Data Policy
Registration Number: 2024/666888/08 | Registered Address: 1101 Etienne Street, Equestria, 0184
Version 1.0 — Effective from date of Board approval 2026-08-04
1. Purpose and Scope
This Data Policy sets out how AgriGeo Spaces NPC ("AgriGeo") collects, holds, processes, shares, secures and disposes of data — including the personal information of farmers, farm workers, staff, directors, training partners and other stakeholders — in the course of operating its agricultural data-collection and advisory platform.
This policy applies to all data processed by AgriGeo, whether held in AgriGeo's own systems or processed on AgriGeo's behalf by contracted service providers, and to all directors, employees, volunteers and contractors who handle data for or on behalf of AgriGeo.
This policy is issued in compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and is structured around POPIA's conditions for the lawful processing of personal information.
2. Data Retention and Deletion
In accordance with POPIA Condition 3 (Purpose Specification), AgriGeo retains personal data only for as long as necessary to fulfil the purpose for which it was collected, unless a longer period is required or permitted by law (for example, tax, labour or contractual obligations).
Once data is no longer required for its original purpose, AgriGeo securely deletes, de-identifies or destroys it. Data subjects may request the deletion of their personal data at any time, and AgriGeo will honour such requests unless a lawful reason requires continued retention.
3. Data Quality
In accordance with POPIA Condition 5 (Information Quality), AgriGeo takes reasonably practicable steps to ensure that the personal data it holds is accurate, complete, not misleading, and kept up to date where necessary. AgriGeo does this by:
- Validating data at the point of collection, including form checks and identity confirmation.
- Periodically reviewing and updating records, including through annual audits.
- Allowing data subjects to access and correct their own data.
- Applying normalisation and deduplication practices during data ingestion.
4. Data Cleaning, Normalisation and Validation
AgriGeo applies structured processes to maintain data integrity throughout its data pipeline:
- Cleaning — removal of duplicate, incomplete or irrelevant entries.
- Normalisation — standardising formats such as dates and addresses.
- Validation — applying logic checks to ensure internal consistency and compliance with AgriGeo's data schemas.
AgriGeo's systems are designed to reject or flag non-compliant data at the point of capture or import.
5. Technical Infrastructure
AgriGeo stores and processes data in a secure, access-controlled environment, using:
- Cloud infrastructure compliant with recognised standards such as ISO 27001 or SOC 2 (or equivalent).
- Encrypted databases with daily backups.
- Identity and Access Management (IAM) tools to control access to systems and data.
- Audit logs that monitor all access to, and processing of, data.
AgriGeo assesses the POPIA compliance of its infrastructure and service-provider partners, with particular attention to any cross-border data transfers.
6. Scalability
AgriGeo's data architecture is cloud-based and designed for scalability. AgriGeo uses containerised applications, horizontal scaling and automated provisioning so that its systems can respond to increased data volume or demand while maintaining compliance, performance and security standards.
7. Data Standards and Interoperability
AgriGeo adopts standardised, open formats and protocols to support interoperability with other systems and platforms, including:
- CSV, JSON and XML for data interchange.
- APIs conforming to REST standards.
- HL7/FHIR standards where health-related data is involved.
- Controlled vocabularies and metadata schemas for consistency.
AgriGeo aligns its interoperability practices with POPIA's requirement that further processing of personal data be compatible with the purpose for which it was originally collected.
8. Governance of Data Standards
AgriGeo maintains a Data Governance function (initially fulfilled by the Board, pending appointment of a dedicated committee as AgriGeo grows) that:
- Reviews AgriGeo's data standards at least quarterly.
- Ensures AgriGeo's systems remain aligned with emerging best practice and regulatory developments.
- Provides guidance and training to staff, volunteers and contracted data processors.
- Documents and version-controls changes to AgriGeo's data schemas and APIs.
9. Integration with Other Systems
Where AgriGeo integrates its data commons with other data systems or platforms, it does so under secure and compliant data-sharing agreements. AgriGeo:
- Uses secure APIs and encrypted channels (TLS 1.2 or higher).
- Requires that participating platforms adhere to POPIA or an equivalent data protection standard.
- Conducts due diligence before integrating any third-party system.
- Includes in any integrated system only the data of subjects who have consented to that sharing.
10. Security Safeguards
In accordance with POPIA Condition 7 (Security Safeguards), AgriGeo implements the following technical and organisational measures:
Technical measures
- Encryption of data at rest and in transit.
- Endpoint security and anti-malware tools.
- Firewalls and intrusion detection systems.
- Access controls, including multi-factor authentication (MFA) and role-based access control (RBAC).
Organisational measures
- Training for staff, volunteers and directors on POPIA compliance and data hygiene.
- A breach-response policy with a designated response team.
- Physical security measures, including secure server facilities operated by AgriGeo's infrastructure providers.
11. Identifying and Mitigating Security Threats
AgriGeo conducts regular risk assessments and, where appropriate, penetration testing to identify vulnerabilities in its systems. AgriGeo's controls include:
- Threat modelling and vulnerability scanning.
- Logging and Security Information and Event Management (SIEM).
- Defined mitigation plans with clear escalation paths.
- Periodic incident-response testing.
Findings from these activities are logged, tracked and resolved as part of AgriGeo's Information Security Management practices.
12. Access Control
Access to AgriGeo's data is granted on the principle of least privilege, using:
- Role-Based Access Control (RBAC).
- Access-provisioning workflows tied to onboarding and offboarding of staff, volunteers and contractors.
- Audit trails that monitor access to, and changes made within, AgriGeo's systems.
- Periodic access reviews, conducted at least quarterly.
AgriGeo monitors for unauthorised access and has procedures in place to respond promptly if it occurs.
13. Authentication and Authorisation
AgriGeo manages authentication and authorisation to its systems using:
- Multi-Factor Authentication (MFA).
- OAuth 2.0 / SAML single sign-on (SSO) for integrated systems, where applicable.
- Session timeouts and enforced password complexity requirements.
- Token-based authentication for system-to-system (API) access.
All authentication events are logged and monitored for anomalies.
14. Roles and Responsibilities
AgriGeo's Board of Directors is ultimately responsible for this policy and for AgriGeo's compliance with POPIA. Day-to-day responsibility for data governance, security and compliance rests with AgriGeo's designated Information Officer (to be appointed and registered with the Information Regulator in accordance with POPIA), supported by any staff, volunteers or contracted service providers involved in handling data on AgriGeo's behalf.
15. Review and Amendment
This policy will be reviewed at least annually, and sooner if there is a material change in AgriGeo's operations, technology, or in POPIA or other applicable law. Amendments will be approved by the Board and version-controlled.
16. Approval
This Data Policy was approved by the Board of Directors of AgriGeo Spaces NPC.
