Legal
Privacy Policy
How we collect, use, disclose, and protect personal information — including the captures, scenes, location data, and customer records that tenant businesses upload to run their operations on Updrone. This notice covers our role as a controller of our own account data and as a processor of the customer records our tenants hold.
Last updated August 28, 2026· Version 2026-08-28
1. Introduction and scope
This Privacy Policy (this “Policy”) describes how Updrone, Inc. (“Updrone,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information. It applies to our marketing website, the Updrone customer portal, our mobile applications, our APIs and capture clients, the hosted pages we render on a tenant’s behalf, and the communications we send in connection with them (collectively, the “Service”).
Throughout this Policy, a “tenant” is a business that licenses Updrone to run its operations, an “authorized user” is a person a tenant grants access to its workspace, and an “end customer” is a person or organization that the tenant serves and whose records the tenant maintains in the Service. “Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular individual or household, and includes “personal data” as that term is used under European and United Kingdom law.
Updrone licenses software. The tenant is the professional of record for its own flights, pilots, airspace authorization, insurance, accuracy sign-off, and regulatory compliance. We display and process the information tenants and their end customers provide — we do not fly, pilot, certify, or authorize anything. That division of responsibility determines who is accountable for the personal information in the Service, which Section 2 sets out.
This Policy does not apply to the practices of third parties we do not control, including the independent websites, applications, and services a tenant may link to or integrate with. Where a tenant uses the Service to communicate with its own end customers, the tenant’s own privacy notice governs that relationship, and this Policy governs only what Updrone does as that tenant’s service provider.
2. Our two roles: controller and processor
Which privacy obligations apply to Updrone — and where you should direct a request — depends on which of two roles we occupy for the information in question. The distinction is legal, not rhetorical, and it runs through the rest of this Policy.
We act in one of the following two capacities:
- Controller (or “business”). For the information we collect to run Updrone as a company — account registration details, authorized-user profiles, billing and subscription records, support correspondence, marketing-site visitors, and product telemetry and diagnostics — Updrone determines the purposes and means of processing and is the controller. Sections 3 through 10 and Sections 15 through 17 describe that processing, and you may exercise your rights with us directly.
- Processor (or “service provider”). For the personal information a tenant puts into its workspace about its own end customers — contact records, job and project files, imagery and scenes of a property, scheduling, proposals, invoices, and messages — the tenant is the controller and Updrone is its processor. We process that information only on the tenant’s documented instructions and to provide, secure, support, and maintain the Service. Our Data Processing Addendum (/dpa) governs that processing and forms part of our agreement with the tenant.
If you are an end customer of a business that uses Updrone and you want to access, correct, delete, or object to the processing of your information, that business is the controller and holds the relationship with you. Direct your request to that business. If you send it to us, we will, where we are legally permitted to do so, forward it to the relevant tenant and support them in responding rather than acting on it unilaterally — acting on a controller's records without instruction would itself be an unauthorized disclosure.
Where Updrone is a processor, we do not use tenant data for our own purposes, do not combine it with data from other sources for our own purposes, and do not disclose it outside the direct business relationship except as this Policy and the Data Processing Addendum permit.
3. Categories of personal information we collect
The table below sets out the categories of personal information we collect, the sources we collect them from, the purposes we use them for, the categories of recipients we disclose them to, and how long we keep them. The category labels correspond to those enumerated in the California Consumer Privacy Act, as amended (Cal. Civ. Code § 1798.140(v)), so that this disclosure can be read directly against the statute. Not every category applies to every individual — what we hold about you depends on how you interact with the Service.
| Category | Examples | Sources | Purposes | Recipients | Retention |
|---|---|---|---|---|---|
| Identifiers | Name, email address, postal address, phone number, account ID, tenant/workspace ID, IP address, device identifiers. | You; your employer or the tenant that invited you; your device; single sign-on providers you choose to use. | Creating and authenticating accounts; provisioning workspace access; transactional and service messaging; support; fraud prevention and security. | Cloud hosting and storage providers; email delivery provider; payment processor; professional advisors; authorities where legally compelled. | For the life of the account, then deleted or de-identified within 90 days of closure, except records retained under Section 14. |
| Customer records and commercial information | Billing contact and address, subscription plan and history, invoices, payment metadata (amount, date, reference, last four digits and card brand), transaction and payout records. | You; our payment processor; the tenant whose workspace the record belongs to. | Billing and collections; tax, accounting, and audit obligations; dispute and chargeback handling; facilitating tenant payouts. | Payment processor; cloud hosting and storage providers; accounting and tax advisors; authorities where legally compelled. | Seven years from the transaction, to satisfy tax and accounting record-keeping obligations. |
| Precise and coarse geolocation | GPS coordinates of a capture and of the device during a mission; property addresses geocoded to coordinates; site and job locations; airspace-lookup coordinates. | Your device (with your operating-system permission); addresses you or a tenant enter; metadata embedded in imagery you upload. | Mission planning and flight logging; georeferencing captures and reconstructions; airspace-class and solar-resource lookups; measurement and deliverable generation. | Cloud compute and storage providers; mapping and solar-data providers (address or coordinates only); the tenant whose workspace the record belongs to. | For the life of the associated capture, project, or account record; deleted with the parent record. |
| Audio, visual, and sensor information | Photographs and video from a capture; 3D scenes, meshes, point clouds, and orthomosaics derived from them; optional voice notes recorded against a mission; profile photographs. | You and your authorized users; the tenant’s end customers where the tenant enables uploads; capture devices you connect. | Running the capture-processing pipeline; generating scenes, measurements, and deliverables; rendering the records the tenant relies on. | Cloud compute and object-storage providers; recipients the tenant chooses to share a scene or deliverable with. | For the life of the associated record or account; deleted with the parent record or on tenant deletion. |
| Internet and network activity | Pages and features used, referring site hostname, cookieless first-party page views (path, campaign tags we published, coarse device / browser / OS family), a daily-rotating anonymous visitor hash, approximate country / region / city as estimated by the hosting provider from the connection, session and request logs, processing-job status and timing, error and crash diagnostics. | Your device and browser automatically; our servers and first-party analytics. | Operating and securing the Service; measuring reliability and performance; diagnosing errors; understanding feature usage to prioritize development. | Cloud hosting providers; crash and diagnostics tooling. | Raw logs for up to 13 months; aggregated and de-identified metrics may be kept indefinitely. |
| Professional and employment information | Business name, job title or role, trade or vertical, team membership and permissions within a workspace. | You; the tenant that invited you. | Provisioning role-based access; configuring the product for your trade; support and account management. | Cloud hosting providers; the tenant that administers your workspace. | For the life of the account, then deleted or de-identified within 90 days of closure. |
| Account credentials and security data | Hashed passwords, multi-factor authentication enrollment, session tokens, sign-in and authorization events. | You; your single sign-on provider; our authentication systems. | Authenticating you; protecting accounts; detecting, investigating, and responding to unauthorized access. | Cloud hosting providers; security tooling. Never sold, shared, or disclosed for any other purpose. | Credentials for the life of the account; security event logs for up to 24 months. |
| Communications content | Support requests and correspondence, in-product messages, email and SMS a tenant sends through the Service to its own contacts, consent and opt-out records. | You; the tenant; the tenant’s end customers. | Delivering the requested communication; providing support; honoring opt-outs and suppression; demonstrating consent and compliance. | Email delivery provider; telecommunications carriers for SMS; cloud hosting providers. | Support correspondence for 24 months. Opt-out and suppression records are kept indefinitely — deleting them would cause us to contact someone who asked us not to. |
| Inferences | Aggregated product-usage patterns and derived reliability and performance metrics. | Derived from the categories above. | Operating and improving the Service; capacity planning; prioritizing development. | Not disclosed in identifiable form. | Kept in de-identified or aggregated form only. |
We do not knowingly collect personal information from categories we have no business need for. In particular, we do not collect government identification numbers, financial account numbers, health information, or information about race, religion, union membership, sexual orientation, or immigration status, and you should not submit them to the Service.
4. Sensitive personal information
Certain of the information described above is designated “sensitive personal information” under California law and “special category” or similarly protected data under other regimes. We collect the following and no more: precise geolocation, which is inherent to a capture platform and is used for mission planning, flight logging, georeferencing, and airspace and solar-resource lookups; account credentials and authentication data, which are used solely to sign you in and secure your account; and the contents of communications a tenant sends through the Service, which are used solely to deliver, support, and log those communications.
We use and disclose sensitive personal information only for the purposes permitted by Cal. Civ. Code § 1798.121(a) and 11 CCR § 7027(m) — performing the services requested, ensuring security and integrity, detecting and resisting malicious or fraudulent activity, and verifying and maintaining the quality and safety of the Service. We do not use or disclose it to infer characteristics about you.
BECAUSE WE DO NOT USE OR DISCLOSE SENSITIVE PERSONAL INFORMATION FOR ANY PURPOSE BEYOND THOSE PERMITTED BY LAW WITHOUT A SEPARATE PURPOSE-LIMITATION NOTICE, THE CALIFORNIA “RIGHT TO LIMIT THE USE OF MY SENSITIVE PERSONAL INFORMATION” DOES NOT APPLY TO OUR PROCESSING. WE STATE THIS AFFIRMATIVELY RATHER THAN BY OMISSION SO THAT THE BASIS FOR IT IS ON THE RECORD.
You can withdraw device location permission at any time in your operating-system settings, as described in Section 18. Doing so will disable the features that depend on it — mission planning relative to your position, in-flight tracking, and automatic georeferencing of a capture — but will not otherwise prevent you from using the Service.
5. Imagery, 3D reconstructions, and people or property depicted in a capture
A capture is a photograph or video of a real place, and a place may contain people, vehicles, addresses, and the interiors visible through an opening. The reconstruction we generate from it — a Gaussian splat scene, a photogrammetric mesh, a point cloud, an orthomosaic — carries whatever the source frames carried. We treat that material as capable of containing personal information and handle it accordingly.
What we do not do
We commit to the following, and these commitments are enforceable representations rather than aspirations:
- We do not derive, extract, generate, or store biometric identifiers or biometric information from imagery or reconstructions. We do not compute or retain scans of face geometry, hand geometry, iris or retina patterns, voiceprints, or gait, and we do not create a mathematical template from any of them.
- We do not perform facial recognition, face matching, face clustering, or any other operation intended to identify, verify, or track an individual person appearing in a capture.
- We do not use captures, scenes, or the people or property depicted in them to build profiles, to enrich records about individuals, or for advertising of any kind.
- We do not use one tenant’s captures to serve, benchmark, or enrich another tenant, and we do not disclose a capture outside the tenant’s workspace except as the tenant directs or as Section 8 permits.
- We do not sell captures or reconstructions, and we do not license them to data brokers, imagery aggregators, or model-training marketplaces.
Where responsibility sits
The tenant chooses what to photograph, when, from what altitude and vantage, and who receives the result. Accordingly, and as the Terms of Service (/terms) provide, the tenant is responsible for obtaining every right, permission, and consent required to capture, process, publish, and retain imagery of a person or of property — including any notice or consent required by state biometric, recording, eavesdropping, two-party consent, trespass, nuisance, or privacy statutes in the jurisdiction of the capture. Updrone hosts and processes what the tenant submits; it is not in a position to know whether a given consent was obtained, and it does not represent that it was.
If you believe you appear in, or your property appears in, a capture hosted on Updrone and you wish to have it addressed, contact us at support@updrone.com. Because the capture belongs to the tenant’s workspace and the tenant is its controller, we will identify and notify the relevant tenant and support them in responding, and we will act directly where the law requires us to.
6. How we use personal information, and our legal bases
We use personal information for the purposes described in Section 3. Where European Economic Area, United Kingdom, or Swiss law applies to our processing as a controller, we must also identify a lawful basis for each purpose under Article 6 of the General Data Protection Regulation. The following table does that.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service, authenticating accounts, running the capture and processing pipeline, and delivering the features you use. | Performance of a contract — Art. 6(1)(b). |
| Billing, collections, and maintaining tax and accounting records. | Performance of a contract — Art. 6(1)(b); and compliance with a legal obligation — Art. 6(1)(c). |
| Securing the Service, preventing fraud and abuse, and investigating incidents. | Legitimate interests in protecting the Service, our customers, and third parties — Art. 6(1)(f). |
| Product telemetry, reliability and performance measurement, and prioritizing development. | Legitimate interests in operating and improving a service our customers depend on — Art. 6(1)(f). |
| Transactional and service messages about your account, security, and the Service. | Performance of a contract — Art. 6(1)(b). |
| Marketing communications to prospective and existing business contacts. | Consent where required — Art. 6(1)(a); otherwise legitimate interests in business-to-business marketing, subject to an unconditional right to opt out — Art. 6(1)(f). |
| Responding to lawful requests, establishing or defending legal claims, and complying with applicable law. | Compliance with a legal obligation — Art. 6(1)(c); and legitimate interests in establishing, exercising, or defending legal claims — Art. 6(1)(f). |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your interests or fundamental rights and freedoms, and you may object to that processing as described in Section 16. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Where Updrone acts as a processor for a tenant, the lawful basis for that processing is the tenant’s to establish as controller, not ours.
7. Artificial intelligence features and automated processing
Parts of the Service use machine learning and generative models — for example, the in-product assistant, generated summaries, and automated detection steps in the capture-processing pipeline. When you use one of these features, the prompt and the context needed to produce a response are processed by our AI subprocessor, identified at /subprocessors, and returned to you.
Our commitments regarding these features:
- We do not train, fine-tune, or otherwise develop models on tenant conversations, captures, customer records, or other tenant data without the tenant’s consent. Where a tenant opts in, the use is limited to the scope agreed and may be withdrawn.
- We contractually require our AI subprocessor not to train its models on the data we send it for these features.
- We may use aggregated and de-identified telemetry — information that cannot reasonably be linked back to a tenant or an individual — to operate, evaluate, and improve the Service.
- Model outputs are generated by statistical prediction and may be incomplete or wrong. They are a drafting and review aid, not a determination, and the Terms of Service (/terms) require human review before reliance.
We do not make decisions producing legal or similarly significant effects concerning an individual through solely automated processing, including profiling, within the meaning of Article 22 of the General Data Protection Regulation and the profiling opt-out provisions of United States state privacy laws. Automated steps in the Service — detecting a roof plane, proposing a measurement, drafting a summary — inform a human decision made by the tenant; they do not substitute for one, and the tenant remains the professional of record for the result.
8. When we disclose personal information
We disclose personal information only in the circumstances below, and only the information the recipient needs for the stated purpose:
- To subprocessors that help us deliver the Service — cloud compute and object storage, payment processing, email delivery, AI features, mapping and solar-resource lookups — each of which is listed at /subprocessors and bound by written contract to process the data only on our documented instructions and to maintain appropriate safeguards.
- To the tenant whose workspace a record belongs to, and to the authorized users that tenant has granted access, in accordance with the permissions the tenant configures.
- To recipients a tenant or user directs us to share with — for example, a scene, proposal, or deliverable sent to an end customer through a share link the tenant creates.
- To professional advisors — lawyers, auditors, accountants, and insurers — bound by professional or contractual duties of confidentiality, where reasonably necessary.
- In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business or assets, subject to the acquirer continuing to honor this Policy for the information transferred and to notice where required by law.
- To comply with applicable law, a subpoena, court order, or other lawful request from a public authority, and to establish, exercise, or defend legal claims. Where we are legally permitted, and unless doing so would risk harm or prejudice an investigation, we will use reasonable efforts to notify the affected tenant before disclosing data we hold on their behalf, so that the tenant has the opportunity to seek protective relief.
- To protect the rights, property, or safety of Updrone, our customers, or the public, including to detect, prevent, or address fraud, security incidents, or violations of our Acceptable Use Policy (/acceptable-use).
We do not disclose personal information to third parties for their own independent purposes, and our contracts with subprocessors prohibit them from using it for anything other than providing their services to us.
11. Tenant data ownership and multi-tenant isolation
Tenants own their data. The leads, scenes, customer records, measurements, and deliverables a tenant creates or uploads remain the tenant’s data. Updrone acts as the tenant’s processor for that data and uses it to provide the Service to that tenant, on that tenant’s instructions, and for no independent purpose of our own.
Tenant data is isolated. Each tenant’s records are logically separated and access is scoped so that one tenant cannot read, query, or enumerate another tenant’s data. We do not reuse one tenant’s data to serve, benchmark, train for, or enrich another tenant. There is no cross-tenant reuse.
Aggregated and de-identified information may be used to operate, secure, and improve the Service. Where we hold information in de-identified form, we maintain it in de-identified form, we publicly commit to processing it only in that form, we do not attempt to reidentify it, and we contractually obligate any recipient to the same, consistent with Cal. Civ. Code § 1798.140(m).
12. Subprocessors
We engage a deliberately short list of vetted vendors to deliver the Service, and we disclose to each only the data it needs for its function. Our current subprocessors, the purpose of each engagement, and the categories of data involved are published at /subprocessors.
Each subprocessor is bound by written contract to confidentiality obligations and to data-protection commitments substantially equivalent to our own, including processing only on our documented instructions and maintaining appropriate technical and organizational measures. Engaging a subprocessor does not relieve Updrone of its obligations: we remain responsible to our customers for each subprocessor’s performance to the same extent as if we performed the service ourselves.
Where a tenant uses the Service to process personal data about its own end customers, our Data Processing Addendum (/dpa) governs that processing and sets out how we give notice of a new subprocessor and how a tenant may object.
13. Security
We maintain a security program with administrative, technical, and physical safeguards appropriate to the nature of the data we hold. These include encryption of data in transit and at rest, role-based and least-privilege access controls, logical isolation of each tenant’s data, multi-factor authentication for administrative access, logging and monitoring of access to production systems, secure development and code-review practices, background-appropriate personnel controls with confidentiality obligations, and vendor security review before engagement.
Access to production systems and to tenant data is restricted to personnel whose role requires it, is logged, and is reviewed periodically. We test and update these practices on an ongoing basis as the Service and the threat landscape change.
No system is perfectly secure, and we do not and cannot guarantee absolute security. Tenants are responsible for safeguarding their own credentials, enabling available account-protection features, managing who on their team has access and promptly removing those who should not, and configuring the sharing settings for the scenes and deliverables they distribute.
To report a suspected vulnerability, unauthorized access, or data exposure, contact support@updrone.com. We investigate every report we receive and will not pursue a good-faith security researcher who reports a finding responsibly and does not access, alter, or exfiltrate data beyond what is necessary to demonstrate the issue.
14. Data retention and deletion
We retain personal information for as long as needed for the purposes described in this Policy. The specific periods and the criteria that determine them are set out per category in the table in Section 3. In general, we retain tenant data for as long as the account is active and for a limited period afterward, and we retain records of a completed transaction for as long as tax, accounting, and audit obligations require.
Where we keep information longer than the period stated in Section 3, it is for one of the following reasons and no others:
- To comply with a legal, tax, accounting, or regulatory obligation that applies to us.
- To establish, exercise, or defend a legal claim, including where litigation is pending or reasonably anticipated and a legal hold applies.
- To detect, investigate, or prevent security incidents, fraud, or abuse, and to maintain the integrity of the Service.
- To honor an opt-out, suppression, or deletion request — a record that someone asked not to be contacted must outlive the record it suppresses, or the request would defeat itself.
Tenants can delete individual records within the platform at any time. On account closure, we delete or de-identify tenant data within 90 days, subject to the exceptions above. Deletion from live systems is immediate or near-immediate; encrypted backups are not purged on demand but age out and are overwritten on a rolling schedule not exceeding 35 days, and data in a backup is not restored to live systems except as part of a disaster-recovery event.
To request deletion, or to ask what we hold, contact support@updrone.com or use the process in Section 15.
15. Your privacy rights — United States
Depending on your state of residence, you may have some or all of the rights below. We extend these rights to residents of every state with a comprehensive consumer privacy law in force, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, and we apply the same process to a request from anyone else who asks.
Subject to verification and to the exceptions the applicable statute provides, you may request to:
- Know and access — confirm whether we process personal information about you and obtain the categories and specific pieces we hold, the categories of sources, the purposes, and the categories of recipients.
- Correct — have inaccurate personal information about you corrected, taking into account the nature of the information and the purpose of the processing.
- Delete — have personal information we collected from you deleted, subject to the retention exceptions in Section 14.
- Obtain a portable copy — receive personal information you provided to us in a portable and, to the extent technically feasible, readily usable format.
- Opt out of sale, sharing, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects. As Sections 7 and 9 state, we do none of these, so there is nothing to opt out of — the right is stated because you are entitled to know its status.
- Limit the use of sensitive personal information, as described and qualified in Section 4.
- Not be discriminated against or retaliated against for exercising any of these rights. We will not deny you the Service, charge you a different price, or provide a different level or quality of service because you exercised a right.
How to submit a request
Submit a request at /privacy-choices, or by email to support@updrone.com. Please tell us which right you are exercising and give us enough information to locate your records. If you need to reach us by another means, ask at that address and we will arrange one.
Verification, agents, and timing
We must verify that a request comes from you before we act on it — acting on an unverified request would itself be a disclosure to a stranger. We verify by matching the information in the request against the information already in our records, and for a request seeking specific pieces of personal information we apply a correspondingly higher standard, which may include asking you to confirm the request from the email address on the account. We do not ask for more information than verification requires, and we use anything you provide for verification only for that purpose and then delete it.
An authorized agent may submit a request on your behalf if the agent provides written permission signed by you, or a valid power of attorney. We may contact you directly to confirm the authorization and to verify your own identity.
We acknowledge a request within 10 business days and respond within 45 days. Where reasonably necessary, we may extend once by a further 45 days and will tell you why within the initial period. There is no charge for a request unless it is manifestly unfounded or excessive, in which case we will explain the reason and any fee before proceeding.
Appeals
If we decline to act on your request, we will tell you why. You may appeal that decision within a reasonable period by replying to our decision or writing to support@updrone.com with the subject line “Privacy Appeal.” We will review the appeal and inform you in writing of the outcome, and of our reasoning, within 45 days (or 60 days where the applicable state statute provides for it). If we deny the appeal, we will provide a method by which you may contact your state attorney general to submit a complaint.
California “Shine the Light”
California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for those parties’ own direct-marketing purposes. We make no such disclosures. To request confirmation, write to support@updrone.com.
If your request concerns data held by a tenant
Where Updrone holds personal information as a processor on a tenant’s behalf — the position described in Section 2 — requests from that tenant’s end customers belong with the tenant as the controller of that data. We will forward such a request to the tenant where we are permitted to do so and will support the tenant in responding within the statutory period.
16. Your privacy rights — EEA, United Kingdom, and Switzerland
If you are in the European Economic Area, the United Kingdom, or Switzerland, and Updrone acts as a controller of your personal data as described in Section 2, you have the rights set out in Articles 15 to 22 of the General Data Protection Regulation and the corresponding provisions of the UK GDPR and the Swiss Federal Act on Data Protection.
Those rights are:
- Access — to obtain confirmation of whether we process your personal data and a copy of it, together with the information set out in Article 15.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure — to have your personal data erased where one of the grounds in Article 17 applies.
- Restriction — to have processing restricted where one of the grounds in Article 18 applies.
- Portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, including profiling; and to object at any time and without justification to processing for direct-marketing purposes, which we will stop on request without exception.
- Withdrawal of consent — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
- Not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. As Section 7 states, we make no such decisions.
To exercise any of these rights, contact support@updrone.com. We will respond within one month, extendable by two further months where the request is complex or numerous, and we will tell you within the first month if we need the extension.
You also have the right to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement; with the Information Commissioner’s Office in the United Kingdom; or with the Federal Data Protection and Information Commissioner in Switzerland. We would welcome the opportunity to address your concern first, but that is your right and nothing here conditions it.
Where a tenant established in these territories uses the Service to process personal data about its own end customers, the tenant is the controller, Updrone is its processor, and our Data Processing Addendum (/dpa) — including the Standard Contractual Clauses where they apply — governs that processing.
17. International data transfers
Updrone is established in the United States, and the infrastructure that runs the Service is located there. Personal information we process may therefore be stored and handled in the United States and in other countries where we or our subprocessors operate. These countries may have data-protection rules different from those where you live, and may permit access by public authorities in circumstances that differ from those in your jurisdiction.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on an appropriate safeguard recognized under applicable law — principally the Standard Contractual Clauses adopted by the European Commission, together with the UK International Data Transfer Addendum and the Swiss adaptations where those apply. We conduct transfer impact assessments where required and apply supplementary technical measures, including encryption in transit and at rest and access controls, to the transferred data.
To request a copy of the safeguards we rely on for a particular transfer, contact support@updrone.com.
18. Mobile applications
Our mobile applications collect certain information that the web portal does not, because a capture happens in the field and on a device. Each of the following is gated behind an operating-system permission that you grant and can revoke at any time in your device settings.
| Permission | What it is used for | If you decline |
|---|---|---|
| Location — while in use | Planning a mission relative to your position, logging flights, and airspace-class lookups for the site. | Mission planning and flight logging that depend on your position are unavailable; you can still use the rest of the app. |
| Location — background | Continuing to track a mission in progress while the app is not in the foreground. | Tracking stops when the app is backgrounded during a mission. |
| Camera | Scanning a pairing code on drone hardware. Frames are processed in the moment and are not stored for this purpose. | Hardware pairing by code scan is unavailable; you can pair by other supported means. |
| Photo library | Importing captures already on your device into a mission. We access only the items you select. | You cannot import existing media; captures made through the app are unaffected. |
| Microphone | Recording an optional voice note against a mission. Audio is uploaded only if you record one. | Voice notes are unavailable. Nothing else changes. We never record ambient audio in the background. |
| Notifications | Alerting you to processing completion, messages, and account or security events. | You will not receive push alerts; the same information remains available in the app and by email. |
The applications also collect device identifiers, crash reports, and diagnostics for reliability and for targeting over-the-air updates. Crash reports are scrubbed of personal information before transmission where technically possible.
We do not use the Advertising Identifier (IDFA), we implement no attribution or ad-network framework, we include no advertising or third-party marketing SDK, and we do not track you across other companies’ apps or websites. Our app-store data-safety filings say the same thing, and are intended to be read consistently with this Policy.
Deleting the app removes locally cached data from your device. It does not delete your account or the data held in the Service — to do that, follow Section 14 or Section 15.
19. Email and text-message communications
We send transactional and service messages about your account, security, billing, and the operation of the Service. These are not marketing, they are part of the Service, and they cannot be unsubscribed from while your account is open — a security alert you have opted out of is a security alert that does not arrive. We also send marketing email to business contacts, and every marketing message carries a working unsubscribe link that we honor promptly.
The Service also lets a tenant send email and text messages to the tenant’s own contacts. In that flow the tenant is the sender and the party responsible for having a lawful basis and any consent required, and Updrone provides the transport. Our Terms of Service (/terms) place that obligation on the tenant expressly.
For text messaging specifically, and consistent with telecommunications-industry requirements:
- Message and data rates may apply, and message frequency varies with your account activity and the tenant you are corresponding with.
- Reply STOP to any message to opt out, and HELP for assistance. We honor an opt-out expressed by any reasonable means, not only the exact keyword, consistent with 47 C.F.R. § 64.1200(a)(10).
- We maintain suppression records so that an opt-out persists. As Section 14 notes, those records are kept indefinitely by design.
- No mobile information — phone numbers, opt-in status, or consent records — is sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. Sharing is limited to the subprocessors that carry the message on our behalf, and those parties are prohibited from any other use.
20. Children’s privacy
Updrone is a business-to-business platform. It is not directed to children, and we do not knowingly collect personal information from anyone under 18 in the ordinary operation of the Service. Our Terms of Service require every account holder and authorized user to be at least 18 years old.
We do not knowingly collect personal information from a child under 13 within the meaning of the Children’s Online Privacy Protection Act, and we do not sell or share the personal information of any individual under 16 as those terms are used in United States state privacy law. Where the General Data Protection Regulation applies, we do not knowingly process the personal data of a child below the age at which consent is valid in the relevant Member State.
If you believe a child has provided us personal information, contact support@updrone.com and we will delete it promptly. If a tenant’s capture incidentally depicts a minor, Section 5 governs and the tenant remains responsible for the permissions required for that capture.
21. Third-party websites and services
The Service links to and integrates with services operated by others — a payment processor’s checkout, map tiles, a tenant’s own website, a share link a tenant sends. This Policy does not apply to them. Their operators handle any information you provide under their own privacy notices, and we encourage you to read those notices before providing information.
Updrone is not responsible for the privacy practices, security, or content of a third-party service, and the inclusion of a link or an integration is not an endorsement.
22. Data-breach notification
If we determine that a security incident has resulted in the unauthorized acquisition of or access to personal information we hold, we will notify affected individuals and, where Updrone acts as a processor, the affected tenant, without undue delay and within the timeframes required by applicable law. Where we act as a processor, the tenant as controller decides whether and how its own end customers and any supervisory authority are notified, and we will provide the information the tenant reasonably needs to make and act on that decision.
Our notification will describe, to the extent then known, what happened, the categories of information involved, what we have done in response, and the steps you can take. Notifying you of an incident, or responding to one, is not an admission of fault or liability by Updrone.
Our incident-response and notification obligations to tenants are set out in more detail in our Data Processing Addendum (/dpa).
23. Accessibility of this notice
We are committed to making this Policy usable by people with disabilities. If you use assistive technology and have difficulty accessing any part of this Policy, contact support@updrone.com and we will provide the information in an alternative format at no charge.
24. Changes to this Policy
We may update this Policy as the Service, our practices, or the law changes. Every version carries a version identifier and a “Last updated” date at the top of this page, and the current version identifier is the one shown there.
When we make a material change — one that expands the categories of personal information we collect, adds a materially different purpose, or changes the categories of recipients — we will provide notice before it takes effect, by posting notice in the Service, by email to the address on the account, or by both, and where the law requires consent for the change we will obtain it. Continued use of the Service after a change takes effect constitutes acceptance of the revised Policy, except where applicable law requires otherwise.
Changes are not applied retroactively to information already collected in a way that would be materially inconsistent with the Policy in force when it was collected, without your consent where such consent is required.
25. How to contact us
Updrone, Inc. is the entity responsible for the personal information described in this Policy where we act as a controller.
EVERYTHING IN THIS POLICY REACHES US AT ONE ADDRESS: support@updrone.com. THAT IS THE ONLY EMAIL ADDRESS UPDRONE PUBLISHES, AND IT IS MONITORED. USE IT FOR PRIVACY QUESTIONS, RIGHTS REQUESTS AND APPEALS, SECURITY REPORTS, DATA-TRANSFER SAFEGUARDS, AND ANYTHING ELSE THIS POLICY REFERS TO. RIGHTS REQUESTS CAN ALSO BE SUBMITTED AT /privacy-choices.
We deliberately publish a single address rather than a directory of departmental ones. A published address that nobody monitors is worse than no address at all — it starts a statutory clock that no one is answering — so the address above is the one that receives mail, and everything routes from there.
Tell us in your message what you are writing about — a rights request, an appeal, a security report — and we will route it. If you need to reach us by post, or if you are in the European Economic Area or the United Kingdom and require the contact details of a representative appointed under Article 27 of the General Data Protection Regulation or the UK GDPR, ask at support@updrone.com and we will provide them.