Privacy Policy
Last updated: 12 August 2026
This Privacy Policy explains how FarmVizion processes personal data when you visit our website, communicate with us, create or use an account, purchase products or services, use AIVA OS or connected digital and IoT services, or otherwise interact with FarmVizion.
1. Controller
FarmVizion UG (haftungsbeschränkt) i.G.
Dankelsried 6, 87742 Erkheim, Germany
Email: support@farmvizion.de
Phone: +49 155 11296230
2. Scope of this Privacy Policy
This policy applies to personal data processed through FarmVizion websites, applications, customer accounts, digital services, SaaS/PaaS products, support channels, orders, IoT integrations and related services. Operational, agronomic, machine or field data that cannot be linked to an identified or identifiable natural person is not personal data under the GDPR. Where such information can be linked to a person, it is treated as personal data.
3. Categories of Personal Data
Depending on how you use our services, we may process:
- Identity and contact data, including name, company, postal address, email address and telephone number.
- Account data, including login identifiers, account settings, roles and authentication information.
- Contract and transaction data, including orders, subscriptions, invoices, payment status and delivery information.
- Communication data, including enquiries, support requests, feedback and correspondence.
- Technical data, including IP address, browser, operating system, timestamps, device information and security logs.
- Usage data relating to how users interact with our website, applications and platform.
- Farm, equipment and IoT data where such information can be linked to an identifiable person.
- Images, video or sensor information where connected systems or customer deployments capture identifiable individuals.
- Consent and preference information, including cookie and marketing preferences.
4. Purposes, Legal Bases and Retention
Website operation and security
Purpose: To provide the website, establish connections, prevent attacks, detect abuse and maintain technical security.
Legal basis: Article 6(1)(f) GDPR, based on our legitimate interest in securely operating our digital services. Where access to information on a user's terminal device is strictly necessary, § 25(2) TDDDG applies.
Retention: Technical logs are retained only for the period reasonably necessary for security, troubleshooting and abuse prevention, unless longer retention is necessary to investigate a specific incident or comply with law.
Accounts, contracts and service delivery
Purpose: To create and manage accounts, provide subscriptions, digital services, IoT integrations, consulting and other contracted services.
Legal basis: Article 6(1)(b) GDPR for performance of a contract or steps requested before entering into a contract.
Retention: For the duration of the contractual relationship and afterwards to the extent necessary for statutory retention obligations or the establishment, exercise or defence of legal claims.
Orders, payments and accounting
Purpose: To process purchases, invoices, payment status, refunds, deliveries, tax records and accounting obligations.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR for applicable tax, accounting and commercial-law obligations.
Retention: Accounting and invoice records are retained for applicable statutory retention periods. In Germany, many accounting records and invoices are currently subject to an eight-year retention period, while certain business correspondence may be subject to six-year retention obligations.
Customer support and communications
Purpose: To answer enquiries, provide support, resolve technical issues and manage customer relationships.
Legal basis: Article 6(1)(b) GDPR where communication concerns a contract, and Article 6(1)(f) GDPR for general business communication and customer support.
Retention: Until the request has been resolved and thereafter only as long as reasonably necessary for documentation, contractual obligations or legal claims.
AIVA OS, IoT and agricultural services
Purpose: To process information required to provide analytics, device integration, monitoring, automation and other contracted FarmVizion services.
Legal basis: Article 6(1)(b) GDPR where FarmVizion determines the purposes of processing. Where FarmVizion processes personal data solely on behalf of a business customer, processing is governed by Article 28 GDPR and the applicable data processing agreement.
Retention: According to the applicable customer contract, account settings and data processing agreement, subject to statutory retention requirements.
Optional analytics and similar technologies
Purpose: Where enabled, to understand website or application usage and improve our services.
Legal basis: Consent under Article 6(1)(a) GDPR and § 25(1) TDDDG where consent is required for storing or accessing information on the user's device.
Retention: According to the lifetime disclosed for the relevant technology in the cookie or consent settings, or until consent is withdrawn where applicable.
Marketing communications
Purpose: To send newsletters, product information or commercial communications where legally permitted.
Legal basis: Article 6(1)(a) GDPR where consent is required. Existing-customer marketing may, where the statutory conditions are satisfied, be based on legitimate interests under Article 6(1)(f) GDPR together with § 7(3) UWG.
Retention: Until consent is withdrawn, an objection is made or the marketing purpose no longer exists, subject to limited retention necessary to document consent or objections.
Legal compliance and claims
Purpose: To comply with legal obligations, respond to authorities and establish, exercise or defend legal claims.
Legal basis: Article 6(1)(c) GDPR and, where applicable, Article 6(1)(f) GDPR.
Retention: For the period required by the applicable legal obligation or until relevant claims can no longer reasonably be asserted.
5. FarmVizion as Processor for Customer Data
For certain business and IoT services, the FarmVizion customer may determine why and how personal data is processed. In those cases, the customer is the controller and FarmVizion acts as a processor under Article 28 GDPR. Such processing is subject to the applicable Data Processing Agreement (DPA), customer instructions and contractual security requirements.
6. Cookies and Similar Technologies
FarmVizion may use cookies, local storage, SDKs or comparable technologies. They are treated according to their purpose:
- Strictly necessary technologies may be used without consent where they are required to provide a digital service expressly requested by the user or to transmit communications.
- Optional analytics, advertising, tracking and comparable technologies are activated only after the required consent has been obtained.
- Where optional technologies process personal data, processing is based on Article 6(1)(a) GDPR unless another lawful basis clearly applies.
- The consent interface should identify the relevant providers, purposes, storage technologies and durations.
Consent may be refused or withdrawn at any time through the cookie or privacy settings made available on the website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7. Recipients of Personal Data
- Hosting, cloud infrastructure and IT service providers.
- Payment and billing service providers where payments are processed.
- Logistics, delivery and fulfilment partners where physical products are supplied.
- Communication, email and customer-support service providers.
- Analytics or similar service providers only where their use is lawful and, where required, consent has been obtained.
- Professional advisers such as lawyers, auditors or tax advisers where necessary.
- Public authorities, regulators or courts where disclosure is legally required.
- Business customers for whom FarmVizion processes information in accordance with the applicable contractual roles.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area, FarmVizion uses a legally permitted transfer mechanism. This may include an adequacy decision of the European Commission, the EU-U.S. Data Privacy Framework for appropriately certified recipients, or Standard Contractual Clauses together with supplementary safeguards where required. Information about applicable safeguards may be requested from FarmVizion.
9. Data Retention
- Personal data is not retained indefinitely and is deleted or anonymised when the relevant processing purpose and legal retention obligations cease to apply.
- Contract and account information may be retained after termination where necessary for legal claims or statutory documentation.
- Invoices and relevant accounting records are retained in accordance with German tax and commercial-law requirements.
- Data subject requests and consent records may be retained where necessary to demonstrate compliance with GDPR obligations.
- Backups may retain deleted data for a limited additional period until the relevant backup cycle expires.
10. Your GDPR Rights
Subject to the applicable legal requirements, you may have the following rights:
- Right of access under Article 15 GDPR.
- Right to rectification under Article 16 GDPR.
- Right to erasure under Article 17 GDPR.
- Right to restriction of processing under Article 18 GDPR.
- Right to data portability under Article 20 GDPR.
- Right to object to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR.
- Right to withdraw consent at any time, without affecting processing carried out before withdrawal.
- Right to lodge a complaint with a competent data protection supervisory authority.
11. AI and Automated Decision-Making
FarmVizion uses AI and automated systems to generate agricultural insights, recommendations and operational analytics. Unless expressly disclosed for a particular service, FarmVizion does not use solely automated processing to make decisions about individuals that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR. If such processing is introduced, the required additional information and safeguards will be provided.
12. Children's Data
FarmVizion services are intended for businesses, professionals and adult users and are not directed to children. We do not knowingly seek to collect personal data from children through our commercial services.
13. Data Security
FarmVizion implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Security measures are reviewed and adapted according to the nature, scope, context and risk of the processing.
14. Right to Lodge a Complaint
You may lodge a complaint with a competent supervisory authority. For private-sector controllers established in Bavaria, the competent supervisory authority is generally the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
15. Privacy Contact
For privacy questions or to exercise your data protection rights, contact: support@farmvizion.de