Your farm data stays yours. In the EU. Encrypted.
Every byte of Koru data lives in the EU, encrypted at rest and in transit. GDPR rights are one tap away. The audit log records every access. Your data is never used to train external models.

Privacy that's built in, not bolted on.
Koru was designed under GDPR from day one. Your farm data — parcels, activities, workers, products — is stored on EU infrastructure, encrypted at rest and in transit, and never shared with third parties without explicit consent. Every access is logged. Every GDPR right is available in-app.
Your data never leaves the EU.
Every Koru workspace runs on EU infrastructure, with strict data residency guarantees. Backups stay in the EU. Processing happens in the EU. AI inference happens in the EU. No sneaky cross-border transfers, no 'except when convenient' clauses.
- All production data hosted on EU infrastructure
- Backups stored exclusively within the EU
- AI inference performed within EU boundaries

GDPR rights, one tap away.
Access, export, rectify, delete — every GDPR right lives as a button inside Koru, not a support ticket queue. Export your data in machine-readable formats. Delete your account and watch it vanish (after legally required retention). See every access in your audit log.
- Self-service data export in machine-readable formats
- Account deletion with compliant retention windows
- Personal audit log of every access to your data

Security and privacy, built into every layer.
The guarantees you need when your data is your livelihood.
EU data residency
Production, backups, and processing all inside the EU — no exceptions, no convenient carve-outs.
Encryption everywhere
Data encrypted at rest with modern ciphers, and in transit with TLS 1.3.
Immutable audit log
Every access, every change, every export logged with tamper-evident signatures.
Self-service GDPR
Access, export, rectification, and deletion rights available as in-app actions.
Role-based access
Granular permissions so workers, advisors, and owners each see only what they should.
No training on your data
Your farm data is never used to train third-party or external AI models.
PII anonymisation for AI
Personally identifiable information is anonymised before reaching any AI inference pipeline.
Named DPO
A named Data Protection Officer reachable directly from every account's privacy screen.
For anyone who takes 'it's just farm data' seriously.
- Start free
Single farm
You get self-service GDPR rights, EU residency, and an audit log of every access — without reading a white paper.
- Ask for demo
Advisor
Advisors can demonstrate compliance posture to every client with EU residency, encryption, and audit logging built in.
- Ask for demo
Cooperative
Cooperatives get documented EU residency, role-based access, and audit logs — the things a board needs to sign off on supplier risk.
“Everything is encrypted, everything stays in the EU. Good enough for me.”
Live, audited, and improving continuously.
Security and privacy practices are reviewed quarterly, with changes documented in our public trust centre. We treat privacy as a product feature, not a compliance checkbox.
Your data. Your rules. In the EU.
Free 14-day trial. GDPR-safe from day one. No credit card.

Keep exploring Koru
Multi-farm hub
Role-based access and data isolation for advisors and cooperatives.
Reporting
Audit-ready reports backed by the same immutable audit log.
Activity management
Structured activity records with a tamper-evident audit trail.