Skip to content

Privacy Policy

Last updated: 22 September 2026

Orijin Oy (“Orijin”, “we”) builds software that helps agricultural producers, cooperatives and exporters record where their crops come from and demonstrate compliance with regulations such as the EU Deforestation Regulation (EUDR).

This policy covers the Orijin OnField mobile app, the Orijin web dashboard, and orijin.io.

Orijin Oy, Finland — privacy@orijin.io

2. Our role: when we are a processor, and when we are a controller

Section titled “2. Our role: when we are a processor, and when we are a controller”

This distinction matters, because it determines who you should contact about your data.

Farmer and supply-chain data — we are a processor. When a cooperative, exporter or producer organisation uses Orijin, they decide which farmers to register, what to record and why. We process that data on their documented instructions, under a data processing agreement. If you are a farmer whose details are held in Orijin and you want to see, correct or delete them, contact the organisation that registered you. They are the controller. We will support them in responding, but we cannot act on your data without their instruction.

Accounts of people who use our software — we are the controller. For the field agents, supervisors and administrators who log in to Orijin, we decide how account and usage data is handled, and this policy applies to us directly.

The Orijin OnField app is used by field agents working for our customers. It collects:

  • Account details — name, email address, and the organisation you belong to.
  • Precise location. The app records GPS coordinates when an agent stamps a form, registers a farm, or walks a plot boundary. Boundary walking uses a foreground service, so location is collected while the walk is running and a notification is shown throughout. We record the accuracy of each reading alongside the coordinates, because accuracy is itself evidence of data quality. Location is never collected when the app is closed.
  • Photographs taken through the app — farms, crops, receipts, signatures and supporting documents.
  • Device information — model, manufacturer, operating system version, app version, a device identifier, and whether the device was online or offline when a record was created.
  • Bluetooth readings from connected weighing equipment. Bluetooth permissions are used only to talk to scales; the app does not scan for or track nearby devices or people.
  • Supply-chain records entered by the agent — farmer and supplier names and contact details, farm and plot locations and boundaries, crop and collection quantities, prices and payments. This is the farmer data described in section 2, for which our customer is the controller.

Receipt text recognition runs entirely on the device. The app bundles an offline text recognition model, so when it reads a printed receipt the image is processed on the phone. The image is not sent anywhere for that purpose.

The app is built to work offline. Records are stored on the device and synchronised when a connection is available.

The dashboard collects account details, authentication data, and a log of actions taken so that changes to supply-chain records are auditable. The website collects standard server logs and any details you submit through a contact form.

Section titled “5. Why we process this data, and on what legal basis”
Purpose Legal basis
Providing the platform to our customers Performance of a contract with the customer; for farmer data, processing on the controller’s instructions
Authenticating users and securing accounts Legitimate interests — keeping the service secure
Diagnosing crashes and improving reliability Legitimate interests — the software must work offline in remote areas, where faults are hard to reproduce
Producing compliance evidence, including EUDR due diligence The customer’s legal obligation, for which we act as processor

We do not sell personal data. We do not use it for advertising or profiling.

Service Purpose Location
Google Cloud / Firebase Hosting, authentication, database, file storage, push notifications EU and US
Sentry Crash and error reporting, including session replay United States
Mapbox / MapLibre Map tiles shown in the app and dashboard United States
Google Sign-In Optional account sign-in United States

About session replay. We use Sentry to understand faults that happen in the field. This includes recording a sample of roughly one in ten sessions so we can see the sequence of screens that led to an error. These recordings mask on-screen text and block images by default, so they show the structure of what happened rather than the content of records. They are stored in the United States.

Transfers outside the EEA. Some of the services above are based in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

We retain supply-chain and compliance records for five years, which matches the record-keeping period required for EUDR due diligence. Our customers may instruct us to delete data sooner, and we return or delete data when a customer contract ends, subject to any retention we are legally required to apply.

Account data is kept while the account is active and deleted within a reasonable period afterwards. Crash and session replay data is kept according to Sentry’s retention settings.

Data is encrypted in transit. Access to production systems is limited to staff who need it. Data on the device is protected by the device’s own security; agents should use a screen lock, because the app is designed to hold records offline.

If you are in the EEA or UK you have the right to access your data, correct it, have it deleted, restrict or object to processing, and receive it in a portable form. You may also complain to a supervisory authority — in Finland, the Office of the Data Protection Ombudsman.

If you are a farmer or supplier recorded in Orijin, please direct these requests to the organisation that registered you, for the reason explained in section 2.

Orijin is workplace software and is not intended for children. We do not knowingly collect data from anyone under 16.

We will update this page when our processing changes, and revise the date at the top. Material changes will be communicated to our customers directly.