Privacy notice
How AgroSys collects and uses personal data, and what rights you have over it. This notice is provided under Articles 13 and 14 of the UK GDPR and the Data Protection Act 2018.
1. Who we are
AgroSys is the trading name of Daniel Comer, a sole trader operating an agricultural technology and controlled-environment agriculture enterprise in the United Kingdom. Daniel Comer is the data controller for the personal data described in this notice and decides how and why it is used.
AgroSys is currently in a research and development phase. It is not trading commercially, is not selling produce, and is not purchasing from suppliers. The registrations collected through this website record interest in a planned Phase 1 pilot.
- Controller: Daniel Comer, trading as AgroSys (sole trader)
- Email: info@agrosys.co.uk
- Postal address: 25 Lockwood Avenue, South Anston, S25 5GQ
- ICO data protection fee: not currently payable. The ICO's data protection fee self-assessment was completed on 4 September 2026 and returned the outcome “You don't need to pay a fee yet — organisations that have not started trading don't have to pay a fee to the ICO”. The ICO confirms that exempt organisations do not need to notify it. This will be reassessed when AgroSys begins trading.
We have not appointed a Data Protection Officer. An organisation of this size and activity is not required to appoint one under Article 37 of the UK GDPR. Data protection enquiries are handled by Daniel Comer directly at the address above.
2. What personal data we collect
We collect only what the registration forms ask for. The tables below list every field the website stores, so you can see exactly what is held.
2.1 Buyer registrations (kitchens, grocers and caterers)
| Data | Required | Notes |
|---|---|---|
| Trading name of the business | Yes | Business information; may identify a sole trader |
| Venue type | Yes | Selected from a list |
| Contact name | Yes | Personal data |
| Mobile telephone number | Yes | Personal data |
| Work email address | Yes | Personal data |
| Venue postcode | Yes | Used to check the planned delivery route |
| Delivery and access notes | No | Free text you choose to provide |
| Preferred supply format, varieties of interest, any custom variety requested, likely weekly volume, preferred delivery days | Partly | Commercial preferences, used to plan the pilot |
| Whether a tasting box is wanted | No | Yes/no |
| Menu style or culinary focus | No | Free text you choose to provide |
| Whether your postcode falls inside the planned route | Derived | Calculated by us, not entered by you |
| Date and time consent was given | Derived | Recorded automatically as proof of consent |
| Date and time of registration | Derived | Recorded automatically |
2.2 Supplier registrations
Most supplier information is about a company rather than an individual, and company data is not personal data. The following fields are, or may be, personal data — particularly where the supplier is a sole trader or partnership.
| Data | Required | Notes |
|---|---|---|
| Registered company name and any trading name | Yes | May identify an individual if a sole trader |
| Companies House number and UK VAT number | Yes | Company identifiers |
| Registered business address | Yes | May be a home address for a sole trader |
| Trade contact name | Yes | Personal data |
| Trade desk telephone number | Yes | Personal data where it identifies an individual |
| Order email address | Yes | Personal data where it identifies an individual |
| Company website | No | — |
| Supply categories and the compliance answers for those categories | Yes | Regulatory information about products, not about people |
| Commercial terms, insurer name and policy expiry, price list URL | Partly | Business information |
| Certificates you upload | No | See 2.3 |
| Internal review status and date of registration | Derived | Recorded automatically |
2.3 Certificates uploaded by suppliers
Suppliers may optionally attach compliance certificates (PDF or image files, up to 10 MB each and up to 20 per registration). These are stored on the server that hosts this website, outside the publicly accessible area, and can only be opened by a signed-in administrator. We ask you not to upload documents containing personal data beyond what is necessary to evidence compliance.
2.4 Website and technical data
- Server logs. Our application records the IP address of failed administrator sign-in attempts and of requests that hit a rate limit, together with the time. This is a security measure.
- Cookies. This website uses only strictly necessary cookies. We do not use analytics, advertising or tracking cookies. See the cookie policy for the full list.
- Google Fonts. Our pages load typefaces from Google's font servers (fonts.googleapis.com and fonts.gstatic.com). Your browser's IP address is necessarily disclosed to Google in order to fetch them. See section 5.
We do not knowingly collect data about children, and this service is aimed at businesses. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. We do not collect special category data.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Recording your interest in the Phase 1 pilot, planning what to grow, planning the delivery route, and contacting you about the pilot | Consent (Article 6(1)(a)) — you tick a box confirming we may contact you, and the time you did so is recorded |
| Sending you an acknowledgement email confirming what you submitted | Consent (Article 6(1)(a)) |
| Assessing and recording suppliers for future pre-qualification, and holding the compliance evidence they provide | Legitimate interests (Article 6(1)(f)) — establishing a compliant supply chain before purchasing begins. A legitimate interests assessment has been carried out and is available on request |
| Meeting food-safety and product-compliance obligations that apply once trading begins | Legal obligation (Article 6(1)(c)), where applicable |
| Protecting the website from abuse: rate limiting, sign-in lockouts and security logging | Legitimate interests (Article 6(1)(f)) — keeping the service and the data on it secure |
Where we rely on consent, you can withdraw it at any time by emailing info@agrosys.co.uk. Withdrawing consent does not affect anything we did before you withdrew it.
We do not sell personal data, and we do not use it for third-party marketing.
4. Where the data comes from
All of it comes directly from you, through the registration forms on this website. We do not buy contact lists and we do not collect personal data about you from other sources.
If you register on behalf of a business and enter someone else's contact details, please make sure that person knows their details have been given to us and can see this notice.
5. Who we share it with
We share personal data only where it is necessary to run the service:
- Our hosting provider, Fasthosts. The website and its database run on a virtual private server provided by Fasthosts, a UK hosting company. Fasthosts acts as a processor: it holds the data on our behalf and under our instructions, and does not use it for its own purposes.
- Infrastructure under the velocitywave.co.uk domain. Some of the infrastructure serving this site, including outbound email, sits under that domain. Velocity Wave is another trading name of the same sole trader, Daniel Comer, so this is not a disclosure to a third party — the data stays with the same controller.
- Google. Fonts are served by Google. Google receives your IP address when your browser requests them. We do not send Google any registration data. If you would prefer this not to happen, the fonts can be served from our own server instead — contact us.
- Professional advisers and authorities. We may disclose data where we are legally required to, or to establish or defend legal claims.
We do not use analytics, advertising, social media or customer-relationship platforms.
6. International transfers
Our database and application are hosted in the United Kingdom, on a virtual private server provided by Fasthosts. Registration data is not transferred outside the UK.
Google's font services are operated by a company with infrastructure outside the UK, so the IP address disclosed when your browser fetches a font may be transferred internationally. Google relies on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses for such transfers. No registration data is transferred to Google.
7. How long we keep it
| Record | Retention period | Reason |
|---|---|---|
| Buyer registrations | 24 months from registration, or from your last contact with us, whichever is later | The pilot is being planned over this horizon. Reviewed annually; deleted sooner on request |
| Supplier registrations and uploaded certificates | 36 months from registration, or from our last contact, whichever is later | Compliance evidence needs to stay current and traceable; certificates expire and are re-requested |
| Copies of outbound emails held on the server | 30 days, then deleted automatically | Operational troubleshooting only |
| Security logs (IP addresses of failed sign-ins and rate-limited requests) | 90 days. Logs kept beyond that only where needed for an ongoing audit or investigation, and deleted as soon as that concludes | Detecting and investigating abuse |
| Administrator accounts | For as long as the person administers the service, then deleted | Access control |
If the Phase 1 pilot does not proceed, we will delete the registration records rather than keep them for the full period above.
8. How we protect it
- Administrator access requires a username and password. Passwords are stored only as a PBKDF2 hash, never in readable form.
- Repeated failed sign-ins lock the account temporarily, and sign-in attempts are rate limited.
- The administration area, including certificate downloads, is not reachable without signing in.
- Registration forms are rate limited to prevent bulk abuse.
- Uploaded files are checked by type and content, stored under names we generate, held outside the public web folder, and served only as downloads to a signed-in administrator.
- The site sets security headers including a content security policy, and administrator session cookies are restricted to HTTPS outside local development.
- Data submitted to this website is transmitted over HTTPS.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell affected people directly where the risk is high.
9. Your rights
Under the UK GDPR you have the right to:
- Be informed about how we use your data — this notice.
- Access a copy of the personal data we hold about you.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data, where there is no overriding reason to keep it.
- Restrict processing in certain circumstances.
- Data portability — receive the data you gave us in a machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these, email info@agrosys.co.uk. We will respond within one month. There is no charge. We may ask you for enough information to be satisfied of your identity before we act, so that we do not disclose your data to someone else.
10. Complaints
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
11. Changes to this notice
We review this notice at least annually, and whenever we change what we collect or how we use it. The version number and dates at the top show when it last changed. If a change materially affects you, we will contact registered users directly.