Last updated: May 31, 2026
Privacy Policy
This Privacy Policy explains what personal data we collect when you use oilgasalert.com, how we use it, and your rights under the EU General Data Protection Regulation (GDPR).
1. Data Controller
The service is operated by an independent professional based in Greece. Contact for privacy requests: .
2. Information We Collect
- Account data: email address, hashed password, account creation date, last login date.
- Usage data: your keywords, negative keywords, source subscriptions, saved favourites, digest preferences.
- Payment data: only an opaque customer ID and subscription status received from Polar. We never see your card number or full billing address — that is handled by Polar.
- Technical data: session cookie (login), IP address in server logs (rotated within 30 days), basic request metadata.
3. How We Use Your Data
- To send job match notifications (email digests) you opted into.
- To operate, authenticate, and secure your account.
- To process subscriptions (via Polar) and prevent abuse.
- To improve service quality (aggregate, non-identifying analytics only).
Legal basis (GDPR Art. 6): performance of contract (account & subscription), legitimate interest (security, abuse prevention), consent (email digests).
4. Third-Party Processors
We share strictly necessary data with:
- Polar Software Inc. (payment processing, Merchant of Record) — receives your email and subscription metadata. Polar Privacy Policy.
- Resend (transactional email delivery) — receives your email address and digest content. Resend Privacy.
- Cloudflare (DNS, CDN, basic edge protection) — processes connection metadata. Cloudflare Privacy.
- Hetzner Online GmbH (server hosting in Germany). Hetzner Privacy.
5. Data Retention
- Account & usage data: while the account is active, plus up to 30 days after deletion for technical reasons.
- Billing records: 10 years (Polar retains, per Greek tax/accounting law).
- Server logs: rotated within 30 days.
- Job listings (anonymous data, not personal): retained indefinitely as part of the public job-aggregation service.
6. Your GDPR Rights
You have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data (“right to be forgotten”);
- request data portability (export);
- object to or restrict certain processing;
- lodge a complaint with the Greek Data Protection Authority (dpa.gr).
To exercise any right, email from your account address. We respond within 30 days.
7. International Transfers
Polar Software Inc. is based in the United States. Data transferred to Polar is protected by Standard Contractual Clauses and Polar’s GDPR compliance commitments.
8. Cookies
See our Cookie Notice. In short: only an essential session cookie for login. No tracking, no third-party analytics.
9. Security
Passwords are stored hashed (bcrypt). All traffic is HTTPS. Database backups are kept for disaster recovery. No system is 100% secure; notify us immediately if you suspect unauthorised access.
10. Changes
We will notify you by email or in-app of material changes to this Policy at least 14 days before they take effect.