GeoenergyOS / OilfieldOS Platform - operated by Apriside ApS
The data controller responsible for the processing of your personal data is:
| Company | Apriside ApS |
| Registration number | CVR 38773771 (Denmark) |
| Address | Sandagerhusvej 103, 3100 Hornbaek, Denmark |
| Privacy contact | [email protected] |
| Website | www.apriside.com |
This Privacy Policy explains how Apriside ApS ("Apriside", "we", "us") collects, uses, stores, and protects personal data when you access or use the GeoenergyOS / OilfieldOS software platform (the "Platform"). It applies to all registered users of the Platform, including employees and contractors of Apriside's customers ("Users").
Access to the Platform is granted through a licence held by your organisation (the "Licence Owner"). If you have questions about how your personal data is processed or wish to exercise your rights, you may contact the Licence Owner in the first instance, or contact Apriside directly at [email protected].
We process your personal data only for the following purposes, each on the legal basis indicated:
| Purpose | Description | Legal Basis (GDPR) |
|---|---|---|
| Platform access and user identification | To authenticate users and record who creates, modifies, or views records within the Platform | Art. 6(1)(b) - performance of contract with Licence Owner |
| Service delivery and technical support | To provide the software services contracted by the Licence Owner, including support and incident resolution | Art. 6(1)(b) - performance of contract |
| Platform security and integrity | To monitor for unauthorised access, detect security incidents, and maintain audit logs | Art. 6(1)(f) - legitimate interest in protecting the Platform and its users |
| Service optimisation | To analyse usage patterns and improve Platform performance. Any machine-learning optimisation uses anonymised or aggregated data only. | Art. 6(1)(f) - legitimate interest in improving the service |
| Legal compliance | To comply with applicable statutory obligations, including accounting, tax, and regulatory requirements | Art. 6(1)(c) - legal obligation |
| Legal claims | To establish, exercise, or defend legal claims arising from the contractual relationship | Art. 6(1)(f) - legitimate interest in legal protection |
We retain personal data only for as long as necessary for the purposes for which it was collected, and in accordance with applicable legal requirements:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account and identity data | Duration of active account + 12 months after account deactivation or contract termination | Operational necessity; potential legal claims |
| Platform usage and activity logs | 12 months from date of creation | Security monitoring and audit requirements |
| Security and system logs | 12 months from date of creation | Information security best practice |
| Backup copies | Maximum 30 days (rolling) | Business continuity and disaster recovery |
| Data subject to an erasure request | Deleted within 30 calendar days of a verified request, unless retention is required by law | GDPR Art. 17 - Right to Erasure |
Upon termination of the Licence Owner's contract, account data will be deleted within 12 months unless the Licence Owner requests earlier deletion or a data export.
To provide the Platform, we share personal data with the following sub-processors. Each is bound by a Data Processing Agreement providing at least the same level of protection as this Policy. We do not sell personal data to any third party.
| Sub-Processor | Location | Purpose | Transfer Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | EU - Frankfurt, Germany | Cloud infrastructure: hosting, storage, compute, backups, encryption | EU region - no international transfer required |
| Cloudflare, Inc. | USA (global CDN network) | Web application firewall, DDoS protection, DNS, CDN. Processes IP addresses and HTTP headers. | EU-US Data Privacy Framework + Standard Contractual Clauses |
| Mailgun (Sinch AB) | Sweden / USA | Transactional email delivery: system notifications and alerts | EU-US Data Privacy Framework + Standard Contractual Clauses |
We may also disclose personal data to legal or tax advisors where necessary to exercise or defend legal claims, or where required by applicable law or a competent authority.
An up-to-date list of sub-processors is available on request at [email protected].
Your personal data is primarily processed within the European Economic Area (EEA). The main infrastructure operates on Amazon Web Services in the EU (Frankfurt, Germany) region.
Cloudflare, Inc. and Mailgun (Sinch AB) may process data in the United States. In each case, transfers are protected by:
You may request a copy of the applicable Standard Contractual Clauses by contacting [email protected].
As a data subject, you have the following rights under GDPR. To exercise any right, contact us at [email protected]. We will respond within 30 calendar days.
| Right | What it means |
|---|---|
| Right of access (Art. 15) | Obtain confirmation that we process your data and receive a copy, together with information about how it is used |
| Right to rectification (Art. 16) | Request correction of inaccurate data or completion of incomplete data |
| Right to erasure (Art. 17) | Request deletion of your data where it is no longer necessary, where consent is withdrawn, or where processing is unlawful. Subject to statutory retention obligations. |
| Right to restriction (Art. 18) | Request that we limit processing of your data in certain circumstances, for example while the accuracy of the data is disputed |
| Right to data portability (Art. 20) | Receive your data in a structured, machine-readable format and transmit it to another controller, where processing is contract- or consent-based |
| Right to object (Art. 21) | Object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. |
| Right to withdraw consent | Where processing is based on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. |
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you, within the meaning of GDPR Article 22.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These include:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Danish Data Protection Agency (Datatilsynet) within 72 hours as required by GDPR Article 33.
Where there is a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with GDPR Article 34.
If you believe our processing of your personal data violates applicable law, you have the right to lodge a complaint with the competent supervisory authority:
| Authority | Datatilsynet (Danish Data Protection Agency) |
| Website | www.datatilsynet.dk |
| Address | Borgergade 28, 5., 1300 Copenhagen K, Denmark |
We would welcome the opportunity to address your concerns directly before you approach the supervisory authority. Please contact us at [email protected] in the first instance.
We may update this Privacy Policy from time to time to reflect changes in our processing activities or applicable law. We will notify you of material changes by email to your registered address, or by a prominent notice within the Platform, at least 30 days before the change takes effect. Non-material clarifications take effect immediately.
The effective date at the top of this document indicates when the current version was last updated.