1. Introduction and Data Controller
This Privacy Policy describes how Hole Plan Ltd. ("HolePlan", "We", "Us", or "Our"), registered in the Republic of Bulgaria, collects, uses, discloses, and protects personal information when You use our website at www.holeplan.com (including Your HolePlan account area), the HolePlan™ desktop application, and the optional Cloud Sync service (collectively, the "Services").
We are committed to protecting Your privacy and complying with the EU General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and applicable Bulgarian data protection legislation. This Privacy Policy is a separate document from the HolePlan Terms and Conditions, although both together govern your relationship with Hole Plan Ltd.
Data Controller
- Company name: Hole Plan Ltd.
- UIC (ЕИК): 208659702
- VAT number: BG208659702
- Registered address: Mladost 2, Bl. 221, Ent. 1, Floor 9, Apt. 41, Sofia Municipality, Mladost District, Sofia 1799, Bulgaria
- Jurisdiction: Republic of Bulgaria
- Contact email: support@holeplan.com
- Website: www.holeplan.com
For all privacy-related enquiries, please contact us at support@holeplan.com or through the contact form at www.holeplan.com/contact. We respond to privacy requests without undue delay and at the latest within one month; for complex or numerous requests, this period may be extended as permitted by GDPR Article 12(3), in which case we will inform You of the extension.
2. Definitions
- "Personal Data": any information that identifies or can identify a natural person, directly or indirectly.
- "Processing": any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
- "Data Subject": the identified or identifiable natural person to whom personal data relates.
- "Processor": a party that processes personal data on behalf of the controller.
- "GDPR": EU General Data Protection Regulation (Regulation (EU) 2016/679).
- "Device ID": a persistent hardware-based device identifier derived from your device's security hardware, used to bind your licence to a specific device.
- "Cloud Sync": the optional feature of the HolePlan desktop application that, when enabled by You, synchronises Your project data to our cloud infrastructure and enables collaboration with other users.
- "Project Data": the project content that You create or manage in the Software, including, without limitation, drilling projects, sites, drill sites, holes, targets, survey data, planning profiles (trajectory, lithology, rod, and accessory profiles), and similar project content types that may be introduced in future versions of the Software.
4. How We Collect Information
- Directly from You — through registration forms, billing forms, contact forms, and subscription requests.
- Automatically — through the desktop application's licence verification, activity tracking, and (where enabled) Cloud Sync, and through technical scripts on the website.
- Through our authentication provider — which automatically records account creation timestamps, last sign-in times, and device metadata when You log in.
- Through third-party services — Google reCAPTCHA and ipinfo.io collect data through scripts loaded on our website (see Section 7).
5. How We Use Your Information
- Account management: to create, maintain, and authenticate Your user account.
- Licensing and device binding: to issue, validate, and manage Your software licence and associate it with Your registered device via the Device ID.
- Cloud Sync and collaboration: where You enable Cloud Sync, to store and synchronise Your Project Data across Your devices, and to share projects with the project members You designate.
- Billing and invoicing: to generate invoices, process subscription requests, and maintain financial records in accordance with applicable tax law.
- Product improvement: to analyse usage patterns, diagnose errors, and improve the reliability and features of the Software.
- Security and fraud prevention: to detect and prevent unauthorised use, account compromise, and abuse of the free trial.
- Customer support: to respond to support tickets and contact form enquiries.
- Service and relationship communications: to inform You about new features, fixed issues, and other changes relevant to Your use of the Software, and to check in with You about Your experience with the Services.
- Legal compliance: to comply with applicable laws, tax obligations, and regulatory requirements.
6. Legal Basis for Processing (GDPR)
- Contractual necessity (Art. 6(1)(b) GDPR): processing Your name, email, billing information, Device ID, and — where You enable Cloud Sync — Your Project Data and collaboration data, is necessary to provide You with the Services and fulfil our contractual obligations.
- Legitimate interests (Art. 6(1)(f) GDPR): processing activity logs, error reports, server request logs, and synchronisation diagnostics is carried out in our legitimate interest to improve the Software, ensure its security, and detect fraud. Sending service and relationship communications to existing customers, and processing contact and support data to respond to enquiries, are likewise based on our legitimate interest; You may object at any time.
- Consent (Art. 6(1)(a) GDPR): where we process personal data on the basis of Your consent, You may withdraw that consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR): retaining VAT numbers, billing records, and invoice data is required for compliance with applicable tax law.
Provision of account and billing data is a contractual requirement: without it, we are unable to create Your account, issue licences, or provide the Services. Provision of all other categories of data is optional, although some optional features (such as Cloud Sync) cannot function without the data they process.
7. Third-Party Service Providers
We use the following third-party service providers in connection with the Services. Where a provider processes personal data on our behalf, it is engaged under a data processing agreement as required by GDPR Article 28, committing it to process personal data only on our instructions and in accordance with GDPR. Providers marked as independent controllers process the relevant data under their own privacy policies, linked below.
Google Cloud Platform (Google LLC / Google Ireland Ltd.)
- Purpose: hosting of the HolePlan website, licensing services, and Cloud Sync infrastructure, including database storage of account, licensing, and (where enabled) Cloud Sync Project Data.
- Data processed: account data, licensing data, activity and error data, contact and support data, Cloud Sync Project Data and collaboration data.
- Location: European Union — Frankfurt, Germany (europe-west3).
- Privacy policy: https://cloud.google.com/terms/cloud-privacy-notice
Authentication (Google Identity Platform / Firebase Authentication, Google LLC)
- Purpose: user account creation, authentication, and management.
- Data processed: email address, display name, password hash, login timestamps, device metadata.
- Location: Central Europe (transfers, where applicable, are safeguarded by Standard Contractual Clauses).
- Privacy policy: https://firebase.google.com/support/privacy
Google Workspace / Gmail (Google LLC)
- Purpose: business email — sending and receiving support, account, and service correspondence.
- Data processed: name, email address, and the content of email correspondence.
- Location: EU and other Google data centre locations (Standard Contractual Clauses).
- Privacy policy: https://cloud.google.com/terms/cloud-privacy-notice
Google reCAPTCHA Enterprise (Google LLC)
- Purpose: bot detection and fraud prevention on forms (registration, password reset, contact).
- Data processed: IP address, browser signals, user interaction patterns.
- Location: United States (Standard Contractual Clauses).
- Privacy policy: https://policies.google.com/privacy
ipinfo.io
- Purpose: real-time IP geolocation to pre-populate billing country and phone dial code.
- Data processed: IP address (transmitted in real time; not stored by HolePlan).
- Role: independent controller — ipinfo.io processes the IP address under its own privacy policy.
- Location: United States.
- Privacy policy: https://ipinfo.io/privacy-policy
We do not sell, rent, or trade Your personal data to any third party for their own marketing purposes.
8. Data Sharing and Disclosure
We may share Your personal data in the following limited circumstances:
- With service providers listed in Section 7, strictly as necessary for them to perform their contracted services.
- At Your direction — when You enable Cloud Sync and add project members, the Project Data of the shared project, together with Your display name and email address, becomes visible to those members in accordance with the roles You assign. Likewise, when a project is shared with You, Your display name and email address become visible to the project owner and other members of that project.
- With professional advisers (lawyers, accountants, auditors) under confidentiality obligations.
- With law enforcement or regulatory authorities where required by applicable law or a valid legal order.
- In connection with a merger, acquisition, or sale of all or substantially all of our assets, provided the acquirer agrees to comply with this Privacy Policy.
Beyond the cases above, we do not share Your Project Data with any third party without Your express written consent. Our personnel access Your Project Data only where necessary for support, troubleshooting, or the operation of the Services, under confidentiality obligations and access controls.
9. Data Retention
We retain personal data for the periods set out below.
- Account data (name, email, display name): for the lifetime of Your account. Upon a verified deletion request, account data is deleted within 30 days, except where retention is required by law.
- Project Data stored via Cloud Sync: retained while stored in the cloud. Upon expiry of Your subscription or non-payment, Your access to cloud-stored Project Data is suspended; the data is retained so that it can be restored when You activate a new subscription, for a maximum of 24 months following expiry, after which it is permanently deleted without further notice. Where a project has been shared, its cloud data is not deleted while project members with active subscriptions retain access; the retention period runs from the end of such access. Cloud-stored Project Data is also permanently deleted earlier upon Your verified written request to support@holeplan.com.
- Backups: our cloud databases are protected by automated encrypted backups. Data removed or deleted from live systems may persist in backups for up to 30 additional days before being overwritten in the normal backup rotation.
- Billing data (address, VAT number, invoices): for a minimum of 10 years following the last transaction, as required by Bulgarian accounting and tax legislation.
- Activity logs (usage events, Device ID, session identifiers): rolling 24-month window. Logs older than 24 months are automatically deleted.
- Error reports (technical traces, email, Device ID): rolling 12-month window. Error reports older than 12 months are automatically deleted.
- Synchronisation diagnostics (rejected operations): up to 30 days from the date of the rejected operation.
- Contact and support data (contact form submissions, support tickets, email correspondence): 12 months from the resolution of the enquiry.
- Server request logs: up to 30 days.
- IP geolocation data: not retained — real-time lookup only.
10. Your Privacy Rights (GDPR)
To exercise any of these rights, please contact us at support@holeplan.com. We respond without undue delay and at the latest within one month of receiving Your request; for complex or numerous requests, this period may be extended as permitted by GDPR Article 12(3).
- Right of Access (Art. 15): You have the right to obtain confirmation of whether we process Your personal data and to receive a copy of the data we hold about You.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data. You may update most of Your profile information directly from Your account settings.
- Right to Erasure / "Right to be Forgotten" (Art. 17): You have the right to request deletion of Your personal data where it is no longer necessary for the purposes for which it was collected, or where You withdraw consent and there is no other legal basis for processing.
- Right to Restriction of Processing (Art. 18): You have the right to request that we restrict the processing of Your personal data in certain circumstances.
- Right to Data Portability (Art. 20): You have the right to receive Your personal data in a structured, commonly used, machine-readable format. Submit a data export request to support@holeplan.com.
- Right to Object (Art. 21): You have the right to object to processing of Your personal data where processing is based on our legitimate interests, including service and relationship communications. To stop receiving such communications, reply to the relevant email or contact us at support@holeplan.com. Transactional emails required to operate Your account (such as email verification and password reset) cannot be opted out of while You maintain an account.
- Right to Withdraw Consent (Art. 7(3)): where processing is based on consent, You may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Commission for Personal Data Protection of Bulgaria (www.cpdp.bg) or another supervisory authority in the EU member state of Your habitual residence, place of work, or the place of the alleged infringement.
Note for shared projects: where Your personal data (display name, email address) appears to other users because a project has been shared with You or by You, requests concerning that data can be addressed to us as described above.
Verification of requests: privacy requests, including deletion requests, must be submitted from the email address associated with Your account. We may request additional information where reasonably necessary to verify Your identity before acting on a request, in order to protect Your data from unauthorised access or deletion.
Effect on the Services: some processing is necessary to provide the Services. Where You request erasure or restriction of data that is required to operate Your account or deliver the Services, we may be unable to continue providing some or all of the Services to You. In such cases, the consequences for Your Subscription — including any termination and refunds — are governed by the Terms and Conditions, in particular the Cancellation and Refund Policy.
Users outside the EU: we apply the protections described in this Policy to all our users worldwide. If You are located outside the EU, You may also have rights under the data protection laws of Your jurisdiction; You may direct any such requests to us at support@holeplan.com.
11. International Data Transfers
Hole Plan Ltd. is based in Bulgaria, an EU member state, and Cloud Sync data is stored in the European Union (Frankfurt, Germany). Where our processors (Google) process limited technical data in the United States or other locations outside the EEA, those transfers are carried out under appropriate safeguards, including Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to GDPR Article 46. Data transmitted to ipinfo.io (see Section 7) is processed by ipinfo.io as an independent controller under its own privacy policy.
We take all reasonable steps to ensure that such transfers comply with applicable data protection law and that Your data receives equivalent protection. You may request a copy of the applicable transfer safeguards by contacting us at support@holeplan.com.
12. Cookies and Similar Technologies
Our website uses only cookies and similar technologies that are necessary for the operation of the Services. We do not use advertising, analytics, or session-recording cookies.
- Authentication (essential): session tokens and authentication state set by our authentication provider to keep You signed in. Duration: session / persistent. These cannot be disabled without losing the ability to sign in.
- Bot protection (essential): cookies set by Google reCAPTCHA Enterprise to distinguish human users from bots when submitting forms. Duration: session / up to 6 months.
The HolePlan desktop application does not use browser cookies. Activity tracking in the desktop application is described in Section 3.5 and operates as part of your licence agreement to verify lawful use and improve the Software.
13. Children's Privacy
The HolePlan Software and Services are designed for professional use in the exploration drilling, mining, oil and gas, and directional drilling industries. They are not intended for or directed at individuals under the age of 18. We do not knowingly collect personal data from individuals under 18. If We become aware that personal data has been collected from an individual under 18, We will take immediate steps to delete it. If You believe We have collected such data, please contact us at support@holeplan.com.
14. Data Security
Hole Plan Ltd. implements and maintains commercially reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. Measures include:
- Account authentication with email verification and secure password policies;
- Licence credentials protected using secure, industry-standard storage mechanisms on Your device;
- HTTPS/TLS encryption for all data in transit, including Cloud Sync traffic;
- Encryption at rest for cloud-stored data;
- Hardware-based device binding to prevent licence sharing;
- Logical separation of each customer's Cloud Sync data, enforced by per-user authorisation rules — users can only synchronise projects they own or that have been shared with them;
- Access controls limiting administrative access to personal data to authorised personnel only.
Personal data breaches are handled in accordance with GDPR Articles 33 and 34, including notification of the competent supervisory authority and, where applicable, of affected data subjects.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. The updated version will be posted on our website at www.holeplan.com/privacy-policy with a revised effective date and version number. For material changes, We will provide You with prominent notice in advance — such as by email or by an in-app notification — before the change takes effect. We encourage You to review this Policy periodically.