Legal

Data Processing Agreement

Last Updated: May 14, 2026

1. Purpose

This Data Processing Agreement ("DPA") forms part of the agreement between OpenPasture ("Processor") and you ("Controller") and governs the processing of personal data in connection with the OpenPasture Service.

This DPA applies to customers subject to GDPR, CCPA, or similar data protection regulations.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Farm Data" means livestock records, animal identification data, premises information, and related operational records entered into the Service.
  • "Processing" has the meaning given in applicable data protection law.

3. Roles

You are the Controller of Personal Data you submit to the Service. OpenPasture is the Processor, processing Personal Data only on your instructions.

4. Processing Instructions

OpenPasture will process Personal Data only:

  • To provide the Service as described in the Terms of Service
  • As required by applicable law
  • As otherwise agreed in writing

OpenPasture will not process Personal Data for its own commercial purposes.

5. Data Subject Rights

OpenPasture will assist you in responding to data subject rights requests (access, correction, deletion, portability) within 30 days of your written request to howdy@openpasture.ai.

6. Sub-Processors

OpenPasture uses the following sub-processors. We will provide 30 days notice before adding new sub-processors:

Sub-ProcessorPurposeLocation
Amazon Web ServicesCloud infrastructure and database hostingUnited States
GoogleOAuth authentication (sign in with Google)United States
StripePayment processingUnited States
ResendTransactional email deliveryUnited States
NeonPostgreSQL database hostingUnited States

7. International Data Transfers

For transfers of Personal Data from the EEA or UK to the United States, OpenPasture relies on Standard Contractual Clauses as the legal transfer mechanism.

Copies of applicable SCCs are available upon written request.

8. Security Measures

OpenPasture uses administrative, technical, and organizational safeguards designed to protect information, including:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest using AES-256
  • Role-based access controls limiting employee access to Personal Data
  • Regular security assessments and vulnerability monitoring
  • Incident response procedures with 72-hour breach notification commitment

9. Data Retention and Deletion

We retain Personal Data while the Service agreement is in effect. After cancellation, we retain Personal Data for a limited period solely to support reactivation or a requested export, unless you request deletion sooner. After a verified deletion request, or when that period ends, we delete or de-identify Personal Data from active production systems without undue delay. Encrypted residual copies may remain in disaster-recovery backups for a limited additional period, are not used for ordinary business purposes, and are removed through normal backup rotation. We may retain limited information when required or permitted for legal, tax, accounting, fraud-prevention, security, dispute-resolution, or regulatory purposes. The specific retention and backup periods are being verified against our infrastructure and will be published here when confirmed. To request an export or deletion, contact howdy@openpasture.ai.

10. Audit Rights

You may audit OpenPasture's compliance with this DPA no more than once per year upon 30 days written notice.

OpenPasture may satisfy audit requests by providing relevant certifications or security reports.

11. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.

12. Governing Law

This DPA is governed by the laws of the State of Delaware.

To execute this DPA

Email howdy@openpasture.ai with subject "DPA Execution Request" and your company name. We will countersign and return within 5 business days.