Privacy policy
Fieldbase is local-first, so the honest version of this policy starts with what we never receive. What follows is the rest: what reaches us, why, who else touches it, and how you get it back or get rid of it.
Last updated
On this page
This policy describes how b0gy LLC (“b0gy”, “we”, “us”) collects, uses,
shares and protects information in connection with Fieldbase — the desktop
application, the phone app, the Fieldbase Cloud service at app.fieldba.se,
and this website at fieldba.se.
b0gy LLC is a Nevada limited liability company based in Las Vegas, Nevada, United States. It is the same company behind b0gy.com; this policy covers Fieldbase only, and the policy at b0gy.com covers that company’s other products.
Questions about anything here go to privacy@fieldba.se, and a person answers.
1. The short version
Fieldbase runs on your machine. A project is a file on your own disk, and the desktop application will record an entire season without an account, without a network, and without sending us anything at all. Several customers run it exactly that way.
Three things change that, and each is a decision you make:
- You sign in. We then hold an account: your name, your email address, and which organisation you belong to.
- Your organisation turns on cloud sync. Your project data is then stored in Fieldbase Cloud so your devices and your colleagues can share it. Sync is off until an administrator turns it on, and paying for it is not the same as using it. Each device then keeps the part of it that device is working with, and the Cloud holds the whole.
- You use a feature that asks a third party something. Satellite imagery, weather, map tiles and the analysis assistants each require a request to somebody outside Fieldbase, and each is described in section 5.
Export is never gated, on any plan, whether or not a subscription is live. A lapsed subscription cannot hold a season hostage, and neither can we.
2. Who is responsible for what
The distinction matters, because it decides who you ask for what.
We are the controller of Service Data and Usage Data: account details, billing correspondence, support conversations, website analytics. We decide why those are held, and requests about them come to us.
Your organisation is the controller of Customer Data — the season itself. Field boundaries, trial designs, observations, photos, machine records and the provenance stamped on each of them belong to the organisation that recorded them. We process that data on its instructions, as its processor (and, under UK and EU law, as a processor under Article 28). If you are an employee, a contractor or a student of a Fieldbase customer and you want to see, correct or delete what is recorded about you, ask that organisation first. We will help them answer, and we cannot answer around them.
Where a lone agronomist or a single-person farm uses Fieldbase, that person is the organisation, and both roles land in the same place.
3. What we collect
3.1 Service Data — you give us this
| Data | Source | Why |
|---|---|---|
| Name, email address | Your Google, Microsoft or SAML identity provider at sign-in | Creating the account, addressing you |
| Organisation name and domain | You, at setup | Tenancy, and routing sign-ins for a verified domain |
| Role and group membership | An administrator in your organisation | Deciding what you may see and do |
| Contact form submissions — name, email, organisation, role, team size, and what you want to run | You, via the contact form | Replying to you |
| Billing and invoicing details | You, during purchase | Invoicing, tax records |
| Support correspondence and diagnostic bundles | You, when you send them | Answering the question you asked |
We hold no passwords. Sign-in is OAuth 2.0 with PKCE through Google or Microsoft, or your own identity provider over SAML; the credential is checked where it lives and we receive an assertion, never a secret. See Security for the rest of that mechanism.
3.2 Customer Data — the season
When your organisation uses Fieldbase Cloud, we store and process, on its behalf:
- Geometry — field and plot boundaries, trial grids, guidance lines, measured areas, and the imported shapefile, KML, GeoJSON or ISOXML they came from. This is location data about land, and in a small operation it can identify a household as well as a holding. We treat it accordingly.
- Observations — notes, scores, traits, assessments, measurements, instrument readings, samples and photographs.
- Provenance — every observation carries who recorded it, when, from what source (GPS, manual entry, instrument), and how good the positional fix was. This is the feature, not a by-product: a trial result that cannot be attributed cannot be defended. It also means Fieldbase records, per person, where an employee was and what they did. If you are an employer deploying Fieldbase, that is yours to disclose to your staff under your own employment and privacy obligations, and section 2 says why the request comes to you and not to us.
- Machine records — run logs, coverage, implement state and the safety events around them.
- Devices — device names, the group a device is in, which organisation approved it, and a one-way hash of each operator’s unlock PIN. A PIN is never stored or transmitted as a PIN, on the device or here.
- Presence — while the app is open, a heartbeat records which field a person or device is currently working in, so a second operator in the same field can see them. It is visible only inside your organisation, it repeats names your colleagues already see, and a row older than ninety seconds is discarded.
3.3 Usage Data — collected automatically
- Service logs — IP address, timestamps, endpoints called, application version, and errors. These are how an outage is diagnosed and how abuse is spotted.
- Licensing and seat counts — which licence minted which token, for which organisation, and how many seats are in use. Fieldbase’s licence tokens are verified offline by the application itself; the count exists so that a subscription can be billed and renewed honestly, and for no other purpose. It is not DRM and does not report on what you do in the app.
- Feature metering — counts of satellite imagery requests, map tile requests and analysis calls against the allowance in your plan.
- Website analytics — see section 7. Nothing is measured on this website until you say yes.
3.4 What we deliberately do not receive
- Your files, unless you sync them. With cloud sync off, projects stay on your disk and we hold no copy.
- Voice. The phone app’s hands-free dictation transcribes on the device. No audio, and no transcript, is sent to us or to anybody else.
- Passwords. As above: we never see one.
- PINs. Only a one-way hash, which cannot be turned back into the PIN.
- Payment card numbers. Fieldbase plans are priced and agreed directly and invoiced; we do not operate a card checkout and do not hold card details.
4. How we use information
| Purpose | Data used | Legal basis (UK/EU) |
|---|---|---|
| Providing the apps and Fieldbase Cloud | Service Data, Customer Data | Contract |
| Authenticating you and enforcing roles | Service Data | Contract |
| Issuing licence tokens and counting seats | Service Data, licensing data | Contract |
| Invoicing, tax and accounting records | Billing data | Contract; legal obligation |
| Transactional email — invitations, device approvals, security notices | Email address | Contract |
| Replying to your contact form or support request | What you sent | Contract; legitimate interests |
| Diagnosing faults and keeping the service up | Usage Data, diagnostics you send | Legitimate interests |
| Detecting and preventing abuse and fraud | Usage Data, log data | Legitimate interests |
| Understanding which pages of this website earn their place | Website analytics | Consent |
| Meeting legal and regulatory obligations | As required | Legal obligation |
We do not train machine learning models on your data. Your observations, photographs, geometry and results are not used to train, fine-tune or evaluate any model, ours or anybody else’s. Where you use an analysis feature that calls a third-party model, section 5.4 says exactly what is sent and on what terms.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not put you on a marketing list because you became a customer.
5. Who else touches it
A current, dated list of every third party, with what each one receives, is maintained separately at Sub-processors. That page is the authoritative one; this section explains the shape of it.
5.1 Always in use
Fieldbase Cloud runs on Google Cloud Platform, and transactional email goes out through Mailgun. Sign-in goes through Google or Microsoft, or through your own identity provider if you have configured SAML. Those apply to every account with cloud sync in use.
5.2 Only if you use the feature
Imagery, weather and map tiles each mean asking somebody else about a place. Turn the feature off and no request is made:
- Map tiles are fetched by our servers and streamed to you, so the map provider sees our service rather than your device or your address. Nothing is cached, stored or re-hosted on our side.
- Satellite imagery requires sending the area of interest — a bounding box around your field — and a date range to the imagery catalogue. The imagery itself comes from public Earth observation programmes.
- Weather requires sending a coordinate.
5.3 Only if you ask us in
Nobody outside your organisation has standing access to your data. Not Fieldbase support, and not the reseller who sold it to you.
- A diagnostic bundle is composed and uploaded by you, deliberately, under your own session, and you are told what is in it.
- A support session requires a live consent handshake on the machine itself: you name who may connect, you read a code off your own screen, a banner names them for as long as they are connected, and there is an end button beside it. Sessions are time-limited and there is no setting that makes one permanent.
- An organisation administrator can refuse all of it with one switch, which refuses us exactly as it refuses a reseller.
5.4 Analysis features that call a model
Two optional features send data to a third-party model, and they are worth stating plainly because “AI” usually is not:
- Photo analysis sends the plot photograph you selected, and the question being asked of it, to Google’s generative language API.
- The notebook assistant sends your request, the trait keys and design attributes your organisation actually uses, and the notebook cells already written, to the same API.
In both cases what comes back is a proposal that a person reads and accepts, never a value written straight into your record. Both are configured per deployment and per organisation, are metered, and can be left off entirely. If your organisation would rather no field data reached a model provider under any circumstances, do not enable them, and say so during your security review so we can confirm it at the deployment level.
5.5 Everyone else
Legal requirements. We may disclose information where required by law, subpoena, court order or government request, or where we reasonably believe disclosure is necessary to protect our rights, your safety or the public’s. Where we are lawfully able to tell you first, we will.
Business transfers. If b0gy is acquired or merges, or sells substantially all of its assets, information may transfer to the successor. We will notify account holders before their information becomes subject to a different policy.
6. How long we keep it
| What | How long |
|---|---|
| Account and organisation data | For as long as the account exists |
| Customer Data in Fieldbase Cloud | For the subscription, plus a 30-day export window; deleted from active systems within 30 days after that |
| A deleted organisation | Marked deleted immediately and invisible at once; rows are purged after 90 days, so a deletion in error can be undone by asking |
| Trial archives | Kept for years by design. A trial’s location and the work done on it are a scientific record, and there is deliberately no path that updates or deletes an archived row |
| Backups | Purged within 90 days of the primary data being deleted |
| Service and security logs | 12 months |
| Diagnostic bundles | 30 days, set on the bundle when you upload it, then deleted |
| Support correspondence | 24 months |
| Contact form submissions | 12 months |
| Invoices and financial records | 7 years, as tax law requires |
The trial archive row deserves its own sentence, because it is the one place we keep something after you ask us to stop. It exists so that a result published in 2026 can still be traced to the ground it was measured on in 2032. If you need an archive expunged, write to privacy@fieldba.se and we will deal with it as an erasure request under section 8 rather than as a support ticket.
And the thing retention does not touch: your own copies. A project kept on your own disk is yours in full; a synced device holds the part of the season it has been asked to keep; and your exports, which are never gated, are yours from day one. Nothing in the table above reaches any of them.
7. This website, and cookies
fieldba.se is static files. It sets no cookies and loads no trackers unless you say yes to one thing: Google Analytics, which counts page views so we know which pages are worth writing.
We ask before it runs. Until you accept, the tag is not on the page at all — nothing is requested from Google and no cookie is set. If you decline, that stays true, and any analytics cookie already set is deleted. Your answer is kept in your browser’s local storage rather than in a cookie, so refusing does not itself store one. Change your mind whenever you like with Cookies at the foot of any page.
The other third party involved in serving this site is Google Fonts, which receives the standard request data any font download does.
The contact form posts to our own service. It is rate-limited by IP to stop abuse, and it carries a hidden honeypot field that a person never sees and a bot fills in. There is no advertising pixel, no retargeting tag, no social widget and no session recording on this site, and there is not going to be.
If your browser sends a Global Privacy Control signal, we honour it as an opt-out of non-essential tracking.
Fieldbase Cloud, separately, sets a strictly necessary session cookie so that being signed in survives a page reload. There is no consent gate on that one, because there is no product without it.
8. Your rights
Wherever you are, you may ask us to:
- Access — give you a copy of the personal information we hold about you
- Correct — fix what is wrong
- Delete — erase it
- Port — hand it over in a structured, machine-readable format
- Restrict or object — pause or stop a particular use
- Withdraw consent — where we relied on consent, withdraw it, with no effect on what was done beforehand
Write to privacy@fieldba.se. We will verify who you are before acting, and respond within 30 days, or sooner where the law requires it. You may use an authorised agent. We will not treat you worse for asking.
For Customer Data, send the request to the organisation that subscribed — see section 2. We will assist them in answering it.
A note on portability that is easy to miss: for Customer Data you do not need to ask us at all. Export is a button, it is on every plan, it produces open formats — XLSX, CSV, shapefile, GeoJSON, KML, ISOXML, BrAPI — and it is never gated by billing state.
9. UK and EU data protection
Where the UK GDPR or the EU GDPR applies, the following is true in addition to section 8.
Roles. We are the controller for Service Data and Usage Data, and the processor for Customer Data, as section 2 sets out. Organisations subscribing from the UK or the EEA are offered a data processing addendum incorporating the Article 28 terms and the current sub-processor list; ask legal@fieldba.se and we will send it.
Legal bases are named against each purpose in the table in section 4. Where we rely on legitimate interests, we have balanced them against your rights and will share that assessment on request.
International transfers. b0gy LLC is in the United States and Fieldbase
Cloud runs by default in Google Cloud’s us-central1 region. Personal data of
UK and EEA individuals is therefore transferred to the United States. We rely
on the European Commission’s Standard Contractual Clauses, with the UK
International Data Transfer Addendum where the UK GDPR applies, together with
the technical measures described on the Security page. A
dedicated instance in a European region is available as part of an
Enterprise deployment, and for organisations whose own obligations require data
residency that is the right conversation to have before signing rather than
after: tell us what your review needs.
Automated decision-making. There is none. No feature of Fieldbase makes a decision about a person with legal or similarly significant effects. The analysis features described in section 5.4 produce proposals for a person to accept or reject, which is the whole design.
Special category data. Fieldbase is not built to hold it and we ask you not to put it there. If your assessments record anything about a person’s health, biometrics or similar, tell us before you begin so we can agree how.
Complaints. You may complain to your supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk; in the EEA, the authority for your country. We would rather you came to us first, at privacy@fieldba.se, and we will not take offence if you do both.
10. California
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the rights below.
Categories collected in the preceding 12 months:
| CCPA category | Examples | Source |
|---|---|---|
| Identifiers | Name, email, account id, IP address | You, your identity provider |
| Commercial information | Subscription, plan and invoice records | You |
| Internet activity | Pages visited, features used, sign-in times | Automatic collection |
| Geolocation | Field and plot coordinates you record; approximate location from IP | You; automatic collection |
| Professional information | Organisation, role, team size | You |
We do not sell or share your personal information, as the CCPA defines those terms, and we have not in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.
Your rights are to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. We do not use or disclose sensitive personal information for purposes that require a limitation right to be offered. Submit a request at privacy@fieldba.se or through the contact form; we verify identity before acting, and an authorised agent may act for you.
11. Nevada
Nevada residents have the right to opt out of the sale of covered information under Nevada SB 220. We do not sell it. To submit an opt-out or ask about it, write to privacy@fieldba.se; we respond within 60 days.
12. Other US states
Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia — have rights similar to those in sections 8 and 10. Write to privacy@fieldba.se.
Where a state requires an appeal route: if we refuse a request, reply with “Appeal” in the subject line and we will respond within 60 days, and tell you how to contact your attorney general if you are still unsatisfied.
13. Children
Fieldbase is a tool for agricultural work and research, sold to organisations. It is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child’s information has reached us, write to privacy@fieldba.se and we will delete it.
We recognise that agricultural colleges and university departments use Fieldbase with students, some of whom may be under 18. Where that is your deployment, the institution is the controller of those records under section 2 and is responsible for the consents and notices its own rules require.
14. Security
The specifics — sign-in, encryption, device controls, remote erase, backups, and how support access is fenced — are on the Security page, which is written for the person doing your review.
No system is completely secure. If we discover a breach affecting personal data, we will notify affected customers promptly and within the deadlines applicable law sets, and we will tell you what we know rather than what sounds best. To report a vulnerability, write to security@fieldba.se.
15. Changes
We may update this policy. When we do, the “last updated” date at the top changes with it. For material changes we will notify account holders by email at least 30 days before they take effect, and where a change requires consent we will ask rather than assume.
16. Contact
b0gy LLC — Las Vegas, Nevada, United States
- Privacy: privacy@fieldba.se
- Legal: legal@fieldba.se
- Security: security@fieldba.se
- Anything else: hello@fieldba.se
The other documents
Terms of service
UpdatedPlans, seats and billing; ownership of your season; the safety terms governing machine control; warranties, liability and how either side ends the agreement.
Acceptable use policy
UpdatedThe limits on how Fieldbase may be used: the service itself, other people's data and land, and the safety rules governing machine control.
Sub-processors
UpdatedThe dated list of every third party that touches data on our behalf, what each receives, where it sits, and how to be told before the list changes.