Back to Home

Data Processing Agreement

Last updated: April 14, 2026

This Data Processing Agreement governs how Robic Rufarm India Private Limited processes personal data on behalf of CAMARON platform users, in compliance with GDPR and other applicable data protection regulations.

Parties & Scope

This Data Processing Agreement ("DPA") is entered into between you ("Data Controller") and Robic Rufarm India Private Limited ("Data Processor"), operating the CAMARON aquaculture intelligence platform. This DPA applies to all personal data processed by CAMARON on your behalf, including employee and operator data, pond access grants, and IoT sensor metadata associated with identifiable individuals. This DPA supplements our Privacy Policy and Terms of Service.

Categories of Data Processed

CAMARON processes the following categories of personal data on behalf of the Controller: • Account data: name, email address, phone number, company name, role, profile avatar • Operational data: pond configurations, farm locations (GPS coordinates), crop logs, growth records • IoT metadata: device identifiers, sensor reading timestamps, device GPS coordinates • Communication data: consultation messages, support tickets, forum posts • Usage data: feature usage patterns, login timestamps, IP addresses • Financial data: subscription tier, billing history (payment details are processed by Paddle as Merchant of Record and are not stored by CAMARON) Data subjects include: farmers, technicians, doctors, lab technicians, exporters, importers, and other platform users authorized by the Controller.

Processing Instructions

The Processor shall process personal data only on documented instructions from the Controller, including: • Providing the CAMARON platform services as described in the Terms of Service • Storing and analyzing sensor data, crop logs, and growth records • Running AI-powered analysis (disease detection, feed optimization, growth forecasting) • Sending notifications and alerts related to pond conditions • Generating reports and export compliance documents The Processor shall not process personal data for any purpose other than providing the contracted services unless required by applicable law, in which case the Processor shall inform the Controller before processing (unless prohibited by law).

Security Measures

The Processor implements the following technical and organizational measures to protect personal data: • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest • Access controls: Role-based access control (RBAC) with row-level security (RLS) on all database tables • Authentication: Multi-factor authentication for administrative access, unique device keys for IoT authentication • Infrastructure: SOC 2 Type II compliant hosting, regular penetration testing and vulnerability assessments • Monitoring: 24/7 intrusion detection, automated anomaly alerts, comprehensive audit logging • Personnel: Background checks for employees with data access, mandatory security training, confidentiality agreements • Incident response: Documented incident response plan with <24 hour notification to Controller for confirmed breaches

Subprocessors

The Controller provides general authorization for the Processor to engage subprocessors. Current subprocessors include: • Cloud infrastructure: AWS / Google Cloud (Mumbai, Jakarta, Ho Chi Minh City, Frankfurt data centers) • Payment processing: Paddle (Merchant of Record — processes payment data independently as a controller) • AI processing: Google AI (anonymized data only, no personally identifiable information transmitted) • Email delivery: Resend (transactional and notification emails) • Analytics: PostHog (anonymized usage analytics) The Processor shall notify the Controller at least 30 days before adding or replacing a subprocessor. The Controller may object within 14 days. If a reasonable objection cannot be resolved, the Controller may terminate the affected services. Each subprocessor is bound by data protection obligations no less protective than those in this DPA.

Data Subject Rights & Breach Notification

The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timeframes required by applicable law. Self-service tools are available in the platform: users can export their data (JSON format) and delete their accounts via Settings. In the event of a personal data breach, the Processor shall notify the Controller without undue delay and within 24 hours of becoming aware of the breach. Notification shall include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

International Transfers & Compliance

For transfers of personal data outside the Controller's jurisdiction, the Processor relies on: • Standard Contractual Clauses (SCCs) as approved by the European Commission (Module 2: Controller to Processor) • Adequacy decisions where available • Data localization: Regional data processing occurs within certified data centers in the respective jurisdictions — Mumbai (India), Jakarta (Indonesia), Ho Chi Minh City (Vietnam), and Frankfurt (EU) This DPA complies with: GDPR (EU), UK GDPR, India's Digital Personal Data Protection Act (DPDPA) 2023, Vietnam's Cybersecurity Law 2018, Indonesia's GR 71/2019, and CCPA (California). This DPA remains in effect for the duration of the service agreement. Upon termination, the Processor shall delete or return all personal data within 30 days, unless retention is required by applicable law. For questions about this DPA or to request an executed copy, contact dpo@robicrufarm.com.