Agribantu / Legal / Privacy Policy

Legal

Agribantu Privacy Policy

What personal information Agribantu processes, where it comes from, why, when it may be shared, how it's protected, how long it's kept, and the rights available to affected persons.

Version 1.0 Effective date: 17 July 2026

1. Introduction

Agribantu respects the privacy of the people, organisations and communities that use its websites, applications, APIs, mobile services and related technology.

This Privacy Policy explains:

  • what personal information Agribantu processes;
  • where that information comes from;
  • why it is processed;
  • when it may be shared;
  • how it is protected;
  • how long it is retained; and
  • the rights available to affected persons.

This policy should be read together with the Agribantu Platform and Website Licence, any applicable customer agreement, data-processing agreement and product-specific notice.

2. Who operates Agribantu

Agribantu is a farmer-led platform and network, currently operated on a small scale as it builds toward public launch. It does not yet operate through a registered company — it is contactable through its web presence and the email addresses below.

Trading nameAgribantu
Country of operationRepublic of South Africa
General enquirieshello@agribantu.co.za
Privacy enquiriesprivacy@agribantu.co.za
Information OfficerNot yet appointed or registered with the Information Regulator. Until an Information Officer is registered, direct privacy queries to the address above.

In this policy, “Agribantu”, “we”, “us” and “our” refer to the operator identified above.

3. Services covered by this policy

This policy applies to personal information processed through:

  • agribantu.co.za;
  • agribantu.com;
  • app.agribantu.com;
  • api.agribantu.com;
  • Agribantu mobile, desktop or embedded applications;
  • Agribantu support, notification and communication services;
  • Agribantu documentation, reports and integrations;
  • location, movement, attendance and device services;
  • livestock, holding and agricultural management services;
  • financial, workforce and organisational services;
  • veterinary, regulatory and authority-facing services; and
  • future services expressly identified as part of Agribantu.

4. Our role when processing information

4.1 Agribantu as responsible party or controller

Agribantu generally acts as the responsible party or controller when it determines why and how information is processed, including for:

  • website visitors;
  • account registration and authentication;
  • subscription and billing administration;
  • support requests;
  • security and fraud prevention;
  • product analytics;
  • direct communications from Agribantu;
  • supplier and business relationships; and
  • Agribantu’s legal and regulatory obligations.

4.2 Agribantu as operator or processor

An organisation using Agribantu normally determines the purposes for which its operational information is collected and used.

In those circumstances:

  • the customer organisation is ordinarily the responsible party or controller; and
  • Agribantu acts as its operator or processor.

This may apply to information concerning:

  • employees and workers;
  • contractors and applicants;
  • managers and organisation administrators;
  • customers and suppliers;
  • livestock owners and handlers;
  • holdings and agricultural operations;
  • veterinary professionals;
  • government or regulatory personnel;
  • beneficiaries, members or community participants; and
  • other persons recorded by a customer.

Where Agribantu acts as operator, the customer is responsible for providing appropriate notices, determining a lawful basis, responding to most data-subject requests and issuing lawful processing instructions.

Agribantu and its customers should enter into an appropriate written data-processing or operator agreement where required.

5. Information we may process

The information processed depends on the Agribantu modules and features used.

5.1 Identity and profile information

This may include:

  • name and surname;
  • preferred name;
  • photograph or avatar;
  • username;
  • employee, membership or reference number;
  • date of birth;
  • nationality;
  • identity or passport information;
  • language preference;
  • signature;
  • job title and department;
  • employment or contractor status;
  • organisational role; and
  • authority, professional or regulatory designation.

5.2 Contact information

This may include:

  • email address;
  • telephone or mobile number;
  • physical or postal address;
  • emergency-contact information; and
  • communication preferences.

5.3 Employment and workforce information

Depending on customer configuration, this may include:

  • employment history;
  • position and reporting structure;
  • qualifications, skills and certifications;
  • contracts and employment classifications;
  • shift and schedule information;
  • attendance and time records;
  • clock-in, clock-out and break information;
  • leave requests and balances;
  • workplace exceptions;
  • performance or operational records;
  • disciplinary or compliance records;
  • training and acknowledgement records;
  • device assignment; and
  • employee-related documents uploaded by authorised users.

5.4 Location, movement and device information

Where a relevant feature is enabled and lawfully authorised, Agribantu may process:

  • GPS or network-derived location;
  • date and time of a location observation;
  • movement route;
  • speed, heading and distance;
  • geofence entry or exit;
  • workplace or holding location;
  • assigned vehicle or asset;
  • mobile device identifier;
  • device operating system and application version;
  • battery status;
  • tracking status;
  • notification token;
  • IP address;
  • session information; and
  • security and diagnostic events.

Location information may be precise and may reveal patterns relating to a person’s work, movement or activities. It must therefore be enabled and used only for a defined, lawful and proportionate purpose.

5.5 Livestock, agricultural and holding information

This may include:

  • holding or farm details;
  • livestock identifiers;
  • ownership or custody information;
  • animal movements;
  • herd and flock records;
  • treatments, vaccinations and inspections;
  • disease and biosecurity events;
  • permit and movement documentation;
  • veterinary assignments;
  • regulatory submissions; and
  • the identity and contact details of persons connected to those records.

Information about an animal or holding may become personal information where it can be linked to an identifiable natural or juristic person.

5.6 Financial and commercial information

Depending on the enabled modules, this may include:

  • customer and supplier information;
  • invoices and transactions;
  • account references;
  • budgets and financial reports;
  • payroll-related information;
  • expense records;
  • subscription and billing information;
  • payment status; and
  • tax or regulatory identifiers.

Agribantu should not collect complete payment-card credentials directly unless an expressly approved payment service and compliant process are in place.

5.7 Authority and regulatory information

This may include:

  • institution and office information;
  • appointments and positions;
  • jurisdiction and service-area information;
  • regulatory campaigns;
  • affidavits, notices and submissions;
  • acknowledgements;
  • inspection or enforcement information;
  • official communications; and
  • audit and routing records.

5.8 Communications and support information

This may include:

  • emails and support requests;
  • feedback;
  • notification preferences;
  • campaign acknowledgements;
  • troubleshooting information;
  • uploaded attachments;
  • survey responses; and
  • records of communications with Agribantu.

5.9 Usage and technical information

This may include:

  • pages and features accessed;
  • timestamps;
  • browser and device type;
  • referring page;
  • application events;
  • error reports;
  • authentication events;
  • API request metadata;
  • security logs; and
  • approximate location inferred from an IP address.

5.10 Special personal information

Some customer-configured workflows may involve information that is treated as special or sensitive under applicable law, such as:

  • health or medical information;
  • biometric information;
  • trade-union information;
  • alleged offences or disciplinary information;
  • racial or ethnic information;
  • religious or philosophical beliefs; or
  • political affiliation.

Agribantu does not require customers to populate such information unless it is necessary for an enabled and lawful workflow. Customers must ensure that additional legal requirements applicable to special personal information are satisfied.

5.11 Information relating to children

Agribantu is primarily intended for organisations and authorised adult users.

A customer must not process information relating to a child through Agribantu unless:

  • the processing is necessary for a legitimate configured service;
  • the customer has appropriate authority or consent;
  • legal requirements relating to children’s information have been met; and
  • suitable safeguards are implemented.

The Information Regulator publishes specific guidance concerning the processing of children’s information and special personal information.

6. How information is collected

Agribantu may receive information:

  • directly from the person concerned;
  • from the person’s employer or contracting organisation;
  • from an organisation administrator;
  • through a mobile or browser application;
  • from an assigned GPS or telematics device;
  • from a connected vehicle, asset or livestock system;
  • through an API or authorised integration;
  • from veterinary or regulatory institutions;
  • from public registers or lawful public sources;
  • from service providers acting on behalf of Agribantu; or
  • automatically through security, diagnostic and usage technologies.

7. Why we process information

Agribantu may process information to:

  • provide, operate and improve the Services;
  • create and secure accounts;
  • authenticate users;
  • apply roles, permissions and organisational boundaries;
  • manage subscriptions and commercial relationships;
  • provide customer support;
  • deliver attendance, workforce and people-management functionality;
  • provide location, movement, fleet and geofence functionality;
  • manage livestock, holdings and agricultural operations;
  • produce operational and financial reports;
  • support veterinary and regulatory workflows;
  • deliver notifications and acknowledgements;
  • integrate with authorised third-party services;
  • prevent fraud, abuse and unauthorised access;
  • investigate errors and security incidents;
  • maintain audit and accountability records;
  • meet contractual and legal obligations;
  • establish, exercise or defend legal claims; and
  • communicate product, service and administrative information.

8. Legal grounds for processing

Depending on the circumstances, processing may be based on:

  • consent;
  • steps requested before entering into a contract;
  • performance of a contract;
  • compliance with a legal obligation;
  • protection of a legitimate interest of the person concerned;
  • performance of a public-law duty by a public body;
  • legitimate interests pursued by Agribantu, a customer or a third party;
  • protection of vital interests;
  • an applicable employment or regulatory requirement; or
  • another ground recognised by applicable law.

Where consent is relied upon, the person may withdraw consent, subject to processing already lawfully undertaken and any other lawful basis that remains applicable.

Agribantu will not describe consent as “freely given” where a person has no genuine choice, such as certain employer-directed activities. The customer must determine and document the appropriate lawful ground for workplace processing.

9. Employee monitoring and location tracking

Agribantu provides tools that may allow organisations to record attendance, location, routes, device status, working time or operational movement.

Agribantu does not independently decide that a particular employee must be tracked. The customer organisation enables and configures these features.

Before using such functionality, the customer should:

  • identify a clear operational or legal purpose;
  • determine an appropriate lawful basis;
  • inform affected persons in understandable language;
  • define when tracking starts and stops;
  • avoid monitoring outside authorised periods;
  • limit access to persons with a legitimate need;
  • configure suitable retention periods;
  • provide an appropriate objection or dispute process; and
  • consider whether a privacy-impact assessment is required.

Agribantu may display a tracking or permission status in the application, but that technical indication does not replace the customer’s legal responsibilities.

10. Automated processing and artificial intelligence

Agribantu may use rules, analytics or artificial-intelligence-assisted functionality to:

  • identify exceptions;
  • classify or summarise records;
  • generate reports;
  • route tasks or submissions;
  • detect unusual activity;
  • make operational recommendations; or
  • assist authorised users in reviewing information.

Unless a specific feature expressly states otherwise, such outputs are intended to assist human users and should not be treated as final legal, veterinary, employment, financial or regulatory decisions.

Agribantu will provide additional information where a feature performs solely automated processing that produces legal or similarly significant effects.

Customers remain responsible for reviewing AI-assisted output before taking consequential action.

11. Cookies and similar technologies

Agribantu may use cookies, browser storage and similar technologies to:

  • maintain secure sessions;
  • remember language and display preferences;
  • prevent cross-site request forgery;
  • preserve application state;
  • measure service performance;
  • diagnose errors; and
  • understand use of public websites.

Strictly necessary technologies may be used where required to operate or secure the Services.

Optional analytics, advertising or marketing technologies should be activated only where an appropriate consent or preference mechanism has been implemented.

A separate Cookie Notice may be published where Agribantu introduces non-essential cookies.

12. When information may be shared

Agribantu may share information with the following recipients where lawful and necessary.

12.1 Customer organisations

Information may be available to authorised customer users such as:

  • organisation owners;
  • administrators;
  • managers;
  • human-resources personnel;
  • finance personnel;
  • compliance personnel;
  • veterinarians;
  • regulatory officials; and
  • other users assigned an appropriate role.

The information visible to each user should depend on their organisation, role, scope and permissions.

12.2 Service providers and operators

Agribantu may use providers for:

  • cloud hosting;
  • databases;
  • content delivery;
  • email and notifications;
  • mobile push delivery;
  • mapping and geocoding;
  • location and telematics;
  • payment processing;
  • support and ticketing;
  • error monitoring;
  • security services;
  • backups; and
  • professional advice.

Providers may process information only for authorised purposes and subject to appropriate contractual and security obligations.

12.3 Customer-authorised integrations

A customer may direct Agribantu to exchange information with an external system.

The customer is responsible for ensuring that:

  • the integration is lawful;
  • the recipient is authorised;
  • credentials are secured; and
  • affected persons receive any necessary notice.

12.4 Legal and regulatory disclosures

Information may be disclosed where reasonably necessary to:

  • comply with applicable law;
  • respond to a valid court order, warrant or regulatory instruction;
  • protect the rights or safety of a person;
  • investigate suspected unlawful activity;
  • report a security compromise;
  • exercise or defend legal claims; or
  • cooperate with a competent authority.

12.5 Corporate transactions

Information may be disclosed under suitable confidentiality safeguards in connection with a proposed or completed merger, acquisition, financing, restructuring or transfer of the Agribantu business.

Agribantu does not sell personal information to advertisers.

13. International and cross-border processing

Agribantu and its service providers may process information outside the country in which it was collected.

Where personal information is transferred across borders, Agribantu will use an appropriate legal mechanism, which may include:

  • transfer to a jurisdiction with adequate protection;
  • a binding agreement providing appropriate safeguards;
  • consent where legally appropriate;
  • contractual necessity;
  • implementation of standard contractual protections; or
  • another transfer basis recognised by applicable law.

Customers should not activate integrations or configure storage locations that result in unlawful cross-border transfers.

For European Economic Area or United Kingdom users, additional safeguards and rights may apply where the GDPR or equivalent legislation applies. The GDPR remains the principal EU framework for the processing of personal data.

14. Information security

Agribantu applies technical and organisational measures intended to protect information against:

  • loss;
  • unauthorised access;
  • unlawful disclosure;
  • alteration;
  • destruction;
  • misuse; and
  • accidental damage.

These measures are described at a high level in the Agribantu Security & Trust Statement.

No online service can guarantee absolute security. Customers and users must also protect their credentials, devices, integrations and account permissions.

15. Security compromises

Agribantu maintains procedures for assessing and responding to suspected security compromises.

Where Agribantu acts as an operator, it will notify the responsible customer as required so that the customer can fulfil its legal obligations.

Where Agribantu acts as the responsible party, it will notify the Information Regulator and affected persons where required by law.

Current Information Regulator guidance states that the responsible party retains the reporting obligation and that an operator must notify the responsible party when a compromise occurs at the operator. The Regulator’s 2025 fact sheet further states that POPIA does not provide a risk threshold below which a compromise may simply go unreported.

16. Retention

Agribantu retains information only for as long as reasonably necessary for the purpose for which it was collected, subject to:

  • customer instructions;
  • contractual obligations;
  • operational requirements;
  • dispute and limitation periods;
  • legal retention duties;
  • security and fraud-prevention needs; and
  • backup and recovery cycles.

Retention periods may differ between categories. Examples include:

CategoryRetention approach
Customer operational dataFor the subscription period and any agreed export or deletion period
Account and access recordsWhile the account is active and for a reasonable security period thereafter
Billing and transaction recordsFor the period required by applicable tax, accounting and company law
Security and audit logsFor a proportionate period based on security and accountability requirements
Support communicationsUntil the issue is resolved and for a reasonable follow-up period
Marketing preferencesUntil withdrawal, objection or suppression, with a limited suppression record retained
BackupsUntil overwritten through the applicable backup cycle
Regulatory recordsAccording to the relevant legal, customer or authority retention requirement

Customers are responsible for configuring or requesting appropriate retention for their own records.

Information may be anonymised rather than deleted where it can no longer reasonably be linked to an identifiable person.

17. Data-subject rights

Subject to applicable law, a person may have the right to:

  • ask whether Agribantu holds information about them;
  • request access to that information;
  • request correction or updating;
  • request deletion or destruction where appropriate;
  • object to processing;
  • withdraw consent;
  • request restriction of processing;
  • request information about recipients;
  • object to direct marketing;
  • request portability where applicable;
  • challenge certain automated decisions; and
  • lodge a complaint with a regulator.

A request may be refused or limited where permitted by law, including where disclosure would affect another person’s rights, reveal protected information or conflict with a legal retention requirement.

Requests concerning customer-controlled information

Where the information was submitted by an employer or other Agribantu customer, the person should ordinarily direct the request to that organisation.

Agribantu will reasonably assist the customer in responding where Agribantu acts as operator.

Identity verification

Agribantu may request reasonable proof of identity and authority before disclosing or changing information.

18. Direct marketing

Agribantu may send administrative and service communications that are necessary for an account or customer relationship.

Marketing communications will be sent only where lawful. Recipients may unsubscribe through the provided mechanism or contact Agribantu.

Withdrawing from marketing does not prevent Agribantu from sending essential:

  • account notices;
  • security alerts;
  • contractual communications;
  • regulatory notifications; or
  • service-operation messages.

The Information Regulator has published specific guidance regarding direct marketing under POPIA, including consent and objection requirements for unsolicited electronic communications.

19. Links and third-party services

Agribantu may contain links to or integrate with third-party services.

Those services operate under their own privacy notices and terms. Agribantu is not responsible for an independent third party’s processing unless that party processes information on Agribantu’s instructions.

20. Changes to this policy

Agribantu may update this Privacy Policy to reflect changes in:

  • law;
  • services;
  • technology;
  • suppliers;
  • security practices; or
  • organisational structure.

The version and effective date will be displayed at the top.

Material changes will be communicated through reasonable means where appropriate.

21. Contacting Agribantu

Privacy requests and questions may be submitted to:

Privacy emailprivacy@agribantu.co.za
Information OfficerNot yet appointed or registered — see Section 2

A request should include enough information to identify the person, the relevant organisation and the records concerned.

22. Complaints

Agribantu encourages persons to contact its privacy address first so that a concern can be investigated.

A person may also lodge a complaint with the Information Regulator of South Africa:

Information Regulator South AfricaWoodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
Telephone010 023 5200
Toll-free0800 017 160
General enquiriesenquiries@inforegulator.org.za
POPIA complaintsPOPIAComplaints@inforegulator.org.za

The Regulator currently provides complaint and compliance services through its website and eServices platform.

Questions about this policy? Contact privacy@agribantu.co.za.