Skip to main content

Draft: Not Yet Binding

This page is a working draft of AgWaterAI's farmer-facing data stewardship pledge, pending review by California ag / privacy counsel. Until this banner is removed, the controlling document is the general Privacy Policy and the data terms in your signed agreement (LOI, MSA, or Terms of Service). Counsel sign-off target: ~1 week from publication of this draft.

Last updated: May 23, 2026 (DRAFT)

Your data. Your land.
Our job is to keep it that way.

We are growers building software for growers. Your sensor readings, your pump records, your field boundaries: those belong to you, not to us, and not to anyone who happens to be paying us this quarter. This page tells you, in plain English, exactly what we do with what we collect, what we don't do, and how to make us stop.

Your data, in plain English

1.

Who owns the sensor data from my fields?

You do. Raw sensor readings (soil moisture, temperature, salinity, pump on/off events) are facts about your land. Under U.S. copyright law (Feist Publications v. Rural Telephone Service, 499 U.S. 340 (1991)), raw facts can't be copyrighted, and no one, including us, can claim to “own” them. We hold them for you, process them on your behalf, and license them only as you direct.

What we do own is the derived analytics: the AI model weights, the prediction outputs, the benchmarks, and the dashboards we build on top of your data. Same as a CPA owns the spreadsheet, but you own the underlying receipts.

2.

Can my lender, banker, or insurance company see my data without my permission?

No. Not your lender, not your crop insurer, not your buyer, not your packing house. We do not ship your raw sensor data, your pump records, your GPS boundaries, or any individually identifiable account information to any third party for any commercial purpose without your written authorization for that specific recipient and purpose.

If we ever build a financial data product (for example, a basin-level risk index sold to ag lenders), it will use only aggregated, anonymized data with at least seven (7) unaffiliated farms in any reported cell, county-level geography or broader, and no GPS, no APNs, no field boundaries. You can opt out of having your data contribute to those aggregated products. See Section 8 below.

3.

Does Sentek (the sensor manufacturer) get to see my data via IrriMAX?

Honest answer: we are still getting written confirmation, and we will update this page when we have it.

Here's what we know today. Sentek's publicly posted Terms & Conditions of Trade (§13) cover hardware IP and Sentek's own development work; the most natural reading does not give Sentek ownership of your sensor readings or of derivative products built from them. Sentek does not publish a public IrriMAX Live End-User License Agreement, Subscriber Agreement, API terms, or data-ownership policy, which means the precise data-handling terms of the IrriMAX Live cloud platform are not on the public record. We have asked Sentek in writing to confirm: (a) the customer owns the raw sensor data flowing through IrriMAX Live, and (b) Sentek does not access or use customer data for its own commercial AI/ML purposes.

Until we have that letter, we treat IrriMAX Live as a potential third-party data path and we are actively standing up direct SDI-12 / Modbus RS-485 ingestion that pulls raw data straight from the probe to our cloud, bypassing IrriMAX Live entirely.

4.

If I bring my own sensors (Bring Your Own Sensors, BYOS) instead of having you install Sentek probes, what changes?

The short version: in BYOS, you control the sensor manufacturer's relationship, and we are only the analytics layer. Whichever path you choose, AgWaterAI's commitments on this page apply equally. BYOS does not give us a smaller obligation; Managed does not give us a bigger right.

BYOS (Bring Your Own Sensors)Managed (we install)
Sensor hardware ownershipYouYou (after install)
Manufacturer's account holderYouOur field-services team, as your authorized custodian under MSA
Where raw data lands firstYour existing platform; you grant us read accessDirect from probe to AgWaterAI cloud
Manufacturer terms apply toYou onlyYou + our field-services team as authorized custodian
Easiest to leaveCancel subscription; data and sensors stay where they areSee Section 5 below
5.

Can I export all my data and leave?

Yes. You can request a full export of your raw sensor data, your pump records, your dashboard inputs, and the predictions we have generated for you, in standard formats (CSV, Parquet, or JSON). We will fulfill the request within thirty (30) days of a written request to data-officer@agwaterai.com.

What stays with us after you leave: the trained AI model weights themselves. Neural-network and gradient-boosted model weights are a one-way mathematical function: once your data is incorporated into a trained model, the individual readings cannot be reconstructed from the weights. Under Feist, the raw facts you contributed are not copyrightable in the first place, so we are not asserting any retained license over your raw data; we simply cannot un-train a model.

6.

Can I delete my account and have you wipe my data?

Yes, with three honest exceptions. On written request, we will delete: your account, login credentials, and dashboard; your raw sensor readings from our long-term storage; your GPS coordinates, APNs, and field boundary data; your personally identifiable contact information.

We may retain, for specific defined purposes:

  1. De-identified aggregated metrics that have already been incorporated into trained model weights, where individual re-identification is no longer mathematically possible.
  2. Submission metadata (IP, user-agent, timestamps) required to support active fraud investigations.
  3. Records of payments and contracts we are required to keep under California tax law and IRS recordkeeping rules (Cal. Civ. Code § 1798.105(d)(7) permits this carve-out).

We will not retain identifiable raw sensor readings after a verified deletion request.

7.

Do you train AI models on my data? Can I opt out?

Yes, for paid Pro / Managed subscribers, we use your sensor data to train and improve the production ML models behind our six decision systems (PULSE, SENTRY, SENTRY-TRANSITION, SALT FLUSH, WATCHDOG, and the irrigation propensity model). This is how we keep per-acre pricing where it is. We disclose this in our Terms of Service and in our general Privacy Policy.

You can opt out of model training without losing access to the platform, consistent with the CCPA's non-discrimination rule (Cal. Code Regs. tit. 11, § 7080). If you opt out, your dashboard, your predictions, and your SGMA reports keep working, but your data is processed in an ephemeral pipeline that does not contribute to model retraining or to aggregated products.

To opt out, email data-officer@agwaterai.com with subject line “Opt out of model training.” We will confirm within ten (10) business days.

For our free tools (SGMA Allocation Estimator, penalty estimator), we do not train models on what you enter. Inputs are used to generate your result and then dropped from long-term storage.

8.

Will my data show up in academic papers without my consent?

No, not without your written authorization for the specific paper or study.

We have a long-term interest in publishing validation work with the University of California Cooperative Extension and similar academic partners. When we do that work, we ask each participating grower for written consent for the specific study, identifying the researcher, the dataset scope, the publication venue, and the destruction date for the working copy. Anything else falls under your standard “no third-party sharing” protection.

We additionally commit that any data we share with academic partners will be k-anonymized to k ≥ 5 at the county-and-crop level (no county-crop combination with fewer than five unaffiliated farms), with GPS truncated and acreages bucketed, consistent with the Cal. Civ. Code § 1798.140(m) “de-identified” standard.

9.

Will any regulator (GSA, SWRCB, CDFA) see my data without a court order?

We will not voluntarily disclose your raw farm data to any government agency, including your Groundwater Sustainability Agency, the State Water Resources Control Board, the California Department of Food and Agriculture, the U.S. Department of Agriculture, or county-level enforcement bodies, for regulatory enforcement purposes.

What we will do, because we have to:

  • Comply with a valid subpoena, search warrant, or court order. A clause in a privacy policy promising “we will never share with government” is void against a valid court order.
  • Notify you promptly of any government request for your data, unless we are legally prohibited from doing so, so you have the opportunity to seek a protective order from the court.
  • Require valid legal process. We do not respond to informal agency inquiries, “voluntary cooperation” requests, or fishing expeditions.

A practical note on California-specific water law: California Water Code § 10730.8(b) allows GSAs to require well-extraction data as part of compliance, but the duty to provide that data runs from you to your GSA, not from us to your GSA. Your MSA with us authorizes us to help you prepare and submit that data on your behalf at your direction. We do not push it to your GSA without your sign-off.

10.

What if there's a data breach?

We notify you in writing within 72 hours of confirming a security incident that has materially compromised, or is reasonably believed to have compromised, your sensor data, account credentials, or personally identifiable information. The notice will tell you what we know, what we don't yet know, what data categories were affected, and what we are doing about it.

You have a private right of action under California Civil Code § 1798.150 if a breach of certain categories of personal information results from our failure to implement reasonable security. We carry cyber-liability insurance against this risk. We maintain industry-standard controls: TLS in transit, AES-256 at rest, principle-of-least-privilege access, multi-factor authentication on all admin accounts, and an annual third-party security review.

What we don't do

  • We don't sell your raw farm data to lenders, insurers, food processors, packing houses, advertisers, or anyone else. Not now, not in any future product.
  • We don't share your GPS coordinates, APNs, or field boundaries in any data product we sell or license to third parties.
  • We don't act as an extension of any regulator. We are not a GSA reporting tool, not a SWRCB monitoring contractor, not paid by any agency to surveil our customers.
  • We don't auto-publish your data in academic papers. Each study requires separate written authorization.
  • We don't use Sentek's IrriMAX Live as a one-way drain. We are actively building direct-from-probe ingestion specifically to remove our dependency on a third-party cloud whose terms we cannot publicly verify.

The legal framework

This pledge is enforceable against us under the following body of California and federal law. The plain-English commitments above are what we owe you in practice; the citations below are how a court would enforce them.

AuthorityWhat it does for you
California Consumer Privacy Act (CCPA): Cal. Civ. Code § 1798.100 et seq.Right to know, delete, correct, and opt out of sale/sharing of personal information
California Privacy Rights Act (CPRA), eff. Jan. 1, 2023Strengthens CCPA; adds Sensitive Personal Information category and household-data expansion
Cal. Civ. Code § 1798.140(ag): 'Service Provider'Where we process data on behalf of a business customer, we are contractually prohibited from using that data for our own purposes
Cal. Civ. Code § 1798.140(m): 'De-identified' standardThe four-part technical/process/policy/contractual test we apply to aggregated and anonymized data
Cal. Civ. Code § 1798.150: Private right of action for breachYour statutory remedy if we fail at security
Cal. Const. Art. I, § 1: Inalienable right to privacyCalifornia's constitutional baseline, the most protective state framework in the country
Cal. Penal Code § 502: CCDAFACriminal liability for unauthorized access to your data on our systems
Cal. Water Code § 10730.8(b)Defines the GSA reporting duty as flowing from well operator to GSA, not from a software vendor to the GSA
CalOPPA: Cal. Bus. & Prof. Code §§ 22575-22579Requires this policy and the conspicuous-link posting you found it through
Federal Trade Commission Act § 5Unfair/deceptive practices liability, the principal federal hammer behind our promises
17 U.S.C. § 102(a) + Feist Publ'ns v. Rural Tel. Serv. (1991)Raw sensor readings are uncopyrightable facts; you own them as a matter of property law
Ag Data Transparent (ADT): AFBF voluntary certificationWe are NOT yet ADT-certified. We hold ourselves to the ADT framework as a self-imposed standard while pursuing certification.

This page does not, and cannot, override a clause in your signed MSA or LOI. If you find a conflict between this page and a signed contract, please contact data-officer@agwaterai.com so we can reconcile.

Sentek IrriMAX clarification (active work in progress)

Sentek Pty Ltd (ABN 78 007 916 672) is the Australian sensor manufacturer behind the TriSCAN probes that Managed-tier customers may have in their fields. Sentek's publicly posted Terms & Conditions of Trade § 13 addresses intellectual property and reads most naturally as covering Sentek's own hardware development work, not customer-generated derivative analytics. However:

  • No public IrriMAX Live EULA, Subscriber Agreement, API Terms, or Data-Ownership Policy is published on sentektechnologies.com as of our most recent review.
  • A clickwrap EULA likely exists during IrriMAX Live account creation, but it is not publicly accessible for us to evaluate.
  • Sentek's § 13(d) is gated by “Unless otherwise agreed by Us in writing”, meaning the default rule can be overridden by a side letter.

What we are doing about it:

  1. We have asked Sentek in writing to confirm customer ownership of raw sensor data and our right to build derivative analytics from it.
  2. We are building direct SDI-12 / Modbus RS-485 ingestion from probe to AgWaterAI cloud, which bypasses the IrriMAX Live platform entirely.
  3. We are diversifying our sensor stack with METER Group, Acclima, and AquaSpy integrations so no single manufacturer sits on the critical path of your data.

Data flow, in words

Your dashboard (default, both tiers)

Soil moisture probe → AgWaterAI cloud (encrypted in transit, encrypted at rest) → your password-protected dashboard. No third party in the middle.

Aggregated / anonymized products (opt-out anytime)

[Your data + at least 6 other unaffiliated farms] → de-identification pipeline (k-anonymity ≥ 5, GPS truncated, acreages bucketed) → basin index or supply-chain metric → institutional buyer. At no point does a sold product contain your raw readings, your GPS, your APNs, or your name.

Lender / banker / insurer (separate consent, per-counterparty)

Your dashboard → you click "Share read-only with [your lender]" → time-boxed, scope-limited API key issued in your name → counterparty sees only what you authorized. You can revoke the key at any time. We do not push data to a counterparty without your action.

Government (subpoena/warrant only)

Subpoena/warrant → AgWaterAI legal review → notify you (unless legally prohibited) → fulfill only what the legal process compels, in the narrowest reasonable form. We do not pre-emptively share with regulators.

Your rights

RightHow to exerciseSLA
Know what data we haveEmail data-officer@agwaterai.com, subject “Right to Know”45 days
Export your raw dataEmail, subject “Data Export”30 days
Correct inaccurate dataEmail, subject “Correction Request”45 days
Delete account + dataEmail, subject “Delete My Account”45 days
Opt out of model trainingEmail, subject “Opt Out of Model Training”10 business days
Opt out of aggregated-data inclusionEmail, subject “Opt Out of Aggregated Data”10 business days
Opt out of 'sale' or 'sharing'Email privacy@agwaterai.com, subject “Do Not Sell My Personal Information”, or set Global Privacy Control (GPC) in your browserOn receipt
Authorize a specific third-party shareEmail with counterparty name, purpose, and scopePer-request
Non-discriminationYou will not be charged more, given degraded service, or terminated for exercising any right aboveAlways

Security architecture

These are the technical controls behind the promises above. We sent a version of this overview to our first Managed-tier customers in writing; this is the canonical, public version.

Section 1

Encryption: data in transit and at rest

  • In transit: All data moving between your sensors, our servers, and your dashboard is encrypted with TLS, the same encryption banks use. Nobody can intercept it in between.
  • At rest: Stored data is encrypted using AES-256-GCM (military-grade). Even physical access to a server would not reveal data without the encryption keys.
  • API credentials: Any stored credentials (sensor API keys, third-party tokens) are individually encrypted before storage. Never stored as plain text.

Section 2

Access control: who can see your data

  • Password-protected dashboards: Your dashboard is behind a unique password. Only people you share that password with can access it.
  • Role-based access: 4 permission levels (farmer, consultant, institutional, admin). Each role only sees what it needs to. A farmer sees their own sites. A consultant sees their client portfolio. Nobody sees data they are not authorized for.
  • Client data isolation: Each client's data is completely separated. Your sensor readings, pump records, and irrigation history are never mixed with or visible to other clients.
  • API authentication: All data exchanges between our systems use authenticated API keys. Every request is verified before any data is returned.
  • Administrative access: Sensor-connection administration and platform-admin actions are restricted to AgWaterAI's authorized field-operations and engineering team. Multi-factor authentication is required on all admin accounts. Access changes are logged and auditable.

Section 3

Infrastructure: where your data lives

  • Google Cloud Platform (GCP): Our backend runs on Google Cloud, the same infrastructure used by major banks, hospitals, and government agencies. GCP is SOC 2 Type II, ISO 27001, and FedRAMP certified.
  • Vercel (dashboard hosting): Your dashboard is hosted on Vercel: automatic HTTPS, DDoS protection, edge security. SOC 2 Type II compliant.
  • Secret management: All passwords, API keys, and sensitive credentials live in Google Cloud Secret Manager, not in code or config files. Access is audited and logged.
  • US-based servers: All data is stored and processed on servers located in the United States. Your farm data does not leave the country.

Section 4

Sensor data protection

  • Your sensor data is yours: We use it to run the AI models and generate your irrigation insights. We do not sell raw sensor data to anyone. Ever.
  • What is shared externally (with your permission): If we publish research or present results, we only share aggregate numbers (e.g., "across orchards in Kern County, the system identified 17.9% water savings potential"). We never disclose farm names, specific locations, or individual site data in any external communication.
  • IrriMAX sensor connection: We connect to your Sentek sensors through the IrriMAX Live API using encrypted credentials. The sensor data flows directly from IrriMAX to our secure servers. See the Sentek IrriMAX clarification section above for our active work to replace this with direct probe-to-cloud ingestion via SDI-12 / Modbus.

Section 5

Additional security practices

  • Security headers: Our dashboard blocks clickjacking attacks (X-Frame-Options), prevents content-type spoofing (X-Content-Type-Options), and restricts browser permissions (no camera, microphone, or location access).
  • Rate limiting: Login attempts are rate-limited to prevent brute-force password attacks.
  • No sensitive-data caching: Dashboard pages with farm data are configured to never be cached by content delivery networks. Your data is always served fresh and never stored in temporary caches.
  • Automatic backups: Your data is backed up daily. If anything ever goes wrong, we can restore to any previous day.
  • Code signing: All code changes to the platform are cryptographically signed and tracked. We know exactly who changed what and when.

The short version

  • Your data is encrypted in transit and at rest using bank-grade encryption.
  • Your data is isolated from all other clients. No one else can see it.
  • Your data lives on US-based Google Cloud servers with SOC 2 and ISO 27001 certifications.
  • Your data is never sold or shared without your explicit permission.
  • Administrative access is role-based and multi-factor-authenticated. Every sensor-connection or platform-admin change is logged.

Incident response

T + 72 hours

Written notice to the email on your account, summarizing what we know, what we don't yet know, what data categories were affected, and the immediate containment steps taken.

T + 7 days

Follow-up notice with root-cause analysis, scope of affected accounts, and remediation plan. If the incident triggers Cal. Civ. Code § 1798.82 statewide notice requirements, we file accordingly.

T + 30 days

Post-incident review available on request, including any third-party forensic findings (redacted as necessary to preserve other customers' confidentiality).

We carry cyber-liability insurance. We do not require you to release any claims as a condition of incident notification or post-incident cooperation.

Contact

Data Stewardship Officer: data-officer@agwaterai.com

General privacy inquiries: privacy@agwaterai.com

Postal: AgWaterAI Inc., Bakersfield, California

If you do not get a response within the SLA above, escalate to info@agwaterai.com. You also have the right to file a complaint with the California Privacy Protection Agency (cppa.ca.gov).

This page complements but does not replace the general Privacy Policy or your signed agreement. Where this page and a signed contract appear to conflict, the signed contract controls until we reconcile in writing.