TraceFarm is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, and safeguard your information in compliance with the EU General Data Protection Regulation (GDPR) and Bulgarian data protection laws.

Data Controller

The data controller for your personal data is Veloxoft EOOD, EIK 123456789, a company registered in Sofia, Bulgaria. For any questions about how we handle your data, please contact us at contact@tracefarm.eu.

Data We Collect

We collect information you provide directly: your name, email address, phone number, farm location, and farm size when you register. We also collect farm operational data you enter: crop records, financial transactions, compliance documents, and agricultural activities. Additionally, we collect usage data: how you interact with our platform, device information, and log data to improve our services.

How We Use Your Data

We use your data to provide and maintain the TraceFarm service, process your transactions and subscriptions, generate reports and compliance documents you request, send you important service updates and notifications, improve our platform based on usage patterns, and respond to your support requests.

Legal Basis for Processing

Under GDPR Article 6, we process your data with the following lawful bases for each purpose: Account management and authentication - contract performance (necessary to provide our service). Payment processing and billing - contract performance (necessary to fulfill your subscription). Farm data storage and processing - contract performance (core service functionality). Service communications and notifications - contract performance (essential service updates). Analytics and platform improvement - legitimate interest for Plausible Analytics (cookie-free, no consent needed); consent under Article 6(1)(a) for Google Analytics 4 (you choose via cookie banner). Advertising measurement - consent under Article 6(1)(a) for Facebook Pixel (you choose via cookie banner). Marketing emails and newsletters - consent (opt-in only; you may withdraw consent at any time via unsubscribe link). Legal and regulatory compliance - legal obligation (required for tax and agricultural regulations).

Data Sharing

We do not sell your personal data. We share data only with: service providers who help us operate TraceFarm (hosting, payment processing), government agencies when required by law or when you use submission features, and analytics services that help us improve the platform. All third parties are bound by data processing agreements that protect your data.

Third-Party Service Providers

We work with the following third-party service providers to operate TraceFarm: Stripe - processes payments and manages subscriptions securely; your payment information is handled directly by Stripe and we never store your full card details. Google - provides authentication services (Google Sign-In) for convenient account access. MongoDB Atlas - hosts our database in EU data centers (Western Europe region) ensuring your farm data remains within the European Union. Plausible Analytics - provides privacy-focused website analytics without cookies and without tracking individual users; fully GDPR compliant and used without consent requirement. Google Analytics 4 - provides detailed website analytics to help us understand how visitors use our site; uses cookies and requires your consent before activation; data processed in EU region; legal basis is consent under GDPR Article 6(1)(a). Meta (Facebook) Pixel - helps us measure the effectiveness of our advertising and reach farmers who may benefit from TraceFarm; uses cookies and requires your consent before activation; legal basis is consent under GDPR Article 6(1)(a). All service providers are bound by data processing agreements and are required to protect your data in accordance with GDPR requirements.

Data Retention

We use activity-based data retention: your personal data and farm records are retained for as long as your account remains active. After you cancel your subscription or terminate your account, you have a 30-day window to export your data. During this period, you can download your farm records, financial data, and compliance documents. After the 30-day export window, your data is permanently deleted from our active systems. We retain only what is legally required for tax records and agricultural regulatory compliance (typically 5-7 years for certain financial and compliance documents). Payment records are retained as required by Bulgarian tax law.

Your Rights Under GDPR

  • Right to access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate personal data
  • Right to erasure: Request deletion of your data
  • Right to data portability: Receive your data in a machine-readable format
  • Right to restrict processing: Limit how we use your data
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent at any time

To exercise these rights, contact us at contact@tracefarm.eu. We will respond within 30 days as required by GDPR.

Cookies and Tracking

TraceFarm uses cookies to provide and improve our services. We categorize cookies as follows: Necessary cookies - required for the website to function (e.g., cc_cookie for storing your consent preferences); these cannot be disabled. Analytics cookies - help us understand how visitors use our website; includes Google Analytics cookies (_ga, _ga_*) which are only set after you grant analytics consent. Marketing cookies - used for advertising measurement and retargeting; includes Facebook Pixel cookie (_fbp) which is only set after you grant marketing consent. When you first visit our site, you will see a cookie consent banner where you can accept all cookies, reject non-essential cookies, or customize your preferences by category. You can change your cookie preferences at any time by clicking 'Cookie Settings' in the footer. Plausible Analytics operates without cookies and does not require consent.

Security Measures

We protect your data with encryption in transit and at rest, secure EU-based data centers, regular security audits, access controls and authentication, and incident response procedures. While no system is completely secure, we implement industry best practices to protect your information.

International Data Transfers

Your data is stored in data centers within the European Union. If we need to transfer data outside the EU, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform. Your continued use of TraceFarm after changes indicates acceptance of the updated policy.

Contact Us

For privacy-related questions or to exercise your rights, contact us at contact@tracefarm.eu, or write to: Veloxoft EOOD, EIK 123456789, Sofia, Bulgaria. We will respond to all privacy requests within 30 days as required by GDPR. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP / KZLD): Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria. Website: www.cpdp.bg. If you reside in another EU member state, you may also contact your local data protection supervisory authority.

Note: This privacy policy provides general guidance on our data practices. We recommend consulting with a legal professional for official legal advice.