Legal documents

Terms of Service

Version:
1.0
Effective from:
17 August 2026

This is a courtesy translation. The Spanish version is the only binding one and prevails in case of any discrepancy.

Read the Spanish version

The contract between you and Agripino: what we give you, what we ask of you, what it costs, who owns the data, and how we end the relationship if we must.

1. Language of the contract

These Terms are drafted in Spanish, which is the only binding version of the contractual relationship. Any translation into another language is offered purely for convenience and has no contractual value. In the event of discrepancy or doubt as to interpretation, the Spanish version always prevails.

We do it this way because article 42(i) of Law 7472 declares absolutely void any clause of an adhesion contract drafted in a language other than Spanish. All communications, invoices and contractual documents are likewise issued in Spanish.

2. Who we are and what you accept

This contract is entered into between you, or the legal entity you represent, and PENDIENTE DE COMPLETAR (razón social registrada), Cédula jurídica PENDIENTE DE COMPLETAR (3-101-XXXXXX), with registered offices at PENDIENTE DE COMPLETAR (dirección exacta), PENDIENTE DE COMPLETAR, PENDIENTE DE COMPLETAR, PENDIENTE DE COMPLETAR, Costa Rica, telephone PENDIENTE DE COMPLETAR (teléfono de contacto) and email [email protected].

By ticking the acceptance box during registration you accept these Terms and their six annexes, which are reproduced in full at the foot of this document and form an inseparable part of the contract.

The annexes are not incorporated by reference to an external document: they are presented to you in full on this same page. Article 42 of the Regulation to Law 7472 renders relatively void any clause making consent depend on presumed knowledge of other normative bodies external to the contract, and we do not want any part of this agreement to be in that position.

If you accept on behalf of a legal entity, you represent that you have sufficient authority to bind it.

3. What Agripino is

Agripino is an online farm management platform. It allows you to record and administer information on cattle, dairy, pigs, poultry and crops, along with inventory, staff, finances and traceability.

As to how it works technically, you should know the following:

  • It requires an internet connection. The web application does not work offline.
  • It works in current browsers. It is compatible with current versions of commonly used browsers, on desktop and mobile.
  • It allows export. Your information can be exported in open formats, so it is never held captive by the platform.
  • It includes no technological protection measures restricting the use or copying of the information you generate.
Agripino is a record-keeping and decision-support tool. The recommendations it displays, including those on nutrition, animal health, stocking density or costs, are indicative and based on published standards. They do not replace the judgement of a qualified veterinarian, agronomist or accountant, nor do they relieve you of your obligations before SENASA, MAG, the CCSS or the Tax Administration.

4. Your account

  • To use Agripino you must create an account with truthful details and keep them up to date.
  • You are responsible for keeping your password confidential and for activity occurring under your account.
  • You must tell us promptly at [email protected] if you detect unauthorised use.
  • Each user must have their own account. The organisation's account holder administers their team's access and roles.

The rules on permissible use of the platform are in Annex A.

5. Who owns the data

The data you record in Agripino is yours. We acquire no ownership over it, nor over information about your animals, your crops, your production, your costs or your staff.

You grant us only the limited, non-exclusive and revocable licence we need to host, process, back up and display that information to you, that is, to deliver the contracted service. That licence ends when the contract ends.

Specifically, we undertake as follows:

  • We do not sell or assign your data to third parties.
  • We do not use your farm data to train artificial intelligence models.
  • We do not publish or commercialise aggregated or anonymised data derived from your operation without your prior express authorisation, given separately and revocable.
  • We let you export all your information at any time, during the contract and for 30 calendar days after it ends.

Processing of third-party personal data that you record is governed by Annex D, and processing of your own data by the Privacy Policy.

6. Prices, taxes and billing

  • Free trial. We offer 30 days of free trial without asking for a credit card.
  • Monthly plans. Plans are billed month to month, with no minimum term and no cancellation penalty.
  • Final price. Prices are published including the 13 % Value Added Tax in force in Costa Rica, with its breakdown, under article 187 of the Regulation to Law 7472.
  • No hidden charges. We charge no activation, setup or cancellation fees. If an additional charge ever existed, you would be told before contracting.
  • Late payment. In the event of non-payment we will tell you and you will have 10 business days to regularise before the account becomes read-only. We do not apply default interest.

Before confirming any contracting we will show you a summary with the service, the total price including taxes, the billing period and the cancellation conditions, and will afterwards send you a durable receipt of the transaction.

7. Term, renewal and cancellation

The contract is for an indefinite term and renews automatically at the start of each monthly cycle unless cancelled.

Cancelling is as easy as subscribing, and is done from your own account. We will not ask you to telephone, write a letter or answer a retention questionnaire. Making cancellation harder than signing up is a prohibited practice.

The full cancellation conditions, the eight-business-day withdrawal right and the refund cases are in Annex C.

8. Changes to these Terms

We may update these Terms, for example to reflect changes to the service or to the law. When we do:

  • We will publish the new version with its number and effective date, keeping earlier ones accessible.
  • We will notify you by email at least 30 calendar days in advance.
  • Material changes will require your express acceptance before taking effect, and will apply from the following billing cycle.
  • If you do not accept the new version you may terminate the contract without penalty and with a pro-rata refund of the unused portion.
Under no circumstances will we unilaterally change the conditions of the cycle you have already paid for, nor suspend the service at our discretion. Article 42(e) of Law 7472 declares absolutely void any clause empowering the provider to unilaterally rescind, modify, suspend or limit the contract, except where the other party is in breach.

9. Suspension and termination for breach

We may suspend or terminate the service if you breach these Terms or Annex A, following the procedure described there: written notice, a period of no less than 10 business days to remedy, and only then suspension.

Immediate suspension is reserved for manifest unlawful activity, attacks on the infrastructure, or real risk to third-party data, and even then we will tell you the reason within the following 24 hours.

You may terminate the contract whenever you wish, without stating a reason, under Annex C.

10. Warranty

The service is provided with the statutory warranty of conformity established by article 43 of Law 7472. We do not exclude, limit or condition that warranty, because a clause to that effect would be void.

We undertake that the service will work as described in this contract and in the informational material we publish. If it does not, you are entitled to have it corrected and, where applicable, to a price reduction or to termination of the contract.

The availability commitment and the credits for shortfall are in Annex B. Those credits are an additional commercial warranty that adds to the statutory warranty and in no case replaces it.

11. Liability

We are liable for damages we cause by breach of this contract, under Costa Rican law.

We do not limit our liability for personal injury, for wilful misconduct or gross negligence, for defective performance or for delay. Article 42(d) of Law 7472 declares absolutely void any clause purporting to do so, and we do not include one.

Outside those cases, and solely as regards indirect economic loss, the parties agree that compensation is limited to the amount actually paid for the service in the twelve months preceding the triggering event.

We are not liable for damages arising from: information you record inaccurately; failure to meet your obligations before administrative authorities; use of the service contrary to Annex A; or force majeure events.

We remind you that responsibility for keeping your own backups of your operation's critical information is shared: we back up the platform, and you can export your data at any time.

12. Intellectual property

The platform, its code, its design, the Agripino brand and the documentation are ours or are used under licence. We grant you a non-exclusive, non-transferable right of use while the contract is in force.

These Terms and several of their annexes are derivative works of documents published under Creative Commons licences. Each document states its licence and attribution at the foot, and is published under the same licence as the original work.

If you send us product suggestions or feedback, we may use them freely to improve it, without this creating any obligation or right to remuneration for you.

13. Complaints

We provide a free complaints channel at [email protected], accessible through the same electronic medium you used to contract. We acknowledge receipt within 2 business days and respond substantively within 10 business days.

If the response does not satisfy you, you may turn to the Dirección de Apoyo al Consumidor, Ministerio de Economía, Industria y Comercio (MEIC), telephone 800-CONSUMO (800-2667866) (https://www.consumo.go.cr).

14. Applicable law and jurisdiction

This contract is governed by the laws of the Republic of Costa Rica.

Disputes are submitted to the ordinary courts of Costa Rica. We do not stipulate mandatory arbitration, waiver of procedural rights, or foreign jurisdiction: article 104 of the Regulation to Law 7472 treats the imposition of arbitration in adhesion contracts as not written, and article 42(g) declares void any waiver of procedural rights.

The electronic contract is deemed concluded at the consumer's domicile, under the Regulation to Law 7472.

Nothing agreed here prevents you from pursuing administrative remedies before the National Consumer Commission or before PRODHAB.

15. Final provisions

Partial invalidity
If any clause is void, the remainder stays in force and the affected clause is interpreted in the manner most favourable to the adhering party.
Interpretation
Ambiguous conditions are interpreted in favour of the adhering party, under article 42 of Law 7472.
Assignment
You may not assign this contract without our written consent. If we assign it as a result of a corporate reorganisation, we will notify you 30 calendar days in advance and you may terminate without penalty.
Notices
Notices will be sent to the email address registered on your account. Please keep it up to date.
Advertising
We will not send you commercial communications without your prior consent. When we do, they will be identified as such from the start of the message and you will be able to unsubscribe immediately.
Entire agreement
These Terms and their six annexes constitute the entire agreement between the parties concerning the use of Agripino.

Annexes

Annex AAcceptable Use Policy

Version 1.0 · Effective from 17 August 2026

1. Scope

This policy forms part of the Terms of Service and applies to everyone who uses Agripino, whether account holder or user invited to an organisation.

The list is deliberately short. We do not try to anticipate every conceivable misuse, but to describe clearly what we will not tolerate.

2. Prohibited uses

You may not use Agripino to:

  • Unlawful activity. Any purpose contrary to Costa Rican law or to the law of the country where you operate, including falsifying sanitary, traceability or payroll records.
  • Impersonation. Passing yourself off as another person or entity, or falsely stating your connection to a farm or organisation.
  • Unauthorised access. Attempting to reach another organisation's data, circumventing authentication or row-level security controls, or probing the infrastructure without written authorisation.
  • Degrading the service. Generating disproportionate automated load, running stress tests without prior coordination, or interfering with other people's legitimate use.
  • Harmful code. Uploading files containing malicious programs, or using the platform to distribute them.
  • Third-party content without rights. Uploading material you have no rights to, or personal data of third parties you are not entitled to process.
  • Unauthorised resale. Reselling, sublicensing or providing the service to third parties outside your organisation without a written agreement with us.
  • Harassment. Using free-text fields, record names or platform messages to harass, threaten or defame anyone, including our support staff.

3. Your staff data

Agripino includes payroll and time-tracking modules. When you record data about your workers, you are the data controller and you assume the obligations of Law 8968.

In concrete terms, it falls to you to:

  • Inform your staff that their data is recorded in Agripino, for what purpose and who may consult it.
  • Obtain their express consent where the law requires it, separately from the employment contract.
  • Handle the access, rectification and suppression requests your workers put to you.
  • Record only the data necessary for employment management, and not sensitive data you do not need.

We act as processor and give you the tools to comply. The relationship is governed by the Data Processing Agreement, incorporated into the Terms as an annex.

4. Accounts and credentials

  • Each user must have their own account. Sharing credentials makes it impossible to know who did what and compromises the traceability of records.
  • You are responsible for keeping your password confidential and for telling us immediately if you suspect unauthorised use.
  • When someone leaves your organisation, it is for you to deactivate their access on the platform.

5. What we do about a breach

We would rather talk than suspend. Unless there is immediate risk to other users or to the integrity of the service, we proceed as follows:

  • Notice. We tell you in writing which conduct we consider contrary to this policy and give you a reasonable period, no less than 10 business days, to correct it.
  • Suspension. If the breach persists after notice, we may suspend the account. Suspension is limited to what is necessary and is lifted once the cause is remedied.
  • Termination. For a serious, unremedied breach we may terminate the contract. In that case we refund the pro-rata unused portion of the current cycle and keep your data available for export for 30 calendar days.

Immediate suspension without prior notice is reserved for manifest unlawful activity, attacks on the infrastructure, or a real risk to third-party data. Even then we tell you the reason within the following 24 hours.

6. How to report abuse

If you observe a use of Agripino that contravenes this policy, write to [email protected] with whatever detail you can provide. We review every report.

License and attribution

Adapted from the Basecamp open-source policies, available under the Creative Commons Attribution 4.0 International licence. Text modified by Agripino.

Basecamp open-source policies — Use Restrictions37signals LLC · CC-BY-4.0

Annex BService Level Agreement

Version 1.0 · Effective from 17 August 2026

1. Availability commitment

We commit to keeping Agripino available 99.5 % of the time in each calendar month, measured as set out in section 3.

A monthly 99.5 % allows roughly 3 hours and 39 minutes of downtime per month. We would rather commit to a figure we can sustain with the infrastructure we actually have than announce a 99.99 % we would not be in a position to guarantee.

This agreement applies to customers on an active paid plan. During the free trial the service is provided without a service level commitment, although we make our best effort to keep it available.

2. Definitions

  • Downtime. A period during which the application does not respond to valid sign-in or data read requests, or returns server errors continuously for more than five consecutive minutes.
  • Scheduled maintenance. Work announced at least 48 hours in advance by email, carried out preferably between 22:00 and 05:00 Costa Rica time.
  • Total time in the month. The number of minutes in the relevant calendar month.

3. How it is measured

Monthly availability is calculated by taking the total time in the month, subtracting recorded downtime, and dividing the result by the total time in the month.

The following do not count as downtime:

  • Scheduled maintenance, up to a maximum of 4 hours per month.
  • Interruptions caused by the customer's network, internet provider or equipment.
  • Interruptions arising from use contrary to the Acceptable Use Policy.
  • Force majeure events, as understood under article 830 of the Commercial Code and article 702 of the Civil Code.

If you disagree with our measurement, you may submit your own records and we will review them in good faith.

4. Credits for shortfall

If in any calendar month we fail to meet the commitment, you are entitled to a credit against that month's fee:

Availability achievedCredit against the monthly fee
99.5 % or aboveNo credit
Between 99.0 % and 99.49 %10 %
Between 95.0 % and 98.99 %25 %
Between 90.0 % and 94.99 %50 %
Below 90.0 %100 %

To claim the credit, write to [email protected] within 30 calendar days of the end of the affected month. The credit is applied to the next invoice or, if the contract has ended, refunded by the same payment method used.

These credits are an additional commercial warranty. They neither replace nor limit the statutory warranty of conformity under article 43 of Law 7472, nor prevent you claiming for defective performance or delay under article 42(d) of that same law.

5. Prolonged outages

If the service remains continuously unavailable for more than 72 hours, you may terminate the contract immediately by written notice, with a pro-rata refund of the unused portion of the current cycle and without any penalty.

6. Support response times

Independently of availability, we commit to the following first-response times on Costa Rican business days:

SeverityDescriptionFirst response
CriticalThe service is down, or there is data loss or exposure.4 business hours
HighA core feature does not work and there is no alternative way to perform it.1 business day
NormalA fault with an available workaround, or a usage question.3 business days

The support channel is [email protected]. The formal complaints channel, free of charge under article 195 of the Regulation to Law 7472, is [email protected].

License and attribution

Adapted from the Basecamp open-source policies, available under the Creative Commons Attribution 4.0 International licence. Text modified by Agripino.

Basecamp open-source policies — Service Level Agreement37signals LLC · CC-BY-4.0

Annex CCancellations and Refunds

Version 1.0 · Effective from 17 August 2026

1. How to cancel

Cancelling is as easy as subscribing, and is done the same way: from your own account, without calling anyone, without writing an email and without answering retention questions.

You will find the cancellation option in your organisation settings. Cancellation takes effect at the end of the current billing cycle, so you keep access for the time you already paid for.

If you prefer to do it in writing, you can write to [email protected] and we will process it. It is not required, simply another route.

2. Right of withdrawal

Under article 40 of Law 7472 and article 72 of its Regulation, you have eight business days from the conclusion of the contract to withdraw, without needing to justify your decision and without penalty.

Withdrawal is exercised through the same medium you used to give consent, and the refund is made by the same payment method.

Statutory limit applicable to services: under article 73 of the Regulation, in the sale of services withdrawal applies only to the portion not yet effectively rendered. As this is a subscription, if you have already used the platform for part of the cycle, the refund is calculated pro rata over the days not consumed.

Example: if you take a monthly plan and withdraw on the fifth business day having used the service for five days, we refund the proportion corresponding to the remaining days of the cycle.

3. Other refunds

Besides withdrawal, we refund in the following cases:

  • Billing error. If we charge you an amount that was not due, we return it in full as soon as we verify it.
  • Prolonged outage. If the service is unavailable for more than 72 continuous hours, you may terminate with a pro-rata refund, under the Service Level Agreement.
  • Objected subprocessor change. If you reasonably object to a new subprocessor and we cannot offer an alternative, you may terminate with a pro-rata refund.
  • Termination by us. If we terminate the contract without any breach on your part, we refund the pro-rata unused portion.

Outside these cases, and outside withdrawal, monthly fees already consumed are not refunded. Plans are month to month with no minimum term, so you can cancel whenever you like to avoid being billed for the next cycle.

4. What happens to your data

On cancellation:

  • You keep access until the end of the paid cycle, including the ability to export all your information.
  • After that date, we keep your data available for export for a further 30 calendar days in read-only mode.
  • Once that period elapses, we delete your data from active systems. Encrypted backups retain it for up to 90 further days while they rotate.

You may request immediate deletion at any time by writing to [email protected]. We will handle it within the 5 business days set by article 7 of Law 8968.

Even after deletion we retain the record that you accepted the contractual documents, together with the associated email address. It is the proof that consent existed, and the law places that burden on us. That record contains no farm data.

5. Price changes

If we change the price of your plan we will tell you at least 30 calendar days in advance. The new price will apply only from the following billing cycle.

A price change is never applied unilaterally to the cycle in progress. If you do not accept the new price you may cancel before it takes effect, without penalty and without losing access to what you have already paid for.

6. Taxes

Published prices include the 13 % Value Added Tax applicable in Costa Rica and are shown with a breakdown, under article 187 of the Regulation to Law 7472. Refunds are calculated on the amount actually paid, tax included.

License and attribution

Adapted from the Basecamp open-source policies, available under the Creative Commons Attribution 4.0 International licence. Text modified by Agripino to incorporate the Costa Rican withdrawal right.

Basecamp open-source policies — Cancellation and Refund37signals LLC · CC-BY-4.0

Annex DData Processing Agreement

Version 1.0 · Effective from 17 August 2026

1. Parties and subject matter

This agreement is entered into between the natural or legal person holding the account, hereinafter the Controller, and PENDIENTE DE COMPLETAR (razón social registrada), hereinafter the Processor.

When you record data about your workers, suppliers or clients in Agripino, you decide what it is used for and are therefore the data controller. We process it only on your instructions, which makes us the processor. This distinction is what Law 8968 requires and is the reason this document exists.

This agreement forms an integral part of the Terms of Service and is incorporated into them as an annex, so that its content is presented alongside the main contract rather than by reference to an external document.

2. Definitions

Personal data
Any data relating to an identified or identifiable natural person, under article 3 of Law 8968.
Processing
Any operation on personal data: collection, recording, storage, consultation, modification, transfer or deletion.
Data subject
The natural person the data refers to: a farm worker, a supplier, a client.
Subprocessor
A third party engaged by the Processor that processes personal data on behalf of the Controller.

3. Scope of processing

The Processor processes the following data on behalf of the Controller:

Category of personsData processedPurpose
Farm staffName, identification number, position, wage, working hours, clock-in and clock-out records, deductions.Payroll management, time tracking and labour cost calculation.
Suppliers and clientsName or corporate name, identification, telephone, email, address.Recording purchases, sales, receivables and payables.
Account usersName, email address, role within the organisation.Authentication and access control.

Processing is carried out by automated means, for the term of the service contract and for the retention periods set out in section 9.

4. Processor obligations

The Processor undertakes to:

  • Process data only on instructions. It will not use the data for its own purposes, nor to build profiles, nor to train models, nor for any purpose other than delivering the contracted service.
  • Not sell or assign the data. Under no circumstances will it commercialise, disseminate or distribute the data to third parties.
  • Maintain confidentiality. The duty of secrecy survives the end of the contractual relationship, under article 11 of Law 8968.
  • Apply security measures. Those described in the Security Overview, which forms part of this agreement.
  • Assist the Controller. It will provide the technical means to handle access, rectification and suppression requests received from data subjects.
  • Notify incidents. It will report without undue delay any security breach affecting data processed on behalf of the Controller, with the information needed for the Controller to meet its own obligations.
  • Return or delete. On termination it will proceed as set out in section 9.

5. Controller obligations

The Controller represents and undertakes to:

  • Have informed data subjects, under article 5.1 of Law 8968, of the existence of the database, its purposes, who may consult it and how to exercise their rights.
  • Have obtained express consent where the law requires it, independently of any other document, and to retain proof of having done so.
  • Record only the data necessary for the stated purposes, refraining from entering sensitive data it does not need for farm management.
  • Handle, in its capacity as controller, requests from data subjects within the 5 business days set by article 7 of Law 8968.
  • Keep the list of users with access to its organisation up to date and revoke access for those who leave.
The Processor does not and cannot verify whether the Controller obtained its staff's consent. That obligation, and liability before PRODHAB for failing it, rest exclusively with the Controller.

6. Subprocessors

The Controller gives the Processor general authorisation to engage subprocessors, subject to the following conditions:

  • The current list is published in the Subprocessor List and forms part of this agreement.
  • The Processor will impose on each subprocessor, in writing, data protection obligations no less demanding than those in this agreement.
  • Any addition or replacement will be notified at least 10 business days in advance.
  • The Controller may object in writing within 30 calendar days of the notification.
  • If the objection is reasonable and no viable alternative exists, the Controller may terminate the contract without penalty, with a pro-rata refund of the unused portion.

The Processor is liable to the Controller for the acts and omissions of its subprocessors as if they were its own.

7. International transfers

The main database remains hosted in Costa Rica. File storage and network routing involve transfer to Cloudflare infrastructure outside the country.

Under Chapter III of Law 8968, those transfers rest on the informed consent of data subjects, which the Controller undertakes to obtain, and on contractual confidentiality and security commitments with the subprocessor.

8. Verification

The Controller may request, once a year and with 30 calendar days' notice, reasonable information to verify compliance with this agreement. The Processor will respond in writing and may satisfy the request with documentation of its security measures.

If the Controller requires an on-site audit, its scope, date and cost must be agreed in advance, and it may not compromise the confidentiality of other customers' data.

9. Return and deletion

On termination of the service contract:

  • The Controller retains read-only access and export capability for 30 calendar days.
  • After that period the Processor deletes the data from active systems.
  • Encrypted backups retain copies for up to a further 90 calendar days while they rotate, without being accessible for ordinary use.

After deletion the Processor retains, for the sole purpose of evidencing compliance with its legal obligations, the record of acceptance of the contractual documents. That record contains no farm or staff data.

10. Liability

Each party is liable for breach of the obligations this agreement places on it.

Nothing in this agreement limits the Processor's liability for personal injury, defective performance or delay, nor the statutory warranty of conformity. Under article 42(d) of Law 7472, a clause purporting to limit it would be absolutely void.

11. Term and applicable law

This agreement takes effect on acceptance of the Terms of Service and remains in force for as long as the Processor processes data on behalf of the Controller.

It is governed by the laws of the Republic of Costa Rica, in particular Law 8968 and its Regulation, and submits to the jurisdiction of the Costa Rican courts.

For any communication relating to this agreement: [email protected].

License and attribution

Based on the Common Paper Data Processing Agreement, available under the Creative Commons Attribution 4.0 International licence. Text modified by Agripino and adapted to Costa Rica's Law 8968.

Common Paper Data Processing AgreementCommon Paper, Inc. · CC-BY-4.0

Annex ESubprocessor List

Version 1.0 · Effective from 17 August 2026

1. Purpose of this list

When a customer uses Agripino, we process personal data on their behalf: that of their staff, their suppliers and their clients. In that relationship the customer is the data controller and Agripino is the processor. To deliver the service we rely on a small number of third parties, which act as subprocessors.

This list forms part of the Data Processing Agreement and is kept current. Any change is communicated at least 10 business days in advance, as described in section 5.

2. Our own infrastructure

Agripino does not use a third-party managed database. The database server, the authentication service and the application run on our own hardware located in Costa Rica, under our exclusive control.

This means your farm data, staff records and financial movements are stored in Costa Rica, on equipment we administer directly. There is no external cloud provider with access to that database.

We use PostgreSQL with Supabase in self-hosted mode. Supabase is open-source software that we run ourselves; Supabase Inc. plays no part in the processing and has no access to the data.

3. Current subprocessors

The following third parties take part in the processing. None is authorised to use the data for its own purposes.

SubprocessorRoleData reachedProcessing location
Cloudflare, Inc. — R2Storage of files and documents uploaded by the user (photographs, receipts, farm documents).File contents and their metadata.United States and Cloudflare global network.
Cloudflare, Inc. — Tunnel and networkRouting of all inbound traffic to the application, attack protection and TLS termination.IP addresses, request metadata and HTTP headers. No database content is stored.Cloudflare global network.
Cloudflare, Inc. — Email SendingDelivery of transactional email: account verification, password reset and invitations.Email address and name of the recipient.Cloudflare global network.
Cloudflare, Inc. is the only third-party company with access to personal data processed on behalf of our customers.
Cloudflare Email Sending is in the process of being enabled. Until it is operational the platform sends no email and accounts are confirmed automatically. This list will be updated when the service goes live.

4. International transfers

File storage and network transit involve transferring data outside Costa Rica. Pursuant to Chapter III of Law 8968, those transfers rest on the informed consent of the data subject and on contractual confidentiality and security commitments with the subprocessor.

The main database, which holds most of the farm, staff and financial information, remains in Costa Rica and is not transferred.

5. Changes to this list

Before adding a new subprocessor:

  • We publish the change on this page and notify the customer by email at least 10 business days in advance.
  • The customer has 30 calendar days to object in writing.
  • If the objection is reasonable and we cannot offer an alternative, the customer may terminate the contract without penalty and with a pro-rata refund of the unused portion of the current cycle.

To receive these notifications or to consult the change history, write to [email protected].

6. What we do not use

For the avoidance of doubt, and because their absence matters as much as their presence, we record that Agripino does not use:

  • Web analytics or behavioural tracking tools.
  • Advertising networks or third-party pixels.
  • Payment processors with access to platform data.
  • Third-party SMS or mapping services.
  • Third-party artificial intelligence services that receive user data.

If any of these are introduced in future, this list will be updated under the procedure in section 5 before they go into operation.

Annex FSecurity Overview

Version 1.0 · Effective from 17 August 2026

1. Our commitment

You trust us with your farm data: your animals, your staff, your costs and your income. That information describes your business rather precisely, and we treat it accordingly.

This document describes what we do today, not what we aspire to do. Section 7 expressly lists the measures we have not yet implemented.

2. Where your data lives

Agripino runs on our own infrastructure located in Costa Rica. The database, the authentication service and the application run on equipment under our direct control, not on a third-party managed cloud.

  • No exposed ports. The server accepts no direct inbound connections from the internet. All traffic enters through a Cloudflare tunnel, so the origin IP address is never exposed.
  • Minimal surface. The API gateway publishes only the authentication and data routes the application needs. Administration, schema editing, GraphQL, realtime and edge function services are disabled on public access.
  • Admin console off the internet. The database administration tool is reachable only through an SSH tunnel from the internal network.

3. Isolation between organisations

Agripino is a multi-tenant platform: several farms share the same database. Separation does not depend on application code but on the database itself.

  • Row Level Security. Every table has row-level security policies restricting each query to the authenticated person's organisation. Even if an application query were written incorrectly, the database would return no rows belonging to another organisation.
  • Automatic verification. An event trigger enables Row Level Security on every new table at creation time, so a table cannot be left unprotected by oversight.
  • Roles. Within an organisation, read and write permissions are controlled by role, and read-only users cannot modify records.

4. Encryption

  • In transit. All traffic between your browser and Agripino travels encrypted with TLS. We do not serve the application over unencrypted HTTP.
  • At rest. The volumes holding the database and its backups are encrypted. Files you upload are stored encrypted at rest at the object storage provider.
  • Passwords. Passwords are never stored in plain text. They are kept as salted cryptographic digests, and we can neither recover nor read them.

5. Staff access

Access to production systems is limited to those who need it to operate the service. In practice, and given the stage of the company, that group is very small.

  • Administrative server access uses SSH keys, not passwords.
  • We do not look at your farm data unless you expressly ask us to in order to resolve a support issue, or unless it is indispensable to restore service.
  • We do not sell, assign or share your data with third parties for their own purposes. The full list of third parties involved is in the Subprocessor List.

6. Backups and continuity

We take periodic backups of the database and keep them encrypted. Backups allow us to restore service after a hardware failure or an accidental deletion.

If you delete your account, your data disappears from active systems immediately and from backups as those rotate, within a maximum of 90 days.

7. What we do not yet have

We would rather say it before you ask. As at the date of this document we do not have:

  • SOC 2, ISO 27001 or equivalent certification.
  • Penetration testing by an independent third party.
  • Two-factor authentication for users.
  • A customer-visible audit log.
  • Round-the-clock security monitoring with an on-call rota.

These measures are on our roadmap. We will update this document when each one goes live, and not before.

8. Vulnerability reporting

If you discover a vulnerability in Agripino, please report it privately to [email protected] before disclosing it publicly.

We commit to acknowledging receipt within 3 business days, keeping you informed of progress, and taking no legal action against anyone researching in good faith, without accessing third-party data, without degrading the service and without exfiltrating information.

9. Security incidents

If an incident occurs affecting the security of your personal data, we will notify you without undue delay by email, describing what happened, which data were affected, what we did about it and what we recommend you do.

License and attribution

Adapted from the Basecamp open-source policies, available under the Creative Commons Attribution 4.0 International licence. Text modified by Agripino to reflect its own infrastructure.

Basecamp open-source policies37signals LLC · CC-BY-4.0

Provider identification

Razón social
PENDIENTE DE COMPLETAR (razón social registrada)
Nombre comercial
Agripino
Cédula jurídica
PENDIENTE DE COMPLETAR (3-101-XXXXXX)
Domicilio social
PENDIENTE DE COMPLETAR (dirección exacta), PENDIENTE DE COMPLETAR, PENDIENTE DE COMPLETAR, PENDIENTE DE COMPLETAR, Costa Rica
Teléfono
PENDIENTE DE COMPLETAR (teléfono de contacto)
Correo electrónico
[email protected]
Sitio web
agripino.io
Registrador del dominio
PENDIENTE DE COMPLETAR
Fecha de registro del dominio
PENDIENTE DE COMPLETAR
Alojamiento
Infraestructura propia ubicada en Costa Rica, con Cloudflare como proveedor de red y de almacenamiento de objetos.

License and attribution

Derivative work of the Automattic legal documents, available under the Creative Commons Attribution-ShareAlike 4.0 International licence. Adapted by Agripino to Costa Rican law and published under the same licence.

Legalmattic — WordPress.com Terms of ServiceAutomattic Inc. · CC-BY-SA-4.0