Legal
Farmsured™ Privacy Policy
Last updated: 7 October 2026
1. Introduction
Agribusiness Dynamics Technology Limited (AgDYNA®) ("AgDyna", "we", "us" or "our") operates Farmsured™, including the Farmtrove™ benefits and financial-services layer made available through Farmsured. We are committed to handling personal data lawfully, fairly, transparently and securely.
This Privacy Policy explains the personal data we collect or receive, how we use it, the circumstances in which we share it, how long we retain it, the choices and rights available to you, and how to contact us. It applies to the Farmsured mobile application, websites and dashboards, APIs, and other supported channels through which Farmsured services are provided.
We process personal data in accordance with the Nigeria Data Protection Act 2023 (NDP Act), the Nigeria Data Protection Act – General Application and Implementation Directive 2025 (GAID 2025), and other applicable Nigerian laws and regulatory requirements.
2. Who We Are and How to Contact Us
| Field | Details |
|---|---|
| Data controller | Agribusiness Dynamics Technology Limited (AgDYNA®) |
| Address | 14 Alaafin Avenue, Oluyole Estate, Ibadan, Oyo State, Nigeria |
| Data protection and privacy contact | hello@farmsured.com |
| Farmsured privacy page | farmsured.com/privacy-policy |
| Account deletion page | farmsured.com/account-deletion |
Where a benefit, payment, identity-verification, banking, insurance, healthcare or other regulated service is provided by a partner, that partner may act as our processor or as an independent data controller, depending on the service and legal arrangement. Where it acts as an independent controller, its own privacy notice also applies. The relevant provider is identified in the Service before you enrol in or use that feature, where required.
3. Information We Collect
Account, profile and authentication data. Your name, phone number, email address, profile image, date of birth where required, account role, organisation or company details, cluster/cooperative membership, preferences, authentication credentials and security settings. We also process login, session and account-status information needed to secure your account.
Identity and KYC information. Where identity verification is required, we may process your BVN, NIN, government-issued identity documents, identity numbers, address, photographs or selfies used for verification, and verification results. We collect only the information required for the relevant KYC or regulated service.
Farm, production and assurance data. Farm identity and ownership/assignment information; farm and production-unit locations; enterprise and production-cycle details; production protocols and checkpoints; activities and submissions; input and tag lineage; treatment and vaccination records; mortality and production measurements; samples and laboratory evidence; non-conformity and corrective-action records; compliance/production-assurance results; and FICS, FPCS and FOCS status or related evidence where those modules are used.
Tag, verification and traceability data. Tag or label PINs and QR codes scanned, product and batch references, scan timestamps, verification/activation results, activity references, and geolocation attached to a scan where location permission is granted and the feature requires it.
Financial, wallet and payment data. Wallet balances and transaction history, virtual-account information, bank account details you provide for payments or transfers, payment records, bill-payment and airtime/data purchase records, escrow activity, transfer records, holds, reversals and other finance-related records generated through Farmtrove.
Linked bank and open-banking data. If you choose to connect an external bank account or use a bank-data service, we may receive account information, balances, transaction history, income indicators and related financial data made available through the authorised connection. This is separate from BVN/NIN identity verification.
Credit, risk and loan data. Loan applications, amount and purpose, facility terms, affordability/income indicators, KYC/risk-check results, offers, approvals, disbursements, repayment history, arrears/default status and related audit information.
Benefits, claims and dependant/beneficiary data. Benefit enrolment, insurance or other benefit selections, claims, supporting documents, provider interactions, redemption history, and the identity/contact details of beneficiaries or dependants you nominate. Where a healthcare or health-related benefit is offered and you choose to use it, this may include health information needed for that benefit or claim.
Marketplace and commercial data. Products or services viewed, listings, orders, opportunity interests/orders, produce sales, booking/trade references, invoices, delivery or waybill information, and payment/settlement status.
AI, advisory and intelligence interactions. Questions, prompts and files you submit to FarmGPT, AI agents or intelligence features; farm, cycle, FICS or other authorised context supplied to those features; generated responses, reports and suggestions; feedback; and usage records needed to operate, secure and improve those features.
Communications and user content. Messages sent through Farmsured, support requests, reports, complaints, notes, documents, images, evidence and other content you submit or share through the Service.
Device, app, security and audit data. Device and app information, operating system, app version, IP address, user-agent, session identifiers, route/request audit events, crash or diagnostic information, feature usage, timestamps, security events and fraud-prevention signals.
Notification data. Push-notification tokens, delivery/status information and communication preferences needed to send service, transaction, security and compliance notifications.
| Important distinction. Providing a BVN/NIN for identity verification is not the same as linking a bank account. A linked-account feature may provide separate account, balance, transaction or income data only when you choose or authorise that connection and the relevant provider flow is completed. |
|---|
4. Device Permissions and Mobile Features
The Farmsured mobile app may request device permissions only when needed for a feature. You can manage permissions through your device settings, although disabling a permission may prevent the related feature from working.
| Permission / feature | How it is used |
|---|---|
| Camera | To scan QR codes or Farmsured tags and, where a feature supports it, to capture evidence you choose to submit. A routine QR/tag scan does not require us to retain a camera image. |
| Location | For farm mapping, geotagged scan/verification records, field activity evidence, fraud prevention and other location-dependent features. Approximate or precise location may be requested depending on the feature and your permission. |
| Notifications | To deliver transaction, security, compliance, activity, loan/benefit and other service notifications. The app stores or transmits a push token needed for delivery. |
| Biometric authentication | Where enabled, the app may use your device’s biometric authentication capability to confirm that the authorised device user is present. The biometric match is performed by the device/operating system; Farmsured receives the authentication result rather than your fingerprint or facial template. |
| Files / photos | Where you choose to upload identity documents, claim documents, farm evidence, laboratory files, profile images or other supporting records. |
5. How We Use Your Information and Our Lawful Bases
| Purpose | Lawful basis |
|---|---|
| Create, secure and operate your account | Performance of a contract; legitimate interest in account security |
| Authenticate you, manage sessions, OTP/biometric login and prevent account abuse | Performance of a contract; legitimate interest; legal obligation where applicable |
| Verify identity and complete KYC for regulated or higher-risk services | Legal obligation and/or performance of a contract, depending on the service |
| Register farms, production units and cycles; execute compliance protocols and record production evidence | Performance of a contract |
| Verify inputs/tags, record scans and maintain traceability | Performance of a contract; legitimate interest in authenticity, fraud prevention and food-safety assurance |
| Use location for mapping, geotagged scans or other location-dependent features | Consent/device permission; performance of the requested feature |
| Calculate compliance, production-assurance, points, eligibility or FOCS-readiness indicators | Performance of a contract; legitimate interest in operating the assurance system |
| Process wallet activity, payments, transfers, escrow, bills and related financial transactions | Performance of a contract; legal obligation where applicable |
| Connect an external bank account and process authorised account/transaction/income data | Consent and/or performance of a contract, depending on the connection and service |
| Process credit applications, risk/KYC checks, offers, disbursements, repayments and collections | Performance of a contract; legal obligation; legitimate interest in credit-risk management |
| Administer insurance, healthcare and other benefits or claims | Performance of a contract; explicit consent where health data or another consent-based category is involved |
| Operate marketplace, order, listing and trade functions | Performance of a contract |
| Operate FarmGPT, AI agents and intelligence features | Performance of a contract; legitimate interest in safety, quality, security and service improvement |
| Send service, transaction, security, compliance and account notifications | Performance of a contract; legitimate interest; legal obligation where applicable |
| Detect fraud, counterfeiting, abuse, security incidents and policy violations | Legitimate interest; legal obligation |
| Maintain audit trails, investigate complaints and defend legal claims | Legitimate interest; legal obligation |
| Produce statistics, research and product-performance analysis | Legitimate interest; anonymised or aggregated data where reasonably possible |
| Meet tax, AML, regulatory, court and law-enforcement obligations | Legal obligation |
We do not sell your personal data. We do not use your personal data for third-party behavioural advertising. If we introduce optional promotional communications, we will provide any consent or opt-out required by law.
6. Automated Processing, Scoring and AI
Farmsured uses automated processing to support parts of the Service. Depending on the feature, this may include:
compliance and production-assurance calculations based on recorded checkpoints, activities and evidence;
points, reward and benefit-eligibility calculations based on applicable rules and status;
fraud, security or risk flags;
credit or risk assessment performed or supported by a financial or lending partner; and
AI-generated advisory, analysis, reports, suggestions or conversational responses.
Where a decision is based solely on automated processing and has a legal or similarly significant effect on you, you may request human review, express your point of view and contest the decision, subject to applicable law. If the decision is made by an independent partner, we will direct or transmit your request to that partner where appropriate.
AI-generated advice is an informational and decision-support feature. We do not treat an AI-generated response by itself as a final credit, insurance, disciplinary or compliance-enforcement decision. When a third-party AI or infrastructure provider processes prompts or context on our behalf, we limit the data shared to what is needed for the feature and apply the contractual and security safeguards appropriate to that service.
7. When We Share Personal Data
We share personal data only where necessary for a service, with your direction or consent where required, under contract, or where the law permits or requires it. Depending on the relationship, a recipient may act as our processor or as an independent controller.
| Recipient category | What may be shared / why |
|---|---|
| Identity-verification and KYC providers | Identity details, BVN/NIN, documents, verification images and results needed to verify identity or meet KYC requirements. |
| Payment, banking and open-banking providers | Payment/transfer details and, where you authorise a linked account, the account, balance, transaction or income data needed to provide the requested feature. |
| Licensed financial, credit and benefit partners | Identity, contact, farm/compliance, financial, loan, benefit and claims data needed to provide a service you apply for or use. |
| Insurance or healthcare providers | Benefit/claim information and, only where needed and lawfully processed, health-related information for the relevant benefit or claim. |
| Cluster/cooperative officers and authorised farm-support personnel | Farm, cycle, activity and compliance information within the role and farm/cluster assignment necessary to support or verify production. |
| Buyers, offtakers and marketplace participants | Information you intentionally include in a listing/order or that is necessary for a transaction, plus assurance or traceability status intended to support market access. |
| Product manufacturers / owners | Aggregated or de-identified verification and scan statistics where possible. Identifiable data is shared only where required for a transaction, investigation or another disclosed purpose. |
| AI, cloud, storage, communications, notification, analytics and security providers | Data they process on our behalf to host, store, transmit, analyse, secure or operate Farmsured, including authorised AI interactions, subject to applicable contracts and safeguards. |
| Credit bureaux and regulatory reporting recipients | Credit, facility and repayment information where reporting is permitted or required by applicable law or the relevant credit arrangement. |
| Professional advisers, auditors and compliance providers | Information necessary for legal, audit, risk, data-protection, accounting or compliance work, subject to professional or contractual confidentiality. |
| Regulators, courts and law-enforcement authorities | Information required by law, lawful process, court order, regulatory request, fraud prevention or safety/security obligations. |
| Other users you choose to interact with | Profile, message, transaction or collaboration information that you intentionally send or make visible through a relevant Farmsured feature. |
If a provider or partnership changes, we stop routine sharing with the former provider unless it must retain or continue processing specific records for legal, contractual, dispute-resolution, fraud-prevention or regulatory reasons.
8. Health, Identity, Financial and Other Higher-Risk Data
Health data. Health information is sensitive personal data. If a healthcare or health-related benefit is available and you choose to use it, we collect only the information needed for enrolment, service delivery or a claim, and we use an appropriate lawful basis, including explicit consent where required. Health information is not used to calculate your general Farmsured production-compliance score or as a general input to credit decisions. You may withdraw consent where consent is the lawful basis, although this may make the health-related feature unavailable.
Government identifiers and KYC data. BVN, NIN and identity-verification material are used for identity/KYC purposes and other legally permitted purposes disclosed at collection. Access is restricted and sensitive KYC identity payloads are protected with application-level encryption in the current system. A BVN/NIN verification request is distinct from an optional linked-bank-account connection.
Financial and linked-bank data. Wallet, payment, transfer, credit and authorised linked-account data are used only for the relevant financial/transactional feature, risk management, fraud prevention and legal/regulatory duties. They are not shared with product manufacturers, ordinary cluster members or unrelated users merely because they use Farmsured.
Dependant and beneficiary data. If you provide personal data about another person, including a minor dependant, you confirm that you have authority to provide it and that it is accurate. We use it only for the benefit, claim, beneficiary or related purpose for which it was provided, unless another lawful basis applies.
9. Data Security
We use technical and organisational safeguards designed for the nature and sensitivity of the data and the risks of the Service. Current controls include:
TLS/HTTPS for data in transit between supported clients, our systems and external services;
application-level encryption for sensitive KYC identity payloads, together with protected secret/key management;
password hashing and protected authentication credentials;
short-lived access tokens, refresh-token/session controls, hardened production cookies and rate limiting on sensitive authentication and AI endpoints;
role-based and permission-based access controls so users and staff can access only authorised functions and data;
audit logging of authenticated requests and sensitive operations, including security-relevant session events;
webhook/signature verification for supported external payment, banking and benefit integrations;
security headers, origin controls and other API protections; and
contractual confidentiality and data-protection obligations for processors and service providers where applicable.
No information system can be guaranteed to be completely secure. Do not share your password, transaction PIN or one-time code with anyone. If you believe your account or personal data has been compromised, contact hello@farmsured.com immediately. If a personal-data breach occurs, we will assess it and make notifications required by applicable law.
10. Data Retention, Account Closure and Deletion
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, to maintain agricultural assurance and traceability records, to provide active services, to resolve disputes and prevent fraud, and to meet legal, financial, tax, AML, credit, insurance, audit or regulatory obligations. Retention may therefore differ by data category and service.
| Data category | Retention approach |
|---|---|
| Account/profile data | While the account is active. After a valid deletion request, data not subject to a retention exception is deleted or de-identified within the operational deletion process. |
| Farm, production, compliance and traceability records | For the period needed to preserve assurance, audit and traceability history and meet contractual, dispute-resolution or regulatory needs; then deleted or de-identified when no longer necessary. |
| Scans, FICS/FPCS/FOCS evidence and assurance decisions | For the period needed for traceability, food-safety assurance, audits, fraud/counterfeit investigations and related legal or contractual requirements. |
| Messages, support and marketplace records | For the life of the relevant account, transaction or support matter and for a limited period afterwards where needed for disputes, safety, fraud prevention or legal claims. |
| AI/advisory interactions and usage logs | For a limited period needed to operate, secure, evaluate and improve the feature, subject to configured retention and any legal hold; data may be de-identified earlier where appropriate. |
| Security, session and audit logs | For a limited security/audit period appropriate to fraud prevention, incident investigation, accountability and legal requirements. |
| Financial, wallet and transaction records | For the statutory or regulatory period applicable to the transaction or service, and longer only where a legal hold, dispute or other lawful requirement applies. |
| KYC/identity records including BVN/NIN | For the period required for KYC/AML, fraud-prevention, regulatory or contractual obligations associated with the service; then securely deleted or de-identified when no longer required. |
| Credit/loan records | For the life of the facility and the applicable legal/regulatory/credit-reporting retention period after settlement or closure. |
| Insurance/health/benefit records | For the period required to administer the benefit/claim and any retention period imposed by the provider or applicable regulator. |
If you request account deletion, we will delete or de-identify personal data that we are not required or permitted to retain, and we will instruct relevant processors to delete associated data where applicable. Some records may remain where necessary for security, fraud prevention, agricultural traceability, an active financial obligation, legal claims or regulatory compliance. Retained records are restricted to those purposes and deleted or de-identified when the retention reason ends.
An active loan, claim, transaction, audit or other obligation may therefore limit deletion of the records needed to administer that obligation, but it does not prevent you from submitting an account-deletion request. You can initiate deletion through the in-app account settings and through farmsured.com/account-deletion. The web route must remain usable even if you no longer have the app installed.
11. Your Data Protection Rights
Subject to the NDP Act, GAID 2025 and any lawful limitations or exemptions, you may have the right to:
be informed about how your personal data is processed;
access personal data we hold about you;
correct inaccurate or incomplete personal data;
request deletion or erasure, subject to lawful retention requirements;
restrict processing in applicable circumstances;
object to processing based on legitimate interests in applicable circumstances;
receive portable data in a structured, commonly used format where the portability right applies;
withdraw consent at any time where consent is the lawful basis, without affecting earlier lawful processing;
request human review of a qualifying solely automated decision;
lodge a complaint with us; and
lodge a complaint with the Nigeria Data Protection Commission.
To exercise a right, contact hello@farmsured.com or use an available in-app privacy/deletion route. We may ask you to verify your identity before acting on a request. We will respond within the period required by applicable law and may explain where a lawful exemption, retention duty or identity-verification requirement applies.
12. Cookies, Secure Storage and Analytics
Our websites may use cookies, session technologies and local storage needed for authentication, security, preferences and service operation. The mobile app may use secure device storage for authentication tokens and settings. Clearing browser/app storage or uninstalling the app removes local data from that device but does not by itself delete your Farmsured account or server-side records.
We may use analytics, diagnostics and crash reporting to understand service performance, investigate faults and improve reliability. We do not use third-party advertising cookies or tracking technologies for behavioural advertising.
13. Age Restriction and Information About Minors
Farmsured user accounts are intended for persons aged 18 and over. Farmtrove financial and regulated benefits may be available only to adults and may require additional eligibility checks.
We do not knowingly permit a person under 18 to open and operate a Farmsured account. If we learn that an account belongs to a minor, we will take steps to close the account and delete data that we are not legally required to retain.
An adult account holder may, however, provide limited data about a child or other minor as a dependant or beneficiary for an eligible insurance, healthcare or other benefit. In that case, we process only the information needed for that benefit or claim, apply heightened protections where sensitive data is involved, and rely on the adult’s authority and the appropriate lawful basis for the processing.
14. International Data Transfers
Some infrastructure, cloud, communications, AI, analytics or other service providers may process data outside Nigeria. Where personal data is transferred internationally, we use an available lawful transfer mechanism and safeguards required by the NDP Act and GAID 2025, taking into account the destination, the recipient and the nature of the processing. These may include an applicable adequacy basis, approved transfer safeguards/instruments, contractual protections, consent where valid, or another lawful basis recognised by Nigerian law.
15. Changes to This Policy
We may update this Privacy Policy to reflect changes to Farmsured, Farmtrove, our partners, technology, law or regulatory guidance. We will update the “Last updated” date and, where a change materially affects your rights or the way we process personal data, provide an appropriate notice through the Service or another reasonable channel before or when the change takes effect, as required by law.
16. Contact and Complaints
For questions, privacy requests, account-deletion issues, complaints or concerns about how we handle personal data, contact:
Agribusiness Dynamics Technology Limited (AgDYNA®)
14 Alaafin Avenue, Oluyole Estate, Ibadan, Oyo State, Nigeria
Email: hello@farmsured.com
If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC).
Farmsured™ and Farmtrove™ are products of AgDYNA® (Agribusiness Dynamics Technology Limited) · www.agdyna.com
