Data Processing Agreement
Last Updated: May 14, 2026
1. Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between OpenPasture ("Processor") and you ("Controller") and governs the processing of personal data in connection with the OpenPasture Service.
This DPA applies to customers subject to GDPR, CCPA, or similar data protection regulations.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Farm Data" means livestock records, animal identification data, premises information, and related operational records entered into the Service.
- "Processing" has the meaning given in applicable data protection law.
3. Roles
You are the Controller of Personal Data you submit to the Service. OpenPasture is the Processor, processing Personal Data only on your instructions.
4. Processing Instructions
OpenPasture will process Personal Data only:
- To provide the Service as described in the Terms of Service
- As required by applicable law
- As otherwise agreed in writing
OpenPasture will not process Personal Data for its own commercial purposes.
5. Data Subject Rights
OpenPasture will assist you in responding to data subject rights requests (access, correction, deletion, portability) within 30 days of your written request to howdy@openpasture.ai.
6. Sub-Processors
OpenPasture uses the following sub-processors. We will provide 30 days notice before adding new sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure and database hosting | United States |
| OAuth authentication (sign in with Google) | United States | |
| Stripe | Payment processing | United States |
| Resend | Transactional email delivery | United States |
| Neon | PostgreSQL database hosting | United States |
7. International Data Transfers
For transfers of Personal Data from the EEA or UK to the United States, OpenPasture relies on Standard Contractual Clauses as the legal transfer mechanism.
Copies of applicable SCCs are available upon written request.
8. Security Measures
OpenPasture uses administrative, technical, and organizational safeguards designed to protect information, including:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest using AES-256
- Role-based access controls limiting employee access to Personal Data
- Regular security assessments and vulnerability monitoring
- Incident response procedures with 72-hour breach notification commitment
9. Data Retention and Deletion
We retain Personal Data while the Service agreement is in effect. After cancellation, we retain Personal Data for a limited period solely to support reactivation or a requested export, unless you request deletion sooner. After a verified deletion request, or when that period ends, we delete or de-identify Personal Data from active production systems without undue delay. Encrypted residual copies may remain in disaster-recovery backups for a limited additional period, are not used for ordinary business purposes, and are removed through normal backup rotation. We may retain limited information when required or permitted for legal, tax, accounting, fraud-prevention, security, dispute-resolution, or regulatory purposes. The specific retention and backup periods are being verified against our infrastructure and will be published here when confirmed. To request an export or deletion, contact howdy@openpasture.ai.
10. Audit Rights
You may audit OpenPasture's compliance with this DPA no more than once per year upon 30 days written notice.
OpenPasture may satisfy audit requests by providing relevant certifications or security reports.
11. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.
12. Governing Law
This DPA is governed by the laws of the State of Delaware.
To execute this DPA
Email howdy@openpasture.ai with subject "DPA Execution Request" and your company name. We will countersign and return within 5 business days.
Related documents