AgroSys
Buyers Suppliers About
Supplier registration Register interest
Legal

Privacy notice

How AgroSys collects and uses personal data, and what rights you have over it. This notice is provided under Articles 13 and 14 of the UK GDPR and the Data Protection Act 2018.

Version 1.0 Effective 4 September 2026 Last reviewed 4 September 2026 Next review due 4 September 2027
  1. Who we are
  2. What personal data we collect
  3. Why we use it, and our lawful basis
  4. Where the data comes from
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. How we protect it
  9. Your rights
  10. Complaints
  11. Changes to this notice

1. Who we are

AgroSys is the trading name of Daniel Comer, a sole trader operating an agricultural technology and controlled-environment agriculture enterprise in the United Kingdom. Daniel Comer is the data controller for the personal data described in this notice and decides how and why it is used.

AgroSys is currently in a research and development phase. It is not trading commercially, is not selling produce, and is not purchasing from suppliers. The registrations collected through this website record interest in a planned Phase 1 pilot.

  • Controller: Daniel Comer, trading as AgroSys (sole trader)
  • Email: info@agrosys.co.uk
  • Postal address: 25 Lockwood Avenue, South Anston, S25 5GQ
  • ICO data protection fee: not currently payable. The ICO's data protection fee self-assessment was completed on 4 September 2026 and returned the outcome “You don't need to pay a fee yet — organisations that have not started trading don't have to pay a fee to the ICO”. The ICO confirms that exempt organisations do not need to notify it. This will be reassessed when AgroSys begins trading.

We have not appointed a Data Protection Officer. An organisation of this size and activity is not required to appoint one under Article 37 of the UK GDPR. Data protection enquiries are handled by Daniel Comer directly at the address above.

2. What personal data we collect

We collect only what the registration forms ask for. The tables below list every field the website stores, so you can see exactly what is held.

2.1 Buyer registrations (kitchens, grocers and caterers)

DataRequiredNotes
Trading name of the businessYesBusiness information; may identify a sole trader
Venue typeYesSelected from a list
Contact nameYesPersonal data
Mobile telephone numberYesPersonal data
Work email addressYesPersonal data
Venue postcodeYesUsed to check the planned delivery route
Delivery and access notesNoFree text you choose to provide
Preferred supply format, varieties of interest, any custom variety requested, likely weekly volume, preferred delivery daysPartlyCommercial preferences, used to plan the pilot
Whether a tasting box is wantedNoYes/no
Menu style or culinary focusNoFree text you choose to provide
Whether your postcode falls inside the planned routeDerivedCalculated by us, not entered by you
Date and time consent was givenDerivedRecorded automatically as proof of consent
Date and time of registrationDerivedRecorded automatically

2.2 Supplier registrations

Most supplier information is about a company rather than an individual, and company data is not personal data. The following fields are, or may be, personal data — particularly where the supplier is a sole trader or partnership.

DataRequiredNotes
Registered company name and any trading nameYesMay identify an individual if a sole trader
Companies House number and UK VAT numberYesCompany identifiers
Registered business addressYesMay be a home address for a sole trader
Trade contact nameYesPersonal data
Trade desk telephone numberYesPersonal data where it identifies an individual
Order email addressYesPersonal data where it identifies an individual
Company websiteNo—
Supply categories and the compliance answers for those categoriesYesRegulatory information about products, not about people
Commercial terms, insurer name and policy expiry, price list URLPartlyBusiness information
Certificates you uploadNoSee 2.3
Internal review status and date of registrationDerivedRecorded automatically

2.3 Certificates uploaded by suppliers

Suppliers may optionally attach compliance certificates (PDF or image files, up to 10 MB each and up to 20 per registration). These are stored on the server that hosts this website, outside the publicly accessible area, and can only be opened by a signed-in administrator. We ask you not to upload documents containing personal data beyond what is necessary to evidence compliance.

2.4 Website and technical data

  • Server logs. Our application records the IP address of failed administrator sign-in attempts and of requests that hit a rate limit, together with the time. This is a security measure.
  • Cookies. This website uses only strictly necessary cookies. We do not use analytics, advertising or tracking cookies. See the cookie policy for the full list.
  • Google Fonts. Our pages load typefaces from Google's font servers (fonts.googleapis.com and fonts.gstatic.com). Your browser's IP address is necessarily disclosed to Google in order to fetch them. See section 5.

We do not knowingly collect data about children, and this service is aimed at businesses. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. We do not collect special category data.

3. Why we use it, and our lawful basis

PurposeLawful basis (UK GDPR Article 6)
Recording your interest in the Phase 1 pilot, planning what to grow, planning the delivery route, and contacting you about the pilot Consent (Article 6(1)(a)) — you tick a box confirming we may contact you, and the time you did so is recorded
Sending you an acknowledgement email confirming what you submitted Consent (Article 6(1)(a))
Assessing and recording suppliers for future pre-qualification, and holding the compliance evidence they provide Legitimate interests (Article 6(1)(f)) — establishing a compliant supply chain before purchasing begins. A legitimate interests assessment has been carried out and is available on request
Meeting food-safety and product-compliance obligations that apply once trading begins Legal obligation (Article 6(1)(c)), where applicable
Protecting the website from abuse: rate limiting, sign-in lockouts and security logging Legitimate interests (Article 6(1)(f)) — keeping the service and the data on it secure

Where we rely on consent, you can withdraw it at any time by emailing info@agrosys.co.uk. Withdrawing consent does not affect anything we did before you withdrew it.

We do not sell personal data, and we do not use it for third-party marketing.

4. Where the data comes from

All of it comes directly from you, through the registration forms on this website. We do not buy contact lists and we do not collect personal data about you from other sources.

If you register on behalf of a business and enter someone else's contact details, please make sure that person knows their details have been given to us and can see this notice.

5. Who we share it with

We share personal data only where it is necessary to run the service:

  • Our hosting provider, Fasthosts. The website and its database run on a virtual private server provided by Fasthosts, a UK hosting company. Fasthosts acts as a processor: it holds the data on our behalf and under our instructions, and does not use it for its own purposes.
  • Infrastructure under the velocitywave.co.uk domain. Some of the infrastructure serving this site, including outbound email, sits under that domain. Velocity Wave is another trading name of the same sole trader, Daniel Comer, so this is not a disclosure to a third party — the data stays with the same controller.
  • Google. Fonts are served by Google. Google receives your IP address when your browser requests them. We do not send Google any registration data. If you would prefer this not to happen, the fonts can be served from our own server instead — contact us.
  • Professional advisers and authorities. We may disclose data where we are legally required to, or to establish or defend legal claims.

We do not use analytics, advertising, social media or customer-relationship platforms.

6. International transfers

Our database and application are hosted in the United Kingdom, on a virtual private server provided by Fasthosts. Registration data is not transferred outside the UK.

Google's font services are operated by a company with infrastructure outside the UK, so the IP address disclosed when your browser fetches a font may be transferred internationally. Google relies on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses for such transfers. No registration data is transferred to Google.

7. How long we keep it

RecordRetention periodReason
Buyer registrations 24 months from registration, or from your last contact with us, whichever is later The pilot is being planned over this horizon. Reviewed annually; deleted sooner on request
Supplier registrations and uploaded certificates 36 months from registration, or from our last contact, whichever is later Compliance evidence needs to stay current and traceable; certificates expire and are re-requested
Copies of outbound emails held on the server 30 days, then deleted automatically Operational troubleshooting only
Security logs (IP addresses of failed sign-ins and rate-limited requests) 90 days. Logs kept beyond that only where needed for an ongoing audit or investigation, and deleted as soon as that concludes Detecting and investigating abuse
Administrator accounts For as long as the person administers the service, then deleted Access control

If the Phase 1 pilot does not proceed, we will delete the registration records rather than keep them for the full period above.

8. How we protect it

  • Administrator access requires a username and password. Passwords are stored only as a PBKDF2 hash, never in readable form.
  • Repeated failed sign-ins lock the account temporarily, and sign-in attempts are rate limited.
  • The administration area, including certificate downloads, is not reachable without signing in.
  • Registration forms are rate limited to prevent bulk abuse.
  • Uploaded files are checked by type and content, stored under names we generate, held outside the public web folder, and served only as downloads to a signed-in administrator.
  • The site sets security headers including a content security policy, and administrator session cookies are restricted to HTTPS outside local development.
  • Data submitted to this website is transmitted over HTTPS.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell affected people directly where the risk is high.

9. Your rights

Under the UK GDPR you have the right to:

  • Be informed about how we use your data — this notice.
  • Access a copy of the personal data we hold about you.
  • Rectification of data that is inaccurate or incomplete.
  • Erasure of your data, where there is no overriding reason to keep it.
  • Restrict processing in certain circumstances.
  • Data portability — receive the data you gave us in a machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these, email info@agrosys.co.uk. We will respond within one month. There is no charge. We may ask you for enough information to be satisfied of your identity before we act, so that we do not disclose your data to someone else.

10. Complaints

If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint

11. Changes to this notice

We review this notice at least annually, and whenever we change what we collect or how we use it. The version number and dates at the top show when it last changed. If a change materially affects you, we will contact registered users directly.

© 2026 AgroSys — Daniel Comer, sole trader enterprise · R&D phase
info@agrosys.co.uk Privacy notice Cookies Terms of use Accessibility Admin