Privacy Policy
Farm Assistant — Privacy Policy & Collection Notice
Version 0.6 · in force from 18 September 2026
Scope and how this relates to the Regen Group policy
This Privacy Policy applies specifically to your use of Farm Assistant (the "Assistant"). Regen Digital Pty Ltd ("Regen Digital," "we," "us," "our") is the entity responsible for your personal information and Farm Data under this Policy — the same contracting entity as under the Terms of Use. Regen Digital operates the Assistant under arrangements with Regen Farmers Mutual Limited and Watney Labs Limited, governed by separate agreements; neither is a data controller under this Policy.
This Policy forms part of the Terms of Use by reference (Terms of Use §13.1). A plain-English summary of both sits in The Plain English Guide — that guide is a summary only; this Policy and the Terms of Use are what apply.
The wider Regen Group (Regen Farmers Mutual Limited and Regen Digital Pty Ltd together) also has a general Data Handling Policy covering regenfarmersmutual.com, membership, and other Regen Group activity. Where you interact with the Assistant, this Policy governs. For anything outside the Assistant (visiting regenfarmersmutual.com, becoming a member, job applications), the Regen Group's Data Handling Policy applies instead.
🌱 Farm Data Code. Regen Digital and Regen Farmers Mutual are working towards managing Farm Data in line with the Farm Data Code from the National Farmers' Federation — making it clear how we collect, use, share and manage Farm Data, with farmer control kept at the front of our decisions.
1. Overview and Privacy Controller
Regen Digital Pty Ltd is the entity responsible for the personal information and Farm Data handled through the Assistant (the Australian Privacy Principles "APP entity").
This Policy assumes you are resident in Australia and is framed against the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). If you are resident outside Australia, contact us for more information about how we handle your personal information.
2. What We Collect
Depending on how you use the Assistant, we may collect:
- Account details: name, farm business name and ABN, email, mobile number, address, payment details.
- Support and relationship records: your Telegram ID, Roadside Assistance conversation and support-ticket records, and management notes about your farm (including summaries of onboarding and support meetings) held in our internal account-management tools.
- Interaction content: messages, voice notes, photos and files you send to or receive from the Assistant, and the resulting chat/conversation history.
- Records your Assistant creates: the farm records it builds and keeps for you, the facts it retains about your farm, and your farm website's content and data.
- Connected-account data: information accessible via third-party systems and online accounts you connect — for example your accounting software, cloud storage, machinery and livestock platforms, or sensors.
- Usage and device data: how you interact with the Assistant and our website, browser/device information, and analytics data.
Sensitive information. We do not seek to collect sensitive information through the Assistant. "Sensitive information" includes health information and information about racial or ethnic origin, political opinions, religion, or sexual orientation. If sensitive information is volunteered (for example, in a message), we will only use or share it for the purpose it was given, or a directly related purpose, with your consent, or as required by law.
Information about other people. If you share information about someone else through the Assistant — for example a farmhand, contractor, family member or neighbouring landholder — you are responsible for having the right to share it with us. We handle that information the same way we handle any other personal information you provide.
This Policy applies to all data that we collect.
How this information is classified
Two classifications run across the data we collect.
Farm Data. Has the meaning given in the National Farmers' Federation Australian Farm Data Code (Edition 2, May 2023) - being any data relating to the operations, conditions or other characteristics of your farm that is:
- produced by you, or by your staff, contractors or equipment;
- created, packaged or acquired at your request, or in the provision of a service to you; or
- produced on your farm.
It covers that data in raw or processed form, on its own or as part of a combined dataset, and data derived from it — including new data created about you, your farm business or its products. Examples include production, sensor, soil, climate, transaction and environmental data, and data from monitors, machinery and other tools.
Personal information. Has the meaning given in the Privacy Act 1988 (Cth) — being information or an opinion about an identified individual, or an individual who is reasonably identifiable. It is the narrower term, and the one Australian privacy law operates on.
Farm Data is therefore a wider classification. Much of what your Assistant handles is about your farm rather than about you as a person, and would not be personal information on its own. However, the two classifications can overlap — Farm Data can include data about your farm such as location, GPS coordinates, plant or animal DNA, or soil information, where it is possible to identify you or your farm through it. This is called Identifying Farm Data and we protect it as we would any other personal information.
3. How We Collect It
Most personal information is collected directly from you — through your messages to the Assistant, through your personal farm website, or when you provide onboarding details. We may also collect information indirectly, for example through website analytics (clause 16), or from a third-party system you've connected and authorised the Assistant to access (clause 11).
4. Purposes of Collection, Use and Disclosure
We collect, hold, use and disclose your personal information and Farm Data to:
- operate and provide the Assistant, including generating Outputs from your Inputs;
- bill and manage your subscription (see the Subscription Agreement);
- provide support, including Roadside Assistance;
- send you scheduled onboarding and check-in messages via Roadside Assistance during your first weeks — you can opt out of these at any time;
- keep account-management records (usage notes, meeting summaries, support history) so our staff can support you consistently;
- where you consent, contribute a Resource to the Regen Library on the consent and attribution basis described in clauses 10 and 14;
- monitor, secure and improve the service using de-identified or aggregated information — including the telemetry reporting in accordance with clause 8;
- communicate with you about your account and, where you haven't opted out, about other products and services;
- comply with our legal obligations.
Once information has been de-identified or aggregated, we keep it in that form. We do not attempt to re-identify it, except where the law requires or permits us to.
Consistent with Terms of Use §8.3, we do not use your Inputs to train or fine-tune any AI model, to provide the service to any other farmer, or for any purpose other than operating Farm Assistant for you.
5. How we separate your data from others
No farmer can reach another farmer’s data. The infrastructure is set-up to physically isolate each Assistant, with the only departure from this approach being for shared access services and internal account management.
- Your farm's own data is separated by infrastructure. Your Assistant workspace and your private website are yours alone, and your farm sits in its own private network. Nothing at this layer is shared.
- The routing layer in the Switchboard is shared. It holds the access token for each authorised connection, encrypted at two layers — the store itself, and each token again under a key that belongs to that connection alone — together with the configuration for that connection. It does not keep an activity log of which of your systems was contacted and when. This store is located in the United States (clause 6). It has no other information about your farm, and no farm can reach another farm’s access tokens: no single key opens more than one connection. (See clause 11.)
- Regen Digital’s account management systems necessarily enable access and management of specific data to support farmers, but do not enable access to a farm’s Assistant infrastructure or website. These systems are only accessible by authorised Regen Digital and Regen Farmers Mutual staff and do not enable any farmer to reach another farmer’s data. (See clause 8 and clause 9.)
6. Sub-Processors and Overseas Disclosure
Your data is not confined to a single device or server. As part of normal operation it flows to the following sub-processors, some of which are located outside of Australia:
- AWS (EC2 / EBS), for compute and storage of your assistant's box — Australia.
- AWS Bedrock, which hosts the Anthropic AI models — Australia.
- OpenAI, for converting voice messages to text AND for generating the memory-search embeddings used in your assistant's recall — US.
- ElevenLabs, for outbound voice calls — limited test cohort only, US.
- GitHub, for source/version storage — US; Internal account-management knowledge base is also GitHub-hosted — US.
- Cloudflare, hosting your personal farm website — your site's data is held in the European Union and in Australia, and is served from the Cloudflare location nearest the visitor.
- Watney Labs — the shared connection service (the Switchboard) that routes requests between your Assistant and the third-party systems you connect — US.
- Telegram, as your messaging channel, US.
- Supabase, for Regen Digital account managment - Australia.
- Anthropic (direct API), used by Regen Digital for internal account-management — US.
Watney Labs Limited is a UK company. Where its staff access your data to provide support (clause 9), that access comes from outside Australia even where the data itself is stored here.
By using the Assistant, you consent to your personal information being disclosed to these overseas recipients. Overseas recipients may not be governed by the Privacy Act and may not comply with the Australian Privacy Principles.
7. AI Processing Disclosure
When you message the Assistant, your interaction content (and relevant Farm Data) is sent to AWS Bedrock for processing by the Anthropic inference (AI) models. As this is not a direct relationship with Anthropic — AWS Bedrock's data-handling terms apply, not Anthropic's consumer-API terms. Bedrock does not store your prompts or completions after the request, does not use them to train any model, and does not share them with model providers (including Anthropic) — inference runs in-region, governed by the AWS Service Terms and AWS Data Processing Addendum.
If you send a voice message, it is sent to OpenAI to convert it to text. The text content indexed into your assistant's memory is also sent to OpenAI, to generate the embeddings used for semantic recall. OpenAI is on a standard API plan; your data is not used to train OpenAI's models by default; it is retained for up to 30 days for abuse-monitoring purposes, then deleted.
For a limited test cohort only, outbound voice calls are handled by ElevenLabs, which receives the call audio and transcripts.
Neither Bedrock nor OpenAI uses your data to improve their models for other customers.
Internal account-management tooling. Regen Digital uses an internal account management system (Kelpie) to manage farmer relationships. Where staff query or discuss farmer records through Kelpie, that data is processed via Anthropic's direct API (not Bedrock). Anthropic retains API request and response data for up to 30 days for trust and safety monitoring, then deletes it. Anthropic does not use this data to train its models.
8. Reporting to Regen Digital / Regen Farmers Mutual
Two things go to Regen Digital and Regen Farmers Mutual each day:
The telemetry feed. A structured daily record for each Assistant, identified by its instance handle. It carries uptime and downtime; model and infrastructure cost, and token counts; a health status; the topics your Assistant worked on; which skills it used and how often; scheduled-job counts; and a record of each failure. Credentials are redacted before it leaves your Assistant.
The fleet report. A written daily summary for our staff, prepared from that feed and from support activity. It identifies you by name and describes what happened on your Assistant — what it was doing for you, what it sent or failed to send, and what needs fixing — so it can include Farm Data and details of what you asked for. It also shows what your Assistant cost to run that day. It goes to named staff at Regen Digital and Regen Farmers Mutual so that problems get found and fixed, and it is not published or shared outside Regen Digital, Regen Farmers Mutual and Watney Labs.
We retain the data from these reports for the life of the relationship.
9. Support and Admin Access
Access to Assistant data is limited to named Regen Digital and Watney Labs accounts, for support purposes:
- Roadside Assistance — our human-based support desk, reached via a dedicated Telegram channel. Your messages to it create support tickets; named staff read and respond. Roadside Assistance also sends your scheduled onboarding check-in messages.
- Kelpie (internal account management) — our staff-only tool holding relationship records about your farm (profile, notes, meeting summaries, ticket history). Staff queries about those records are processed via Anthropic's direct API. It is not farmer-facing and access is limited to an allow-list of named staff. We also analyse patterns across farms internally (staff-only) to decide what to build for the Regen Library. (See clause 10.)
- Fleet monitoring — an automated, read-only process on the Watney side that checks each Assistant's health and reads its diagnostic logs for reporting & support purposes only.
- Watney support access — specific staff at Watney Labs can connect to your Assistant's server to fix a problem. This is on an as-required basis, and for support only.
What access is recorded? Automated monitoring runs through a managed channel and every run it takes is logged. Access to those records is available to Regen Digital on request. The Watney support connection is not logged.
10. Consent for Sharing a Resource
The Regen Library is a key shared asset across farmers using Farm Assistant - with farmers contributing knowledge and know-how as Resources. You control whether your workflow or knowledge is contributed as a Resource. Nothing is contributed unless you say yes. If something looks like it could help others, you are asked whether you want to share it, and declining has no consequence (Terms of Use §14.10).
Under the Terms of Use, sharing a Resources has specific terms that are set out here so the privacy position is clear:
- Sharing is permanent. Once a Resource is published you cannot withdraw it — other farms may already be relying on it (Terms of Use §14.4). Regen Farmers Mutual can remove a published Resource if it turns out to be unsafe, wrong or in breach of the Terms (Terms of Use §14.9).
- Attribution to your Assistant is required. Every Resource is tagged with the Assistant instance and model version that produced it, for traceability and quality. You cannot contribute anonymously.
- Whether you are personally named is your choice, and the default is de-identified. You can change that at any time.
Every Resource that is shared goes to the Regen Library; there is no separate open-access or public route (Terms of Use §14.5). Any usage-based recognition or compensation would operate under the Contributor Agreement and would need your separate opt-in.
11. Connected Accounts and How the Assistant Reaches Them
Where you choose to connect a third-party system or online account, you authorise the Assistant to access it. Before you connect a third-party account, you must have the authority to do so. Where an account is shared or held in someone else's name (for example a joint farm account), you confirm you are authorised to connect it and to grant the Assistant the level of access described below. There are two ways this happens, and they work differently.
Authorised read-only connections routed through Switchboard. For platforms that support it, you authorise the connection at the provider's own site — you log in to Xero, or John Deere, on their page — and the provider issues an access token. Your password is never given to the Assistant or to us. These connections are routed by Switchboard, a shared connection service hosted and operated by Watney Labs, which passes requests between your Assistant and the provider and does not store your Farm Data.
When connecting via the Switchboard, the Assistant can see what is in those systems but cannot change or delete anything in them, and where the provider supports fine-grained permissions you can narrow what it may see at the consent screen.
Working inside your own logged-in web session. For platforms not available through Switchboard — which today is most of them — the Assistant can work within a web session you have logged in to, in the same way you would use that site yourself. There is no separate permission layer here: the Assistant can reach whatever you can reach.
This second path is not limited — you may connect the Assistant to any platform you hold an account with, and it will have the same permissions as if you logged in directly, including the ability to change and delete. We publish guides for common platforms, but a guide only helps you set a connection up. Whether you connect to a platform this way is your choice to make, and it means we cannot tell you in advance which systems the Assistant will reach. What we can tell you is the rule: on this path it has the same access you do, including the ability to change and delete.
Access tokens for authorised connections are held by Switchboard in encrypted storage shared across farms and located in the United States, each token under its own key (clauses 5 and 6). Everything else — the credentials for platforms reached inside your own logged-in session, and the keys your Assistant uses to run — is held on your own Assistant's server.
You can revoke any connection at any time, at the provider or by asking us. Revoking stops future access; it does not recall data already read, or reverse entries already written.
12. Data Written to Your Own Systems
Where you ask the Assistant to do so, it may write files (for example CSVs or reports) to your own connected storage or platforms. This is data leaving Regen Digital's systems into yours, and is separate from the data flows described in clauses 5–11.
Writing to one of your systems only happens where the Assistant is working inside a session you have logged in to — connections you authorise at the provider's own site are read-only (clause 11).
13. Retention, Deletion and Export
13A. Deleting your data
You may ask us to delete your Farm Data and your Assistant's workspace at any time, and we will (Terms of Use §13.3). This is unconditional.
Two things survive deletion:
- Resources you have contributed are not deleted. Other farms may already rely on them, and publication is permanent. This holds however your account ends.
- Anything we are required by law to retain.
Your account may also be deleted by us where an invoice remains unpaid for three months (Subscription Agreement §6.5, Terms of Use §18.2). Otherwise we will not delete your data without your consent.
Where your account closes and you have not asked us to delete your data, we keep it for at least three months. After that we may delete it.
13B. Getting an export of your data
Separately from deletion, you may ask us for an export of your data and your farm-specific memory (Terms of Use §13.4). Every farmer may ask for:
- files you uploaded;
- your farm records;
- your farm-specific memory — the facts your Assistant keeps about your farm;
- your farm website's content and data.
An export does not include the material that makes the Assistant work rather than the material about your farm — its system prompt and configuration files, the Resources installed on it, and the connection service's code.
We aim to provide an export within 30 days, the same as an access request (clause 17).
13C. How long each store keeps data
Data retention is varied by system:
- Telegram chat/session data on your assistant's box: retained for the life of the relationship; underlying system logs rotate at 7 days.
- CRM and account-management records (Roadside Assistance tickets, notes, meeting summaries, relationship files): retained for the life of the relationship.
- GitHub working copy (your assistant's workspace): retained for the life of the relationship with full version history.
- Cloudflare (your personal website): retained for the life of the relationship, with 30-day point-in-time recovery.
- Memory index / embedding vectors: retained for the life of the relationship; persists on your assistant's storage volume, rebuilt if reindexed, no separate time limit.
- Switchboard connection records: your encrypted access tokens and connection settings are kept until you revoke the connection; short-lived authorisation state expires within minutes. No activity log is kept — Switchboard does not retain a record of which of your systems was contacted and when.
- EBS server-volume snapshots: retained per snapshot, taken periodically rather than on a fixed schedule (see clause 18).
- OpenAI transcription/embedding data: retained up to 30 days for abuse-monitoring purposes, then deleted.
- Anthropic direct API (internal account-management tooling only): retained up to 30 days for trust and safety monitoring, then deleted.
- Supabase onboarding/reporting data: retained for the life of the relationship.
- Daily fleet report: retained for the life of the relationship.
Where a store above is within our control, a deletion request under 13A applies to it.
14. Attribution and the Regen Library
Only sanitised workflow logic and knowledge travels to the Regen Library — never your underlying Farm Data, photos, or figures — with provenance and lineage tagging so every contribution can be traced. Every Resource is reviewed before publication to remove personal and identifying information.
Attribution works at two levels (Terms of Use §14.8): 1) attribution to the Assistant instance and model version is required and cannot be waived; whether you personally are credited by name is your choice, and the default is de-identified. 2) Where Regen Farmers Mutual amends a Resource or prepares one as part of its review (clause 10), attribution is recorded by hand instead.
15. Direct Marketing and Testimonials
You can opt out of marketing emails at any time using the unsubscribe link in any message we send. We may use de-identified or aggregate usage information for analytics and product improvement (clause 4). Where we use a farmer's name, photo, or story as a testimonial (for example on our website), we do so only with that farmer's specific, separate consent — not as part of general acceptance of this Policy.
16. Cookies and Website Analytics
We may use cookies and similar technologies (such as web beacons) on farmassistant.com.au to remember your preferences and measure how the site is used, including via Google Analytics. Cookies alone do not identify you personally, but if you provide personal information we may link it to cookie data. You can control cookies through your browser settings, and can browse our marketing pages anonymously or under a pseudonym — though you will need to identify yourself to use the Assistant itself.
17. Access and Correction Rights
You can ask us what personal information we hold about you, and ask us to correct it, by contacting our Privacy Officer (clause 24). We aim to respond to access and correction requests within 30 days. Where a request is complex, we may need longer — if so, we'll tell you and explain why. We may need to verify your identity first. We don't charge a fee for access or correction requests, but may charge a reasonable fee to retrieve and copy material if a request is extensive — we'll tell you the cost beforehand. For an export of your data and your farm-specific memory, see clause 13B.
18. Security and Data Breach Response
We use physical, electronic and management safeguards to protect your personal information against misuse, loss, unauthorised access, modification and disclosure.
Your account security. You reach the Assistant through Telegram, so access to your Telegram account is access to your Assistant and to anything you have connected to it. If your phone is lost or stolen, or you think your Telegram account has been compromised, tell us immediately through Roadside Assistance, secure your Telegram account with Telegram, and revoke your connections at the providers (Terms of Use §4.3, §11.1).
We can't guarantee the security of information transmitted over the internet. In the event of an eligible data breach, we will follow our data breach response plan and the Notifiable Data Breaches scheme administered by the Office of the Australian Information Commissioner (OAIC).
Monitoring and notification of unauthorised access. We and our infrastructure providers log and review attempts to gain unauthorised access to our systems.
Where we become aware that someone has gained unauthorised access to your Farm Data or personal information, we will tell you — whether or not it reaches the threshold for notification under the Notifiable Data Breaches scheme described above.
Automated scanning and similar attempts, blocked before reaching any farm's data, are logged and monitored but not notified individually.
19. Business Continuity and Insolvency
If Regen Digital Pty Ltd becomes insolvent, is placed into administration, liquidation or receivership, or otherwise ceases to be able to operate the Assistant, we will take reasonable steps, so far as we are able and subject to the requirements of any insolvency process, to either:
- return your data to you in a usable form, in accordance with clause 13B; or
- delete your data, in accordance with clause 13A,
before the Assistant ceases to be available to you, and will notify you of which of these will occur and the timeframe for it, as far in advance as the circumstances reasonably allow.
Where a sub-processor described in clause 6 (including Watney Labs) ceases to be able to operate, we will take reasonable steps to preserve access to and the integrity of your data during any transition to an alternative provider, and will notify you if this affects the availability or security of your data.
This clause does not override the rights of any insolvency practitioner, liquidator or administrator under applicable law, and we cannot guarantee a particular outcome where our ability to act is constrained by that process.
20. Compelled Disclosure to Third Parties
We will not disclose your personal information or Farm Data to a third party, including a law enforcement agency, court, tribunal, regulator or government body, unless we are required or authorised to do so by law.
Where disclosure is legally required, we will limit what we disclose to what the law requires, and will not disclose more than is necessary to comply.
Where legally permitted to do so, we will notify you before any such disclosure is made. If prior notice is not legally permitted or not practicable in the circumstances (for example, where we are subject to a non-disclosure or non-notification order), we will notify you as soon as practicable afterwards.
This clause does not apply to disclosures to our sub-processors described in clause 6, which are made to operate the Assistant under this Policy and are not disclosures made under legal compulsion.
21. Sponsor / Funder Data-Sharing
Where a third party funds onboarding or specific Resources for a cohort of farmers, that sponsor is not given access to your personal information or Identifying Farm Data. Any terms a sponsor wishes to impose on their funding are disclosed to you, and must be agreed separately by you prior to their activation (Terms of Use §7).
22. Complaints and OAIC Escalation
If you have a concern about how we've handled your personal information, contact our Privacy Officer (clause 24) — we'll usually deal with it over the phone first. If we haven't resolved it to your satisfaction, we'll meet with you to discuss further. If you're still not satisfied within 30 days of that meeting, you can refer your complaint to the Office of the Australian Information Commissioner: oaic.gov.au, enquiries@oaic.gov.au, or 1300 363 992.
23. Changes to This Policy
We'll update this Policy if the way we handle personal information changes, or if privacy law changes. Material changes require your positive re-acceptance and we record the version you accepted; if you do not accept a material change, we may stop providing the Assistant to you. Non-material changes take effect on notice. This follows the same mechanism as the Terms of Use §20.3.
24. Contact Us
For privacy questions, access/correction requests, or complaints, contact our Privacy Officer at hello@farmassistant.com.au.
This Policy is read with the Terms of Use (including Schedule 1 — Disclaimers and Reliance Wording) and, where you subscribe, the Subscription Agreement. The Plain English Guide summarises all three and does not add to them.
