Privacy Policy
This Privacy Policy explains how GRAM Systems (trading name of Matthew Hudson), based at 43 Bromley Avenue, Monkseaton, Whitley Bay, Tyne and Wear, NE25 8TN, United Kingdom ("we", "us", or "our"), collects, processes, and protects personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Identity
The sole data controller for personal data collected through this website and during client onboarding consultations is:
| Data Controller | GRAM Systems (trading name of Matthew Hudson) |
| Principal Contact | Matthew Hudson |
| Registered Address | 43 Bromley Avenue, Monkseaton, Whitley Bay, Tyne and Wear, NE25 8TN, United Kingdom |
| info@gramsystems.co.uk | |
| Telephone (UK) | +44 (0)7918 174779 |
When clients utilize the Roger That! platform to record their operational data (e.g. equipment inspections, personnel sign-offs), the client organisation acts as the Data Controller, and GRAM Systems acts as a Data Processor carrying out processing strictly under the client's instructions.
2. Information We Collect
We collect personal data strictly necessary to communicate with you and provide our technical services:
- Enquiry & Demonstration Details: Name, work email address, company or operator name, fleet profile, and technical requirements provided via our contact form.
- Platform User Accounts: Business contact details (name, email, role, job title) provisioned by client organisations for authorized software access.
- Audit & Operational Records: User IDs and timestamps associated with technical task completions, checklist sign-offs, and report approvals within the software (required to maintain maritime audit traceability).
- Technical Server Logs: Standard IP addresses, browser user-agent headers, and request timestamps logged by our web servers to ensure system security and prevent abuse.
3. Lawful Bases for Processing (UK GDPR Art. 6)
We process personal data under the following recognized legal bases:
- Consent (Art. 6(1)(a)): When you voluntarily submit an operational enquiry or request a live demonstration via our website.
- Contractual Performance (Art. 6(1)(b)): To provision user accounts, provide customer support, and fulfill service agreements.
- Legitimate Interests (Art. 6(1)(f)): To maintain the security, stability, and audit non-repudiation of our software platform.
- Legal Obligation (Art. 6(1)(c)): To comply with applicable statutory accounting and tax record-keeping requirements in the United Kingdom.
4. How We Use Personal Data
Your personal data is used solely to:
- Respond to your technical enquiries and schedule platform walkthroughs.
- Authenticate authorized users and enforce role-based access permissions.
- Maintain immutable operational history logs for maintenance tasks and daily progress reports.
- Provide direct technical engineering support and incident resolution.
5. Data Storage & Security Standards
All central cloud platform databases and automated backups are hosted in certified, high-security data centres situated within the United Kingdom.
We implement comprehensive technical security controls, including TLS 1.3 encryption in transit, encrypted storage volumes at rest, strict least-privilege administrative access, and regular backup integrity verifications.
6. Absolute Rule: Zero Data Selling
We do not sell, rent, monetize, or trade personal data under any circumstances. We do not use marketing trackers or advertising networks. Personal data is disclosed only to vetted technical infrastructure providers (such as secure UK data centre hosts) strictly acting under written data processing agreements, or where required by law or valid court order.
7. Data Retention
Personal data is retained only for as long as necessary to satisfy the purpose for which it was collected, or as required by applicable UK law. Commercial enquiry records are retained for up to 24 months. Active client accounts and operational logs are retained for the duration of the commercial engagement and purged in accordance with our Data Retention Schedule following termination.
8. Your Statutory Rights under UK GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you (see our Subject Access Request Procedure).
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data where retention is no longer justified.
- Right to Restrict Processing: Request suspension of processing in certain circumstances.
- Right to Object: Object to processing carried out under legitimate interests.
To exercise any of these rights, contact Matthew Hudson at info@gramsystems.co.uk. We respond to all verified requests within one calendar month, free of charge.
10. Supervisory Authority & Complaints
You have the right to lodge a complaint with the UK data protection supervisory authority:
| Authority | Information Commissioner's Office (ICO) |
| Address | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
| Telephone | 0303 123 1113 |
| Website | ico.org.uk |