Trust
Data governance
Who controls the record, who processes it, and what crosses a boundary. The answers are structural, not policy statements, because a policy can be changed by whoever wrote it.
01
Controller and processor
The operating tenant — the scheme, the packhouse, the programme — is the controller of its operational record. We are the processor. A capital partner or buyer reading across a consent grant is the controller of its own decisions, not of the underlying record.
That split matters at the moment somebody asks for data to be deleted, because it decides who may answer.
02
What never crosses a consent grant
Grower-level personal data does not cross a portfolio or buyer mandate. Not as a setting that defaults to off — there is no endpoint that would serve it. Contact details, identity documents and plot coordinates are removed structurally from anything shared outward.
This is a deliberate constraint on what we can sell. A buyer who wants grower-level visibility across someone else's scheme is asking for something we do not build.
03
Data-protection regimes we operate under
South Africa's POPIA, and the equivalent instruments in each market we deploy into. We name the instrument and its chapter in the data-processing terms rather than paraphrasing it here, because a paraphrase of a statute ages badly and is not what anyone signs.