1. Controller and contact
The controller is Landbrugsguiden, CVR 43823620, Gammelmark 14, 6310 Broager, Denmark. Contact: support@cropmate.dk. This English version is provided for information; the Danish policy is authoritative until a legal review approves every translation.
2. Data we process
We may process account and profile data, garden spaces, crops, tasks, notes, harvest records, photos, AI prompts, support messages, approximate location for weather, security logs, consented analytics and subscription status. Precise location is used only when you grant permission. Stripe handles card details; CropMate does not receive the full card number or CVC.
3. Purposes and legal bases
Account and core product delivery rely on performance of contract; bookkeeping on legal obligation; security and abuse prevention on legitimate interests; optional analytics, marketing and diagnosis sharing on prior consent. Optional consent can be withdrawn without losing core functionality.
4. Providers and AI
Generative AI responses are primarily processed by Anthropic (Claude). OpenAI is used only in flows that require embeddings of search text. Provider logging, abuse monitoring and any temporary retention follow the current API agreement and production configuration. CropMate does not promise a fixed provider-retention period or “no training” without evidence for the active agreement, and does not itself use private AI input for model training without separate voluntary consent.
Other operational providers can include Supabase, Vercel, Stripe, Sentry, PostHog, Resend, Open-Meteo, Cloudflare and OpenStreetMap/Nominatim. Only the data needed for the relevant function should be sent.
5. International transfers
Some providers are based in or may process data in the United States. The lawful transfer mechanism depends on the current contract and configuration. This page is not proof that a specific DPA, SCC or certification is active. A versioned subprocessor and transfer register, followed by legal review, is a launch requirement.
6. Retention and deletion
Account and garden data are normally kept while the account is active. A deletion request has a 48-hour cancellation window before the deletion process starts. Legal records, security logs, backups and provider copies can follow separate documented schedules. Exact production retention periods must be published in a versioned register before commercial launch; CropMate does not promise an unverified fixed period here.
7. Your rights
Depending on the GDPR conditions, you can request access, correction, deletion, restriction, portability, object to legitimate-interest processing and withdraw consent. Export and deletion controls are available under Settings → Privacy, or contact support@cropmate.dk. You may complain to the Danish Data Protection Agency or your local supervisory authority.
8. Security, children and changes
CropMate uses encrypted transport, access controls and database row-level security. The service is not directed at children under 13. Material policy changes will be communicated in the app or by email. No technical system is risk-free, and this policy still requires external privacy and legal review before launch.