Privacy Policy
Last Updated: April 3, 2026
This Privacy Policy describes how Drillvisor ("Company", "we", "us", "our") collects, uses, and shares information about you when you use our website at drillvisor.com and related services (collectively, "Services").
We are registered in Switzerland (Rue du Petit Valentin, Lausanne, VD 1004). Our Services are hosted on Hetzner Online GmbH infrastructure in Germany and Finland (European Union). We comply with the EU General Data Protection Regulation (GDPR) and applicable Swiss data protection law (nDSG).
Please read this policy carefully. By using the Services, you acknowledge that you have read and understood this Privacy Policy.
1. Information we collect
Information you provide directly
We collect the following information when you register, use the Services, or contact us:
| Category | Details |
|---|---|
| Names | Your first and last name, provided at registration or via the Contact Sales form. |
| Email addresses | Used for account creation, authentication, and communications. |
| Phone numbers | Collected via the Contact Sales form only. Not required for platform registration. |
| Job titles | Collected at registration or via Contact Sales (e.g., Drilling Engineer, Drilling Supervisor). |
| Usernames | Your chosen username or display name within the platform. |
| Passwords | Stored as salted hashes. We never store or transmit plaintext passwords. |
| Authentication data | Session tokens and login activity used to secure your account. |
Information collected automatically
When you use the Services, we automatically collect certain technical information:
- IP address and approximate geographic location (country/city level)
- Browser type and version
- Device type and operating system
- Pages visited, features used, and session duration
- Referring URL
This information is collected via PostHog (EU instance, eu.posthog.com) and is subject to your cookie consent. PostHog analytics are not activated until you explicitly accept analytics cookies.
Uploaded content
When you use the platform, you may upload Daily Drilling Reports (DDRs) and related operational documents in PDF format. This content is stored securely on our servers and is used solely to provide the parsing and analytics features of the platform. It is not used to train machine learning models, shared with other users, or disclosed to third parties, except as described in Section 4.
2. How we use your information
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing and operating the Services | Performance of contract (Art. 6(1)(b)) |
| Account management and authentication | Performance of contract (Art. 6(1)(b)) |
| Responding to Contact Sales inquiries | Legitimate interest / pre-contractual steps (Art. 6(1)(b)(f)) |
| Sending service-related communications (billing, updates, security) | Performance of contract (Art. 6(1)(b)) |
| Product analytics to improve the platform (PostHog) | Consent (Art. 6(1)(a)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
We do not use your personal data for advertising, profiling for third parties, or automated decision-making that produces legal or similarly significant effects.
3. Data retention
- Account data: retained for the duration of your subscription, plus 30 days following account termination or deletion.
- Uploaded DDRs and extracted data: retained for the duration of your subscription, plus 30 days following termination. Trial account data is deleted 30 days after trial expiration if not converted to a paid subscription.
- Analytics data (PostHog): retained for 12 months.
- Contact Sales inquiries: retained for 12 months from the date of last contact.
- Billing records: retained for 10 years as required by Swiss accounting law.
After the applicable retention period, data is permanently deleted from our systems and backups within a reasonable timeframe.
4. How we share your information
We do not sell your personal data. We do not share personal data with advertising networks or data brokers. We share data only in the following limited circumstances:
Service providers (data processors)
| Provider | Purpose / Location |
|---|---|
| Hetzner Online GmbH | Cloud hosting infrastructure — Germany and Finland (EU) |
| PostHog Inc. | Product analytics — EU instance (eu.posthog.com), data processed in EU |
All service providers are bound by data processing agreements and are required to process data only as instructed by us and in compliance with applicable law.
Legal disclosure
We may disclose personal data if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, prevent fraud, or ensure user safety.
Business transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the acquiring entity. We will notify affected users in advance of any such transfer.
5. International data transfers
Our Services are hosted exclusively in the European Union (Germany and Finland via Hetzner Online GmbH). PostHog analytics data is processed on the EU instance (eu.posthog.com) and does not leave the EU.
Our company is registered in Switzerland, which the European Commission has recognized as providing an adequate level of data protection for GDPR purposes. No additional transfer mechanisms are required for data flows between the EU and Switzerland.
If you access the Services from outside the EU/EEA, your data will be transferred to and processed within the EU. By using the Services, you consent to this transfer.
6. Your data protection rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data, subject to legal retention obligations.
- Right to restriction: request that we restrict processing of your data in certain circumstances.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest.
- Right to withdraw consent: where processing is based on consent (e.g., analytics cookies, Format Improvement Program), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing.
To exercise any of these rights, you can: (1) log in to your account settings and update or delete your account, or (2) contact us at info@drillvisor.com. We will respond within 30 days.
If you are in the EU/EEA and believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority.
7. Account management
You may update your account information at any time by logging in to your account settings. You may request deletion of your account by logging in to your account settings or by contacting us at info@drillvisor.com.
Upon account deletion, your personal data will be retained for 30 days (to allow for recovery in case of accidental deletion), after which it will be permanently deleted. Billing records are excluded from deletion and retained as required by law.
8. Data security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Passwords stored as salted hashes (never plaintext)
- HTTPS encryption for all data in transit
- Access controls limiting employee access to personal data
- Regular security reviews of our infrastructure
- Data hosted exclusively on ISO 27001-certified Hetzner infrastructure in the EU
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to using industry-standard practices.
9. Uploaded DDR data - special provisions
Daily Drilling Reports and related operational documents uploaded to the platform may contain sensitive proprietary and commercial information. We treat this data with particular care:
- DDR data is used solely to provide the parsing and analytics features of the platform.
- DDR data is never shared with other users or organizations.
- DDR data is never used to train machine learning models without explicit opt-in consent via the Format Improvement Program.
- DDR data is never sold or disclosed to third parties except as required by law.
- DDR data is deleted 30 days after account termination or trial expiration.
You are solely responsible for ensuring you have the legal right to upload any DDR or related document. See Section 25 of our Terms of Use for full details.
10. Format Improvement Program
The Format Improvement Program is an optional feature allowing users to contribute anonymized structural metadata from uploaded DDRs (field names, layout patterns — never operational data) to improve parsing accuracy across the platform.
Participation is strictly opt-in. Consent is requested via an explicit modal on your first DDR upload. You may withdraw consent at any time from your account settings. Withdrawal is effective immediately for all future processing.
11. Children's privacy
The Services are intended for business users only and are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor without parental consent, we will delete it promptly.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address at least 14 days before the changes take effect. The updated date at the top of this document reflects when the policy was last revised.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated policy.
13. Contact us
For any questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact us:
Drillvisor — Data ControllerRue du Petit Valentin
Lausanne, VD 1004
Switzerland
info@drillvisor.com
© 2026 Drillvisor. All rights reserved.