Privacy Policy
Last updated: 22 September 2026
Orijin Oy (“Orijin”, “we”) builds software that helps agricultural producers, cooperatives and exporters record where their crops come from and demonstrate compliance with regulations such as the EU Deforestation Regulation (EUDR).
This policy covers the Orijin OnField mobile app, the Orijin web dashboard, and orijin.io.
1. Who to contact
Section titled “1. Who to contact”Orijin Oy, Finland — privacy@orijin.io
2. Our role: when we are a processor, and when we are a controller
Section titled “2. Our role: when we are a processor, and when we are a controller”This distinction matters, because it determines who you should contact about your data.
Farmer and supply-chain data — we are a processor. When a cooperative, exporter or producer organisation uses Orijin, they decide which farmers to register, what to record and why. We process that data on their documented instructions, under a data processing agreement. If you are a farmer whose details are held in Orijin and you want to see, correct or delete them, contact the organisation that registered you. They are the controller. We will support them in responding, but we cannot act on your data without their instruction.
Accounts of people who use our software — we are the controller. For the field agents, supervisors and administrators who log in to Orijin, we decide how account and usage data is handled, and this policy applies to us directly.
3. What the field app collects
Section titled “3. What the field app collects”The Orijin OnField app is used by field agents working for our customers. It collects:
- Account details — name, email address, and the organisation you belong to.
- Precise location. The app records GPS coordinates when an agent stamps a form, registers a farm, or walks a plot boundary. Boundary walking uses a foreground service, so location is collected while the walk is running and a notification is shown throughout. We record the accuracy of each reading alongside the coordinates, because accuracy is itself evidence of data quality. Location is never collected when the app is closed.
- Photographs taken through the app — farms, crops, receipts, signatures and supporting documents.
- Device information — model, manufacturer, operating system version, app version, a device identifier, and whether the device was online or offline when a record was created.
- Bluetooth readings from connected weighing equipment. Bluetooth permissions are used only to talk to scales; the app does not scan for or track nearby devices or people.
- Supply-chain records entered by the agent — farmer and supplier names and contact details, farm and plot locations and boundaries, crop and collection quantities, prices and payments. This is the farmer data described in section 2, for which our customer is the controller.
Receipt text recognition runs entirely on the device. The app bundles an offline text recognition model, so when it reads a printed receipt the image is processed on the phone. The image is not sent anywhere for that purpose.
The app is built to work offline. Records are stored on the device and synchronised when a connection is available.
4. What the dashboard and website collect
Section titled “4. What the dashboard and website collect”The dashboard collects account details, authentication data, and a log of actions taken so that changes to supply-chain records are auditable. The website collects standard server logs and any details you submit through a contact form.
5. Why we process this data, and on what legal basis
Section titled “5. Why we process this data, and on what legal basis”| Purpose | Legal basis |
|---|---|
| Providing the platform to our customers | Performance of a contract with the customer; for farmer data, processing on the controller’s instructions |
| Authenticating users and securing accounts | Legitimate interests — keeping the service secure |
| Diagnosing crashes and improving reliability | Legitimate interests — the software must work offline in remote areas, where faults are hard to reproduce |
| Producing compliance evidence, including EUDR due diligence | The customer’s legal obligation, for which we act as processor |
We do not sell personal data. We do not use it for advertising or profiling.
6. Who else processes data on our behalf
Section titled “6. Who else processes data on our behalf”| Service | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, database, file storage, push notifications | EU and US |
| Sentry | Crash and error reporting, including session replay | United States |
| Mapbox / MapLibre | Map tiles shown in the app and dashboard | United States |
| Google Sign-In | Optional account sign-in | United States |
About session replay. We use Sentry to understand faults that happen in the field. This includes recording a sample of roughly one in ten sessions so we can see the sequence of screens that led to an error. These recordings mask on-screen text and block images by default, so they show the structure of what happened rather than the content of records. They are stored in the United States.
Transfers outside the EEA. Some of the services above are based in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
7. How long we keep data
Section titled “7. How long we keep data”We retain supply-chain and compliance records for five years, which matches the record-keeping period required for EUDR due diligence. Our customers may instruct us to delete data sooner, and we return or delete data when a customer contract ends, subject to any retention we are legally required to apply.
Account data is kept while the account is active and deleted within a reasonable period afterwards. Crash and session replay data is kept according to Sentry’s retention settings.
8. How we protect data
Section titled “8. How we protect data”Data is encrypted in transit. Access to production systems is limited to staff who need it. Data on the device is protected by the device’s own security; agents should use a screen lock, because the app is designed to hold records offline.
9. Your rights
Section titled “9. Your rights”If you are in the EEA or UK you have the right to access your data, correct it, have it deleted, restrict or object to processing, and receive it in a portable form. You may also complain to a supervisory authority — in Finland, the Office of the Data Protection Ombudsman.
If you are a farmer or supplier recorded in Orijin, please direct these requests to the organisation that registered you, for the reason explained in section 2.
10. Children
Section titled “10. Children”Orijin is workplace software and is not intended for children. We do not knowingly collect data from anyone under 16.
11. Changes
Section titled “11. Changes”We will update this page when our processing changes, and revise the date at the top. Material changes will be communicated to our customers directly.