Privacy Policy
This Privacy Policy describes how HortiHub (operated by Get2Grow) collects, uses, and protects information about users of our professional horticulture platform. We are committed to your privacy and comply with the EU General Data Protection Regulation (GDPR).
1. Who We Are
Data Controller: Get2Grow
Contact: willem@get2grow.nl
Platform: HortiHub — professional horticulture calculation tools and learning platform
2. Data We Collect
We collect only the data necessary to provide our service:
- Email address — required for account creation and authentication
- Name and company — optional, provided when requesting access
- Learning progress — which courses you have completed and quiz scores. Visible to you and, in summary, to the owner of your company account (see section 8)
- Tool activity — which tools you visited and when (used for your dashboard activity feed)
- Session data — authentication tokens stored in your browser's local storage to keep you signed in
- Company and greenhouse data — the greenhouses, crops and cultivation dates you enter, and the climate exports you upload from your climate computer or have it mail to your company's import address (below)
- Mailed climate exports, only if your company switches them on — your climate computer can mail its daily export to an address we give your company, which names that company and nothing else. We read that mailbox every half hour, without ever writing to, moving or replying from it. Per message we keep the sender address, the subject, the attachment's name and size, a fingerprint of the file, the message identifier, the times it arrived and was read, and what happened to it — that log is what you see on the Climate page. The export itself is stored as climate data of the greenhouse it belongs to, exactly as an upload you make yourself. Mail addressed to no company, or from a sender your company has not set up, is not imported; the message text is never stored
- The location of a greenhouse — the place or coordinates you enter for a greenhouse under Setup. This is company data, stored with that greenhouse, and used to pick the nearest KNMI weather station and to fetch that greenhouse's forecast. The coordinates are sent to Open-Meteo for the forecast (see section 4)
- Water analyses — the water sources you name (a bore, a rain basin, a drain line) and the laboratory analyses of them that you type in or import from a lab report, with the sample date, the laboratory and the report number. A lab report PDF carries your company name and address; those are read past and never stored. What is kept with an analysis you confirm: the values, and the report's own type-of-water, location, cultivation and crop lines — your own naming from the lab's order form — so the tool can tell which source, greenhouse and cultivation a report belongs to. When you confirm that reading, a rule "a report titled X belongs to source S" is kept for your company, so the next report with that title is recognised
- Your fertilisers — the products you keep for the nutrient calculator: the name you give them, solid or liquid with its density, the analysis as printed on the label, the tank you choose and the data sheet's solubility. Nothing else about your supplier is stored
- Your notes on the advice — the comments and preferences you write on a Dagrapport, which the platform keeps so later advice follows on from earlier advice
- Your browser's own position, only if you ask for it — if you use "use my location" on the weather or energy card, your browser's position is rounded to about one kilometre and stored in this browser so the forecast is for your area. We never ask for it on our own, that browser position is not sent to or stored on our servers, and you can remove it by choosing a location by name instead. The rounded coordinates are sent to Open-Meteo to fetch the forecast (see section 4)
We do not collect payment information or any sensitive personal data.
3. How We Use Your Data
- Authentication — to verify your identity and keep your session active
- Service delivery — to show your learning progress and recent tool usage on your dashboard
- Password recovery — to send you a reset link when requested
- Product improvement — aggregate, anonymised usage data helps us understand which tools are most used
- Climate advice — to analyse your uploaded climate data and generate the Dagrapport. This involves sending the relevant context to an AI provider; see section 4
- Fertiliser calculation — to read the lab report you import, blend your water sources and calculate the doses. Reading the report is done by our own file-processing service (section 4); no AI provider is involved
- Automatic climate import — to read the export your climate computer mails to your company's address, match it to the right greenhouse and store it as climate data, and to keep the log of what arrived. The file is processed exactly as one you upload yourself
We never sell your personal data. We do not use your data for advertising.
4. Data Processors (Sub-processors)
We use the following third-party services to operate the platform:
- Supabase — database and authentication provider. Servers located in the EU (Frankfurt). Supabase is GDPR-compliant and acts as a data processor under our agreement with them. Supabase Privacy Policy
- Vercel — web hosting, CDN and (with your consent) cookieless web analytics. Vercel Privacy Policy
- Anthropic — the AI model behind the Climate Advisor's Dagrapport and its rule suggestions. When you generate a brief we send the greenhouse name, the crop and growth stage, that day's measured climate values, the advice cards produced for that day, and any comments or standing preferences you have written. Anthropic processes this only to return the brief; under their commercial terms, inputs and outputs are not used to train their models. Anthropic processes it in the United States; the transfer is covered by our data processing agreement with them, which incorporates the EU Standard Contractual Clauses. Anthropic Privacy Policy
- Railway — hosting for our file-processing service. A climate export you upload is sent there to be read and matched to the right measurements, and the trained models behind the advice are stored and loaded from there. A water-analysis lab report you import is sent there to be read; the file is processed temporarily and discarded after parsing. Analysis values and sample metadata (location, cultivation and crop, when present) come back; grower names and addresses are not extracted. It is also this service that reads the import mailbox, over IMAP, read-only. Servers located in the EU (Amsterdam). Railway Privacy Policy
- Mail provider — the mailbox your climate computer mails its export to, if your company uses the automatic import. The provider holds those messages: the sender, the recipient, the subject, the date and the attached export. Our file-processing service reads the mailbox and never writes to it. We are selecting the provider; it is named here, with its servers' location, before the automatic import is switched on for any company — as section 4 promises for every processor we add
- Open-Meteo — the weather forecast shown on the dashboard and used by the energy planner. Your browser requests the forecast directly, so Open-Meteo receives the approximate coordinates of the location you chose (rounded to about one kilometre) or the place name you typed, and your IP address. Nothing identifying you or your company is sent, and no account data passes through them. Open-Meteo Terms and Privacy
Each of these acts as a data processor under Article 28 GDPR. If we add or replace one, this section is updated before the change goes live.
Typography and icon fonts are served by this website. Loading them does not contact Google Fonts or Cloudflare cdnjs.
5. Cookies and Local Storage
We use essential cookies and browser local storage only:
- Authentication session — a session token stored in local storage to keep you signed in
- Preferences — your dashboard layout, language preference (EN/NL), and — only if you asked for it — the approximate coordinates of your weather location, stored in local storage
- Tool settings — the calculator inputs and saved CHP presets you last used, so a tool opens where you left it. Cleared when you sign out or switch company
- Cookie consent — a record of your consent choice, stored in local storage
These are strictly necessary for the platform to function and are used whatever you choose in the consent banner.
Optional — analytics. If you choose "Accept all", our public website also loads Vercel Web Analytics, which counts page views and referrers. It sets no cookie and does not identify you. Choosing "Essential only" means it is never loaded, and you can change your mind by clearing site data in your browser. We do not use tracking cookies or third-party advertising cookies.
6. Data Retention
- Account data is retained while your account is active
- Learning progress and tool activity are retained for the lifetime of your account
- Water sources, their analyses and the report-recognition rules belong to your company account and are retained until someone in the company deletes them or the company account is deleted (deleting a source deletes its analyses and rules)
- Your fertilisers belong to your company account and are retained until someone in the company removes them or the company account is deleted; a saved setup keeps its own copy of the products it used
- The log of mailed imports (sender, subject, filename, file fingerprint, times and outcome) belongs to your company account and is kept with your climate data until the company account is deleted. The messages themselves stay in the import mailbox until we clear it, and are used for nothing else
- Upon account deletion, your personal data is removed within 30 days
- Anonymised aggregate data (e.g., total tool usage counts) may be retained indefinitely
7. Your Rights Under GDPR
As an EU resident you have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your account and data
- Right to data portability — receive your data in a machine-readable format
- Right to restrict processing — limit how we use your data
- Right to object — object to processing based on legitimate interest
To exercise any of these rights, contact us at willem@get2grow.nl. We will respond within 30 days.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Data Security
We take reasonable technical and organisational measures to protect your data, including:
- HTTPS encryption for all data in transit
- Row-level security on all database tables, scoped to your company
- Authentication managed by Supabase with industry-standard password hashing
What your colleagues can see. Your data is walled off from other companies, not from your own. Everyone who belongs to your company account can see the greenhouses, climate uploads, Dagrapporten, advice and history belonging to that company, whoever entered them. That is deliberate — growing is a team activity and a colleague covering a weekend needs the same picture you have — but it means work you do here is visible to your company, not private to you.
Your training, and what an owner sees of it. Learning progress is personal: nobody sees which slides you read, how long you took or what you answered. The owner of your company account has a Team view showing, per colleague, how many courses are completed or started and when the last activity was — so a nursery can see its team's training. Growers and assistants do not see each other's.
9. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. For significant changes we will notify active users by email.
10. Contact
Get2Grow
Email: willem@get2grow.nl