Privacy Policy
This Privacy Policy explains how Roger That!, delivered by GRAM Systems and Concept Informatics Ltd in partnership ("we", "us"), collects, uses, shares and protects personal data, in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and applicable Cyprus data protection law. It covers this website, our consultation and migration process, and the platform accounts of the people who use Roger That!. It does not replace the privacy notice each customer operates for its own crew and staff — see Our role below for that distinction.
1. Who we are
Roger That! is asset management and planned maintenance software for ROV, subsea and offshore operations. It is delivered by GRAM Systems (Global Reach Asset Management) and Concept Informatics Ltd, a company registered in the United Kingdom, working together in partnership. The two are separate companies; neither is a trading name of the other.
For the personal data described in this policy, GRAM Systems and Concept Informatics Ltd act as joint controllers under Art. 26 GDPR. We have agreed between us who does what, and the essence of that arrangement is set out in this policy. Whichever of us you contact, you may exercise all of your rights against either of us, and a single point of contact handles every request: info@rogerthat.cloud.
| Joint controllers | GRAM Systems and Concept Informatics Ltd |
| Company registration | Concept Informatics Ltd — registered in the United Kingdom |
| Single point of contact | info@rogerthat.cloud |
| Phone (UK) | Geoff Davison +44 7830 231672 · Matthew Hudson +44 7918 174779 |
| Phone (Cyprus) | +357 95984544 |
| Data location | Customer platform data is held on a local server aboard the customer's vessel, in the cloud in the United Kingdom or the European Union, or both — per the deployment agreed with each customer |
| Supervisory authority | Office of the Commissioner for Personal Data Protection, Cyprus — dataprotection.gov.cy; or the UK Information Commissioner's Office — ico.org.uk |
We have not appointed a formal Data Protection Officer under Art. 37 GDPR, as we do not carry out large-scale systematic monitoring or process special-category data at scale. Data protection queries are handled by our team at the email address above.
2. Our role: controller vs. processor
Roger That! sits in two different roles depending on whose data is involved. This affects which rights apply and who you should address them to.
- Website visitors and prospective customers — for example, the demo request form on this site;
- Our own commercial, contractual and billing relationship with customers;
- The login and account details of the people our customers give platform access to (name, work email, role) — though not the asset, maintenance or operational content they enter.
- Personal data contained in the operational records a customer enters into the platform — for example the names and signatures of the technicians who carried out a maintenance job, who moved a part, or who signed off a checklist step.
For that data the customer is the data controller. We act strictly on their documented instructions under a Data Processing Agreement (Art. 28 GDPR), and requests about that data — access, correction, erasure — should go to the customer, not to us. If you are a technician, crew member or shore-side employee asking what your employer holds about you in Roger That!, contact your employer. We will support them in responding to you.
3. What data we collect
Website visitors and enquiries
When you complete the demo request form: your name, work email address, company, the number of vessels or ROV systems you operate, what you currently use to track parts and maintenance, and anything else you choose to tell us.
Platform accounts
Name, work email address, role (for example: administrator, superintendent, technician) and authentication data. Passwords are stored only as a salted hash — we cannot read them.
Billing contacts
Billing contact name, email and the details of the agreed subscription. Customers are invoiced directly, so we do not collect or store payment card numbers.
Technical data
Standard web and application logs — IP address, browser type, pages or screens accessed, and error reports — collected for security, troubleshooting and reliability.
4. Why we process it (legal bases)
| Purpose | Legal basis | Can you object? |
|---|---|---|
| Responding to a demo or assessment enquiry | Art. 6(1)(f) — legitimate interests | Yes, at any time |
| Providing your account access to the platform | Art. 6(1)(b) — necessary for the contract with the customer that engaged us | No — necessary for the service |
| Billing and payment collection | Art. 6(1)(b) contract; Art. 6(1)(c) legal and tax obligation | No — statutory or contractual |
| Product and service communications | Art. 6(1)(a) consent, or Art. 6(1)(f) legitimate interests for existing customers | Yes — unsubscribe link on every email |
| Security, fraud prevention and service reliability | Art. 6(1)(f) — legitimate interests | Yes, but may be overridden |
6. International transfers
Customer platform data is held on the customer's own vessel hardware, or in the cloud in the United Kingdom or the European Union, and is not routinely transferred outside those locations. A small number of supporting services — principally email delivery — rely on providers based in the United States. Where personal data is transferred outside the UK or EEA, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent adequacy mechanism with that provider. See the sub-processor table above for each provider's location.
7. How long we keep it
We keep personal data only for as long as necessary for the purpose it was collected for, or as required by law. The full schedule, with the legal basis for each period, is published separately:
Read the Data Retention Schedule →
Operational data uploaded by a customer is retained for as long as their agreement runs, and is deleted or returned on their instruction at the end of it, per our Data Processing Agreement.
8. How we protect it
- Encryption in transit (TLS) for all traffic to and from the platform, and encryption at rest for the database and backups;
- Role-based access control — platform users see only the systems, vessels and locations their role permits;
- Passwords stored only as salted hashes; administrative access restricted to authorised personnel and logged;
- Daily backups with point-in-time recovery, held in the same region as the primary database and restore-tested;
- A self-contained stack — Go, PostgreSQL and Linux — which keeps the number of parties touching your data small;
- Every sub-processor bound by a written data processing agreement.
9. Your rights
| Right | Article | Notes |
|---|---|---|
| Access | Art. 15 | A copy of the personal data we hold about you, in our role as controller |
| Rectification | Art. 16 | Correct inaccurate data |
| Erasure | Art. 17 | Subject to our own legal and billing retention obligations |
| Restriction | Art. 18 | Pause processing while a dispute is resolved |
| Portability | Art. 20 | Applies to data we hold under contract or consent |
| Objection | Art. 21 | Object to legitimate-interests processing at any time |
| Complaint to the DPA | Art. 77 | Lodge a complaint with a supervisory authority at any time |
These rights apply to data we hold as controller. See Section 2 if you are asking about maintenance or operational records your employer holds in the platform.
10. Requesting your data
To exercise any of the rights above, email info@rogerthat.cloud. We will acknowledge your request within 5 working days, verify your identity, and respond within 30 calendar days — extendable by up to two further months for complex requests, with reasons given. There is no charge for a standard request. We may decline, or charge a reasonable fee for, requests that are manifestly unfounded or excessive, and we will always explain why.
12. Data breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR), and will notify affected individuals directly, without undue delay, where the breach is likely to result in a high risk to them (Art. 34). Where a breach affects data we process on behalf of a customer, we will notify that customer without undue delay so they can meet their own notification obligations.
13. Changes to this policy
We review this policy at least annually, or sooner if our processing activities or the applicable law change materially. The effective date at the top of this page always reflects the current version.
14. Contact us & complaints
For any data protection query, or to request a Data Processing Agreement if you are a customer acting as a data controller: info@rogerthat.cloud. This one address reaches both joint controllers — you do not need to write to us separately.
By phone: Geoff Davison on +44 7830 231672, Matthew Hudson on +44 7918 174779, or our Cyprus office on +357 95984544.
You may also lodge a complaint with a supervisory authority at any time — for us, the Cyprus Commissioner for Personal Data Protection (dataprotection.gov.cy, 1 Iasonos Street, 1082 Nicosia, Cyprus), or the authority in your own country.