Privacy policy
Version 1.0 · effective 2026-08-28 · controller: [COMPANY LEGAL NAME], org.nr [ORG NUMBER], [ADDRESS] — contact: [CONTACT EMAIL]
This page is short because we collect little. Ultimate QC is a
well-data quality-control service for professional drilling operations.
We do not run analytics trackers, advertising pixels, or third-party
scripts of any kind: every request your browser makes on this site goes
to this site.
What we collect, and why
- Account data — username, a salted password hash (never the
password), optional two-factor secrets (encrypted), sign-in times.
Legal basis: performance of the service contract.
- Access requests — the name, work email, and company you
submit when requesting access. Legal basis: taking steps prior to a
contract, at your request.
- Free sag-check leads — the email you leave to see your
result, plus the engineering inputs you typed. Legal basis:
legitimate interest (following up on a request you initiated);
write to us and we delete it.
- Audit log — which account viewed or changed which well
data, and when. Legal basis: legitimate interest — this service
exists to make drilling data trustworthy, and an access record is
part of that trust. Retained for the life of the instance.
- Well and survey data — trajectories, sensor readings and
related engineering data delivered by or for our customers. This is
customer data processed on the customer's instructions under the
service agreement, not data about private individuals.
Cookies
Only strictly necessary ones: a session cookie when you sign in, a
short-lived two-factor cookie during sign-in, an optional
trust-this-device cookie you explicitly tick, and a local theme
preference. No consent banner is shown because nothing requiring
consent is set.
Where data lives
On infrastructure operated by the controller for this instance,
within the EEA. Transport to your browser is TLS via Cloudflare, which
acts as a network processor for traffic. No personal data is sold or
shared with third parties for their own purposes.
Your rights
Under the GDPR you can request access, correction, deletion, or
export of your personal data, and object to processing based on
legitimate interest — write to [CONTACT EMAIL]. You can complain to
Datatilsynet (the Norwegian Data Protection Authority). We answer
requests within 30 days.
Security, in one paragraph. Passwords are
scrypt-hashed; two-factor authentication is available on every account;
stored third-party credentials are encrypted at rest; every read and
write of well data is audited; private wells are invisible to other
accounts down to the event stream. Report security issues to
[CONTACT EMAIL] — we read those first.