DATA PROTECTION POLICY
Version: 1.0
Effective Date: 25 June 2026
CHAPTER 1: INTRODUCTION
1.1 Purpose
This Data Protection Policy describes how Coffee Business Planning & Analytics ("the Platform") protects personal data, customer information, farm records and business information throughout its collection, storage, processing, transmission, retention and disposal.
This Policy demonstrates our commitment to protecting the confidentiality, integrity and availability of information entrusted to us by our users and customers.
1.2 Scope
This Policy applies to:
- All Platform users.
- Farm owners.
- Farmer organisations.
- Cooperatives.
- Companies.
- Government institutions.
- Financial institutions.
- Employees.
- Contractors.
- Support personnel.
- Third-party service providers processing Platform data.
CHAPTER 2: DATA PROTECTION PRINCIPLES
The Platform seeks to process information according to the following principles:
- Lawfulness.
- Fairness.
- Transparency.
- Purpose limitation.
- Data minimisation.
- Accuracy.
- Storage limitation.
- Integrity.
- Confidentiality.
- Accountability.
CHAPTER 3: TYPES OF DATA PROTECTED
3.1 Personal Information
- Names.
- Email addresses.
- Telephone numbers.
- Usernames.
- User roles.
- Organisation membership.
- Login records.
3.2 Organisation Information
- Organisation details.
- Subscription information.
- Billing information.
- Organisation settings.
- User permissions.
3.3 Farm Information
- Farm records.
- Farm blocks.
- Coffee cohorts.
- Tree populations.
- Harvest records.
- Sales information.
- Planning scenarios.
- Agronomy records.
- Labour records.
- Inventory records.
- Forecasts.
3.4 Technical Information
- IP addresses.
- Browser information.
- Session identifiers.
- Device information.
- Error logs.
- Security logs.
- Audit logs.
CHAPTER 4: DATA COLLECTION
Information is collected only where reasonably necessary for Platform operation, customer support, legal compliance, security, reporting or agreed business purposes.
Data may be collected through:
- User registration.
- Organisation administration.
- Farm management activities.
- Financial records.
- Planning and forecasting modules.
- File uploads.
- Support requests.
- System logs.
CHAPTER 5: DATA CLASSIFICATION
Information may be classified into one or more categories.
5.1 Public Information
Information approved for public release.
5.2 Internal Information
Operational information intended only for authorised Platform users.
5.3 Confidential Information
- Farm financial records.
- Production records.
- Planning scenarios.
- Investment analysis.
- Supplier information.
- Customer records.
5.4 Highly Confidential Information
- Password credentials.
- Authentication tokens.
- Security logs.
- Administrative credentials.
- Encryption keys.
CHAPTER 6: ACCESS CONTROL
Access to information is granted only to authorised users based on business need and assigned responsibilities.
Access controls may include:
- Role-based permissions.
- Organisation isolation.
- User authentication.
- Session management.
- Administrative approval.
- Audit logging.
CHAPTER 7: DATA SECURITY
The Platform implements reasonable safeguards including:
- Secure authentication.
- Password hashing.
- Encrypted communications where supported.
- Session protection.
- Database access restrictions.
- Application security controls.
- Regular software updates.
- Security monitoring.
- Backups.
- Audit trails.
CHAPTER 8: DATA SHARING
Customer information is not sold to third parties.
Data may be shared only where necessary for:
- Providing Platform services.
- Cloud hosting.
- Email delivery.
- Payment processing.
- Technical support.
- Legal compliance.
- Court orders.
- Law enforcement requests where legally required.
CHAPTER 9: DATA RETENTION
Data is retained only for as long as reasonably necessary for:
- Platform operation.
- Business continuity.
- Customer support.
- Legal compliance.
- Audit requirements.
- Fraud prevention.
- Dispute resolution.
Retention periods may vary according to the type of information and applicable legal requirements.
CHAPTER 10: DATA DISPOSAL
When information is no longer required, it may be securely deleted, anonymised or destroyed using reasonable technical and administrative measures.
Backup copies may remain until scheduled backup rotation or deletion processes are completed.
CHAPTER 11: CUSTOMER RIGHTS
Subject to applicable law and contractual obligations, customers may request:
- Access to their personal information.
- Correction of inaccurate information.
- Deletion of eligible information.
- Restriction of processing.
- Export of available records.
- Information about processing activities.
CHAPTER 12: DATA BREACH MANAGEMENT
If a data breach is suspected or confirmed, the Platform owner may:
- Investigate the incident.
- Contain the breach.
- Assess affected information.
- Restore services.
- Strengthen security controls.
- Notify affected customers where required by law or contract.
- Notify regulators where legally required.
CHAPTER 13: EMPLOYEE RESPONSIBILITIES
Personnel authorised to access customer information are expected to:
- Maintain confidentiality.
- Use information only for authorised purposes.
- Follow Platform security procedures.
- Protect passwords and credentials.
- Report suspected security incidents immediately.
- Complete required security awareness activities where applicable.
CHAPTER 14: THIRD-PARTY PROCESSORS
Where third-party providers process customer information on behalf of the Platform, reasonable efforts are made to ensure they maintain appropriate confidentiality, security and data protection standards.
Examples include:
- Cloud hosting providers.
- Email providers.
- Payment gateways.
- Backup providers.
- Monitoring services.
- Customer support systems.
CHAPTER 15: INTERNATIONAL DATA TRANSFERS
Where customer information is processed or stored outside the customer's country, reasonable safeguards will be applied to protect the information in accordance with applicable law and contractual obligations.
CHAPTER 16: TRAINING AND AWARENESS
The Platform owner may provide security and privacy awareness guidance to authorised personnel responsible for administering or supporting the Platform.
CHAPTER 17: POLICY REVIEW
This Policy will be reviewed periodically to reflect changes in technology, legal requirements, operational practices and security risks.
CHAPTER 18: CONTACT INFORMATION
Questions regarding this Data Protection Policy or requests relating to personal information may be directed to:
Platform: Coffee Business Planning & Analytics
Data Protection Contact: [Insert Data Protection Email]
Business Address: [Insert Business Address]
CHAPTER 19: ACCEPTANCE
By creating an account, accessing or using the Platform, users acknowledge that they have read and understood this Data Protection Policy and agree that their information may be protected and processed in accordance with this Policy, the Privacy Policy and other applicable legal documents.