This notice explains how PROOF AG LTD handles personal information when people create, contribute to, manage or use Proof Records and related Proof services.
Proof is designed to separate private farm information from the evidence that can be used for an authorised purpose.
- A Proof Record is private by default.
- Locking preserves a version. It does not publish the record.
- Named access, group use, programme use and public publication are separate permissions.
1. Who we are
PROOF AG LTD is a private limited company registered in England and Wales.
In this notice, “Proof”, “we”, “us” and “our” mean PROOF AG LTD.
PROOF AG LTD
Company number: 17211914
Registered office:
Grosvenor House
11 St Pauls Square
Birmingham
England
B3 1RB
ICO registration reference: ZC145363
Privacy contact:
Christopher Turner
ct@proof.ag · subjectPrivacy request
2. Who this notice applies to
This notice may apply to:
- farmers;
- farm-business owners;
- sole traders;
- farm employees;
- authorised farm representatives;
- agronomists;
- Proof Accredited Contributors;
- researchers;
- trial partners;
- programme participants;
- advisers;
- reviewers;
- organisation users;
- people named in evidence or record provenance;
- people whose professional information is recorded as part of an agricultural event.
Not every piece of farm information is personal information.
Information becomes personal information for UK data-protection purposes where it relates to an identified or identifiable living person.
A farm business name, field location or agricultural record may therefore be personal information in some circumstances and not in others.
3. Proof’s role under data-protection law
“Farm-controlled” describes Proof’s product and governance model.
It does not necessarily mean that the farm is the legal data controller for every processing activity.
The legal role depends on who decides why personal information is being processed and the essential means of that processing.
Proof as controller
Proof will normally act as controller for purposes it determines itself, including:
- creating and administering Proof accounts;
- verifying identity and contributor status;
- recording contributor credentials;
- operating the Proof Record system;
- maintaining record IDs, versions and audit integrity;
- administering Proof permissions;
- protecting platform security;
- preventing fraud and misuse;
- maintaining access and permission logs;
- operating Proof’s accreditation process;
- enforcing Proof Record Rules;
- investigating complaints, disputes and incidents;
- maintaining Proof’s own legal and regulatory records.
Depending on the circumstances, Proof may also act as controller for public Proof Record infrastructure, privacy-protected group evidence and other products where Proof determines the relevant processing purpose and rules.
Proof as processor
Proof may act as a processor where an organisation determines the purpose of particular personal-data processing and instructs Proof to process that information solely on its behalf.
Where this applies:
- the organisation is responsible for its controller obligations;
- Proof processes the relevant personal information under written instructions;
- a data-processing agreement applies;
- Proof assists the controller with applicable rights, security and compliance obligations.
Joint controllers
Proof and another organisation may be joint controllers where both genuinely determine the purpose and essential means of the same processing activity.
Where this occurs, the parties will document their respective responsibilities and make the essence of that arrangement available to affected individuals.
How you will know
The relevant programme notice, order form, permission screen or other collection-point notice will identify the applicable arrangement where this is necessary to understand how your personal information is used.
4. Proof permissions and data-protection lawful bases are different things
A Proof permission tells the platform what a farm has authorised Proof to do with a Proof Record.
For example:
- private use;
- named adviser access;
- use in a defined evidence programme;
- use in a defined group comparison;
- approved research use;
- public redacted view.
These permissions are purpose-specific and recorded in the system.
A Proof permission is not automatically the same thing as consent under UK data-protection law.
Where personal information is processed, Proof or the relevant controller must separately identify a lawful basis under data-protection law.
Withdrawal of a Proof permission and withdrawal of UK GDPR consent may therefore have different legal consequences.
The applicable interface will explain those consequences where relevant.
5. The information the platform may hold
A Proof Record can contain a large amount of agricultural information.
Not every Proof Record will contain every category.
Records may be incomplete, particularly historic records.
Proof records the information that genuinely exists rather than inventing missing information.
Account and identity information
This may include:
- name;
- email address;
- telephone number;
- authentication details;
- organisation;
- job title;
- professional role;
- account ID;
- profile information;
- account status;
- preferred language;
- authentication and security events.
Passwords must be stored using appropriate one-way cryptographic protection rather than in readable form.
Contributor and accreditation information
This may include:
- identity verification;
- professional role;
- employer or organisation;
- contributor status;
- training completed;
- accreditation scope;
- credential status;
- issue and renewal dates;
- restrictions;
- suspensions;
- appeals;
- audit history;
- declared professional interests;
- relevant commercial relationships.
Authority information
Proof may record:
- the farm or organisation granting authority;
- the person granting it;
- the authority basis;
- scope;
- date granted;
- relevant farms or records;
- expiry or review date;
- changes;
- withdrawal;
- evidence supporting authority.
Standing authority to create records does not automatically authorise every later use of those records.
Farm and field identity
Private record information may include:
- farm name;
- farm reference;
- holding reference;
- field name;
- field reference;
- field boundaries;
- exact coordinates;
- field area;
- geographic information;
- land-management information;
- information capable of linking the record back to a particular farm or person.
Exact farm and field identity is private by default.
Agricultural context
A Proof Record may contain:
- crop or enterprise;
- season;
- variety;
- rotation;
- previous crops;
- field history;
- soil type;
- soil texture;
- pH;
- organic matter;
- nutrient status;
- establishment information;
- cultivation information;
- weather and environmental context;
- agronomic history.
Observations
This may include:
- what was observed;
- when it was observed;
- where it was observed;
- crop stage;
- severity;
- extent;
- photographs;
- video;
- sensor data;
- diagnostic information;
- notes;
- measurements.
Decisions
This may include:
- what was decided;
- who made the decision;
- why it was made;
- evidence considered;
- alternatives considered;
- agronomic rationale;
- expected outcome;
- known uncertainties.
Actions and field operations
This may include:
- field operations;
- dates and times;
- products;
- inputs;
- rates;
- application methods;
- machinery;
- operators;
- GPS logs;
- telemetry;
- controller logs;
- calibration;
- as-applied files;
- operational notes.
Evidence
This may include:
- photographs;
- video;
- machinery files;
- maps;
- laboratory reports;
- soil tests;
- tissue tests;
- weather data;
- sensor data;
- satellite information;
- drone information;
- yield files;
- invoices;
- delivery documents;
- weighbridge records;
- product information;
- research material;
- supporting documents.
Some raw evidence can contain personal information or metadata capable of identifying a person or exact location.
Outcomes
This may include:
- measurements;
- yield;
- quality;
- treatment and comparator values;
- economic information;
- environmental measurements;
- outcome direction;
- uncertainty;
- limitations;
- missing outcomes;
- null, negative, mixed or inconclusive outcomes.
Provenance
Proof may record:
- who entered information;
- who generated it;
- who authorised it;
- source system;
- source file;
- capture time;
- upload time;
- transformation history;
- funding source;
- professional affiliation;
- relevant conflicts;
- evidence custody;
- version history.
Permissions
Proof may record:
- who granted permission;
- the records covered;
- purpose;
- recipient;
- data categories;
- permitted output;
- geographic scope;
- start and end dates;
- restrictions;
- changes;
- withdrawal.
Audit information
This may include:
- record creation;
- edits;
- locked versions;
- access;
- sharing;
- permission changes;
- public publication;
- redactions;
- addenda;
- evidence additions;
- disputes;
- security events;
- legal removals.
6. Where information comes from
Information in Proof may come from:
- the farm;
- the farmer;
- a farm employee;
- an authorised agronomist;
- another authorised contributor;
- a researcher;
- a trial partner;
- machinery;
- farm-management software;
- laboratories;
- weather providers;
- sensors;
- satellite or remote-sensing services;
- imported files;
- third-party agricultural systems;
- public historical sources;
- lawful successor or stewardship records.
Proof records provenance where reasonably possible so that a user can understand where information came from and whether it was:
- entered by a person;
- imported;
- machine-generated;
- calculated;
- transformed;
- estimated;
- historic;
- unavailable;
- unknown.
Proof does not treat information from a commercial partner as more authoritative merely because that organisation has a commercial relationship with Proof.
7. Why we use platform information
Create and maintain Proof Records
To:
- create structured agricultural records;
- preserve versions;
- add evidence;
- add outcomes;
- create addenda;
- maintain links between events and evidence;
- enable authorised users to understand record history.
Verify identity, role and authority
To:
- identify contributors;
- verify relevant roles;
- establish contributor status;
- confirm authority;
- prevent unauthorised record creation;
- maintain accountability.
Operate permissions
To:
- record permissions;
- enforce permitted purposes;
- manage named access;
- manage programme use;
- manage group use;
- manage public display;
- record withdrawal;
- maintain permission history.
Protect private information
To:
- separate private identifiers from other datasets;
- control access;
- apply redaction;
- apply pseudonymisation;
- prevent re-identification;
- suppress unsafe outputs;
- monitor unusual access or query behaviour.
Produce permitted group evidence
Where a valid permission allows it, Proof may use relevant records to:
- identify records matching defined criteria;
- create a permitted comparison group;
- calculate descriptive measures;
- show distributions and ranges;
- identify evidence coverage;
- identify missing information;
- produce privacy-protected group evidence.
Proof does not provide the organisation with unrestricted private farm records merely because those records contributed to a group output.
Operate evidence programmes
To:
- manage authorised participants;
- implement the agreed question or method;
- collect or receive evidence;
- manage permissions;
- produce permitted outputs;
- maintain programme provenance;
- preserve funding and conflict information.
Create public redacted views
Where specifically authorised, Proof may create a separate public representation of a Proof Record.
The public view contains only information permitted for publication.
The private source record remains separate.
Manage Proof Accredited Contributors
To:
- administer credentials;
- verify scope;
- manage training;
- review conformance;
- investigate concerns;
- restrict, suspend or withdraw accreditation where appropriate;
- operate an appeal process.
Accreditation concerns conformance to the relevant Proof recording standard.
It does not mean Proof endorses every piece of agronomic advice given by the contributor.
Maintain record integrity
To:
- create timestamps;
- preserve locked versions;
- maintain audit events;
- detect unauthorised alteration;
- operate addenda;
- maintain stable record references.
Security and abuse prevention
To:
- authenticate users;
- detect suspicious behaviour;
- investigate unauthorised access;
- protect records;
- protect permissions;
- prevent scraping or re-identification;
- respond to security incidents.
Compliance, disputes and legal obligations
To:
- handle rights requests;
- investigate Proof Record enquiries;
- resolve authority issues;
- investigate accreditation concerns;
- respond to complaints;
- maintain evidence of compliance;
- establish, exercise or defend legal rights;
- respond to lawful regulatory or court requirements.
Improve Proof
Proof may use appropriately minimised platform information to:
- diagnose errors;
- measure system reliability;
- improve workflows;
- improve record schemas;
- improve permission controls;
- improve privacy protections;
- assess whether product features are functioning correctly.
Proof will not use “product improvement” as an unrestricted purpose for repurposing private farm records.
Where a materially different use is proposed, Proof will assess the lawful basis, compatibility, permissions and transparency requirements before it begins.
8. Lawful bases
The lawful basis depends on the particular activity and Proof’s role.
Likely: contract and legitimate interests.
Provide the requested platform service and operate secure user accounts.
Likely: contract and legitimate interests.
Maintaining an accountable evidence system and preventing unauthorised contribution.
Likely: contract and legitimate interests.
Demonstrating that a contributor had an appropriate authority basis for the relevant activity.
Where Proof is controller, the likely lawful basis is contract and legitimate interests.
Where Proof acts only on another controller’s instructions, the relevant controller determines the lawful basis and Proof acts as processor.
Likely: contract and legitimate interests.
Enforcing agreed data-use boundaries and demonstrating who accessed information, when and under which permission.
Likely: legitimate interests and, where applicable, legal obligation.
Likely: contract and legitimate interests.
Operating a credible, auditable recording standard and protecting the integrity of Proof Records.
The lawful basis depends on the information involved, whether it remains personal information, Proof’s role, the purpose, the relationship between the parties and the applicable programme.
Possible lawful bases may include contract or legitimate interests.
Where the data is processed solely on another controller’s instructions, that controller determines the lawful basis.
Research processing is assessed separately. The relevant lawful basis, safeguards and any additional conditions for special-category information will be documented before the processing begins.
A product permission for research does not by itself establish the data-protection lawful basis.
Where a public view contains personal information, Proof must identify an appropriate lawful basis before publication.
Contributor attribution or other optional personal information may, where appropriate, be based on a specific consent or another lawful basis that is clearly explained at the time.
A farm’s permission to create a public view does not automatically authorise publication of another person’s personal information.
Legal obligation or legitimate interests, depending on the circumstances.
Legitimate interests.
Where special-category information is involved, Proof will identify an appropriate additional legal condition.
9. Special-category and criminal-offence information
Proof is not designed to collect health, genetic, biometric, political, religious, trade-union, sexual-life or criminal-offence information as part of ordinary agricultural records.
Contributors should not upload this information unless:
- it is genuinely necessary;
- Proof has provided an appropriate route;
- there is a clear lawful basis;
- any required additional legal condition has been identified.
Where unnecessary sensitive personal information is uploaded, Proof may restrict, redact or delete it.
10. Incomplete and historic records
Proof permits incomplete records.
Historic agricultural evidence may have:
- missing dates;
- missing machine logs;
- incomplete crop history;
- unavailable soil information;
- uncertain provenance;
- unknown measurement methods;
- no surviving outcome data.
Proof does not require a contributor to invent or reconstruct information that is not known.
Where information is:
- unknown;
- unavailable;
- estimated;
- reconstructed;
- imported;
- declared retrospectively;
the system should identify that state where reasonably practicable.
A record that cannot contribute to one comparison can remain a legitimate Proof Record.
11. Named sharing
A farm may authorise specified information to be made available to a named person or organisation for a defined purpose.
A named-access permission should identify:
- who receives access;
- what information they may see;
- why;
- how long access lasts;
- applicable restrictions.
Named access does not automatically permit:
- onward disclosure;
- another purpose;
- public publication;
- group use;
- downloading every private attachment.
Access is logged where the platform supports that activity.
12. Group use and comparisons
A farm may permit a Proof Record to contribute to a defined group use without exposing the individual private record to the recipient.
Proof may use relevant contextual fields to determine whether records are suitable for the specific question.
A record is not rejected as “bad evidence” merely because it is incomplete.
Instead, Proof records:
- what information exists;
- what information is missing;
- whether the record meets the criteria for that particular use.
Group outputs should distinguish:
- eligible records;
- included records;
- excluded records;
- known differences;
- missing information;
- limitations;
- suppression.
Proof does not silently manufacture missing values.
Any modelled or estimated value must be identified as such.
13. Privacy protection for group evidence
Removing a farm name does not necessarily make a dataset anonymous.
Proof therefore uses multiple controls to reduce re-identification risk.
These may include:
- pseudonymisation;
- separation of identity information;
- minimum group sizes;
- dominance checks;
- rare-combination checks;
- geographic generalisation;
- time-period generalisation;
- suppression;
- filter limits;
- query-history monitoring;
- rate limits;
- controls against differencing;
- manual review for sensitive queries.
A minimum of five distinct holdings is an absolute floor for a group output.
Five is not an automatic pass.
Proof may require a larger group or refuse an output where the context creates a higher identification risk.
Where information is pseudonymised rather than genuinely anonymised, Proof continues to treat it as personal information where data-protection law requires.
14. Public redacted views
A private Proof Record is not automatically published.
Locking does not publish it.
A public redacted view is created only where the relevant farm authority has expressly permitted that use.
Before publication, Proof applies the relevant public-view rules.
Information that may remain private or be generalised includes:
- farm name;
- field name;
- exact boundary;
- exact GPS coordinates;
- personal contact information;
- private raw files;
- private machinery metadata;
- confidential commercial information;
- information capable of identifying a farm or person where disclosure is not permitted.
The public view may contain permitted agricultural context, evidence metadata, outcomes, declarations and addenda.
Public views are intended to provide useful evidence without exposing the private source record.
15. Corrections, addenda and removals
Draft records
A draft record can be edited by an authorised user.
Locked records
Locking preserves a version.
A locked version is not silently overwritten.
Where information needs correcting before publication, a new version or linked correction may be created while the earlier history remains recorded.
Published records
Once a record has been publicly published, substantive corrections and additional information are made through dated addenda.
The original history remains visible unless information must be restricted or removed for a lawful reason.
Sensitive-information removal
Proof may remove, restrict or generalise sensitive information where necessary.
The relevant audit event is retained where lawful.
Exceptional legal removal
Where Proof is required to remove published content for legal reasons, it may remove the affected content.
Where legally permitted and safe, the Proof Record ID remains visible with:
- a notice that content was removed;
- the date;
- a neutral explanation.
Where the law prevents even that information remaining public, Proof will comply with the applicable legal requirement.
Technical record permanence does not override a legal obligation or an applicable individual right.
16. Changing or withdrawing permissions
A farm may withdraw future named access or future use for a defined Proof purpose where the relevant permission model allows it.
A withdrawal is recorded with:
- date;
- scope;
- affected purpose.
Withdrawal normally stops future use from the time it takes effect.
Withdrawal does not automatically erase:
- access that lawfully occurred before withdrawal;
- audit events;
- group evidence already lawfully produced;
- a public view already lawfully created;
- historic record references;
- legal or compliance records that Proof must retain.
Where data-protection law gives an individual a separate right to erasure, objection, restriction or withdrawal of consent, Proof will assess that request under the applicable law rather than relying only on the Proof permission model.
18. International transfers
Some platform providers may process personal information outside the United Kingdom.
Where a restricted international transfer occurs, Proof will use an appropriate lawful transfer mechanism.
This may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved Standard Contractual Clauses;
- another lawful safeguard or exception.
Where required, Proof will carry out a transfer-risk assessment and apply additional technical or contractual safeguards.
Information about relevant providers and transfer locations should be maintained at/legal/subprocessors.
You may contact ct@proof.ag for information about the safeguard used for a particular transfer.
19. Retention
Proof does not keep personal information merely because storage is technically possible.
Retention depends on:
- the record state;
- purpose;
- permission;
- contractual requirements;
- Proof’s legal role;
- applicable individual rights;
- the need to preserve an audit history;
- legal obligations;
- dispute and limitation periods.
Account information is normally retained while the account is active.
Necessary account, contract, authority and audit records may normally be retained for up to six years after the relationship ends.
Private draft material may be deleted by authorised users where the applicable service permits.
Inactive drafts may be removed after a notified inactivity period unless there is a reason to retain them.
Locked record versions may be retained for as long as the relevant Proof Record remains active or referenced and for as long as necessary to maintain lawful record integrity.
Personal identifiers within that history should be minimised, restricted or removed when they are no longer necessary.
A locked state does not create an unlimited legal right for Proof to retain personal information indefinitely.
Public views are intended to be durable.
Personal information within them is retained only where there remains a lawful basis and the continued publication is necessary and proportionate.
Where personal information must be removed, the public view is redacted or removed in accordance with the Proof Record Rules.
Normally retained for the life of the relevant record or programme and for up to six years afterwards where necessary to demonstrate authority, access and compliance.
Normally retained while the credential is active and for up to six years after expiry, withdrawal or revocation where required for audit, dispute handling and integrity.
Commercial and administrative programme records are normally retained for six years after the relevant relationship ends.
Farm evidence within a programme follows the applicable Proof Record retention rules rather than being automatically deleted with the commercial contract.
Normally retained for up to 12 months unless required longer for an active security investigation, legal claim or regulatory matter.
Normally retained for up to 24 months after the issue is resolved unless they form part of a legal, security or record-integrity matter.
Normally retained for six years after closure.
Deleted information may remain in protected backups for a limited recovery period before being overwritten.
It is not restored to ordinary production use except where necessary for disaster recovery.
20. Security
Proof applies technical and organisational controls appropriate to the risk.
These are designed to include:
- least-privilege access;
- role-based permissions;
- separation of identity information from analytical datasets where appropriate;
- strong authentication;
- encryption in transit;
- encryption at rest where appropriate;
- secure credential storage;
- access logging;
- permission logging;
- monitoring;
- secure backups;
- vulnerability management;
- incident response;
- supplier due diligence;
- staff and contractor confidentiality;
- separation of development and production environments;
- testing of permission boundaries;
- review of public redaction controls.
No system is completely secure.
If you believe private information, a Proof Record or a permission has been exposed or misused, use /legal/security or emailct@proof.ag with the subject Security concern.
21. Pseudonymisation and anonymisation
Proof does not use “anonymous” merely because a name has been removed.
Where Proof can reconnect information to a person using additional information, that information is treated as pseudonymised personal information rather than anonymous information.
Where Proof describes an output as anonymised, that description should be supported by a documented assessment considering whether a person could reasonably be identified from:
- the output itself;
- other available information;
- rare attributes;
- geographic information;
- time information;
- repeated queries;
- combinations of characteristics.
Proof may use pseudonymisation as a security and privacy measure, but it does not remove the relevant data-protection obligations by itself.
22. AI and automated processing
Proof may use AI-assisted or automated tools to help:
- extract structured fields from supplied evidence;
- classify evidence types;
- suggest vocabulary mappings;
- detect duplicate information;
- detect unit or date inconsistencies;
- assist redaction;
- identify possible missing fields;
- flag privacy or security risks;
- draft summaries for human review.
AI must not:
- invent observations that did not occur;
- invent missing measurements;
- invent authority;
- silently convert an assumption into fact;
- decide that a product works;
- recommend an agronomic action on Proof’s behalf;
- create a trust score;
- override a farm permission;
- infer an identity for a customer;
- silently rewrite source information.
Where automated processing materially contributes to a Proof output, Proof should preserve sufficient information about the source, transformation and system version to make the process accountable.
Proof does not use solely automated processing to make lending, insurance, regulatory, employment, farm-compliance or similarly significant decisions about individuals.
If Proof introduces significant solely automated decision-making in future, the relevant notice will be updated before the processing begins and the safeguards required by law will be provided.
23. Your rights
Where UK data-protection law applies and subject to the relevant conditions and exemptions, you may have the right to:
- be informed;
- access your personal information;
- correct inaccurate personal information;
- request erasure;
- request restriction;
- object to processing;
- receive qualifying information in a portable format;
- withdraw consent where consent is relied upon;
- obtain safeguards in relation to qualifying automated decisions.
The availability of a right can depend on:
- Proof’s role;
- the lawful basis;
- the type of processing;
- whether the information is still personal information;
- legal exemptions.
Your right to object
Where Proof processes your personal information on the basis of legitimate interests, you may object.
Tell us:
- what processing you object to;
- why it affects your rights and interests.
Proof will consider the objection and stop the relevant processing unless it can demonstrate an applicable legal basis for continuing, including compelling legitimate grounds or the establishment, exercise or defence of legal claims.
This is separate from withdrawing a Proof Record permission.
24. How to exercise a right
Email ct@proof.ag with the subjectPrivacy request.
Include:
- your name;
- the right you wish to exercise;
- the information or activity concerned;
- relevant account or Proof Record ID;
- whether you are acting for another person.
Proof may request proportionate evidence of identity or authority.
Where Proof is acting only as processor for another controller, Proof may refer the request to that controller and assist it in responding.
Proof normally responds without undue delay and within the period required by law.
25. Data-protection complaints
If you are concerned about Proof’s handling of personal information, use/legal/data-protection-complaints or email ct@proof.ag with the subjectData protection complaint.
Proof will acknowledge a complaint within 30 days and investigate it without undue delay.
You may also complain to the Information Commissioner’s Office.
26. Proof Record enquiries
Privacy rights are not the only way to challenge information in Proof.
Use the Proof Record enquiry route if the issue concerns:
- farm authority;
- factual correction;
- a proposed addendum;
- public attribution;
- provenance;
- sensitive information;
- redaction;
- public-view removal;
- misuse of a record;
- funding or conflict disclosure.
Route:/legal/proof-record-rules#record-enquiries
A Proof Record enquiry does not remove any separate data-protection right.
27. Children
Proof’s professional platform is not intended for children.
Proof does not knowingly permit children to create contributor accounts or commercial Proof accounts.
If a Proof Record legitimately relates to a child or contains information capable of identifying a child, that processing requires separate assessment and safeguards before use.
28. Changes to this notice
Proof will update this notice when there is a material change to:
- the platform;
- processing purposes;
- lawful bases;
- data categories;
- Proof’s controller or processor role;
- recipients;
- international transfers;
- retention;
- AI use;
- privacy safeguards.
A materially new use of personal information will not be introduced merely by silently changing this page.
Where required, affected users will receive notice before the new processing begins.
Previous versions will be available at /legal/archive.
29. Contact
Email ct@proof.ag · subjectPrivacy request
Grosvenor House
11 St Pauls Square
Birmingham
England
B3 1RB