DataGovernance&Management
Last updated: 30 June 2025
1. Overview
AINTELLIGENCE is committed to responsible data governance across all operations. This Data Governance & Management document outlines the principles, processes, and controls we apply to data collected and processed through our agricultural intelligence platform, in alignment with GDPR, the EU Deforestation Regulation (EUDR 2023/1115), and applicable Ivorian data protection law.
2. Data Classification
We classify data into four tiers: Public (marketing content, published reports), Internal (operational data, aggregated analytics), Confidential (personal data, customer farm records, screening results), and Restricted (authentication credentials, payment data). Each tier carries specific handling, storage, and access controls.
3. Data Processing Principles
All data processing at AINTELLIGENCE is governed by the principles of lawfulness, fairness, and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. We maintain records of processing activities (ROPAs) in accordance with Article 30 GDPR.
4. EUDR Data Obligations
Geolocation data and due diligence statements processed for EUDR compliance are handled under Article 9 of Regulation (EU) 2023/1115. We retain all compliance records for a minimum of five years. Operator and trader data submitted for deforestation risk assessments is processed solely for the purpose of regulatory due diligence.
5. Security Measures
We implement technical and organisational security measures including AES-256 encryption at rest, TLS 1.3 in transit, role-based access control (RBAC), multi-factor authentication for administrative access, regular penetration testing, and automated vulnerability scanning. Security incidents are managed under our Incident Response Policy.
6. Third-Party Processors
We engage third-party data processors (cloud infrastructure providers, satellite data vendors, mapping APIs) under data processing agreements that require GDPR-equivalent protections. A current list of sub-processors is available on request. We conduct annual reviews of all third-party data handling practices.
7. Audit & Accountability
Our data governance framework is reviewed annually by management and on an ad-hoc basis following any material change to processing activities or applicable regulation. Audit logs of data access and processing events are retained for 12 months. Staff with data access responsibilities receive annual data protection training.
8. Contact & Data Protection Enquiries
For data governance enquiries, to request a copy of our Data Protection Impact Assessment (DPIA), or to raise a concern, contact us at: admin@aintelligence-ci.com. We are committed to responding to all enquiries within 30 days.
Questions about our data practices?
Our team is available to walk you through how we collect, process, and protect agricultural data across our platform.
Get in Touch