Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) is incorporated by reference into, and forms part of, the EcoIntel Terms of Service (the “Terms”). It governs the processing of personal data that Ecological Intelligence Ltd (“EcoIntel”, “we”, the “Processor”), registered in England and Wales (No. 16866497), registered office Brimbles, Ashburton, Newton Abbot, England, TQ13 7HU, carries out on behalf of a customer (the “Customer”, the “Controller”) in providing the EcoIntel Land Health System and related services (the “Services”). References in this DPA to the “main agreement” mean the Terms.
1. Definitions
Terms not defined here have the meaning given in the UK GDPR.
- Data Protection Legislation: the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR (Regulation 2016/679), together with any successor or implementing legislation.
- Controller, Processor, Personal Data, Processing, Data Subject, Personal Data Breach, Supervisory Authority: as defined in the Data Protection Legislation.
- Customer Personal Data: Personal Data that EcoIntel processes on behalf of the Customer in providing the Services.
- Sub-processor: any third party engaged by EcoIntel to process Customer Personal Data.
- Transfer Mechanism: the UK International Data Transfer Agreement (IDTA); the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914); the EU Standard Contractual Clauses with the UK Addendum; the EU-US Data Privacy Framework and its UK Extension (the “UK-US data bridge”); or another lawful mechanism for international transfers of personal data.
2. Roles and scope of processing
2.1 The Customer is the Controller and EcoIntel is the Processor in respect of Customer Personal Data.
2.2 EcoIntel will process Customer Personal Data only to provide the Services and only on the Customer’s documented instructions, including those in this DPA, the main agreement, and any later written instructions. If EcoIntel considers that an instruction infringes the Data Protection Legislation, it will inform the Customer. Where EcoIntel is required by UK or EU law to process Customer Personal Data otherwise than on the Customer’s instructions (including any transfer of Customer Personal Data to a third country or international organisation), it will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
2.3 The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
2.4 EU/EEA controllers. Where the Customer is established in the EU/EEA, or the processing of Customer Personal Data is subject to the EU GDPR: (a) references in this DPA to provisions of the UK GDPR are read as references to the equivalent provisions of the EU GDPR; (b) the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply to, and govern, transfers of such Customer Personal Data to EcoIntel and onward to Sub-processors outside the EU/EEA, prevailing over this DPA on transfer matters and on their own governing law and forum; and (c) “Supervisory Authority” includes the competent EU/EEA supervisory authority.
3. EcoIntel’s obligations
EcoIntel will:
3.1 Instructions. Process Customer Personal Data only as set out in clause 2.2.
3.2 Confidentiality. Ensure that the people authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality.
3.3 Security. Implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking account of the state of the art, the costs of implementation and the nature, scope and purposes of processing, as required by Article 32 of the UK GDPR (and the equivalent provision of the EU GDPR where it applies). The measures set out in Annex 2 are the contractual baseline; EcoIntel may add to them but will not materially reduce the overall security of the Services during the term.
3.4 Sub-processors.
(a) The Customer gives a general authorisation for EcoIntel to engage the Sub-processors listed in Annex 3.
(b) EcoIntel will give at least 30 days’ notice of any intended addition or replacement of a Sub-processor (by updating its published sub-processor list or by written notice). The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Services. If the Customer terminates the affected Services for that reason, EcoIntel will refund any pre-paid fees for the unexpired part of the term on a pro-rata basis.
(c) EcoIntel will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable to the Customer for each Sub-processor’s performance.
3.5 Assistance. Taking account of the nature of the processing, EcoIntel will assist the Customer by appropriate technical and organisational measures, so far as possible, to: (a) respond to Data Subjects exercising their rights; and (b) comply with its obligations on security, Personal Data Breach notification, data protection impact assessments and prior consultation with a Supervisory Authority (Articles 32 to 36 of the UK GDPR, and the equivalent provisions of the EU GDPR where it applies). EcoIntel provides reasonable assistance of this kind at no charge; where assistance is extensive or repeated, EcoIntel may charge its reasonable costs, notified in advance.
3.6 Breach notification. Notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide the information the Customer reasonably needs to meet its own notification obligations.
3.7 Deletion or return. At the end of the Services, and at the Customer’s choice, delete or return all Customer Personal Data and delete existing copies, unless the law requires EcoIntel to retain it.
3.8 Records and audits. Make available the information reasonably necessary to demonstrate compliance with this clause 3, and allow for and contribute to audits on reasonable prior notice, no more than once a year (unless a Supervisory Authority or a Personal Data Breach requires otherwise), subject to confidentiality and EcoIntel’s security policies. EcoIntel may satisfy this obligation by providing relevant third-party certifications and reports (its own and its Sub-processors’, such as Google Cloud’s ISO 27001 and SOC 2 reports) together with reasonable responses to a security questionnaire, with on-site inspection reserved for where there is good cause. EcoIntel may charge its reasonable costs for audits beyond one per year or beyond this standard support.
3.9 Artificial intelligence. Where EcoIntel uses an AI service (currently Anthropic’s Claude API) to generate the Customer’s reports or, where the Customer enables it, to help draft and structure the Customer’s disclosure evidence, Customer Personal Data sent to that service is processed only to produce the outputs the Customer has requested, under this DPA, and is not used to train or improve the AI provider’s models. AI-generated text is decision-support only and is not treated as evidence; the Customer’s authorised user attests the final wording. The data sent to that service is retained by the provider only for a limited period (currently up to around 30 days) for abuse-monitoring before deletion, and is transferred to the United States under the Transfer Mechanism shown for that Sub-processor in Annex 3.
3.10 Disclosure evidence. Where the Customer’s authorised users upload files or notes as evidence for disclosures, EcoIntel stores them in a private, access-controlled store located in the European Union, reachable only through short-lived, owner-scoped links, and deletes them on deletion of the relevant property or account in accordance with clause 3.7.
3.11 Anonymisation for service improvement. Where the Customer’s authorised user has enabled the “platform improvement” permission, EcoIntel may irreversibly anonymise Customer Personal Data and use the resulting anonymised data to maintain and improve the Services, including after the end of the Services. Anonymised data that can no longer be attributed to an identified or identifiable Data Subject is not Customer Personal Data and is outside the scope of this DPA. EcoIntel does not attempt to re-identify anonymised data.
4. International transfers
EcoIntel will not transfer Customer Personal Data outside the UK or the European Economic Area unless it has put in place a valid Transfer Mechanism or the transfer is otherwise lawful. The current Sub-processors and the countries in which they process Customer Personal Data are listed in Annex 3, together with the Transfer Mechanism that applies to UK-origin and to EU/EEA-origin data respectively.
5. General
5.1 This DPA forms part of, and is subject to, the main agreement between the parties. Where this DPA and the main agreement conflict on the parties’ data-protection obligations, this DPA prevails; in all other respects, including the allocation and limitation of liability, the main agreement governs.
5.2 This DPA takes effect when the Services begin and continues for as long as EcoIntel processes Customer Personal Data.
5.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without prejudice to any mandatory rights of Data Subjects and without prejudice to clause 2.4 (where the EU Standard Contractual Clauses carry their own governing law and forum for transfer matters).
5.4 Each party’s total liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the main agreement, except for liability that cannot be excluded or limited under the Data Protection Legislation or other mandatory law.
Annex 1: Details of the processing
- Subject matter: EcoIntel’s provision of the Land Health System and related diagnostic and reporting services.
- Duration: the term of the Services.
- Nature and purpose: hosting, assessing, diagnosing and reporting on the health of land, from data the Customer provides or authorises, and supporting the Customer’s use of the Services.
- Types of Personal Data: account and user contact details (name, email, role); land-holding and business identifiers that may be personal data (for example Single Business Identifier (SBI) numbers, field and parcel boundaries, holding addresses); files or notes the Customer uploads as disclosure evidence; and any other Personal Data the Customer chooses to submit.
- Categories of Data Subjects: the Customer’s authorised users, and individuals identifiable from the data the Customer submits, such as named landowners, farmers or land managers.
Annex 2: Technical and organisational measures
This Annex is the contractual baseline for the security measures. The summary published at www.ecointel.io/trust may add current detail but does not reduce it.
- Encryption in transit: all connections use TLS.
- Encryption at rest: stored data is encrypted by default (AES-256) on Google Cloud Platform. Backups are additionally encrypted client-side before leaving EcoIntel’s systems, versioned, made immutable, with keys held offline.
- Data location: the primary database is hosted in the United Kingdom (London); encrypted backups are held in the European Union (Amsterdam); disclosure-evidence files are held in a private Google Cloud Storage bucket in the European Union, reachable only through short-lived, owner-scoped signed URLs.
- Access control: access to Customer Personal Data is restricted to a small number of named, authorised personnel under confidentiality (currently the founders and our development partner, Vu Digital).
- Infrastructure: the Services run on Google Cloud Platform, which holds ISO 27001 and SOC 2 certification.
- Resilience: regular, encrypted, versioned, immutable off-site backups.
Annex 3: Sub-processors
Transfer mechanisms are shown for both UK-origin and EU/EEA-origin Customer Personal Data.
| Sub-processor | Purpose | Location | UK-origin transfer | EU/EEA-origin transfer |
|---|---|---|---|---|
| Google Cloud Platform | Application hosting, database, satellite data processing | United Kingdom (London) | Not applicable (UK) | EU adequacy decision for the UK |
| Backblaze | Encrypted off-site backups | European Union (Amsterdam) | UK adequacy (EEA) | Not applicable (EEA) |
| Anthropic | AI generation of land-health reports and, where enabled, AI assistance for disclosure evidence | United States | IDTA | EU SCCs |
| Resend | Transactional email delivery (account, report and billing notifications) | United States | UK-US data bridge | EU-US DPF (or EU SCCs) |
| Stripe | Payments and billing | European Union (Ireland) | UK adequacy (EEA) | Not applicable (EEA) |
| Cloudflare | Website delivery, security, analytics | United States | UK-US data bridge | EU-US DPF (or EU SCCs) |
| Microsoft Azure | Sign-in and authentication | United States | UK-US data bridge | EU-US DPF (or EU SCCs) |
| Google Workspace | Business email and documents | United States | UK-US data bridge | EU-US DPF (or EU SCCs) |
| Vu Digital | Application development and marketing | United Kingdom | Not applicable (UK) | EU adequacy decision for the UK |
| FreeAgent | Accounting and billing administration | United Kingdom | Not applicable (UK) | EU adequacy decision for the UK |
The current list is maintained at www.ecointel.io/trust. Transfer mechanisms reflect each provider’s current Data Privacy Framework status, verified on the official DPF list; where a provider is not DPF-certified (currently Anthropic only; Cloudflare, Microsoft, Google and Resend are certified under the EU-US DPF and its UK Extension, verified on the official DPF list), the IDTA applies to UK-origin data and the EU SCCs apply to EU/EEA-origin data. EcoIntel reviews these if a provider’s status changes.