Skip to content
ROGERTHAT!
Book Demo
← Roger That!

Data Protection Policy

Effective 23 July 2026 · Version 1.0 · Reference: RT-GDPR-POL-001

This Policy sets out how GRAM Systems and Concept Informatics Ltd (a company registered in the United Kingdom) — separate companies delivering Roger That! in partnership, and joint controllers under Art. 26 GDPR — protect personal data across the platform, in compliance with Regulation (EU) 2016/679 (GDPR), the UK GDPR and, where applicable, Cyprus Data Protection Law 125(I)/2018.

On this page

  • Scope
  • Principles
  • Lawful bases
  • Security measures
  • Residency & recovery
  • Sub-processors
  • Breach procedure
  • Review
  • Contact

1. Scope

This Policy covers personal data Roger That! controls directly — platform account holders such as administrators, superintendents, supervisors and technicians, along with billing contacts and website enquirers — and personal data we process as a processor on behalf of a customer, such as the names, roles and sign-offs of that customer's personnel recorded against maintenance jobs, part movements and checklist steps.

It does not replace the privacy notice, data protection policy or retention schedule that each customer operates for its own personnel. Those govern the relationship between an employer and its crew and staff directly.

2. Data protection principles

We process personal data in accordance with the six principles of Art. 5 GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality.

Applied to this product, data minimisation matters in a specific way: Roger That! is built to record what was done to an asset and by whom, not to monitor individuals. We do not collect location data, biometric data, productivity scoring or any special-category data, and the platform must not be configured to use maintenance records as a performance-management tool without the customer having its own lawful basis and notice for that.

3. Lawful bases

  • Contract (Art. 6(1)(b)) — operating accounts, billing and support for platform customers.
  • Legal obligation (Art. 6(1)(c)) — accounting, tax and regulatory record-keeping.
  • Legitimate interests (Art. 6(1)(f)) — platform security, fraud prevention and service improvement.
  • Processor instructions — for personal data inside customer operational records, we act strictly on the documented instructions of the controlling customer (Art. 28 GDPR), under a Data Processing Agreement.

4. Security measures

Data is encrypted in transit and at rest. Access is role-based and scoped per organisation, system and location, so a user sees only the vessels, warehouses and assets their role covers. Documents, certificates and photo attachments are held in access-controlled storage and are never exposed directly to the public internet. Passwords are stored only as salted hashes. Administrative access is logged and restricted to authorised personnel.

The platform runs on a self-contained stack — Go, PostgreSQL and Linux — which deliberately keeps the number of third parties with any access to customer data small.

5. Data residency and recovery

Roger That! can be deployed in three ways, and the customer chooses at deployment: on a local server aboard the vessel, in the cloud in the United Kingdom or the European Union, or both — with the vessel syncing to the cloud when connectivity allows. Where the platform runs on the customer's own vessel or shore-side hardware, the customer controls the physical security of that hardware and we have no access to it except as they grant.

Backups are taken daily, encrypted, held in the same region as the database they protect, and restore-tested — a backup nobody has restored is not a backup. Point-in-time recovery is available within the retention window of the backup set.

Customers may request a full export of their data in a machine-readable format at any time, and on termination.

6. Sub-processors

We use a small number of infrastructure sub-processors — cloud hosting, database and object storage, backup storage and email delivery — strictly to operate the platform, each under a written data processing agreement. The current list is published in our Privacy Policy and is also available on request. Customers are notified before any addition or change.

7. Data breach procedure

Suspected breaches are assessed within 24 hours of discovery. Where required, the relevant supervisory authority is notified within 72 hours (Art. 33 GDPR) and affected data subjects are notified without undue delay where there is a likely high risk to their rights and freedoms (Art. 34 GDPR). Where data processed on behalf of a customer is affected, that customer is notified without undue delay so they can meet their own controller obligations. All incidents, including those that do not meet the notification threshold, are recorded in our breach log.

8. Review

This Policy is reviewed annually, or sooner following a material change in law or in our processing activities.

9. Contact

GRAM Systems and Concept Informatics Ltd, joint controllers, share a single point of contact: info@rogerthat.cloud. By phone: Geoff Davison on +44 7830 231672, Matthew Hudson on +44 7918 174779, or our Cyprus office on +357 95984544.

See also our Privacy Policy and Data Retention Schedule. Back to Home
© GRAM Systems & Concept Informatics. All rights reserved.
Roger That!™ and GRAM Systems™ are trademarks of GRAM Systems.