Privacy Policy

GeoenergyOS / OilfieldOS Platform - operated by Apriside ApS

Version 2.0 | Effective date: 11 May 2026 | Replaces version 1.0 (2019)

1. Data Controller

The data controller responsible for the processing of your personal data is:

CompanyApriside ApS
Registration numberCVR 38773771 (Denmark)
AddressSandagerhusvej 103, 3100 Hornbaek, Denmark
Privacy contact[email protected]
Websitewww.apriside.com

2. Scope of This Policy

This Privacy Policy explains how Apriside ApS ("Apriside", "we", "us") collects, uses, stores, and protects personal data when you access or use the GeoenergyOS / OilfieldOS software platform (the "Platform"). It applies to all registered users of the Platform, including employees and contractors of Apriside's customers ("Users").

Access to the Platform is granted through a licence held by your organisation (the "Licence Owner"). If you have questions about how your personal data is processed or wish to exercise your rights, you may contact the Licence Owner in the first instance, or contact Apriside directly at [email protected].

3. Personal Data We Collect

3.1 Account and Identity Data

  • First name and surname
  • Work email address
  • Work telephone number
  • Job title and professional role
  • Profile photograph (optional, uploaded at your discretion)

3.2 Technical and Usage Data

  • IP address
  • Browser type and version
  • Operating system type and version
  • Activity logs: actions performed in the Platform, timestamps, and session identifiers

3.3 Integration-Specific Data

  • Personal identifier from helicopter flight booking systems, where applicable and configured by the Licence Owner
We do not collect special category data (such as health data, racial or ethnic origin, or political opinions). The Platform is not designed to process such data. We do not collect any information beyond the categories listed above.

4. Purposes of Processing and Legal Basis

We process your personal data only for the following purposes, each on the legal basis indicated:

PurposeDescriptionLegal Basis (GDPR)
Platform access and user identification To authenticate users and record who creates, modifies, or views records within the Platform Art. 6(1)(b) - performance of contract with Licence Owner
Service delivery and technical support To provide the software services contracted by the Licence Owner, including support and incident resolution Art. 6(1)(b) - performance of contract
Platform security and integrity To monitor for unauthorised access, detect security incidents, and maintain audit logs Art. 6(1)(f) - legitimate interest in protecting the Platform and its users
Service optimisation To analyse usage patterns and improve Platform performance. Any machine-learning optimisation uses anonymised or aggregated data only. Art. 6(1)(f) - legitimate interest in improving the service
Legal compliance To comply with applicable statutory obligations, including accounting, tax, and regulatory requirements Art. 6(1)(c) - legal obligation
Legal claims To establish, exercise, or defend legal claims arising from the contractual relationship Art. 6(1)(f) - legitimate interest in legal protection

5. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, and in accordance with applicable legal requirements:

Data CategoryRetention PeriodRationale
Account and identity data Duration of active account + 12 months after account deactivation or contract termination Operational necessity; potential legal claims
Platform usage and activity logs 12 months from date of creation Security monitoring and audit requirements
Security and system logs 12 months from date of creation Information security best practice
Backup copies Maximum 30 days (rolling) Business continuity and disaster recovery
Data subject to an erasure request Deleted within 30 calendar days of a verified request, unless retention is required by law GDPR Art. 17 - Right to Erasure

Upon termination of the Licence Owner's contract, account data will be deleted within 12 months unless the Licence Owner requests earlier deletion or a data export.

6. Sub-Processors and Recipients

To provide the Platform, we share personal data with the following sub-processors. Each is bound by a Data Processing Agreement providing at least the same level of protection as this Policy. We do not sell personal data to any third party.

Sub-ProcessorLocationPurposeTransfer Safeguard
Amazon Web Services (AWS) EU - Frankfurt, Germany Cloud infrastructure: hosting, storage, compute, backups, encryption EU region - no international transfer required
Cloudflare, Inc. USA (global CDN network) Web application firewall, DDoS protection, DNS, CDN. Processes IP addresses and HTTP headers. EU-US Data Privacy Framework + Standard Contractual Clauses
Mailgun (Sinch AB) Sweden / USA Transactional email delivery: system notifications and alerts EU-US Data Privacy Framework + Standard Contractual Clauses

We may also disclose personal data to legal or tax advisors where necessary to exercise or defend legal claims, or where required by applicable law or a competent authority.

An up-to-date list of sub-processors is available on request at [email protected].

7. International Data Transfers

Your personal data is primarily processed within the European Economic Area (EEA). The main infrastructure operates on Amazon Web Services in the EU (Frankfurt, Germany) region.

Cloudflare, Inc. and Mailgun (Sinch AB) may process data in the United States. In each case, transfers are protected by:

  • The EU-US Data Privacy Framework (DPF) - both providers are certified
  • Standard Contractual Clauses (EU Commission Decision 2021/914/EU)

You may request a copy of the applicable Standard Contractual Clauses by contacting [email protected].

8. Your Rights

As a data subject, you have the following rights under GDPR. To exercise any right, contact us at [email protected]. We will respond within 30 calendar days.

RightWhat it means
Right of access (Art. 15) Obtain confirmation that we process your data and receive a copy, together with information about how it is used
Right to rectification (Art. 16) Request correction of inaccurate data or completion of incomplete data
Right to erasure (Art. 17) Request deletion of your data where it is no longer necessary, where consent is withdrawn, or where processing is unlawful. Subject to statutory retention obligations.
Right to restriction (Art. 18) Request that we limit processing of your data in certain circumstances, for example while the accuracy of the data is disputed
Right to data portability (Art. 20) Receive your data in a structured, machine-readable format and transmit it to another controller, where processing is contract- or consent-based
Right to object (Art. 21) Object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to withdraw consent Where processing is based on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Because Platform access is granted via a licence held by your organisation, some requests may need to be coordinated with the Licence Owner. We will inform you if this is the case.

9. Automated Decision-Making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you, within the meaning of GDPR Article 22.

10. Security Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These include:

  • Encryption of data in transit (TLS) and at rest (AES-256)
  • Role-based access controls and least-privilege principles
  • Multi-factor authentication (MFA) available for all users
  • Regular independent penetration testing
  • Vulnerability management with defined remediation timelines
  • Centralised security logging and monitoring
  • Restricted administrative access via VPN
  • Separate development, testing, and production environments

11. Personal Data Breaches

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Danish Data Protection Agency (Datatilsynet) within 72 hours as required by GDPR Article 33.

Where there is a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with GDPR Article 34.

12. Complaints

If you believe our processing of your personal data violates applicable law, you have the right to lodge a complaint with the competent supervisory authority:

AuthorityDatatilsynet (Danish Data Protection Agency)
Websitewww.datatilsynet.dk
AddressBorgergade 28, 5., 1300 Copenhagen K, Denmark

We would welcome the opportunity to address your concerns directly before you approach the supervisory authority. Please contact us at [email protected] in the first instance.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities or applicable law. We will notify you of material changes by email to your registered address, or by a prominent notice within the Platform, at least 30 days before the change takes effect. Non-material clarifications take effect immediately.

The effective date at the top of this document indicates when the current version was last updated.

To Top