Privacy Policy
Subsurface data is the most guarded asset our customers own. We treat personal data with the same seriousness. This policy explains what we collect, why, and what you can ask us to do about it.
Version 1.0 · Last updated 23 August 2026
Who we are
Greenstone Energy Ltd (“Greenstone”, “we”, “us”) is a technology company registered in England and Wales, company number 17151768. We build software for well operations, including the GeoMaster and MudMaster platforms.
We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR. Privacy questions are handled by our leadership team at the address above.
Our two roles: controller and processor
The law distinguishes between deciding why data is processed and simply handling it on someone else’s instructions. We do both, in different contexts, and your rights differ accordingly.
For our website, enquiries, marketing, and the account details of people who use our platforms. This policy governs that processing.
For operational well data our customers upload to GeoMaster and MudMaster. The operator or consultancy is the controller. That processing is governed by our Data Processing Agreement, not this policy.
If you are an employee of one of our customers and want to know how your employer uses the platform, please contact them directly. We will support any request they make of us under Article 28.
What we collect
From this website
If you complete the contact form we collect your name, work email address, company, enquiry type and message. Name, email and message are required; the rest are optional. If you email us directly we receive whatever you choose to put in that email.
Automatically, for security
Our hosting provider records your IP address, browser type and the pages requested. This is used to keep the site available and to block attacks. It is not used to build a profile of you and it is not shared for advertising.
From platform users
If your organisation licenses GeoMaster or MudMaster, we hold your name, work email, job role and records of when you signed in and what you accessed. Audit logging is a security control we owe to the operator whose data you are working with.
We do not collect special category data as defined in Article 9 — no health, biometric, racial or ethnic, political, religious, trade union or sexual orientation data. Please do not send it to us.
Why we process it, and our lawful basis
Every use of personal data needs a lawful basis under Article 6. Ours are set out below.
Responding to your enquiry
Legitimate interests · Art. 6(1)(f)Data: Name, work email, company, enquiry type, message
You contacted us and expect a reply. We assessed that this does not override your rights.
Providing GeoMaster and MudMaster
Contract · Art. 6(1)(b)Data: Account name, work email, job role, authentication records
Necessary to give you access to the platform your organisation has contracted for.
Keeping the platform and website secure
Legitimate interests · Art. 6(1)(f)Data: IP address, request logs, sign-in events
Protecting our service and our customers’ commercially sensitive well data.
Meeting our legal and accounting duties
Legal obligation · Art. 6(1)(c)Data: Contract records, invoices, correspondence
UK company, tax and statutory record-keeping requirements.
Product updates and marketing email
Consent · Art. 6(1)(a)Data: Name, work email
Only if you opt in. You can withdraw at any time, with no effect on prior processing.
Where we rely on legitimate interests we have carried out a balancing assessment. You can ask for a summary of it, and you can object at any time under Article 21.
International transfers
We prefer to keep data in the UK and EEA, and we offer UK and EU data residency options to platform customers.
Some of our providers are headquartered outside the UK, principally in the United States. Where personal data is transferred outside the UK we rely on one of the safeguards permitted by Articles 44 to 49: the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, or the ICO’s International Data Transfer Agreement or Addendum to the Standard Contractual Clauses, supported by a transfer risk assessment.
You can request details of the safeguards applying to any specific transfer.
How long we keep it
We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires.
When a retention period ends we delete the data or irreversibly anonymise it. Backups are overwritten on their own cycle and are not restored to reinstate deleted records.
Your rights
You have the following rights over your personal data.
Get a copy of the personal data we hold about you.
Have inaccurate or incomplete data corrected.
Have your data deleted where we have no overriding reason to keep it.
Ask us to pause processing while a dispute is resolved.
Receive data you gave us in a structured, machine-readable format.
Object to processing based on legitimate interests, or to direct marketing at any time.
Withdraw consent at any time, without affecting processing already carried out.
To exercise any of these, email privacy@greenstone.energy. We respond within one month as required by Article 12(3). If a request is complex we may extend by up to two further months and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive.
We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.
Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, so Article 22 does not apply.
GeoEngine, the intelligence layer inside our platforms, analyses well and drilling data and makes recommendations about subsurface operations. It does not profile people, evaluate employees, or make decisions about individuals. A qualified person remains responsible for every operational decision.
How we protect it
We apply the technical and organisational measures required by Article 32, including encryption in transit and at rest, role-based access control, multi-factor authentication for production access, and audit logging.
Our security overview sets out our controls in detail.
If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours as required by Article 33, and tell affected individuals without undue delay where Article 34 requires it.
Complaints
Please raise concerns with us first at privacy@greenstone.energy — we would rather put something right than have you go elsewhere.
You also have the right under Article 77 to complain to the supervisory authority at any time, without contacting us first.
Changes to this policy
We review this policy at least once a year and whenever we change how we handle personal data. The version number and date at the top of this page tell you which version you are reading.
If we make a change that materially affects you, we will tell you directly before it takes effect — we will not rely on you noticing an updated page.
Questions about your data?
Ask us anything about how we handle personal data, or request a copy of our Data Processing Agreement.