Twilight Drilling Privacy Policy and SMS Program Disclosures

Twilight Drilling Ltd., a Canadian company with a principal mailing address at PO Box 1025, Nisku AB T9E 0S7, Canada ("Twilight Drilling Ltd."), and Twilight Drilling US Inc., a United States company with a principal mailing address at 307 W. Pearl St #319, Granbury TX 76048, USA ("Twilight Drilling US Inc." and, together with Twilight Drilling Ltd., "Twilight Drilling," "we," "our," or "us"), provide this Privacy Policy to explain how we collect, use, disclose, retain, and protect personal information and what rights may be available to individuals in Canada and the United States, including California. "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identifiable individual or household, and includes "Sensitive Personal Information" as described in this Privacy Policy. This Privacy Policy applies to our public-facing website at www.twilightdrilling.com (the "Website"), to our "Twilight Drilling Alerts" SMS program (the "SMS Program"), to our human resources and payroll operations, and to other business interactions with us.

 

By visiting or using the Website, submitting the Website contact form, participating in the SMS Program, or working with or for Twilight Drilling, you acknowledge this Privacy Policy. Employees and job applicants are provided this Privacy Policy through onboarding and human resources communications. This Privacy Policy should be read together with our Terms of Service available at www.twilightdrilling.com. The current version of this Privacy Policy is posted at https://www.twilightdrilling.com/privacy-policy and replaces any prior version on that page as of [?] (the "Effective Date"). All privacy requests should be submitted through the Contact Us page at https://www.twilightdrilling.com/contact-us.

 

1. Who We Are and What This Policy Covers.  Twilight Drilling is an oil and gas drilling contractor operating in Canada and the United States. Our operations include drilling and related field services, human resources and payroll administration, safety and compliance programs, and maintenance of the Website, which includes a public contact form for inquiries.

 

This Privacy Policy covers the following audiences:

(a) employees and job applicants (together, "Personnel");

(b) contractors and business contacts, including customers, vendors, and visitors to our sites ("Business Contacts");

(c) visitors and users of the Website ("Website Users"); and

(d) participants in the Twilight Drilling Alerts SMS Program ("SMS Participants").

This Privacy Policy covers the following channels and systems we use to process Personal Information: Microsoft Office 365 for email and files ("Microsoft 365"), Workhub (safety and compliance), Aprio (U.S. payroll and benefits), QuickBooks/Intuit (Canadian payroll and accounting), Oil Country Computers (IT services and managed service provider), Telus Business Connect (SMS services), and our Website and hosting provider(s) [?].

 

Data may be processed and stored in Canada and the United States. We do not currently process or store Personal Information in other countries.

 

2. Categories of Personal Information We Collect.

2.1. Employees and Job Applicants.  We collect the following Personal Information from Personnel, which may include Sensitive Personal Information:

(a) Identifiers: name, home address, phone number(s), email address(es), date of birth, and emergency contact details.

(b) Government identification: Social Insurance Number (SIN) or Social Security Number (SSN), driver’s license number and other work eligibility documentation.

(c) Employment information: job title, department, work location(s), work schedules, timesheets, payroll and benefits elections, compensation details, and performance and disciplinary records.

(d) Background screening (as applicable): criminal background checks, references, and driving records/abstracts.

(e) Safety and health compliance: drug and alcohol testing results, health and safety incident reports, training records, and certifications.

(f) Information technology and communications: company account credentials, device and network logs, and usage metadata associated with email, Microsoft Teams, Workhub, and related systems.

Sensitive Personal Information for Personnel may include government identifiers (SIN/SSN), background checks, drug and alcohol testing results, and health and safety incident data.

 

2.2. Contractors and Business Contacts.  We collect the following Personal Information from Business Contacts:

(a) Identifiers and professional details: name, company name, job title, role, and business contact details.

(b) Communications and preferences: inquiries, correspondence records, and records of SMS opt-ins and opt-outs (where applicable).

 

2.3. Website Visitors.  We collect the following Personal Information from Website Users:

(a) Contact form submissions: name, email, phone number, and the contents of messages you submit.

(b) Technical data: internet protocol (IP) address, device and browser information, server logs, and strictly necessary cookies required for site functionality and security. We do not currently use analytics or advertising technologies.

 

2.4. SMS Participants ("Twilight Drilling Alerts").  We collect the following Personal Information from SMS Participants:

(a) Mobile phone number, message content, timestamps, delivery status, and records of consent and opt-in.

(b) Opt-out and help interactions (e.g., STOP and HELP requests).

Sensitive Personal Information in the SMS Program is generally not collected or required. If a message contains Sensitive Personal Information that you submit, we will handle it in accordance with this Privacy Policy.

 

3. Sources of Personal Information.  We collect Personal Information from the following sources:

(a) Directly from individuals: onboarding forms, timesheets, HR and payroll documents, Website contact forms, and SMS Program opt-ins and communications.

(b) Automatically: server logs, device and network telemetry, and SMS metadata (such as timestamps and delivery status).

(c) Third parties and service providers: background check vendors (if engaged), payroll and benefits platforms (Aprio, QuickBooks/Intuit), safety platform (Workhub), IT/MSP (Oil Country Computers), Microsoft 365, Telus Business Connect for SMS, and our Website hosting provider(s) [?].

(d) Public sources: where applicable, driver abstract agencies and licensing databases. Generally, public sources are not used unless required for safety or compliance.

 

4. Why We Use Personal Information (Purposes of Processing).  We use Personal Information for the following purposes:

(a) Employment and HR administration: recruiting and hiring, onboarding, payroll and benefits administration, scheduling and timesheets, performance management and discipline, and general HR operations.

(b) Safety and compliance: drug and alcohol testing (as permitted by law and policy), incident reporting, occupational health and safety (OHS/OSHA) compliance, training and certification management, and site access control.

(c) Operations and service delivery: project management, vendor and customer communications, and provisioning of services to clients.

(d) Security and integrity: fraud prevention, access controls, audit logs, network and information security, and incident detection and response.

(e) Legal and regulatory obligations: tax and employment law compliance, responding to lawful requests, and recordkeeping.

(f) SMS Program: sending operational and transactional messages such as reminders, notifications, and safety alerts. We do not send marketing messages via the SMS Program.

(g) Website and contact form: responding to inquiries, maintaining site functionality and security. We do not use advertising or analytics tracking under current practice.

 

5. Legal Bases/Consent Frameworks.

5.1. Canada (PIPEDA and Alberta PIPA).  We collect, use, and disclose Personal Information for purposes that a reasonable person would consider appropriate in the circumstances, including employment and operations. We rely on consent where required (which may be express or implied depending on context and sensitivity) and may rely on other lawful bases under applicable law, including where collection, use, or disclosure is authorized or required by law. For Sensitive Personal Information such as SIN/SSN, background checks, drug and alcohol testing results, and health and safety incident data, we collect and use such information only as necessary for employment, safety, and legal compliance purposes and provide appropriate notice and obtain consent consistent with employment and privacy laws.

 

5.2. United States (General).  We collect, use, and disclose Personal Information for legitimate business purposes, compliance with legal obligations, protection of our operations and security, and other purposes described in this Privacy Policy.

 

5.3. California (CCPA/CPRA).  For California residents, including Personnel, contractors, and consumers/business contacts, we identify the categories of Personal Information we collect, the sources, purposes, and categories of recipients in this Privacy Policy and Section 20. We limit the use of Sensitive Personal Information to necessary purposes such as employment, safety, and legal compliance. Rights available under the CCPA/CPRA are described in Section 12.

 

6. Cookies, Tracking, and Online Technologies.  We currently deploy only strictly necessary cookies and technical logs needed for Website functionality and security. We do not use analytics tools (such as Google Analytics), advertising cookies, or tracking pixels for cross-context behavioral advertising.

 

If we implement analytics or advertising technologies in the future, we will update this Privacy Policy and our cookie disclosures and provide appropriate choices.

 

We recognize applicable browser-based opt-out signals such as Global Privacy Control ("GPC") for "Do Not Sell or Share" preferences as described in Section 12.

 

7. Sharing and Disclosure of Personal Information.  We disclose Personal Information as follows:

(a) Service providers (acting on our behalf): Microsoft 365 (email/files), Workhub (safety/compliance), Aprio (U.S. payroll/benefits), QuickBooks/Intuit (Canadian payroll/accounting), Oil Country Computers (IT/MSP), Telus Business Connect (SMS transport), and our Website hosting and related infrastructure provider(s) [?]. We contractually require service providers to use Personal Information only to perform services for us and to protect it appropriately.

(b) Affiliates: Twilight Drilling Ltd. (Canada) and Twilight Drilling US Inc. (USA) may share Personal Information within the corporate group for the purposes described in this Privacy Policy.

(c) Legal and compliance: courts, regulators, law enforcement, and other parties where we believe disclosure is required or appropriate to comply with law, respond to lawful requests, protect rights, safety, or property, or enforce our terms.

(d) Corporate transactions: in connection with a merger, acquisition, financing, insolvency, reorganization, or asset sale, subject to continued protection of Personal Information or notice of material changes.

(e) SMS consent disclosure: SMS consent is not shared with third parties.

(f) Sale/Share for targeted advertising: We do not sell Personal Information and do not "share" Personal Information for cross-context behavioral advertising. Nonetheless, we provide a "Do Not Sell or Share My Personal Information" mechanism to satisfy CPRA requirements at [Insert Do Not Sell/Share Link], and we honor GPC signals where required.

 

8. Cross-Border Transfers.  Personal Information may be transferred between Canada and the United States, including to service providers such as Aprio, Microsoft 365, Telus Business Connect, and QuickBooks/Intuit. Personal Information may be accessible to governmental or regulatory authorities in those jurisdictions pursuant to lawful process. We do not currently transfer Personal Information to other countries. If our cross-border practices change, we will update this Privacy Policy.

 

For Canadian residents, you may contact us through https://www.twilightdrilling.com/contact-us with questions about cross-border processing and the safeguards we use with service providers.

 

9. Retention of Personal Information.  We retain Personal Information only as long as necessary to fulfill the purposes described in this Privacy Policy, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Subject to applicable law and any legal holds:

(a) Payroll, tax, and core HR records: typically retained for 7 years after the applicable tax year or the termination of employment, whichever is later.

(b) Safety and incident records: retained at least for legal minimums under OHS/OSHA; generally 5 to 10 years depending on record type and local requirements.

(c) Background check results: for non-hired candidates, typically 2 to 3 years; for hired employees, retain summary/consent for applicable legal minimums (e.g., 2 to 7 years) and then delete results.

(d) Timesheets and scheduling: at least 3 to 4 years, aligned to Alberta Employment Standards and U.S. Fair Labor Standards Act (FLSA).

(e) Access logs and IT telemetry: typically 12 to 24 months unless needed longer for security investigations or legal compliance.

(f) SMS consent records and logs: at least 4 years from the last message for compliance and audit purposes.

If a legal hold applies, we retain relevant records until the hold is lifted.

 

10. Security.  We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the Personal Information we process, including role-based access controls, least-privilege permissions, encryption in transit and at rest where supported by our vendors, multi-factor authentication for key systems, employee training, vendor due diligence, logging and monitoring, and incident response procedures. We comply with applicable breach notification laws in Canada and the United States and will notify affected individuals and regulators as required.

 

11. Your Privacy Rights – Canada.  For residents of Canada, subject to applicable law (including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the Alberta Personal Information Protection Act (PIPA)):

(a) You may request access to your Personal Information and information about our handling of it.

(b) You may request correction of inaccurate or incomplete Personal Information.

(c) Where consent is the basis for processing, you may withdraw consent, subject to legal and contractual restrictions and reasonable notice.

(d) You may challenge our compliance with applicable privacy laws and ask about cross-border transfers.

How to exercise your rights: submit requests through https://www.twilightdrilling.com/contact-us. We will take steps to verify your identity and relationship to us before responding. We generally respond within 30 days, subject to permitted extensions.

 

Escalation: If you are not satisfied, you may contact the Office of the Information and Privacy Commissioner of Alberta (https://oipc.ab.ca) or the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) for guidance or to file a complaint.

 

Employment context: Certain records (e.g., legal privilege, investigations, safety records) may be restricted by law. Some Personal Information is necessary for employment and safety compliance; withdrawal of consent may limit our ability to employ or engage you.

 

12. Your Privacy Rights – California (CCPA/CPRA).  Covered individuals: This section applies to California residents, including Personnel, contractors, and consumers/business contacts.

 

Your rights, subject to exceptions:

(a) Right to know/access: You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties to whom we disclose Personal Information.

(b) Right to delete: You may request deletion of Personal Information we collected from you, subject to legal exceptions.

(c) Right to correct: You may request correction of inaccurate Personal Information.

(d) Right to opt out of sale or sharing: We do not sell Personal Information or share it for cross-context behavioral advertising. We nonetheless provide an opt-out mechanism at [Insert Do Not Sell/Share Link] and honor GPC signals where required.

(e) Right to limit use/disclosure of Sensitive Personal Information: We limit the use of Sensitive Personal Information to necessary purposes such as employment, safety, and legal compliance. We do not use Sensitive Personal Information to infer characteristics for marketing.

(f) Non-discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

How to submit requests: Use https://www.twilightdrilling.com/contact-us. We will verify your identity and residency, and may request additional information to process your request. You may authorize an agent to submit a request on your behalf; we may require proof of authorization and verification of your identity. We will respond within 45 days of receipt, extendable once by an additional 45 days where reasonably necessary with notice.

 

Annual reporting: If we meet applicable CPRA thresholds in the future, we will publish required request metrics or provide a link to such metrics on our Website.

 

13. Other U.S. State Rights (If Applicable).  If other state privacy laws (for example, Virginia, Colorado, Connecticut, Utah) apply to our operations or to you, we will honor comparable rights available under those laws, including rights to access, delete, correct, obtain a copy, and opt out of certain processing where applicable. Where a mandatory appeals process applies, you may submit an appeal within 45 days of our decision by using https://www.twilightdrilling.com/contact-us and indicating "Privacy Rights Appeal" in your request.

 

14. Employee and Applicant Privacy Notice (Employment-Specific Disclosures).  This section consolidates disclosures specific to Personnel and applicants:

(a) Data collected: SIN/SSN; driver’s license and other work eligibility documentation; background check results (as applicable); drug and alcohol testing results; health and safety incident data; timesheets and scheduling information; benefits selections; emergency contacts; and other HR records.

(b) Purposes: HR administration, payroll and benefits, scheduling and operations, safety and compliance, performance management and discipline, and legal and regulatory compliance.

(c) Sharing: payroll and benefits processors (Aprio/QuickBooks/Intuit), safety platform (Workhub), IT/MSP (Oil Country Computers), Microsoft 365, and regulators or authorities as required by law.

(d) Monitoring and access: We may monitor and access company devices, accounts, and networks for legitimate business purposes, security, and compliance, consistent with local law and our policies. Usage metadata (e.g., email, Teams, and Workhub logs) may be collected.

(e) Sensitive data handling: Access to Sensitive Personal Information is restricted to a need-to-know basis and is not used for marketing and is not sold or shared for cross-context behavioral advertising.

(f) Retention: See Section 9 for default retention benchmarks applicable to Personnel records.

(g) Rights and contacts: See Sections 11 and 12 for Canada and California rights. Submit requests through https://www.twilightdrilling.com/contact-us.

 

15. "Twilight Drilling Alerts" SMS Program Disclosures.  Program name: "Twilight Drilling Alerts."

(a) Message types: operational and transactional messages only (e.g., reminders, notifications, safety alerts). No marketing messages.

(b) Numbers used: messages are sent via Telus Business Connect using registered 10DLC long codes and/or toll-free numbers. We do not use short codes.

(c) Consent and enrollment: enrollment occurs through employment onboarding forms, Website forms, or written consents where offered. We maintain records of consent, opt-ins, and opt-outs. SMS consent is not shared with third parties.

(d) Message frequency: message frequency may vary.

(e) Costs: message and data rates may apply.

(f) Opt-out instructions: Text "STOP" to cancel.

(g) Help instructions: Text "HELP" or visit www.twilightdrilling.com.

(h) Carriers disclaimer: Carriers are not liable for delayed or undelivered messages.

(i) Privacy link: https://www.twilightdrilling.com/privacy-policy.

(j) Terms link: www.twilightdrilling.com (Terms of Service).

(k) Program changes/termination: We may modify or terminate the SMS Program at any time, with notice where required by law or carrier rules.

(l) Compliance: We endeavor to comply with applicable U.S. Telephone Consumer Protection Act (TCPA) and CTIA guidelines and with Canada’s Anti-Spam Legislation (CASL). We maintain SMS consent and program logs for at least 4 years.

 

16. Children’s Privacy.  Our services are not directed to children. We do not knowingly collect Personal Information from children under 13 (United States) or under 16 (California) without appropriate consent as required by law. If we learn that we have collected Personal Information from a child in violation of applicable law, we will delete it and take appropriate remedial measures. Parents or guardians who believe we have collected such information should contact us via https://www.twilightdrilling.com/contact-us.

 

17. Third-Party Links and Websites.  The Website may contain links to third-party websites or services that we do not control. We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of those sites and services.

 

18. Changes to This Policy.  We may update this Privacy Policy from time to time. We will post the updated version with a new Effective Date at https://www.twilightdrilling.com/privacy-policy. For material changes, we will provide additional notice through the Website, the SMS Program, or HR communications, as appropriate. Please review this Privacy Policy periodically.

 

19. How to Contact Us and Exercise Your Rights.  All privacy requests, questions, and communications should be submitted through https://www.twilightdrilling.com/contact-us. We do not maintain a separate privacy email or phone number for rights requests.

 

Mailing addresses (for reference only; postal submissions are not required for rights requests unless requested by us during verification):

(a) Twilight Drilling Ltd., PO Box 1025, Nisku AB T9E 0S7, Canada

(b) Twilight Drilling US Inc., 307 W. Pearl St #319, Granbury TX 76048, USA

Information to include with requests: your full name, your relationship to Twilight Drilling (employee/applicant, contractor, business contact, Website visitor), your jurisdiction of residence, a description of your request, and any information we may reasonably need to verify your identity and relationship to us.

 

20. Jurisdiction-Specific Addenda (Optional if Drafter Prefers Modular Approach).

20.1. Canada Addendum (PIPEDA/Alberta PIPA).

(a) Consent types: We rely on express consent for Sensitive Personal Information and for uses beyond those a reasonable person would expect. We rely on implied consent for routine business communications and operations where appropriate. We may collect, use, or disclose Personal Information without consent where authorized or required by law.

(b) Cross-border information: We may transfer Personal Information to service providers in the United States for processing. Such information may be accessible to U.S. authorities under lawful process. We use contractual and organizational measures with service providers to protect Personal Information. Contact us via https://www.twilightdrilling.com/contact-us with questions about cross-border processing.

(c) Access and correction timelines: We generally respond to access and correction requests within 30 days, subject to permitted extensions where necessary due to complexity or volume. Fees may apply where authorized by law and will be disclosed in advance if applicable.

(d) Complaint routes: If unresolved, you may contact the Office of the Information and Privacy Commissioner of Alberta (https://oipc.ab.ca) or the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca).

 

20.2. California Addendum (CCPA/CPRA).

(a) Data category mapping: Depending on your relationship with us, we may collect identifiers (e.g., name, contact details, device identifiers); customer records information (e.g., account and billing information); protected classification information (where provided voluntarily or required by law); commercial information (transactional details with vendors/customers); internet or network activity (server logs, device/browser info); professional or employment-related information (job applications, HR records); education information (where provided in applications); geolocation (coarse IP-based only); audio/electronic information (voicemail or system logs); and Sensitive Personal Information (e.g., SIN/SSN, driver’s license, background screening, drug/alcohol testing, health/safety incident data). Sources, purposes, and disclosures are described in Sections 2 through 7. We do not sell Personal Information or share it for cross-context behavioral advertising.

(b) Do Not Sell or Share: Exercise opt-out preferences at [Insert Do Not Sell/Share Link]. We recognize GPC signals as an opt-out of sale/share to the extent required by law.

(c) Limit Sensitive Personal Information: We limit use and disclosure of Sensitive Personal Information to necessary purposes such as employment, safety, and legal compliance. If we offer additional choices in the future, we will provide a "Limit the Use of My Sensitive Personal Information" mechanism.

(d) Request methods and verification: Submit requests through https://www.twilightdrilling.com/contact-us. Provide sufficient information to verify your identity and residency. Authorized agents must provide proof of authorization and, where required, verification of the consumer’s identity.

(e) Metrics/reporting: If we meet CPRA thresholds, we will publish annual metrics regarding consumer requests and responses and provide a link on the Website.

 

20.3. Employee Notice Addendum.  Summary for California Personnel and applicants:

(a) Categories collected: identifiers (name, contact details, SIN/SSN), government IDs (driver’s license), employment and HR data (job history, timesheets, compensation, benefits), background checks (as applicable), safety and incident data, and IT logs/metadata.

(b) Purposes: HR operations, payroll/benefits, safety and compliance, scheduling, performance/discipline, security, and legal compliance.

(c) Disclosures: service providers (Aprio, QuickBooks/Intuit, Workhub, Microsoft 365, Oil Country Computers), affiliates, and regulators as required. We do not sell or share Personnel Personal Information for cross-context behavioral advertising.

(d) Sensitive Personal Information: limited to necessary purposes; not used to infer characteristics for marketing; not sold or shared.

(e) Rights: access/know, delete (subject to exceptions), correct, opt out of sale/share (we do not sell/share), limit use of Sensitive Personal Information (we already limit use to necessary purposes), and non-discrimination. Submit requests via https://www.twilightdrilling.com/contact-us. We honor GPC signals where applicable.