Legal
Privacy & Data Protection Policy
- Effective date
- 18 August 2026
- Last updated
- 18 August 2026
Farmreach Technologies Pvt Ltd respects the privacy of individuals whose personal data it processes.
This Privacy & Data Protection Policy explains how Farmreach may collect, use, store, disclose, protect and otherwise process personal data in connection with farmreach.in and related interactions.
For platform customers and enterprise engagements, additional data-processing terms may apply through contracts, data-processing agreements, statements of work or customer-specific policies.
This policy should be read together with applicable contractual documents where relevant.
Farmreach’s role in relation to personal data depends on the particular processing activity and relationship: in some cases it determines the purposes and means of processing for its own business purposes, and in others it processes personal data on behalf of a customer under that customer’s instructions. This policy addresses processing in connection with the public website; personal data processed within enterprise customer platforms is governed by the applicable customer agreement and data-processing terms.
This document sets out Farmreach’s policy position for its public website. It is drafted in the Indian legal context, including the Information Technology Act, 2000 and rules made under it, and the Digital Personal Data Protection Act, 2023 and applicable Rules. It does not claim certification or guaranteed legal compliance, and should be reviewed by qualified Indian legal counsel before being treated as contractual or legal advice.
1Scope
This policy applies to personal data collected through:
- farmreach.in
- Contact and enquiry forms
- Careers and recruitment interactions
- Business communications
- Events and meetings
- Partner interactions
- Other Farmreach-controlled digital channels covered by this policy
Where Farmreach processes personal data on behalf of a customer through an enterprise platform, the customer may determine the purposes and means of processing. In such circumstances, Farmreach’s role, responsibilities and data-processing obligations will be defined by the applicable customer agreement and data-processing terms.
2Types of Personal Data
Depending on the interaction, Farmreach may process:
Identity information
- Name
- Professional designation
- Organisation
Contact information
- Work email
- Phone number
- Business address
- Communication details
Professional information
- Organisation
- Role
- Industry
- Business requirements
- Professional profile information voluntarily provided
Enquiry information
- Enquiry route
- State or region
- Description of business requirement
- Information voluntarily included in communications
Technical information
- IP address
- Browser type
- Device information
- Operating system
- Approximate location derived from technical information
- Website usage information
- Log and security information
Recruitment information, where applicable
- CV/resume
- Professional history
- Qualifications
- Skills
- Application information
Farmreach will seek to avoid collecting unnecessary personal data through public website forms.
3How Data Is Collected
Personal data may be collected:
- Directly from the individual
- Through website forms
- Through business correspondence
- During meetings and events
- Through recruitment applications
- Through business partners
- Through publicly available professional information
- Automatically through website technologies such as cookies or server logs
4Purposes of Processing
Farmreach may process personal data for purposes including:
- Responding to enquiries
- Communicating with prospective customers
- Understanding business requirements
- Providing requested information
- Managing customer and partner relationships
- Delivering contracted services
- Operating and securing digital platforms
- Providing technical support
- Managing user accounts where applicable
- Managing recruitment
- Maintaining business and operational records
- Preventing fraud and misuse
- Protecting systems and information
- Complying with applicable legal obligations
- Improving services and website functionality
- Conducting internal analysis and operational planning
- Communicating relevant business information where permitted
Farmreach will seek to process personal data only for legitimate and appropriate purposes.
5Consent and Other Lawful Bases
Where consent is required under applicable law, Farmreach will obtain consent in an appropriate manner.
Depending on the processing activity, processing may also occur where permitted or required by applicable law, including for contractual, legal, security, operational or other recognised purposes.
Where applicable, consent may be withdrawn through an appropriate mechanism.
Withdrawal of consent does not affect processing already carried out lawfully before withdrawal.
6Cookies and Similar Technologies
Farmreach may use cookies and similar technologies for:
- Essential website functionality
- Security
- Preferences
- Analytics
- Performance measurement
- Understanding website usage
Where consent is required for non-essential cookies, appropriate controls should be provided.
Users may also manage cookies through browser settings, although disabling certain cookies may affect website functionality.
7Data Sharing
Farmreach may share personal data where reasonably necessary with:
- Employees and authorised personnel
- Technology and infrastructure providers
- Cloud service providers
- Communication and email service providers
- Professional advisers
- Legal, audit and compliance advisers
- Service providers working under appropriate contractual obligations
- Government or regulatory authorities where legally required
- Business partners where necessary for a stated purpose and permitted by law
Farmreach does not sell personal data as a business asset.
8Customer Data
Enterprise customers may provide Farmreach with personal data relating to farmers, employees, field officers, channel partners, suppliers or other individuals.
In such cases, the customer may be responsible for determining the purpose and lawful basis of processing.
Farmreach will process customer-provided personal data in accordance with applicable law and the relevant customer agreement.
Customer data may include:
- Farmer information
- Contact details
- Field officer information
- Location information
- Farm and plot information
- Activity records
- Transaction or operational records
- Images and documents
- Communication records
- Other data configured by the customer
The exact categories and processing activities will depend on the relevant platform and customer implementation.
9Location and Field Data
Certain Farmreach and Farminsta solutions may process GPS, location, plot, field and activity information.
Such information may be used for:
- Field activity recording
- Territory management
- Operational monitoring
- Mapping
- Agricultural intelligence
- Service delivery
- Compliance
- Analytics
- Customer-defined business workflows
Location data collected through enterprise platforms is subject to the applicable customer configuration, notices, consent mechanisms and contractual arrangements.
10Data Retention
Farmreach will retain personal data only for as long as reasonably necessary for the purpose for which it was collected, contractual requirements, legitimate operational needs, security, dispute resolution and applicable legal or regulatory obligations.
Retention periods may differ depending on the category and purpose of data.
Customer data retention may be governed by the relevant customer agreement.
When personal data is no longer required, Farmreach will seek to delete, anonymise or otherwise securely dispose of it, subject to applicable legal, contractual and operational requirements.
11Data Security
Farmreach will implement reasonable and appropriate technical and organisational safeguards designed to protect personal data against:
- Unauthorised access
- Unauthorised disclosure
- Accidental loss
- Destruction
- Alteration
- Misuse
- Unauthorised processing
Depending on the system and risk profile, safeguards may include:
- Access controls
- Authentication
- Encryption where appropriate
- Network and infrastructure controls
- Logging and monitoring
- Backups
- Secure development practices
- Vulnerability management
- Employee access controls
- Incident response procedures
- Vendor controls
No internet-based system can guarantee absolute security.
12Data Breaches and Incidents
Farmreach maintains processes for identifying, investigating and responding to information-security incidents.
Where applicable law requires notification of a personal-data breach to affected individuals, customers, authorities or other parties, Farmreach will follow the applicable legal and contractual requirements.
Where Farmreach processes customer data on behalf of a customer, notification responsibilities and timelines may be further defined in the relevant customer agreement or data-processing terms.
13Data Subject Rights
Subject to applicable law, individuals may have rights relating to their personal data, which may include:
- Access to information about processing
- Access to personal data
- Correction of inaccurate or incomplete information
- Updating personal data
- Erasure where legally applicable
- Withdrawal of consent where processing is based on consent
- Grievance redressal
- Nomination or other rights where provided under applicable law
Requests may be submitted to:
Farmreach may need to verify the identity of the requester before processing a request.
Certain rights may be subject to legal, contractual, security or other permitted limitations.
14Children’s Data
Farmreach’s public website is primarily intended for business and professional audiences.
Farmreach does not knowingly seek to collect personal data from children through the public website for purposes that are not permitted by applicable law.
Where a Farmreach service involves children or other protected categories of individuals, additional safeguards and customer-specific requirements may apply.
15International Data Transfers
Farmreach may use cloud, technology and service providers that process information in India or other jurisdictions.
Where personal data is transferred outside India, Farmreach will seek to comply with applicable legal, regulatory and contractual requirements relating to such transfers.
Customer-specific data-location requirements may be addressed through the applicable customer agreement.
16Third-Party Service Providers
Farmreach may use third-party providers for services such as:
- Cloud hosting
- Email delivery
- Analytics
- Security
- Communications
- Infrastructure
- Recruitment
- Website functionality
Such providers may process information on Farmreach’s behalf where necessary for the relevant service.
Farmreach will seek to maintain appropriate contractual and security controls for relevant providers.
17Business Transfers
If Farmreach undergoes a merger, acquisition, restructuring, financing, sale of assets or similar transaction, personal data may be transferred as part of the transaction where legally permitted.
Any such transfer will remain subject to applicable privacy and data-protection obligations.
18Links to Other Websites
Farmreach may link to third-party websites including:
- Farminsta
- Xpedition Labs
- Partner websites
- Government or institutional websites
Farmreach is not responsible for the privacy practices of those external websites.
Users should review the privacy policies applicable to those websites.
19Marketing Communications
Where permitted by applicable law, Farmreach may send relevant business communications to individuals who have requested information, engaged with Farmreach or otherwise have a legitimate business relationship.
Where consent is required, Farmreach will seek appropriate consent.
Recipients may request cessation of non-essential marketing communications.
20Government and Enterprise Data
Farmreach may operate systems for government departments, public institutions and enterprise customers.
The privacy responsibilities for data processed within such systems may be distributed between Farmreach and the relevant customer according to the applicable law and contractual arrangement.
The customer may establish specific:
- Data collection requirements
- Consent mechanisms
- Retention periods
- Access controls
- User roles
- Data-sharing rules
- Data residency requirements
- Security requirements
- Deletion requirements
Such requirements may be documented through customer agreements, implementation specifications or data-processing agreements.
21Data Processing Agreements
For enterprise customers where Farmreach processes personal data on behalf of the customer, the parties may enter into a Data Processing Agreement or equivalent contractual provisions.
Such agreements may define:
- Subject matter of processing
- Duration
- Nature and purpose
- Categories of personal data
- Categories of data principals
- Processing instructions
- Security obligations
- Sub-processors
- Data breach procedures
- Retention and deletion
- Audit or assurance mechanisms
- Data-subject assistance
- International transfer requirements
The applicable customer agreement will prevail where it contains more specific contractual requirements.
22Changes to This Policy
Farmreach may update this Privacy & Data Protection Policy periodically to reflect:
- Changes in law
- Regulatory developments
- Changes in services
- Changes in technology
- Changes in data-processing practices
- Security or operational improvements
The updated policy will be published on this page with a revised effective date.
23Grievance / Privacy Contact
For privacy questions, data requests or concerns, contact:
Farmreach Technologies Pvt Ltd1st Floor, SSR Arcade,
Plot No. 328, Road No. 1/2,
Mathrusree Nagar, Hafeezpet,
Miyapur, Hyderabad,
Telangana 500049, India
Email: ypr@farmreach.in
If Farmreach formally designates a Data Protection Officer or Grievance Officer, their details should be added here before publication.
24Governing Law
This policy shall be interpreted in accordance with applicable laws of India.
Where a specific customer agreement contains additional privacy or data-processing provisions, those provisions will apply to the relevant customer relationship to the extent permitted by law.