Data Protection Policy
This Policy defines the technical, operational, and physical security standards enforced by GRAM Systems (trading name of Matthew Hudson) to safeguard all client databases, operational maintenance records, and user data processed within the Roger That! platform.
1. Scope & Core Commitment
This policy applies to all operational equipment records, planned maintenance checklists, inventory databases, certification documents, and personal user data managed by GRAM Systems on behalf of client organisations.
Our primary commitment is to uphold data confidentiality, availability, and mathematical integrity. We design our software architecture to eliminate single points of failure and ensure all technical asset records remain verifiable and audit-ready.
2. Access Control & Authentication
Access to customer databases and software environments is governed by the principle of least privilege:
- Role-Based Access Control (RBAC): Users are granted granular permissions tailored to their operational responsibilities (e.g. Administrator, Technical Superintendent, Offshore Supervisor, Technician, Client Representative, Read-Only).
- Unique Credentials: Every operator and technician authenticates using individual credentials. Passwords are never stored in plaintext and are hashed using modern, salted cryptographic functions.
- Administrative Separation: Backend infrastructure maintenance requires encrypted SSH key authentication. Customer production databases are strictly isolated from development and staging environments.
3. Cryptographic Standards (Transit & Rest)
All data transmitted between web browsers, mobile tablets, vessel edge servers, and our central cloud platform is encrypted using modern Transport Layer Security (TLS 1.3) protocols. Insecure legacy protocols and ciphers are disabled at the server level.
Production database storage volumes, file attachment repositories, and automated snapshot archives are encrypted at rest using industry-standard AES-256 encryption.
4. Multi-Instance Database Isolation
GRAM Systems employs dedicated database architectures to prevent cross-tenant data contamination. Each commercial deployment operates on isolated PostgreSQL database instances with dedicated application credentials, preventing unintended cross-organisation data exposure.
5. Backup Strategy & Disaster Recovery
We operate under the operational motto: "Prevention is better than cure."
- Automated Daily Backups: Full transactional snapshots of all active databases are generated daily.
- Geographic Separation: Encrypted backup archives are replicated to secondary certified UK data centre facilities to protect against localized facility outages.
- Restore Verifications: Database restoration scripts and integrity checksums are tested periodically to guarantee rapid recovery in the event of an operational anomaly.
6. Vessel Edge Server Resilience
Offshore marine operations frequently experience satellite communication drops. When deployed to a vessel-local edge server, Roger That! operates as a completely autonomous, standalone relational instance.
Maintenance completions, stock adjustments, and Daily Progress Reports are recorded directly to local disk with full ACID transaction guarantees. Once connectivity is restored, records synchronize seamlessly back to the central corporate cloud.
7. Audit Trails & Non-Repudiation
To satisfy maritime, IMCA, and classification society requirements, Roger That! maintains immutable history trails for all critical actions:
- PM checklist completions, status updates, and supervisor approvals record the specific user ID and timestamp.
- Equipment service state transitions (e.g. In Service, Fault, Out of Service) are permanently logged.
- Statutory certification uploads and validity changes are linked to traceable user records.
8. Incident Response & ICO Notification
GRAM Systems maintains an active incident monitoring procedure. In the unlikely event of a security incident resulting in the unauthorized access, disclosure, or alteration of personal data:
- We will immediately contain the incident and initiate forensic analysis.
- Affected client organisations will be notified without undue delay following confirmation of the incident.
- Where required under UK GDPR Art. 33, notifications will be submitted to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach.