Privacy Policy — Application

Privacy Policy — Application

Last updated: September 2026

Agromigo is operated by Agromigo B.V., a private limited liability company (besloten vennootschap) incorporated under Dutch law, with statutory seat in Rotterdam and registered address at Maashaven N.z. 797, 3072 AE Rotterdam, the Netherlands, and registered with the Dutch Chamber of Commerce under number 42155329. You can reach us by email at hello@agromigo.com. We are committed to handling your personal data with care, transparency, and in full compliance with the General Data Protection Regulation (GDPR), the Dutch Implementation Act on the GDPR (Uitvoeringswet AVG), and other applicable privacy legislation.

This policy explains how we handle personal data through the Agromigo Workforce platform and every device through which it is accessed or to which it reports data — including the Agromigo Crew mobile app, on-site kiosk and tablet terminals, and IoT-tracked equipment such as harvest carts and weighing systems (together, the “Application”). It applies to Platform Users and to Employees of organizations that use the Application. It is provided to you at the point of access to the Application. If you are simply visiting our marketing website, agromigo.com, a separate, shorter Website Privacy Policy applies to that visit instead.

The Application operates on a separate, secured cloud infrastructure from our website, with role-based access controls, encrypted storage, and full audit logging. It processes significantly more, and more sensitive, personal data than the website — including data about individual Employees who do not themselves choose to use Agromigo, but are enrolled by their employer.

1. Who Uses and Appears In the Application

Our customer for the Application is the employer organization (the “Organization”). Within that relationship, several categories of individuals appear in the system:

  • Platform Users — people who log in to the Agromigo dashboard (e.g. managers, supervisors, administrators). Platform Users authenticate through our identity provider, Clerk.
  • Employees — agricultural workers managed within the platform by their employer. Employees are the primary subject of this policy’s sensitive-data disclosures below. Many Employees are also Platform Users insofar as they log in to the Agromigo Crew app.
  • Contacts — individuals recorded as an Employee’s primary or secondary emergency contact.
  • Organizations — the employer entities themselves, along with the staffing agencies they may work with. Organization records are business data (company name, business address, billing address), not personal data, except where they include a named business contact.

The employer Organization determines what data is entered about its Employees and is, in most cases, the data controller for that Employee data under GDPR; Agromigo B.V. processes it as a data processor on the Organization’s behalf, and is separately the controller for Platform User account data. Where you are an Employee and have questions about your data, your employer is usually best placed to assist, though you may also contact us directly using the details in Section 10.

2. Data We Collect and Process

Platform User account data (all Platform Users): name, email address, phone number, username, and profile image, managed through Clerk.

Employee identity and contact data: full name, email address, phone and mobile phone numbers, date and place of birth, home address, nationality, assigned role, work site assignments, language preference, and profile photo/avatar. Where recorded, we also process the name, email, and phone number of the Employee’s designated primary and secondary emergency contact.

Employee sensitive data: where required for payroll, tax, and identity-verification purposes, we process a smaller, more tightly access-controlled set of data:

  • Citizen service number (BSN) — the Dutch national identification number, used strictly where required by tax and social-security law. The BSN is subject to specific handling requirements under the Dutch Uitvoeringswet AVG (Article 46) in addition to the GDPR, and access to it is restricted beyond our standard access controls.
  • IBAN (bank account number) — used to support payroll processing by the employer.
  • Identity documents — copies or scans of a passport, national ID card, driver’s license, visa/work-permit, professional certificate, or other identity/eligibility document, together with the document type, number, issuing country and authority, and issue/expiry dates. These are used to verify an Employee’s identity and right to work, and are stored with restricted access.

Employment and organizational data: employment contracts and contract versions (start date, end date, employment type), assigned employee role, reporting/supervisor relationships, and group/tag classifications used for scheduling and permissions.

Time, attendance, and location data: time entries and timesheets (clock-in/clock-out times, activities performed, approvals), and, where the Agromigo Crew app is used, geolocation data — see Section 6 below for details specific to location tracking.

Performance and pay data: where an employer uses performance-based (piece-rate) pay, we process productivity data tied to time entries and activities in order to calculate variable pay under the formulas configured by the employer.

Leave and absence data: annual, sickness, maternity, parental, care, and unpaid leave balances and mutations, recorded to support statutory leave entitlement tracking. Sickness and maternity leave categories constitute special category health data under Article 9 GDPR — see Section 3 for the specific legal basis that applies to this data.

3. Why We Process This Data

We process Employee and Platform User data on the following legal bases: performance of the contract between the employer and Agromigo, and between the employer and its Employees, which the Application exists to support (Article 6(1)(b) GDPR); compliance with legal obligations the employer is subject to, such as payroll, tax, and labor-law record-keeping, which is the basis on which the citizen service number specifically is processed (Article 6(1)(c) GDPR); and the legitimate interests of the employer and Agromigo in operating accurate labor records, verifying identity and work eligibility, and preventing fraud (Article 6(1)(f) GDPR). Employees are informed of this processing by their employer prior to use of the Application.

Where we process sickness or maternity leave data, this is special category data concerning health under Article 9 GDPR. We process it on the basis of Article 9(2)(b) GDPR — necessary for the employer or Agromigo to carry out obligations and exercise specific rights in the field of employment and social security law, in accordance with the safeguards required under Dutch law. Access to this data is limited to what is needed for leave administration.

4. Automated and AI-Assisted Processing

The Application uses Google’s Vertex AI (Gemini models), hosted in the EU region, for three specific automated processing activities. None of these produce a decision with legal or similarly significant effects on an Employee without human involvement — results are always presented to a Platform User for review, not acted on automatically.

  • Identity document extraction and redaction. When an identity document is uploaded during onboarding, Vertex AI (Gemini) reads the document and extracts structured biographical data — name, date and place of birth, gender, nationality, address, and document number and issuing details — to pre-fill the Employee’s record and flag expired documents. Google Cloud DLP (Data Loss Prevention) is then used to automatically redact this same personal data from a copy of the document image before that copy is stored, limiting exposure of the raw document.
  • AI-generated avatars. With the identity document photo as a visual reference, Vertex AI (Gemini image generation) produces a stylized, illustrated avatar of the Employee (a portrait and two full-body poses) for use inside the app. The Employee’s likeness is used only as a generation reference for these images and is not used for biometric identification or matching.
  • “Migo” AI advisory assistant. Migo is an in-app assistant that answers operational questions for managers (e.g. about labor cost or activity performance). To do so, it sends relevant operational data — which may include Employee names together with their time-entry, activity, and cost data — to Vertex AI (Gemini) to generate a natural-language summary or answer.

Data sent to Vertex AI for these purposes is processed within the EU and is not used by Google to train its general-purpose models. A Data Processing Agreement with Google covers this processing.

5. Data Retention

Employee data is retained for the duration of the employment relationship with the employer Organization, and thereafter for as long as required by applicable Dutch tax, social security, and labor-law record-keeping obligations, or as configured by the employer’s retention settings. In particular, financial and payroll-related records — including the IBAN and the time-entry data used to calculate pay — must be retained for at least 7 years after they are created, in line with the Dutch statutory retention obligation for financial administration (“fiscale bewaarplicht”, Article 52 of the Algemene wet inzake rijksbelastingen). Identity documents and the citizen service number are retained only for as long as necessary for identity verification and statutory compliance, and are subject to the same restricted-access treatment as other sensitive data described above. Where an Employee is removed from the system, identifying data is disassociated from historical operational records in accordance with the retention periods set out in the Application’s Terms of Use; anonymized operational records may be retained for audit and reporting purposes. If you would like to request earlier deletion, see Section 10.

6. Location Data (Agromigo Crew App)

The Agromigo Crew mobile application collects location data to support labor tracking functionality. Specifically, the app records GPS coordinates (latitude, longitude, accuracy, and the time of capture), which are linked to the individual Employee, associated with a defined work area or zone, and used to determine proximity to that work area. Location data is collected only while the app is in active use and only from Employees who have been granted access to the platform by their employer.

Location data is processed solely for operational purposes: recording where work was performed, supporting field coordination, and enabling accurate labor records tied to specific farm zones or assets (including equipment such as harvest carts, which are tracked using the same mechanism). This data is not used for advertising, profiling, or any purpose unrelated to agricultural labor tracking.

Within the app, your location is visible in real time to your manager or supervisor at your employer, on an operations map used to coordinate field activity and respond to on-site safety needs — this is a core purpose of the feature, not an incidental exposure. Location data is stored securely on Google Cloud Platform infrastructure within the EEA (Netherlands and Belgium regions), using TLS encryption in transit and AES-256 encryption at rest. Beyond your employer’s own authorized personnel, access is restricted through role-based access controls, and Agromigo does not share your location with any party outside your employer’s organization.

When an Employee is removed from the system, their personally identifiable information is disassociated from historical location records as described in Section 5. The legal basis for processing location data is the performance of the contract between the employer and Agromigo (Article 6(1)(b) GDPR), and the legitimate interest of the employer in accurately recording labor activities (Article 6(1)(f) GDPR). Employees are informed of this processing by their employer prior to use of the application.

7. Third-Party Processors

To deliver the Application, we work with the following third-party processors. We have entered into Data Processing Agreements with each of them where required under GDPR Article 28.

Google Cloud Platform (Google LLC) — Our primary cloud infrastructure and data storage provider. Employee and Platform User personal data, including identity, contact, employment, and operational records, is stored and processed exclusively within the EEA. Data at rest is stored in Google’s Netherlands region (europe-west4), and data processing via Cloud Functions runs in Belgium (europe-west1) and the Netherlands (europe-west4). No personal data is transferred to the United States or any country outside the EEA in connection with this service.

Google Vertex AI, incl. Gemini models and Cloud DLP (Google LLC) — Used for the automated and AI-assisted processing described in Section 4 (identity document extraction, image redaction, avatar generation, and the Migo assistant). Processing occurs within the EU region.

Clerk (Clerk Inc., United States) — Our authentication provider. When a Platform User or Employee registers for or logs into the Application, Clerk processes their first name, last name, and email address for identity verification and account management. As Clerk Inc. is a US-based company, transfers of personal data outside the EEA are governed by Standard Contractual Clauses as approved by the European Commission under Article 46 GDPR.

Bird (Bird B.V., Netherlands) — Used to send SMS verification and conversational messages as part of onboarding and authentication. Bird processes a user’s phone number solely for the purpose of delivering messages such as a one-time verification code. Bird is a Dutch company and all data is processed within the EEA. No additional transfer safeguards are required.

8. International Data Transfers

We aim to keep Application personal data within the European Economic Area (EEA) at all times. Google Cloud Platform and Google Vertex AI store and process Application data within EEA/EU regions in Belgium and the Netherlands. Bird is EEA-based and processes data entirely within the EEA. The one exception is Clerk, our authentication provider, which is based in the United States; for this transfer we rely on Standard Contractual Clauses as approved by the European Commission under Article 46 GDPR to ensure your personal data receives an adequate and consistent level of protection. We do not transfer personal data to countries outside the EEA beyond what is described in this policy.

9. Security

We take appropriate technical and organizational measures to prevent unauthorized access, loss, or misuse of your personal data. Our infrastructure uses TLS encryption for data in transit and AES-256 encryption for data at rest, with role-based access controls and full audit logging, and additional access restrictions on the most sensitive Employee data (citizen service number, IBAN, identity documents). Credentials, such as app PIN codes, are stored only as one-way hashes and are never included in data exports. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Dutch Autoriteit Persoonsgegevens within 72 hours as required under Article 33 GDPR, and inform affected individuals without undue delay as required under Article 34 GDPR. To report a security concern, please contact us at security@agromigo.com.

10. Your Rights Under GDPR

Under the GDPR and the Dutch Uitvoeringswet AVG, you have the following rights regarding any personal data we hold about you. To exercise any of these rights, contact us at privacy@agromigo.com. We will respond within one calendar month. You also have the right to lodge a complaint with the supervisory authority in the EU member state where you live, work, or where an alleged infringement took place. In the Netherlands, this is the Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl.

  • Access: You have the right to request a copy of the personal data we hold about you, including a structured export of your identity, contact, and compliance data.
  • Correction: You have the right to have inaccurate or incomplete data corrected.
  • Deletion: You have the right to request that we delete your personal data, subject to legal retention obligations.
  • Restriction: You have the right to request that we restrict processing of your data in certain circumstances.
  • Objection: You have the right to object to processing based on legitimate interest. Where you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format. The Application includes a built-in data export tool that generates such a file on request.
  • Withdraw consent: Where we process your data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal.
  • Complaint: You have the right to lodge a complaint with the Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl. Before doing so, we ask that you contact us first at complaints@agromigo.com. We respond within one calendar month.

11. Changes to This Policy

We may update this policy from time to time to reflect changes in legislation or our practices. We will update the date at the top of this page when we do. We encourage you to review this policy periodically.

Privacy inquiries and GDPR requests: privacy@agromigo.com
General complaints: complaints@agromigo.com
Security incidents and data breach reports: security@agromigo.com