Trust
Data processing and sub-processors
Better Yield is the engine behind partner-branded precision agriculture services. This page sets out who holds which role, where data is hosted, and which providers process it, so a partner can complete due diligence without a call.
Controller and processor roles
Partner customer data — we are the processor
Field boundaries, zones, soil analyses, prescriptions and export files belong to the partner who operates the account. The partner determines the purposes and means and is the controller; Better Yield processes that data only on the account holder’s instructions and never for its own purposes.
Account and login data — we are the controller
We are the controller for the data needed to run the service itself: account identities, authentication events, audit records and the security logs that show who did what. This is what lets us keep the platform available and accountable.
This website — we are the controller
Enquiries and technical access data from betteryield.farm are our own responsibility as controller and are covered by the privacy notice rather than by any partner agreement.
Sub-processors
These providers may process customer data on our behalf. Each is bound by its own confidentiality and security terms, and we remain responsible for how the service uses them.
| Provider | Purpose | Processing location |
|---|---|---|
| DigitalOcean | Application hosting, managed PostgreSQL database, object storage for uploads and exports | Frankfurt, Germany (EU) |
| Cloudflare | DNS, TLS termination, content delivery and protection against attack traffic | EU edge, global network |
| Mailgun (Sinch) | Delivery of transactional and notification email | European Union |
| Sentry | Application error and performance monitoring | Germany (EU) |
| PostHog | Website analytics and session replay on this marketing site, only where the visitor has consented. Not used inside the platform. | Frankfurt, Germany (EU); provider established in the United States |
| Mapbox | Map tiles and geocoding shown in the product interface | United States |
| Optional single sign-on, and appointment scheduling from this website | United States and European Union |
Where data is hosted
The application, its PostgreSQL database and uploaded files are hosted in the European Union, in a Frankfurt region. Backups stay within the same region. Agronomic data does not leave the EU in the ordinary course of running the service.
What we hold
Field boundaries and geometry, zone definitions, soil laboratory results, crop and fertiliser selections, calculated prescriptions and exported files; plus the account identities, roles and audit records needed to operate them. We do not ask for special-category personal data and the platform is not designed to receive it.
How long we keep it
Customer data is retained for as long as the account is active. On termination it is deleted or returned at the partner’s choice, subject to any retention we are legally required to observe. Website enquiries are deleted after twelve months. Operational logs are short-lived and used only for security and reliability.
Transfers outside the EU
Map tiles and optional Google sign-in involve providers established in the United States. Those transfers rest on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise on standard contractual clauses together with supplementary measures.
Security
Access is authenticated and role-based, and separated per account so one partner cannot reach another’s data. Traffic is encrypted in transit, secrets are held in the platform configuration rather than in the code base, and administrative actions including any support impersonation are recorded in an audit trail.
Effective date: 16 August 2026