal data processed are as described in Sections 1 through 6 of the Application Privacy Policy, which this DPA incorporates by reference. In summary: the categories of data subjects are Employees and their designated emergency Contacts; the categories of personal data include identity and contact data, employment and organizational data, time, attendance, and location data, performance and pay data, and leave and absence data (including special category health data relating to sickness and maternity leave, processed under Article 9(2)(b) GDPR), and, where required for payroll, tax, or identity-verification purposes, the citizen service number (BSN), IBAN, and identity documents.

4. Confidentiality

Agromigo ensures that persons authorized to process Employee Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to Employee Data is limited to personnel who require it to perform the Services.

To provide support, designated Agromigo support personnel can access the Customer’s organization within the Services with the permissions of an administrator. This access is standing: it does not require a separate request to, or approval from, the Customer on each occasion. Support personnel act under their own identity and never as one of the Customer’s Employees. Every access is recorded, and the Customer’s administrators can review on which days, by whom, and how often their organization was accessed in this way from within the Services.

5. Sub-processors

The Customer provides Agromigo with a general written authorization to engage the following sub-processors in connection with the Services:

Sub-processor Service Processing location Transfer mechanism
Google LLC (Google Cloud Platform)
Cloud Data Processing Addendum
Google Cloud sub-processors
Cloud infrastructure and data storage EEA (Netherlands, Belgium) Not applicable — processed within the EEA
Google LLC (Vertex AI, incl. Gemini models and Cloud DLP)
Cloud Data Processing Addendum
Service Specific Terms
AI-assisted processing described in Section 4 of the Application Privacy Policy EU region Not applicable — processed within the EEA
Google LLC (Firebase Authentication)
Firebase Data Processing and Security Terms
Sign-in and account management Not pinned to an EEA region; may be outside the EEA Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), as incorporated in Google’s Data Processing Addendum
Bird B.V.
Bird Data Processing Agreement
SMS verification and messaging Netherlands (EEA) Not applicable — processed within the EEA

Agromigo will inform the Customer, for example via an updated version of this DPA, of any intended addition or replacement of a sub-processor with at least thirty (30) days’ notice, giving the Customer the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Customer may terminate the Agreement in accordance with its termination provisions to the extent it relates to the Services affected by that sub-processor. Agromigo imposes data protection obligations on each sub-processor that are substantially equivalent to those set out in this DPA, and remains liable to the Customer for a sub-processor’s performance of those obligations.

6. International Data Transfers

Agromigo keeps Employee Data within the European Economic Area (EEA) wherever possible. Google Cloud Platform and Google Vertex AI store and process Employee Data within EU regions in the Netherlands and Belgium, and Bird B.V. is established in, and processes data entirely within, the Netherlands. The one exception is Firebase Authentication, the Google service that holds sign-in account records: these are not pinned to an EEA region and may be stored outside the EEA. For this transfer Agromigo relies on Google’s Data Processing Addendum, which incorporates the Standard Contractual Clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914 pursuant to Article 46 GDPR. Agromigo does not transfer Employee Data to a country outside the EEA beyond what is described in this Article and will not do so in the future without ensuring an appropriate transfer mechanism under Applicable Data Protection Law is in place.

7. Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risk to the rights and freedoms of Employees, Agromigo implements the following technical and organizational measures, as required under Article 32 GDPR:

  • TLS encryption for Employee Data in transit and AES-256 encryption for Employee Data at rest.
  • Role-based access controls and full audit logging, with additional access restrictions on the most sensitive categories of Employee Data (citizen service number, IBAN, and identity documents).
  • Storage of credentials, such as application PIN codes, only as one-way hashes, which are never included in data exports.
  • Data residency for Employee Data within the EEA, with the one exception described in Article 6.
  • The automated erasure and retention practices described in Section 5 of the Application Privacy Policy, applied consistently to Employee Data.

Agromigo may update these measures from time to time provided the updated measures do not materially decrease the overall level of security. Details of Agromigo’s current security measures are available on request at security@agromigo.com.

8. Personal Data Breaches

Agromigo will notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Employee Data, so that the Customer can meet its own notification obligations under Articles 33 and 34 GDPR. This notification will describe, to the extent known at the time: the nature of the breach, including where possible the categories and approximate number of Employees and Employee Data records concerned; the likely consequences of the breach; and the measures taken or proposed by Agromigo to address the breach and mitigate its possible adverse effects. Agromigo will supplement this information without undue delay as it becomes available, and will provide reasonable assistance to the Customer in meeting its own notification obligations to the Autoriteit Persoonsgegevens or affected Employees. Agromigo does not itself notify the Autoriteit Persoonsgegevens or Employees of a Personal Data Breach affecting Employee Data, as that responsibility rests with the Customer as Controller; this obligation is separate from Agromigo’s own direct breach-notification duties as Controller of Platform User account data, described in Section 9 of the Application Privacy Policy.

9. Assistance with Data Subject Rights

Taking into account the nature of the processing, Agromigo assists the Customer, insofar as reasonably possible and using appropriate technical and organizational measures, in fulfilling the Customer’s obligation to respond to requests from Employees exercising their rights under Chapter III GDPR, including through the built-in data export tool described in Section 10 of the Application Privacy Policy. If Agromigo is contacted directly by an Employee about the processing of their Employee Data, Agromigo will, where it can identify the relevant Customer, refer the Employee to that Customer without undue delay, consistent with Section 1 of the Application Privacy Policy.

10. Data Protection Impact Assessments and Audits

Agromigo provides the Customer, on reasonable request, with the information reasonably necessary to demonstrate compliance with this DPA and to allow the Customer to carry out a data protection impact assessment or prior consultation under Articles 35 and 36 GDPR in relation to its use of the Services.

Agromigo allows for, and contributes to, audits, including inspections, conducted by the Customer or an independent, mutually agreed auditor with demonstrable data protection expertise and bound by confidentiality, no more than once every twelve (12) months unless a Personal Data Breach or a substantiated compliance concern justifies an additional audit. An audit is carried out at the Customer’s cost, on at least thirty (30) days’ prior written notice, during ordinary business hours, and in a manner that does not unreasonably disrupt Agromigo’s operations or compromise the confidentiality or security of other customers’ data. Agromigo may decline an audit instruction it reasonably believes would infringe Applicable Data Protection Law or disproportionately compromise its security measures, and may instead provide equivalent assurance through a relevant third-party certification, audit report, or summary, where available.

11. Liability

Liability arising out of or in connection with this DPA is governed by the limitation of liability provisions of Section 11 of the Terms and Conditions. Nothing in this DPA expands Agromigo’s liability beyond what is agreed there, except to the extent such a limitation is not permitted under Applicable Data Protection Law.

12. Return or Deletion of Employee Data

Following termination or cancellation of the Agreement, Agromigo retains Employee Data for ninety (90) days in accordance with Section 7 of the Terms and Conditions, during which the Customer may request a full export in a standard machine-readable format. After this period, Agromigo deletes or anonymizes Employee Data, except for personal data Agromigo is required to retain under Applicable Data Protection Law or other Union or Member State law — in particular, the citizen service number (BSN) and IBAN, which are retained for seven (7) years under the Dutch statutory retention obligation for financial administration (“fiscale bewaarplicht”, Article 52 of the Algemene wet inzake rijksbelastingen), as described in Section 5 of the Application Privacy Policy. Agromigo continues to protect any Employee Data retained under this exception in accordance with this DPA for the duration of the applicable statutory retention period, and processes it only to the extent required by that legal obligation.

13. Changes to This DPA

Agromigo may update this DPA to reflect changes in Applicable Data Protection Law or in its processing activities. Where a change is material, Agromigo provides notice in accordance with Section 18 of the Terms and Conditions. In the event of a conflict between this DPA and the Agreement regarding the processing of Employee Data, this DPA prevails.

14. Governing Law and Jurisdiction

This DPA is governed by the laws of the Netherlands and is subject to the governing law and dispute resolution provisions of Sections 19 and 20 of the Terms and Conditions, including the exclusive jurisdiction of the Rechtbank Rotterdam.

15. Contact Information

For questions about this DPA, contact Agromigo at privacy@agromigo.com. To report a security incident or suspected Personal Data Breach, contact security@agromigo.com.

Trading name: Agromigo
Statutory name: Agromigo B.V.
Legal form: Private limited liability company (Besloten Vennootschap)
Chamber of Commerce (KvK) number: 42155329
RSIN: 869958136
VAT identification number: NL869958136B01
Statutory seat: Rotterdam, the Netherlands
Registered address: Maashaven N.z. 797, 3072 AE Rotterdam, the Netherlands
Email: hello@agromigo.com
Website: www.agromigo.com