1. Scope and institutional commitment
This Privacy Policy governs the processing of personal data carried out by AGM on its website, mobile applications, APIs, market intelligence dashboards and B2B marketplace environment. It has been structured to comply simultaneously and strictly with the European Union General Data Protection Regulation (GDPR 2016/679), the UK GDPR, Quebec Law 25 (Canada), the California Consumer Privacy Act as amended by the CPRA (USA), the Lei Geral de Proteção de Dados (LGPD, Brazil), the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP, Mexico) and Law 1581 of 2012 (Colombia).
2. Categories of personal data collected
AGM collects only the personal data strictly necessary to provide its agri-food market intelligence services and to facilitate B2B trade:
- Professional identification and contact data: first name, surname, corporate email address, direct or mobile telephone number, job title, employing company, agricultural sector or industry (e.g. grains, rendering, biofuels, fertilizers) and country of residence.
- Account and security data: authentication credentials (passwords stored using irreversible cryptographic hashing), unique user identifiers (UUID), session tokens and access logs.
- Transactional and billing data: subscription history, tokenized payment methods provided by PCI-DSS certified gateways (Stripe), and corporate tax and billing data (legal name, Tax ID / VAT / RFC / RUT, registered address). AGM never stores full card numbers (PAN) or CVV codes on its servers.
- Platform usage and intelligence data: dashboards consulted, search filters applied by product or CIF/FOB tariff heading, PDF/Excel download volumes, AI engine queries and commercial interaction records in the Marketplace.
- Technical and telemetry data: IP addresses (anonymized or truncated for analytics), browser type, operating system, device identifiers, screen resolution, regional settings and strictly necessary session cookies.
3. Legal bases for processing
AGM's processing of personal data relies on the following legal bases (Art. 6 GDPR / Art. 7 LGPD / LFPDPPP / Law 1581):
- Performance of a contract (Art. 6.1.b GDPR): processing of credentials, billing data and platform access is indispensable to provide the market intelligence subscriptions and marketplace requested by the user.
- Express and informed consent (Art. 6.1.a GDPR / Quebec Law 25 / Colombian Law 1581): required by affirmative action for analytical newsletters, commercial communications and the use of non-essential analytics cookies.
- Compliance with legal obligations (Art. 6.1.c GDPR): retention of invoices and accounting records, and cooperation with competent tax or judicial authorities.
- Overriding legitimate interest (Art. 6.1.f GDPR): prevention of computer fraud, network security and technical optimization of the platform, provided this does not override the fundamental rights and freedoms of data subjects.
4. Specified purposes of processing
The personal data collected will be used to:
- Provide and personalize access to the Market Intelligence tools (70+ countries).
- Manage corporate user onboarding, multi-factor authentication and 24/7 technical support.
- Issue commercial invoices and process payments for annual subscriptions or individual chart purchases.
- Connect verified buyers and suppliers within the B2B agricultural Marketplace.
- Send market alerts, FOB/CIF price movements and sector reports where these have been expressly requested.
- Ensure cybersecurity, prevent DoS/DDoS attacks and audit unauthorized access.
5. Third-party security services (CAPTCHA)
AGM uses Google reCAPTCHA v2, a security and anti-abuse service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, United States), to protect its contact forms, sign-up flows and platform access against automated abuse ("bots").
The widget is not loaded when the page opens. It is activated only once you begin to interact with the form it protects, so that no data is transmitted to Google if you merely visit the page.
When the widget is activated, Google processes certain personal data, including your IP address, browser and operating-system version, referring and visited pages, mouse and keyboard behaviour, session duration and device characteristics, and sets Google cookies on your browser. AGM processes this data for the purposes of fraud prevention, abuse mitigation and the security of its network and service (Art. 6(1)(f) GDPR — legitimate interest, Recital 49 GDPR). Where reCAPTCHA sets non-essential cookies, activation additionally requires your prior consent through the Cookie Preference Center, which may be withdrawn at any time (Art. 6(1)(a) GDPR; ePrivacy Directive Art. 5(3)).
Google may transfer this data to servers located in the United States. Such transfers rely on the EU-US Data Privacy Framework certification of Google and, where the DPF does not apply, on the European Commission's Standard Contractual Clauses (SCCs) supplemented by appropriate technical and organizational measures.
Further information: Google Privacy Policy — https://policies.google.com/privacy — and Google Terms of Service — https://policies.google.com/terms.
6. Social sign-in (Google / LinkedIn OAuth)
You may create and access your account using "Sign in with Google" or "Sign in with LinkedIn". These are authentication services operated by Google Ireland Limited / Google LLC and LinkedIn Ireland Unlimited Company (Wilton Place, Dublin 2, Ireland) respectively; the integration is powered by NextAuth.js on AGM infrastructure.
If you choose social sign-in and authorize the connection on the provider's own consent page, AGM receives only the following categories of personal data from the provider:
- Google: name, email address (when marked verified by Google) and profile picture URL.
- LinkedIn: first and last name, email address, profile picture URL and — only where you grant the corresponding permission on LinkedIn's authorization screen — your current company or organization name and professional headline.
AGM uses this data solely to create and authenticate your AgriGlobal Market account, to personalize your dashboard and to keep legally required account records. OAuth profile data is not used for advertising, behavioural profiling, cross-site tracking or automated decision-making, and AGM never requests access to your contacts, messages or posting permissions.
Legal bases: Art. 6(1)(b) GDPR (performance of the contract — authentication at your express request) and, for optional provider fields such as company name, Art. 6(1)(a) GDPR through the consent you grant on the provider's own consent screen, which you may revoke at any time in your provider account settings. Using social sign-in is entirely optional; form-based registration remains available without any OAuth processing.
Where a provider transfers data outside the EEA, transfers rely on the EU-US Data Privacy Framework and/or the Standard Contractual Clauses. Processing performed by the provider before the handover is governed by the provider's own terms: https://policies.google.com/privacy and https://www.linkedin.com/legal/privacy-policy.
7. Recipients and international data transfers
To operate a global agri-food intelligence platform, AGM shares data with technology service providers under strict data processing agreements (DPA, Art. 28 GDPR):
- Edge infrastructure and network: Cloudflare Inc. (USA — certified under the EU-US Data Privacy Framework and Standard Contractual Clauses).
- Cloud hosting and computing: Amazon Web Services (AWS) / Vercel Inc. (data centres in the USA and the European Union).
- Secure payment processing: Stripe Inc. (PCI-DSS Level 1 certification).
- Transactional email and communications: Resend / SendGrid / Amazon SES.
All international transfers outside the European Economic Area (EEA), the United Kingdom, Quebec or countries without an adequacy decision are carried out under the Standard Contractual Clauses (SCCs) approved by the European Commission, supported by Transfer Impact Assessments (TIA).
8. Retention periods
Personal data is retained only for as long as strictly necessary to fulfil the purposes described:
- Account and subscription data: for the duration of the contractual relationship plus a statutory limitation period of 5 to 10 years under applicable tax and commercial law.
- Form and prospect data: a maximum of 24 months from the last interaction, unless consent is withdrawn earlier.
- Security and access logs: 12 months, after which they are irreversibly deleted or anonymized.
- Consent records: retained immutably for 5 years as evidence of compliance (accountability).
9. Data subject rights (DSAR / GDPR / CCPA)
Users hold the following inalienable rights over their personal data:
- Right of access: to know what data is processed, for what purpose and who receives it.
- Right to rectification: to request correction of inaccurate, incomplete or outdated data.
- Right to erasure ("right to be forgotten"): to require definitive deletion and purging of personal data once it is no longer necessary for the contracted purposes.
- Right to object: to object to processing based on legitimate interest or direct marketing.
- Right to restriction of processing: to request temporary suspension of processing where accuracy is contested.
- Right to data portability: to receive data in a structured, commonly used and machine-readable format (JSON / CSV).
- Right not to be subject to automated decision-making, including profiling with legal effects.
- CCPA/CPRA rights (California): right to know, right to delete and right to opt out of the sale or sharing of personal information. AGM expressly declares that it does NOT sell or trade its users' personal information.
How to exercise your rights: send a request to [email protected] stating your full name, company, the email address associated with your account and the right you wish to exercise. AGM will respond within a maximum of 30 calendar days (GDPR / Law 25) or 20 business days (LFPDPPP).
10. Jurisdiction-specific clauses
- Quebec residents (Law 25): the Personal Data Protection Officer is the corporate Privacy Director ([email protected]). Identification and geolocation technologies are disabled by default. Users retain the punitive damages action under Art. 93.1 of Law 25.
- Colombian residents (Law 1581): processing is governed by the principle of freedom and prior, express and informed consent. Corporate databases are structured in accordance with the requirements of the Superintendence of Industry and Commerce (SIC).
- Mexican residents (LFPDPPP): this document constitutes the Comprehensive Privacy Notice made available to you. In the event of disagreement, you may contact the National Institute for Transparency, Access to Information and Personal Data Protection (INAI).
