Rooted Commons
HomeOur NetworkGet InvolvedWeekly ShopFAQs
Sign in
Become a Member
Legal & policies

Data arrangements

Version RC-DATA-2026-09-v1 · 12 September 2026

These schedules form part of the agreement that incorporates them. Its data record identifies the organisations, activity, purposes, information, people affected, duration, contacts, security arrangements and permitted service providers. Only the schedule matching the actual activity applies. An organisation can have different responsibilities for different activities.

A. Handling information on instructions

The organisation deciding the purposes is the Controller. The organisation handling information solely on its behalf is the Processor. The Controller provides lawful instructions and determines what is collected, who may receive it and how long it is needed. The Processor must:

  1. Use information only on documented instructions, including instructions for transfers outside the UK. If law requires different use, inform the Controller beforehand unless prohibited. Immediately flag an instruction believed to breach data-protection law.
  2. Limit access to authorised people bound by confidentiality. Use appropriate technical and organisational security, including access controls, secure devices and transfers, recovery arrangements and regular checks of their effectiveness, to meet Article 32 of the UK GDPR.
  3. Obtain prior written authorisation before appointing another processor. Give it equivalent written data-protection obligations and remain responsible to the Controller for its performance.
  4. Help the Controller respond to individual rights requests through appropriate measures, considering the nature of the processing. Forward requests promptly and do not disclose information without authority.
  5. Help with security, breach reporting, impact assessments and any required consultation with the regulator, considering the information available and the processing involved.
  6. Report a personal-data breach without undue delay. Provide known facts immediately and further information as it becomes available; do not wait for a completed investigation.
  7. At the end of the service, return or delete personal information at the Controller’s choice, including copies, unless law requires retention. Protect any required retained copy and use it only for that duty.
  8. Provide information needed to demonstrate compliance and allow and contribute to audits and inspections by the Controller or its appointed auditor.

The data record describes the authorised work. For collection hosting, this normally means viewing or printing member names, relevant contact details, order contents and collection arrangements to prepare handovers and resolve problems for the agreed hosting period. It does not include marketing, private growing records or unrestricted account access.

For platform hosting or other processing, the record separately specifies the operations, data types and affected people before processing starts. Neither party may extend the activity simply by making more information technically accessible.

B. Sharing between independently responsible organisations

Where each organisation decides how to use information for its own duties, each is responsible for its own lawful basis, privacy information, security, retention and response to individual rights. Examples include a seller’s sale and tax records and a Circle Operator’s membership records.

Share only information necessary for the recorded purpose, such as fulfilling an order, settling a sale or investigating a safety concern. Check accuracy, use secure channels and correct relevant recipients when a material error is found. Do not use received contact details for unrelated marketing without a separate lawful basis and any required consent.

Cooperate on requests, complaints and incidents. Tell the other organisation promptly where its information or users may be affected, without delaying either organisation’s own legal reporting duties. Keep unnecessary copies no longer than needed.

If the organisations jointly determine an activity’s purposes and means, they must record their respective responsibilities, including privacy information and rights handling, and make the essence of that arrangement available to affected people. Individuals may exercise their rights against either joint controller.

Changes and accountability

Keep the data record current and agree changes before extending the use, recipients or international transfers. A role-holder change does not itself authorise a new purpose or transfer of private records. Each party retains its direct legal obligations; this agreement does not restrict individuals’ rights against a responsible organisation.

Rooted Commons

Rooted Commons is a pilot project operated by Roots to Fruits CIC.

info@rootedcommons.uk

Contact · Portal · Member terms · Privacy notice · Terms of sale