Privacy policy

Contents
  1. Cookies
  2. What is counted, if you accept
  3. What is never collected
  4. What the server itself records
  5. On what basis
  6. Email we send
  7. Where it is kept
  8. How long any of it is kept
  9. Your choice, and what you may ask for
  10. Who is asking
  11. The policy in full
  12. 1. Definitions and Interpretation
  13. 2. Scope and Status of this Policy
  14. 3. Controller and Contact
  15. 4. Roles of the Company
  16. 5. Categories of Personal Data and Sources
  17. 6. Purposes and Legal Bases
  18. 7. Provision of Personal Data
  19. 8. Service Communications and Other Communications
  20. 9. Cookies and Similar Technologies
  21. 10. Recipients
  22. 11. Customer Content and Requests Concerning It
  23. 12. Location of Processing and International Transfers
  24. 13. Retention
  25. 14. Security
  26. 15. Your Rights
  27. 16. Automated Decision-Making
  28. 17. Children
  29. 18. Jurisdiction-Specific Provisions
    1. 18.1 European Economic Area
    2. 18.2 United Kingdom
    3. 18.3 United States
    4. 18.4 Republic of Kazakhstan
  30. 19. Third Parties
  31. 20. Changes to this Policy
  32. 21. Contact
  33. Annex A — Usage Measurement

Version 2026-09-25a.

What you type about a well stays in your browser until you save it. Rates, pressures, depths, fluid properties and the request you assemble are held in the page and gone when you close the tab. A production file is read in your browser and is never uploaded, and the documents are written in your browser. When you press Save calculation, the name of the well, the values on the form, the answer and your note are sent to your cabinet on our server and kept until you delete them or the account.

What this page does send, if you agree to it, is a count of how the tool is used. Nothing is sent to anybody else: no advertising network, no third-party script, no other site. Counting runs only where this notice has been answered and accepted. An account, if you ask for one, is the other half and is described below.

Cookies

NameWhat it holdsWhyKept
ls_consentyour choice — granted or refused — and the date of the notice you were shownso the banner does not ask again on every page
set whatever you answer — it is your answer
6 months
ls_ida random number, generated in your browser, that means nothing outside this siteso a returning visit can be told from a first one — otherwise every visit looks new
set only if you accept
12 months
ls_sa random number for this visitso the pages of one visit hang together
set only if you accept
until the tab is closed
ls_accta random number standing for the sign-in, and nothing about youso a cabinet you asked for is still yours on the next visit
set only when you ask for a sign-in code or sign in
30 days, or until you sign out
ls_codea random number standing for one request for a sign-in code, and nothing about youso a sign-in code works only in the browser that asked for it
set only when you ask for a sign-in code or sign in
one hour, or until you sign in
ls_deva random number standing for this browser once it has signed in to your account, and nothing about youso a browser you have signed in from is not shut out when somebody else keeps asking for codes to your address
set only when you ask for a sign-in code or sign in
180 days, or until you sign out everywhere or delete the account
ls_betaa signed expiry and nothing about you — the server keeps no copy of itso the closed test knows an invited browser without asking for the password again
set once you enter the access password for the closed test
30 days

Those are all the cookies. Your browser also keeps a few notes on your device; none is sent to us. For the tab only: the address and the tick typed into the sign-in form, until you sign in; the calculation you came from, so Back returns to it; whether a panel is open; that the invitation to open a cabinet was closed. Until you clear this site's data: that this browser has signed in before, and that the offer to set a password was shown. No fingerprint of your device is taken.

What is counted, if you accept

  • the page was opened
  • a step was opened
  • a region tab of the library was opened
  • a field was chosen from the library
  • the library search was used
  • a value in the form was changed
  • the lift was sized for a different case
  • a request for quotation was opened
  • a company was ticked or unticked in a request
  • a request for quotation was taken from the page
  • a file of wells was screened
  • the tab was closed or left
  • the techno-economic case was downloaded as a PDF
  • a document was asked for by somebody not signed in

Each carries at most which thing was opened or chosen, and one number — a count, a width, a number of seconds. Never what you typed.

What is never collected

  • the request for quotation itself, or any document the page generates
  • your postal address, and anything about you beyond what is listed under “On what basis”. An application says who is asking — a name, a company and a telephone number — because an account here is opened for a company, and we have to know whom we are opening it for
  • your IP address in full: the web server cuts the last part off before it writes a line, and the collector is never given it
  • anything sold, or shared with an advertising network, a data broker or another site. There is no third-party script here. The email we send you is delivered by the provider that hosts our mailbox — see "Where it is kept"

What the server itself records

An ordinary access log, whether you accept or refuse: the time, the page asked for, the site that linked you here by name, what the browser says about itself, and your address with the last part cut off before the line is written — the last part of an IPv4 address, the interface half of an IPv6 one. If you accept counting, a visit also carries the country that address belongs to — IP Geolocation by DB-IP — the size of your screen and window, and your time zone. The log is never joined to anything counted.

On what basis

Different things happen here, and they do not rest on the same ground.

that this browser entered the access password, and when that fact expires rests on our legitimate interest in keeping an unfinished tool to the people we invited — One cookie carries the fact that the access password was entered in this browser. It holds a signed expiry and nothing else, the server keeps no copy of it, and it is gone after 30 days. Attempts at the password are counted for a few minutes against a truncated address, so the door cannot be tried thousands of times.

the name, company and telephone number stated in the application, and the address you sign in with; a password, if you set one; the wells you mark; the calculations you save — the name of the well, the values on the form, the answer and your note; a line for each calculation you run and each document you take — the date, which one, and the name of the well; the version of the terms you accepted; and whether the account was opened or refused, by whom and why rests on the service you asked us for — Needed to give you the cabinet you asked for. A password is optional and is stored as a salted scrypt hash, never the password. Calculation and document lines are kept for 400 days; saved calculations and the rest until you delete them or the account, which takes one press in the cabinet and takes the address with it. Backup copies of the database are overwritten within 14 days. What an application states, and the decision on it, are kept as a screening record for five years — that is what the sanctions rules require of it; the rest goes with the account when you delete it.

everything counted about how the tool is used, and the two cookies that carry it rests on your consent — Nothing is stored or counted until you say yes, and one press takes it back.

the ordinary web-server log, with the address already truncated rests on our legitimate interest in keeping the server answering and able to defend itself — It is written whether you accept or refuse, it is never joined to anything you did on the page, and it is thrown away after the period below.

the record of sign-ins to an account, the notices we send about them, the count of failed sign-in attempts, and the cookie that marks a browser you have signed in from rests on our legitimate interest in keeping accounts from being taken over and mailboxes from being flooded with codes — Each sign-in is recorded for 90 days: the time, whether by code or by password, and the browser, operating system and kind of device as the browser reports them — never the address. Failed attempts are counted for up to 24 hours under a keyed fingerprint of the email typed, not the email, whether or not it belongs to an account. You can read the record in the cabinet, end every sign-in with "Sign out everywhere", and object by writing to us.

Email we send

We email you only about your account: a sign-in code when you ask for one; a notice when a password is set, changed or removed; and a notice when the account is signed in to from a device it has not seen in 90 days. That notice names the browser, the operating system, the kind of device and whether a code or the password was used. No marketing email is sent.

Where it is kept

The server stands in Finland, inside the European Economic Area, on hardware rented from Hetzner Online GmbH. Email from this site — sign-in codes and account notices — is delivered through Google Workspace, which hosts our mailbox; Google LLC is certified under the EU-US Data Privacy Framework. Nothing is sold, and nobody else receives any of it.

How long any of it is kept

WhatKept
Your account — address, password hash, marked wells, accepted version of the termsuntil you delete it
Calculation and document lines400 days
The record of sign-ins90 days
A sign-in30 days unused
Counted events and visits400 days; then day totals only, for 10 years
Your answer to the cookie notice1,100 days
Web-server log90 days

Deleting an account removes everything under it from the database at once.

Your choice, and what you may ask for

  • change your mind at any time — "Change what is counted", at the foot of every page
  • have everything recorded under your number deleted, in one press, from the same place
  • ask what is held under your number, and be given a copy of it
  • have it corrected if it is wrong, or its use paused while a question about it is open
  • object to it being counted at all — which is the same press as refusing
  • take a copy away in a form a machine can read
  • complain to a supervisory authority where you live, without asking us first
  • see everything kept under an account, in the cabinet itself
  • delete an account, its address and everything under it, in one press from the same place

Change what is counted

A browser that sends Global Privacy Control or Do Not Track is treated as a refusal: nothing is set, nothing is counted, and the notice is not shown at all.

Who is asking

Write to hello@pallarium.com, the address of Pallarium (not yet incorporated — operated by its founder).

The policy in full

Version 24 September 2026

1. Definitions and Interpretation

1.1 In this Policy the following terms have the following meanings:

  • "Account" means a user account on the Service, identified by an email address.
  • "Account Data" means the email address of an Account; the password verifier of the Account, where a password has been set; the dates on which the Account was created and last used; the version of the Terms accepted for the Account and the time of acceptance; and the Starred Items of the Account.
  • "Activity Records" means the records kept under an Account of each calculation run, each Saved Calculation created, amended or deleted, and each document generated, comprising the time, the calculation type and the document type, together with: (a) for a calculation run on an entry of the Well Library, the name of that entry; (b) for a calculation run on values entered by the Authorised User or read from a Local File, a fixed label that contains no value entered or read; and (c) for a Saved Calculation, an identifier of the Saved Calculation only.
  • "Applicable Data Protection Law" means all laws and regulations relating to the processing of Personal Data that apply to the Company's processing under this Policy, including, where applicable, the GDPR, the UK GDPR, Directive 2002/58/EC as implemented in the Member States of the European Economic Area, the Privacy and Electronic Communications (EC Directive) Regulations 2003 of the United Kingdom, the California Consumer Privacy Act of 2018 as amended ("CCPA"), and the Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 "On Personal Data and their Protection" ("Kazakhstan Law").
  • "Authorised User" means a natural person who accesses the Service through an Account.
  • "Billing Data" means the name, company name, billing address, tax identification number and payment records required to issue invoices and account for payments under a paid plan.
  • "Business Contact Data" means the name, employer, job title and business contact details of a representative of a customer, prospective customer, supplier or other business counterparty of the Company.
  • "Company", "we", "us" and "our" mean Pallarium, a prototype service run before incorporation by its founder, and, before its incorporation, the person identified in Section 3.5.
  • "Compliance Data" means the Personal Data processed for compliance with Trade Control Laws, as described in Section 5.14.
  • "Consent Notice" means the notice displayed on the Site by which a Visitor accepts or refuses Usage Measurement.
  • "Consent Record" means the record of a choice made on the Consent Notice, or of an act relating to an Account listed in Section 5.7, comprising the choice or act, the version of the notice or of the Terms concerned, the time, the environment of the Service in which it was made and, where Usage Measurement was accepted, the Visitor Identifier.
  • "Contact Email" means [CONTACT EMAIL = hello@pallarium.com].
  • "Cookie Policy" means the Company's cookie policy published on the Site.
  • "Correspondence Data" means the content and metadata of messages sent to or received from the Contact Email or any other mailbox of the Company.
  • "Customer" means the natural or legal person on whose behalf an Authorised User uses the Service, including an individual acting in a business or professional capacity on his or her own behalf.
  • "Customer Content" has the meaning given in the Terms, and includes Saved Calculations.
  • "Directory Data" means the information concerning suppliers held by the Company for the supplier directory of the Service, comprising their names, the categories of goods and services and the roles attributed to them, their regions of activity, the locations of their headquarters, their website domains, their brand names, descriptions of them and extracts of their published materials.
  • "DPA" means the Company's Data Processing Addendum published on the Site.
  • "GDPR" means Regulation (EU) 2016/679.
  • "Local Data" means data entered into, loaded into or generated by the Service within the browser of a User that has not been stored in the Service by use of the Save Function, including the contents of Local Files, the values of input fields, calculation results and documents generated in the browser.
  • "Local File" means a file that a User selects for reading by the Service within the User's browser.
  • "Measurement Data" means the data collected by Usage Measurement, as described in Annex A.
  • "Non-Public Environment" means any working copy, testing or pre-release instance of the Service and any administrative interface of it, whether or not protected by a password.
  • "Personal Data" means any information relating to an identified or identifiable natural person, and includes "personal information" and "personal data" as defined in Applicable Data Protection Law.
  • "Public Data" means data obtained from public registers, publications and other publicly available sources and included in the Service, including the Well Library and reference data.
  • "Retention Schedule" means the Company's retention schedule published on the Site.
  • "Sanctions Policy" means the Company's Sanctions and Export Compliance Policy published on the Site.
  • "Save Function" means the function of the Service by which an Authorised User stores a calculation in the Service.
  • "Saved Calculation" means the input values, results and document parameters of a calculation stored by an Authorised User by use of the Save Function, together with any well, field or file label stored with them.
  • "Security Data" means: the records of sign-ins to an Account, comprising the time, the method, the browser, operating system and device class as reported by the browser, and the country associated with the Truncated IP Address of the sign-in; hashed identifiers of browsers from which an Account has been accessed; hashed session identifiers; records of sign-in codes issued, comprising the email address to which the code was issued, a hash of the code, a hash of the requesting browser's identifier, the time and the number of attempts; and counters of code requests, failed attempts and notices, held under keyed hashes of email addresses or under Account identifiers.
  • "Server Log Data" means (a) web-server access log entries comprising the time, the requested address, the response status and size, the referring address, the user-agent string of the request and a Truncated IP Address; and (b) web-server error log entries generated where a request produces an error or is rejected by a rate limit, which may contain the full IP address of the request.
  • "Service" means the online service made available by the Company at the Site and at any Non-Public Environment, including its calculations, documents, supplier directory, Accounts, Saved Calculations and Service Communications, and any associated support.
  • "Service Communications" means emails sent by the Service to the email address of an Account or to an email address entered for sign-in, namely sign-in codes, notices of sign-in from a browser or device not previously used with the Account, and notices of the setting, change or removal of a password.
  • "Site" means the website at pallarium.com, its subdomains and any successor or additional domain operated by the Company for the Service.
  • "Starred Items" means the entries of the Well Library that an Authorised User marks for later use, recorded with their names.
  • "Subprocessor List" means the Company's list of subprocessors published on the Site.
  • "Terms" means the Company's Master Terms of Service published on the Site.
  • "Test Account" means an Account issued by the Company for testing or demonstration whose email address is on a domain of the Company.
  • "Tester Data" means the name, employer, job title, country of residence or jurisdiction, registration number, postal address, email address, signature and date recorded on a confidentiality undertaking or other document signed by or for a person who tests the Service, and the names of the permitted users recorded on it.
  • "Trade Control Laws" means "Sanctions" and "Export Control Laws" as defined in the Terms.
  • "Truncated IP Address" means an IP address from which, before it is recorded, the last octet (IPv4) or the last sixty-four bits (IPv6) have been removed.
  • "Usage Measurement" means the measurement of the use of the Service carried out by the Company after a Visitor accepts it on the Consent Notice.
  • "User" means any Visitor or Authorised User.
  • "Visitor" means any natural person who accesses the Site or the Service.
  • "Visitor Identifier" means the random identifier generated in the browser of a Visitor who has accepted Usage Measurement.
  • "Well Library" means the collection of representative field and basin entries, and the parameters associated with them, made available through the Service.

1.2 Headings are for convenience only. "Including" and similar words do not limit the words that precede them. References to a statute or regulation are to it as amended, consolidated or replaced from time to time. The singular includes the plural and vice versa.

1.3 Relationship with the Terms. Where the Terms refer to "Account Data", that term comprises the Account Data, Security Data and Activity Records described in this Policy. Where the Terms refer to "Usage Data", that term comprises, to the extent that they contain Personal Data, the Measurement Data, Server Log Data, Consent Records and service fault records described in this Policy. The processing of each is governed by this Policy in accordance with Section 2.3(b) of the Terms.

2. Scope and Status of this Policy

2.1 This Policy describes the processing of Personal Data by the Company as controller in connection with the Site and the Service.

2.2 This Policy does not govern the processing of Personal Data contained in Customer Content, which the Company processes as processor on behalf of the Customer under the DPA. Section 11 sets out how requests concerning Customer Content are handled.

2.3 This Policy does not apply to websites, services or data of any third party, including suppliers named in the supplier directory.

2.4 This Policy provides the information required by Articles 13 and 14 of the GDPR and by the corresponding provisions of Applicable Data Protection Law. It is incorporated into the Terms solely for the purpose stated in Section 2.2 of the Terms. Neither this Policy nor the acceptance of the Terms constitutes consent to any processing; where the Company relies on consent, consent is requested separately. Save to the extent that the Terms give it effect between the Company and the Customer, this Policy creates no contractual right or obligation and no right in favour of any person other than the rights conferred by Applicable Data Protection Law.

2.5 Where Applicable Data Protection Law requires information in addition to that set out in Sections 3 to 17, Section 18 sets out that information for the relevant jurisdiction.

3. Controller and Contact

3.1 The controller of the Personal Data described in this Policy is the Company.

3.2 All communications concerning this Policy and all requests under Section 15 shall be sent to the Contact Email.

3.3 No representative has been appointed under Article 27 of the GDPR or of the UK GDPR. One is appointed before visitors are counted or an account is opened for a person in the Union or in the United Kingdom.

3.4 The Company has not designated a data protection officer.

3.5 Until Pallarium is incorporated, the controller is the founder of Pallarium, acting for the company to be incorporated. On incorporation, Pallarium becomes the controller, and Authorised Users are informed in accordance with Section 20.2.

4. Roles of the Company

4.1 The Company acts as controller in respect of Account Data, Security Data, Activity Records, Measurement Data, Consent Records, Server Log Data, service fault records, Service Communications, Correspondence Data, Business Contact Data, Tester Data, Billing Data, Compliance Data, Directory Data and Public Data.

4.2 The Company acts as processor on behalf of the Customer in respect of Personal Data contained in Customer Content that the Company processes in the provision of the Service, including in Saved Calculations, and processes it only in accordance with the DPA. The Customer is the controller of that Personal Data. Where the Company processes that Personal Data to establish, exercise or defend legal claims or to investigate a breach of the Terms, it acts as controller of that processing, as provided in the DPA.

4.3 Save as described in Section 5.3 (Activity Records) and in Annex A (Usage Measurement), the Company does not receive Local Data. Local Files are read within the User's browser and are not transmitted to the Company; no name or value contained in a Local File is transmitted to the Company unless it forms part of a Saved Calculation. Input values, results and document parameters are transmitted to the Company only when an Authorised User stores them by use of the Save Function, at which point they become Customer Content.

4.4 In respect of a Test Account, the Company is the Customer and is controller of any Personal Data contained in the Customer Content stored under it. The DPA does not apply to a Test Account.

5. Categories of Personal Data and Sources

5.1 Account Data is provided by the Authorised User when opening and using an Account, and generated by the Service.

5.1A Application Data is provided by the person applying for an Account: the full name of the individual who will hold it, the company for which it is held, a telephone number and a company email address. It is provided once, at the application, and is kept with the Account. It is processed to decide whether an Account may be opened at all, which includes the screening required by the Sanctions and Export Compliance Policy, and to reach the applicant about that decision. The Company also records the decision itself, the person who took it, the date and the reason. The legal bases are Article 6(1)(b) — the steps taken at the request of the person before entering into the agreement — and Article 6(1)(c) together with Article 6(1)(f), for the screening and the record of it.

5.2 Security Data is generated by the Service when an email address is entered for sign-in, when a sign-in code is requested or used, when a password is set, changed, removed or used, and when an Account is accessed. The description of the browser, operating system and device class is derived from information that the browser transmits with each request. The country associated with the Truncated IP Address of a sign-in is determined on the Company's server from an offline table, is recorded with the sign-in and is used to detect sign-ins from unfamiliar browsers or locations. That country is not displayed in the Account or in any Service Communication.

5.3 Activity Records are generated by the Service when an Authorised User runs a calculation, creates, amends or deletes a Saved Calculation, or generates a document under an Account. An Activity Record does not contain any value entered by the Authorised User, any name or value read from a Local File, or any content of a Saved Calculation.

5.4 Customer Content is provided by the Authorised User by use of the Save Function.

5.5 Measurement Data is collected from the Visitor's browser after the Visitor accepts Usage Measurement, and comprises the data described in Annex A. Measurement Data does not include values typed into the calculation forms, the contents of Local Files or documents generated by the Service.

5.6 Service fault records are generated by the Service when a request is rejected or a Service Communication cannot be delivered, and comprise the reason and a sample of the rejected input, in which any email address is reduced to its domain.

5.7 Consent Records are generated when a Visitor makes, changes or withdraws a choice on the Consent Notice, and when an Account is opened, the Terms are accepted, a password is set, changed or removed, or an Account is deleted.

5.8 Server Log Data is generated by the web server for every request received by the Site or the Service, whether or not Usage Measurement is accepted.

5.9 Service Communications are generated by the Service and comprise the recipient email address and the content of the message.

5.10 Correspondence Data is provided by the sender of a message.

5.11 Business Contact Data is provided by the person concerned or by his or her employer, or obtained from business cards, correspondence, events and publicly available professional sources.

5.12 Tester Data is provided by the person concerned, or by the organisation for which he or she acts, on a signed document.

5.13 Billing Data will be provided by the Customer when a paid plan is purchased. Payment card data is entered directly with the payment service provider named in the Subprocessor List and is not received by the Company.

5.14 Compliance Data comprises the names, email addresses and email domains, employers, positions and locations of Authorised Users and of other persons acting for a Customer; the name, registration number, address and country of the Customer; information on the persons who own or control the Customer; the country associated with the Truncated IP Address of a request; information identifying the persons to whom results, documents or Saved Calculations of the Service are made available and the locations of the wells, fields and projects concerned; documents provided under the Sanctions Policy; the results of screening against lists of restricted persons published by public authorities; and records of decisions and communications under the Sanctions Policy. Compliance Data is provided by the Customer or the person concerned, including in answer to requests made under the Sanctions Policy; is generated by screening; and is derived from Truncated IP Addresses. Information on persons who own or control a Customer, and on persons acting for it, is provided by the Customer.

5.15 Directory Data is obtained from the suppliers' own publicly available websites and materials. Public Data is obtained from public registers and publications. Directory Data and Public Data concern organisations; they may incidentally contain the names of natural persons where these appear in the underlying public source.

5.16 The Company does not collect, and Users shall not submit to the Service, special categories of personal data within the meaning of Article 9 of the GDPR, personal data relating to criminal convictions and offences, government identification numbers, payment card data, precise geolocation data, biometric data, or the Personal Data of children.

6.1 The Company processes Personal Data for the following purposes and on the following legal bases under Article 6(1) of the GDPR (and the corresponding provisions of the UK GDPR):

CategoryPurposesLegal basis
Account DataOpening and maintaining an Account; authenticating Authorised Users; recording acceptance of the Terms; providing the Starred Items, the history of Activity Records and the Saved Calculations of the Account; communicating about the AccountPerformance of a contract, Art. 6(1)(b); recording of acceptance: legitimate interest in establishing, exercising and defending legal claims, Art. 6(1)(f)
Security DataProtecting Accounts against unauthorised access; detecting sign-ins from unfamiliar browsers or locations; limiting abuse of sign-in codes and mailbox flooding; informing Authorised Users of sign-ins and password changes; investigating incidentsLegitimate interest in the security of the Service and of Accounts, Art. 6(1)(f)
Activity RecordsDisplaying the history of an Account; applying plan limits and metering use under a paid plan; operating, maintaining and improving the Service; statisticsPerformance of a contract, Art. 6(1)(b); operation and improvement: legitimate interest in operating and improving the Service, Art. 6(1)(f)
Customer ContentStoring and making available Saved Calculations to the CustomerProcessed as processor on the Customer's instructions (Section 4.2)
Measurement DataMeasuring how the Service is used; improving the Service; statisticsConsent, Art. 6(1)(a)
Consent RecordsDemonstrating that consent was obtained or refused and that the Terms were acceptedLegal obligation, Art. 6(1)(c) and Art. 7(1); legitimate interest in demonstrating compliance and in establishing, exercising and defending legal claims, Art. 6(1)(f)
Server Log Data and service fault recordsDelivering the Site and the Service; maintaining availability, integrity and security; detecting and preventing attacks and abuse; diagnosing faults; counting requests that do not reach Usage MeasurementLegitimate interest in operating and securing the Site and the Service, Art. 6(1)(f)
Service CommunicationsDelivering sign-in codes and security noticesPerformance of a contract, Art. 6(1)(b); security notices: legitimate interest in the security of Accounts, Art. 6(1)(f)
Correspondence DataAnswering enquiries; handling requests under Section 15; support; record of communicationsLegitimate interest in responding to and recording communications, Art. 6(1)(f); requests under the GDPR or the UK GDPR: legal obligation, Art. 6(1)(c)
Business Contact DataManaging business relationships; offering and supplying the Service to businesses; eventsLegitimate interest in conducting business with other businesses, Art. 6(1)(f); consent where Applicable Data Protection Law requires it for electronic marketing, Art. 6(1)(a)
Tester DataConcluding and enforcing confidentiality undertakings; administering testingPerformance of a contract, Art. 6(1)(b); legitimate interest in protecting confidential information and in establishing, exercising and defending legal claims, Art. 6(1)(f)
Billing DataInvoicing; collection of payments; accounting and tax compliancePerformance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c), subject to Section 6.2
Compliance DataScreening against lists of restricted persons; verifying the location of access and of use; restricting, suspending or refusing the Service; responding to and reporting to competent authorities; keeping records, in each case as provided in the Sanctions PolicyObligations under the law of the European Union or of a Member State: legal obligation, Art. 6(1)(c); obligations under other law to which the Company is subject: legitimate interest in complying with that law and in not being exposed to penalties under it, Art. 6(1)(f)
Directory Data and Public DataProviding the supplier directory, the Well Library and reference dataLegitimate interest in providing a technical reference service to businesses, Art. 6(1)(f)

6.2 Article 6(1)(c) of the GDPR is relied on only for obligations laid down by the law of the European Union or of a Member State (and, under the UK GDPR, by the law of the United Kingdom). Where the Company complies with an obligation laid down by other law to which it is subject, it relies on its legitimate interest in complying with that law, Art. 6(1)(f).

6.3 In addition, the Company may process any category of Personal Data where necessary to comply with a legal obligation (Section 6.2); to establish, exercise or defend legal claims, to enforce the Terms and to prevent fraud, misuse and unlawful activity (Art. 6(1)(f)); and in connection with a merger, acquisition, financing, reorganisation or sale of all or part of the Company's business, including the assumption of the Service by Pallarium on its incorporation (Art. 6(1)(f)).

6.4 The Company does not use Personal Data for advertising, does not sell Personal Data, does not share Personal Data for cross-context behavioural advertising, and does not use Personal Data to train machine-learning or artificial-intelligence models.

6.5 The Company may create aggregated or de-identified information that does not identify any natural person, Customer or well and may use it for any lawful purpose. Such information is not Personal Data.

7. Provision of Personal Data

7.1 An email address is required to open and use an Account. Without it, no Account can be opened; the parts of the Service that do not require an Account remain available.

7.2 Acceptance of Usage Measurement is optional. Refusal has no effect on the availability of the Service.

7.3 Billing Data is required to purchase a paid plan.

7.4 Compliance Data requested under the Sanctions Policy is required to obtain or continue to receive the Service. Where it is not provided, the Service may be refused, suspended or restricted.

7.5 All other Personal Data is provided at the User's discretion.

8. Service Communications and Other Communications

8.1 The Service sends Service Communications only. Service Communications are necessary for the operation and security of Accounts and cannot be switched off while the Account exists.

8.2 Service Communications do not contain hyperlinks.

8.3 The Company may send business communications concerning the Service to Business Contact Data where permitted by Applicable Data Protection Law. Every such communication identifies how to object, and an objection sent to the Contact Email is given effect without charge.

9. Cookies and Similar Technologies

9.1 The Site and the Service use cookies and browser storage as described in the Cookie Policy. Cookies used for Usage Measurement are set only after the Visitor accepts Usage Measurement. A browser that transmits a Global Privacy Control or Do Not Track signal is treated as having refused Usage Measurement.

9.2 No third party sets cookies, loads scripts or collects Personal Data on the Site or the Service. The Site and the Service do not permit third parties to collect Personal Data about a User's online activities over time and across different websites.

10. Recipients

10.1 The Company discloses Personal Data only to the following recipients:

(a) subprocessors that process Personal Data on the Company's behalf under contracts restricting them to the Company's instructions, as identified in the Subprocessor List;

(b) the Customer and its Authorised Users, in respect of Customer Content, Activity Records and Account Data of Accounts that the Customer controls;

(c) professional advisers, auditors and insurers bound by duties of confidentiality;

(d) courts, law-enforcement authorities, regulators and other public authorities, including authorities competent under Trade Control Laws, and parties to legal proceedings, where disclosure is required by law or is necessary to establish, exercise or defend legal claims or to protect the rights, property or safety of the Company, its Users or others; as to Personal Data of persons in the European Economic Area or the United Kingdom, subject to Chapter V of the GDPR or the UK GDPR, including Article 48;

(e) any actual or prospective acquirer, successor, investor or financing party in connection with a transaction referred to in Section 6.3, subject to confidentiality obligations; and

(f) any other person with the consent or at the direction of the data subject.

10.2 Personnel of the Company have access to Personal Data only to the extent necessary for their duties and are bound by confidentiality obligations.

11. Customer Content and Requests Concerning It

11.1 The Company does not determine the purposes of processing of Personal Data contained in Customer Content. The Customer is responsible for the lawfulness of that processing, for providing any notices and obtaining any consents required, and for responding to requests of data subjects.

11.2 A request concerning Personal Data contained in Customer Content is forwarded to the Customer. The Company does not respond to such a request except to identify the Customer or as the Customer instructs, unless required by law.

12. Location of Processing and International Transfers

12.1 The Service is hosted on servers located in Finland, within the European Economic Area. Customer Content, Account Data, Security Data, Activity Records, Measurement Data, Consent Records, Server Log Data and service fault records are stored there. Encrypted copies of the production database are also held outside the production server, on equipment used exclusively by authorised personnel of the Company, located in the country the operator works from, for the period stated in Section 13.1.

12.2 The Company is established in the United States. Its personnel access Personal Data stored in Finland from the United States and from the country the founder works from. The Company applies the GDPR to its processing of the Personal Data of persons in the European Economic Area. [TRANSFER BASIS FOR THE COUNTRY WHERE THE FOUNDER WORKS, IF IT IS NOT IN THE EUROPEAN ECONOMIC AREA AND NOT SUBJECT TO AN ADEQUACY DECISION.]

12.3 Service Communications and Correspondence Data are processed through Google Workspace. Google LLC, a subprocessor of the Company, is established in the United States and has certified its adherence to the EU-U.S. Data Privacy Framework, which is the subject of Commission Implementing Decision (EU) 2023/1795 of 10 July 2023.

12.4 Where Personal Data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country that is not subject to an adequacy decision and no other transfer mechanism applies, the Company relies on the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 and, for the United Kingdom, the international data transfer addendum issued by the Information Commissioner. A copy of the relevant safeguards may be requested at the Contact Email.

12.5 Personal Data of persons located in the Republic of Kazakhstan is transferred and stored as set out in Section 18.4.

13. Retention

13.1 The Company retains Personal Data only for the periods set out in the Retention Schedule, which are summarised below.

CategoryRetention period
Account DataFor the life of the Account. The Company may delete an Account that has not been accessed for 730 days, after thirty (30) days' notice to its email address
Starred ItemsFor the life of the Account, or until unmarked
Customer ContentUntil deleted by the Authorised User, or until the Account is deleted; where access to it depends on a paid plan, thirty (30) days after the end of that plan, unless a plan giving access to it is again in force; where the Company closes an Account otherwise than at the Customer's request, thirty (30) days after closure, save as provided in the DPA
Activity Records400 days, or until the Account is deleted
Sign-in records90 days, or until the Account is deleted
Sign-in sessions30 days from last use and 90 days at most; ended on sign-out
Known-browser identifiers180 days, ten per Account; removed on "Sign out everywhere", on a password change (other than the current browser) and on deletion of the Account
Sign-in code records, including the email address1 hour after issue; the code is valid for 15 minutes; deleted earlier when used or superseded
Counters of requests, failed attempts and notices24 hours; failed password attempts 15 minutes
Measurement Data400 days; thereafter only daily totals that identify no person are kept, for up to 10 years
Consent Records1,100 days; the Visitor Identifier is removed on withdrawal of consent
Server Log Data — access log entries90 days
Server Log Data — error log entries14 days
Service fault records30 days
Correspondence Data and records of requests under Section 153 years from the last message or from the closure of the request
Business Contact Data3 years from the last contact
Tester Data5 years after the end of the evaluation period, or until the final resolution of any claim then pending; thereafter the signed document alone, without contact details not recorded on it, for as long as an obligation of confidentiality under it remains in force, reviewed at least every 5 years
Billing Dataseven years
Compliance Datafive years from the act to which it relates, or longer where a Trade Control Law requires
Copies of the production database14 days on the production server; 30 days for encrypted copies held outside it

13.2 Records whose period has ended are deleted by a routine that runs at least once every 24 hours, and in any case within 24 hours after the end of the period.

13.3 Deletion of an Account deletes the Account Data, Customer Content, Activity Records, Starred Items and Security Data of the Account from the production database at once. Copies of the production database are deleted when they expire in accordance with the Retention Schedule and are not restored except to recover the Service, in which case deleted Accounts are deleted again before the Service is resumed.

13.4 The Company may retain Personal Data beyond the periods stated where required by law, or where necessary to establish, exercise or defend legal claims, for the duration of that requirement or claim.

14. Security

14.1 The Company implements technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption of copies of the production database held outside the production server, restriction of access to authorised personnel, storage of passwords, sign-in codes and session identifiers in hashed form only, truncation of IP addresses in access logs, limitation of sign-in attempts, notification of new sign-ins, and regular backups.

14.2 No method of transmission or storage is completely secure. The Company does not warrant that Personal Data will be free from unauthorised access. Authorised Users are responsible for the security of their mailboxes, passwords and devices, and for ending sessions on shared devices.

14.3 In the event of a personal data breach, the Company notifies the competent supervisory authorities and affected data subjects where and as required by Applicable Data Protection Law, and notifies affected Customers in accordance with the DPA.

15. Your Rights

15.1 Subject to the conditions and exceptions of Applicable Data Protection Law, a data subject may request:

(a) confirmation of whether the Company processes Personal Data concerning him or her, and access to it;

(b) rectification of inaccurate Personal Data;

(c) erasure of Personal Data;

(d) restriction of processing;

(e) receipt of Personal Data that he or she has provided, in a structured, commonly used and machine-readable format, and its transmission to another controller;

(f) objection to processing based on legitimate interests, on grounds relating to his or her particular situation, and objection at any time to processing for direct marketing; and

(g) withdrawal of consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

15.2 Channel. Requests shall be made by email to the Contact Email. The Company designates the Contact Email as the channel for requests under this Section; to the extent permitted by Applicable Data Protection Law, a request sent by any other means is deemed received when it reaches the Contact Email.

15.3 Functions of the Service. Independently of any request, an Authorised User may view the Account's sign-ins, Activity Records, Starred Items and Saved Calculations, end all sessions, and delete the Account and everything stored under it, from within the Account; and any Visitor may change or withdraw a choice on the Consent Notice through the link displayed at the foot of every page of the Site, which deletes the Usage Measurement cookies and the Measurement Data recorded under the Visitor Identifier.

15.4 Verification. The Company verifies the identity of the requester before acting on a request. For Account Data, verification is by confirmation of control of the email address of the Account. The Company may request additional information where reasonable doubts exist, and may refuse to act until the identity is verified. A request made through an authorised agent requires written authorisation signed by the data subject and verification of the data subject's identity.

15.5 Time limits. The Company responds without undue delay and within one month of receipt of a verified request, which may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case the Company informs the requester within the first month. Where the CCPA applies, the Company responds within 45 days, extendable once by 45 days on notice.

15.6 Charges and refusal. Requests are handled free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Company may charge a reasonable fee taking into account the administrative costs, or refuse to act on the request.

15.7 Limits. The rights in Section 15.1 do not extend to Personal Data contained in Customer Content (Section 11), and are subject to the rights and freedoms of others, to legal obligations of the Company, including obligations under Trade Control Laws not to disclose certain information, and to the establishment, exercise or defence of legal claims. Where the Company declines to act on a request in whole or in part, it informs the requester of the reasons, save where the law prohibits it, and of the right to lodge a complaint.

15.8 Complaints. A data subject may lodge a complaint with the supervisory authority of the Member State of his or her habitual residence, place of work or place of the alleged infringement, or with the competent authority of his or her country.

16. Automated Decision-Making

16.1 The Company does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning a natural person or similarly significantly affect him or her, save that access to the Site or the Service may be restricted automatically by reference to the country associated with the network address of a request, where a Trade Control Law requires it. A person affected by such a restriction may request review by a person at the Contact Email, express his or her point of view and contest the restriction.

16.2 The calculations of the Service produce technical outputs concerning wells and equipment and do not evaluate natural persons.

17. Children

17.1 The Service is intended for use by businesses and by persons acting in a professional capacity. It is not directed to persons under 18 years of age, and Accounts may not be opened by them. The Company does not knowingly collect Personal Data of persons under 18. Where the Company becomes aware that it has collected such data, it deletes it.

18. Jurisdiction-Specific Provisions

18.1 European Economic Area

18.1.1 The Company is not established in the European Union. The GDPR applies to its processing of Personal Data of persons who are in the Union to the extent provided by Article 3(2) of the GDPR.

18.1.2 The Company's representative under Article 27 of the GDPR is identified in Section 3.3. A supervisory authority or data subject may address the representative in addition to or instead of the Company.

18.2 United Kingdom

18.2.1 Section 18.1 applies to persons in the United Kingdom, with references to the GDPR read as references to the UK GDPR. A complaint may be made to the Information Commissioner.

18.3 United States

18.3.1 California. The CCPA applies to a "business" as defined in Cal. Civ. Code § 1798.140(d). To the extent the CCPA applies to the Company:

(a) the categories of personal information collected in the preceding twelve months are identifiers (email address, online identifiers, Truncated IP Address), internet or other electronic network activity information (Server Log Data, Measurement Data, Activity Records, Security Data), approximate geolocation at country level derived from Truncated IP Addresses, professional or employment-related information (Business Contact Data, Tester Data, Compliance Data) and commercial information (Billing Data);

(b) the sources, purposes and retention periods are those set out in Sections 5, 6 and 13;

(c) personal information is disclosed for business purposes only to the recipients in Section 10;

(d) the Company does not sell or share personal information, does not use or disclose sensitive personal information for purposes that require a right to limit, and has not done so in the preceding twelve months;

(e) California residents have the rights to know, to delete and to correct personal information, and not to be discriminated against for exercising those rights, exercisable under Section 15; and

(f) the Company does not offer financial incentives relating to personal information.

18.3.2 Do Not Track and Global Privacy Control. The Site treats a Do Not Track or Global Privacy Control signal as a refusal of Usage Measurement, as stated in Section 9.1. No other party collects Personal Data about a User's online activities over time and across different websites when the User uses the Site or the Service.

18.3.3 Other states. Where a comprehensive consumer privacy law of another State of the United States applies to the Company, residents of that State may exercise the rights that law confers, including the right to appeal a refusal, by writing to the Contact Email. The Company responds to an appeal within the period that law allows and informs the requester of the means to contact the State Attorney General.

18.3.4 Federal. With respect to Personal Data, the Company is subject to the investigatory and enforcement powers of the United States Federal Trade Commission.

18.4 Republic of Kazakhstan

18.4.1 This Section applies where the Kazakhstan Law applies to the collection or processing of Personal Data of a data subject.

18.4.2 Consent. By opening an Account, or by signing a document on which Tester Data is recorded, the data subject gives consent to the collection and processing of his or her Personal Data on the following terms: operator — Pallarium, employer identification number none assigned before incorporation, or, before its incorporation, its founder (Section 3.5); no business identification number or individual identification number of the Republic of Kazakhstan has been assigned to the operator; list of data — the categories set out in Section 5 that relate to the data subject; purposes — those set out in Section 6; term — until the purposes are achieved or the consent is withdrawn, and in any case not longer than the periods in Section 13; transfer to third parties — to the recipients set out in Section 10, and to Pallarium on its incorporation; cross-border transfer — to Finland, to the United States, to the country the founder works from, to the country the operator works from and to the countries of the subprocessors in the Subprocessor List; dissemination in publicly accessible sources — none.

18.4.3 Storage. Personal Data is stored in databases located in Finland, as stated in Section 12.1. Paper documents are held by the Company in the country the founder works from.

18.4.4 Rights. The data subject has the rights conferred by Article 24 of the Kazakhstan Law, including to know of the processing and receive information about it, to require the amendment, blocking and destruction of Personal Data in the cases provided by law, and to withdraw consent. Requests are made under Section 15. On withdrawal of consent the Company ceases processing within fifteen working days, unless storage or processing is required by law, or provides a reasoned refusal.

18.4.5 Complaints. The data subject may appeal to the authorised body in the field of personal data protection of the Republic of Kazakhstan.

18.4.6 Responsible person. The person responsible for the organisation of the processing of Personal Data may be contacted at the Contact Email.

19. Third Parties

19.1 The pages of the Site and of the Service made available to Users, and the Service Communications, contain no hyperlinks to websites of third parties. The supplier directory does not display the website addresses or contact details of suppliers. The Company is not responsible for the processing of Personal Data by any third party with which a User communicates on his or her own initiative, including suppliers to which a User sends a document generated by the Service.

20. Changes to this Policy

20.1 The Company may amend this Policy at any time. The version and effective date appear at the top of this Policy.

20.2 Where an amendment materially changes the identity of the controller, the categories of Personal Data processed, the purposes, the recipients or the countries to which Personal Data is transferred, the Company publishes the amended Policy on the Site before it takes effect and informs Authorised Users by a notice in the Account or by email to the Account's email address.

20.3 Earlier versions of this Policy are available on request to the Contact Email.

21. Contact

21.1 Pallarium, hello@pallarium.com; before its incorporation, the founder of Pallarium. Contact Email: [CONTACT EMAIL = hello@pallarium.com].

Annex A — Usage Measurement

A.1 Usage Measurement operates only after acceptance on the Consent Notice and ceases on withdrawal. It records the events below under the Visitor Identifier and a random identifier for the visit.

EventData recorded
Page openedThe type of arrival (direct, search engine, other website, campaign tag in the address), desktop or phone, window width
Step openedThe step, and the seconds spent on the preceding step
Library tab openedThe region tab
Field chosen from the libraryThe Well Library identifier of the field and the region tab
Library search usedThe words typed into the search box, truncated at 40 characters, and the number of matching entries
Form value changedThe name of the input field and the number of changes — never the value entered
Calculation case changedThe case selected
Request for quotation openedThe step
Supplier selected in a requestThe directory identifier of the supplier, and whether selected or deselected
Request for quotation downloadedWhether downloaded, the step, and the number of suppliers selected
File of wells screenedThe stage reached (read, screened, opened, packaged) and the number of wells — never the contents of the file
Page leftThe furthest step reached, the proportion of the page scrolled, and the seconds spent
Techno-economic document downloadedThe calculation for which it was generated
Document requested without an AccountThe calculation to which it belongs

A.2 With each visit the following is also recorded: the date and time, and the local hour of the Visitor; the environment of the Service; whether the request appears to be automated; the host name of the referring website, without the rest of its address; campaign parameters present in the address; the language of the browser; the country associated with the Truncated IP Address, determined on the Company's server from an offline table; the browser, operating system and device class as reported by the browser; the screen and window size; and the time zone setting of the device.

A.3 Users shall not enter Personal Data into the library search box.