Skip to content

A product of FEEC

feec.asia

Legal

Data Processing Agreement

Version 1.0 · Effective 2026-09-22 · Last updated 2026-09-22

Status of this document

This is the standard data processing agreement (DPA) that accompanies a BarrierLedger engagement. It is published so it can be read before a conversation. Jurisdiction-specific legal review is outstanding and is required before the first pilot; a signed copy for your engagement is issued with your order form, and where the two differ the signed copy prevails.

1. Roles

You (the operator or licence holder) are the controller of the personal data in your registers and integrity records. FEEC is the processor. Where FEEC uses a sub-processor, that party acts under FEEC’s instructions and the terms in section 5.

2. What we process

  • Well, facility and register data, including wellbore, casing, cement, completion, barrier and annulus records.
  • Annulus pressure readings, fluid data and bleed-off records.
  • Well integrity test records and their evidence attachments.
  • Statuses, assessments, overrides, approvals and audit history.
  • Account data for your users: name, work email, role, and authentication events.
  • Personal data that happens to appear inside an engineering document, such as a name against a test sign-off.

3. What we do with it

We process your data only to provide the service, to support you, to keep the audit trail the product is built around, and to comply with law. We do not sell it, do not use it for advertising, do not use it to train models, and do not disclose it to another customer.

4. Where it is held

A live customer register is not held on the shared host. Depending on the hosting option in your order form, your data is held on an isolated dedicated server and database managed by FEEC, or inside your own infrastructure under a self-hosted licence. Backups are encrypted. The hosting option, backup retention and recovery expectations are recorded in the order form.

5. Sub-processors

The sub-processors engaged for a BarrierLedger engagement are listed on the Sub-processors page, with what each one does. We will tell you before a new sub-processor is engaged for your data, and you may object.

6. Security

Technical and organisational measures include: tenant isolation enforced in the database with row-level security; one-time codes at sign-in; role-based access; encryption of backups; and an assessment record that names who approved what and when. FEEC holds no certification for BarrierLedger and claims none.

7. Your obligations

You are responsible for the lawfulness of the data you give us, for the accuracy of the register, readings and limits, for your own regulatory submissions and official well records, and for the roles you assign to your users.

8. Assistance and rights

We help you answer data subject requests, and we pass on a request that reaches us directly. We assist with impact assessments and prior consultations where the law requires it.

9. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know: what happened, what data is involved, the likely consequences, and what we have done or propose to do. We keep a record of the breach and of the response.

10. Return and deletion

At the end of an engagement you can export everything, including the assessment history. On request we delete your data and confirm it in writing, subject to any legal retention obligation, which we will tell you about at the time.

11. Audit

You may ask for the information you need to satisfy yourself that we process your data as agreed. Where a visit is needed it is arranged in advance, at a reasonable time and cost, and under confidentiality.

12. Contact

There is no published BarrierLedger mailbox. Use the enquiry form or the FEEC contact page.