Privacy Policy
Last updated: January 21, 2026
1. Introduction
Rhino Intelligence Ltd ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our software platforms and related services, including the Oil and Gas Project Development Toolkit and any other products we offer.
We are registered in England and Wales with our registered office at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE. For the purposes of data protection law, we are the data controller.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, company name, job title, and password when you register
- Payment Information: Billing address and payment details (processed securely via Stripe)
- Project Data: Technical calculations, cost estimates, financial models, and project documentation you create
- Communications: Information you provide when contacting support or providing feedback
2.2 Information Collected Automatically
- Usage Data: Features used, calculation types, time spent, and interaction patterns
- Device Information: Browser type, operating system, IP address, and device identifiers
- Cookies: Session cookies for authentication and preference cookies (see our Cookie Policy)
3. How We Use Your Information
We use your information for the following purposes:
- Service Provision: To provide, maintain, and improve our platform
- Account Management: To create and manage your account and subscription
- Payment Processing: To process payments and manage billing
- Communication: To send service updates, security alerts, and support messages
- Analytics: To understand usage patterns and improve our services
- Legal Compliance: To comply with legal obligations and protect our rights
Legal Basis (GDPR): We process your data based on: (a) contract performance, (b) legitimate interests, (c) legal obligations, and (d) your consent where applicable.
4. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. For oil and gas project documentation, we maintain records for a minimum of 7 years in compliance with UK Continental Shelf (UKCS) regulations and industry standards.
After account closure, we retain certain data as required by law or for legitimate business purposes, including audit trails, financial records, and legal compliance documentation.
5. Data Sharing
We may share your information with:
- Service Providers: Stripe (payments), Resend (email), Railway (hosting), and analytics providers
- Team Members: Within your organisation if you use team features
- Legal Requirements: When required by law or to protect our rights
We do not sell your personal data or share it with third parties for marketing purposes.
6. International Data Transfers
Your data may be transferred to and processed in countries outside the UK/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO).
7. Your Rights (GDPR)
Under data protection law, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request restriction of processing
- Portability: Request transfer of your data in machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
8. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption of data in transit (TLS 1.3) and at rest
- Secure password hashing (bcrypt)
- Role-based access control (RBAC)
- Regular security assessments and monitoring
- Secure cloud infrastructure (Railway, PostgreSQL)
9. Children's Privacy
Our services are not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through our platform. Your continued use of our services after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related inquiries:
Data Protection Contact:
Rhino Intelligence Ltd
3rd Floor, 86-90 Paul Street
London, England, EC2A 4NE
Email: [email protected]
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.