Skip to content
ROGERTHAT!
Book Demo
← Roger That!

Privacy Policy

Effective 23 July 2026 · Version 1.0 · Reference: RT-GDPR-PRV-001

This Privacy Policy explains how Roger That!, delivered by GRAM Systems and Concept Informatics Ltd in partnership ("we", "us"), collects, uses, shares and protects personal data, in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and applicable Cyprus data protection law. It covers this website, our consultation and migration process, and the platform accounts of the people who use Roger That!. It does not replace the privacy notice each customer operates for its own crew and staff — see Our role below for that distinction.

On this page

  • Who we are
  • Our role
  • What we collect
  • Legal bases
  • Who we share with
  • Transfers
  • Retention
  • Security
  • Your rights
  • Requesting your data
  • Cookies
  • Breach notification
  • Changes
  • Contact & complaints

1. Who we are

Roger That! is asset management and planned maintenance software for ROV, subsea and offshore operations. It is delivered by GRAM Systems (Global Reach Asset Management) and Concept Informatics Ltd, a company registered in the United Kingdom, working together in partnership. The two are separate companies; neither is a trading name of the other.

Joint controllers

For the personal data described in this policy, GRAM Systems and Concept Informatics Ltd act as joint controllers under Art. 26 GDPR. We have agreed between us who does what, and the essence of that arrangement is set out in this policy. Whichever of us you contact, you may exercise all of your rights against either of us, and a single point of contact handles every request: info@rogerthat.cloud.

Joint controllersGRAM Systems and Concept Informatics Ltd
Company registrationConcept Informatics Ltd — registered in the United Kingdom
Single point of contactinfo@rogerthat.cloud
Phone (UK)Geoff Davison +44 7830 231672 · Matthew Hudson +44 7918 174779
Phone (Cyprus)+357 95984544
Data locationCustomer platform data is held on a local server aboard the customer's vessel, in the cloud in the United Kingdom or the European Union, or both — per the deployment agreed with each customer
Supervisory authorityOffice of the Commissioner for Personal Data Protection, Cyprus — dataprotection.gov.cy; or the UK Information Commissioner's Office — ico.org.uk

We have not appointed a formal Data Protection Officer under Art. 37 GDPR, as we do not carry out large-scale systematic monitoring or process special-category data at scale. Data protection queries are handled by our team at the email address above.

2. Our role: controller vs. processor

Roger That! sits in two different roles depending on whose data is involved. This affects which rights apply and who you should address them to.

We are the data controllers (jointly) for:
  • Website visitors and prospective customers — for example, the demo request form on this site;
  • Our own commercial, contractual and billing relationship with customers;
  • The login and account details of the people our customers give platform access to (name, work email, role) — though not the asset, maintenance or operational content they enter.
We are the data processor for:
  • Personal data contained in the operational records a customer enters into the platform — for example the names and signatures of the technicians who carried out a maintenance job, who moved a part, or who signed off a checklist step.

For that data the customer is the data controller. We act strictly on their documented instructions under a Data Processing Agreement (Art. 28 GDPR), and requests about that data — access, correction, erasure — should go to the customer, not to us. If you are a technician, crew member or shore-side employee asking what your employer holds about you in Roger That!, contact your employer. We will support them in responding to you.

3. What data we collect

Website visitors and enquiries

When you complete the demo request form: your name, work email address, company, the number of vessels or ROV systems you operate, what you currently use to track parts and maintenance, and anything else you choose to tell us.

Platform accounts

Name, work email address, role (for example: administrator, superintendent, technician) and authentication data. Passwords are stored only as a salted hash — we cannot read them.

Billing contacts

Billing contact name, email and the details of the agreed subscription. Customers are invoiced directly, so we do not collect or store payment card numbers.

Technical data

Standard web and application logs — IP address, browser type, pages or screens accessed, and error reports — collected for security, troubleshooting and reliability.

4. Why we process it (legal bases)

PurposeLegal basisCan you object?
Responding to a demo or assessment enquiry Art. 6(1)(f) — legitimate interests Yes, at any time
Providing your account access to the platform Art. 6(1)(b) — necessary for the contract with the customer that engaged us No — necessary for the service
Billing and payment collection Art. 6(1)(b) contract; Art. 6(1)(c) legal and tax obligation No — statutory or contractual
Product and service communications Art. 6(1)(a) consent, or Art. 6(1)(f) legitimate interests for existing customers Yes — unsubscribe link on every email
Security, fraud prevention and service reliability Art. 6(1)(f) — legitimate interests Yes, but may be overridden

5. Who we share data with

We do not sell, rent or trade personal data. We share it only with the sub-processors that help us run the platform, each bound by a written data processing agreement, and with public authorities where we are required by law to do so.

VendorPurposeData categoryLocation / safeguard
Cloudflare Website hosting, DNS, CDN and bot protection Technical logs, demo form submissions Global edge; EU/UK data localisation, SCCs
Resend Transactional and enquiry email delivery Name, work email, enquiry content United States — Standard Contractual Clauses
Application and database hosting Running the Roger That! application and PostgreSQL database All platform data United Kingdom or European Union, per the region agreed with the customer. Not applicable where the customer runs the platform on their own vessel or shore-side hardware
Backup storage Encrypted database backups and disaster recovery All platform data Same region as the primary database

A current sub-processor list is available on request, and customers are notified before any change.

6. International transfers

Customer platform data is held on the customer's own vessel hardware, or in the cloud in the United Kingdom or the European Union, and is not routinely transferred outside those locations. A small number of supporting services — principally email delivery — rely on providers based in the United States. Where personal data is transferred outside the UK or EEA, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent adequacy mechanism with that provider. See the sub-processor table above for each provider's location.

7. How long we keep it

We keep personal data only for as long as necessary for the purpose it was collected for, or as required by law. The full schedule, with the legal basis for each period, is published separately:

Read the Data Retention Schedule →

Operational data uploaded by a customer is retained for as long as their agreement runs, and is deleted or returned on their instruction at the end of it, per our Data Processing Agreement.

8. How we protect it

  • Encryption in transit (TLS) for all traffic to and from the platform, and encryption at rest for the database and backups;
  • Role-based access control — platform users see only the systems, vessels and locations their role permits;
  • Passwords stored only as salted hashes; administrative access restricted to authorised personnel and logged;
  • Daily backups with point-in-time recovery, held in the same region as the primary database and restore-tested;
  • A self-contained stack — Go, PostgreSQL and Linux — which keeps the number of parties touching your data small;
  • Every sub-processor bound by a written data processing agreement.

9. Your rights

RightArticleNotes
AccessArt. 15A copy of the personal data we hold about you, in our role as controller
RectificationArt. 16Correct inaccurate data
ErasureArt. 17Subject to our own legal and billing retention obligations
RestrictionArt. 18Pause processing while a dispute is resolved
PortabilityArt. 20Applies to data we hold under contract or consent
ObjectionArt. 21Object to legitimate-interests processing at any time
Complaint to the DPAArt. 77Lodge a complaint with a supervisory authority at any time

These rights apply to data we hold as controller. See Section 2 if you are asking about maintenance or operational records your employer holds in the platform.

10. Requesting your data

To exercise any of the rights above, email info@rogerthat.cloud. We will acknowledge your request within 5 working days, verify your identity, and respond within 30 calendar days — extendable by up to two further months for complex requests, with reasons given. There is no charge for a standard request. We may decline, or charge a reasonable fee for, requests that are manifestly unfounded or excessive, and we will always explain why.

Read the Subject Access Request Procedure →

11. Cookies

This website sets no cookies and runs no analytics or advertising trackers. The Roger That! application itself uses strictly necessary cookies and local storage to keep you signed in and to remember interface preferences. We do not use third-party advertising cookies or cross-site trackers anywhere.

12. Data breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR), and will notify affected individuals directly, without undue delay, where the breach is likely to result in a high risk to them (Art. 34). Where a breach affects data we process on behalf of a customer, we will notify that customer without undue delay so they can meet their own notification obligations.

13. Changes to this policy

We review this policy at least annually, or sooner if our processing activities or the applicable law change materially. The effective date at the top of this page always reflects the current version.

14. Contact us & complaints

For any data protection query, or to request a Data Processing Agreement if you are a customer acting as a data controller: info@rogerthat.cloud. This one address reaches both joint controllers — you do not need to write to us separately.

By phone: Geoff Davison on +44 7830 231672, Matthew Hudson on +44 7918 174779, or our Cyprus office on +357 95984544.

You may also lodge a complaint with a supervisory authority at any time — for us, the Cyprus Commissioner for Personal Data Protection (dataprotection.gov.cy, 1 Iasonos Street, 1082 Nicosia, Cyprus), or the authority in your own country.

See also our Terms of Service and Data Protection Policy. Back to Home
© GRAM Systems & Concept Informatics. All rights reserved.
Roger That!™ and GRAM Systems™ are trademarks of GRAM Systems.