Skip to content

Legal

Privacy Policy

How we collect, use, disclose, and protect personal information — including the captures, scenes, location data, and customer records that tenant businesses upload to run their operations on Updrone. This notice covers our role as a controller of our own account data and as a processor of the customer records our tenants hold.

Last updated August 28, 2026· Version 2026-08-28

1. Introduction and scope

This Privacy Policy (this “Policy”) describes how Updrone, Inc. (“Updrone,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information. It applies to our marketing website, the Updrone customer portal, our mobile applications, our APIs and capture clients, the hosted pages we render on a tenant’s behalf, and the communications we send in connection with them (collectively, the “Service”).

Throughout this Policy, a “tenant” is a business that licenses Updrone to run its operations, an “authorized user” is a person a tenant grants access to its workspace, and an “end customer” is a person or organization that the tenant serves and whose records the tenant maintains in the Service. “Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular individual or household, and includes “personal data” as that term is used under European and United Kingdom law.

Updrone licenses software. The tenant is the professional of record for its own flights, pilots, airspace authorization, insurance, accuracy sign-off, and regulatory compliance. We display and process the information tenants and their end customers provide — we do not fly, pilot, certify, or authorize anything. That division of responsibility determines who is accountable for the personal information in the Service, which Section 2 sets out.

This Policy does not apply to the practices of third parties we do not control, including the independent websites, applications, and services a tenant may link to or integrate with. Where a tenant uses the Service to communicate with its own end customers, the tenant’s own privacy notice governs that relationship, and this Policy governs only what Updrone does as that tenant’s service provider.

2. Our two roles: controller and processor

Which privacy obligations apply to Updrone — and where you should direct a request — depends on which of two roles we occupy for the information in question. The distinction is legal, not rhetorical, and it runs through the rest of this Policy.

We act in one of the following two capacities:

  • Controller (or “business”). For the information we collect to run Updrone as a company — account registration details, authorized-user profiles, billing and subscription records, support correspondence, marketing-site visitors, and product telemetry and diagnostics — Updrone determines the purposes and means of processing and is the controller. Sections 3 through 10 and Sections 15 through 17 describe that processing, and you may exercise your rights with us directly.
  • Processor (or “service provider”). For the personal information a tenant puts into its workspace about its own end customers — contact records, job and project files, imagery and scenes of a property, scheduling, proposals, invoices, and messages — the tenant is the controller and Updrone is its processor. We process that information only on the tenant’s documented instructions and to provide, secure, support, and maintain the Service. Our Data Processing Addendum (/dpa) governs that processing and forms part of our agreement with the tenant.

If you are an end customer of a business that uses Updrone and you want to access, correct, delete, or object to the processing of your information, that business is the controller and holds the relationship with you. Direct your request to that business. If you send it to us, we will, where we are legally permitted to do so, forward it to the relevant tenant and support them in responding rather than acting on it unilaterally — acting on a controller's records without instruction would itself be an unauthorized disclosure.

Where Updrone is a processor, we do not use tenant data for our own purposes, do not combine it with data from other sources for our own purposes, and do not disclose it outside the direct business relationship except as this Policy and the Data Processing Addendum permit.

3. Categories of personal information we collect

The table below sets out the categories of personal information we collect, the sources we collect them from, the purposes we use them for, the categories of recipients we disclose them to, and how long we keep them. The category labels correspond to those enumerated in the California Consumer Privacy Act, as amended (Cal. Civ. Code § 1798.140(v)), so that this disclosure can be read directly against the statute. Not every category applies to every individual — what we hold about you depends on how you interact with the Service.

CategoryExamplesSourcesPurposesRecipientsRetention
IdentifiersName, email address, postal address, phone number, account ID, tenant/workspace ID, IP address, device identifiers.You; your employer or the tenant that invited you; your device; single sign-on providers you choose to use.Creating and authenticating accounts; provisioning workspace access; transactional and service messaging; support; fraud prevention and security.Cloud hosting and storage providers; email delivery provider; payment processor; professional advisors; authorities where legally compelled.For the life of the account, then deleted or de-identified within 90 days of closure, except records retained under Section 14.
Customer records and commercial informationBilling contact and address, subscription plan and history, invoices, payment metadata (amount, date, reference, last four digits and card brand), transaction and payout records.You; our payment processor; the tenant whose workspace the record belongs to.Billing and collections; tax, accounting, and audit obligations; dispute and chargeback handling; facilitating tenant payouts.Payment processor; cloud hosting and storage providers; accounting and tax advisors; authorities where legally compelled.Seven years from the transaction, to satisfy tax and accounting record-keeping obligations.
Precise and coarse geolocationGPS coordinates of a capture and of the device during a mission; property addresses geocoded to coordinates; site and job locations; airspace-lookup coordinates.Your device (with your operating-system permission); addresses you or a tenant enter; metadata embedded in imagery you upload.Mission planning and flight logging; georeferencing captures and reconstructions; airspace-class and solar-resource lookups; measurement and deliverable generation.Cloud compute and storage providers; mapping and solar-data providers (address or coordinates only); the tenant whose workspace the record belongs to.For the life of the associated capture, project, or account record; deleted with the parent record.
Audio, visual, and sensor informationPhotographs and video from a capture; 3D scenes, meshes, point clouds, and orthomosaics derived from them; optional voice notes recorded against a mission; profile photographs.You and your authorized users; the tenant’s end customers where the tenant enables uploads; capture devices you connect.Running the capture-processing pipeline; generating scenes, measurements, and deliverables; rendering the records the tenant relies on.Cloud compute and object-storage providers; recipients the tenant chooses to share a scene or deliverable with.For the life of the associated record or account; deleted with the parent record or on tenant deletion.
Internet and network activityPages and features used, referring site hostname, cookieless first-party page views (path, campaign tags we published, coarse device / browser / OS family), a daily-rotating anonymous visitor hash, approximate country / region / city as estimated by the hosting provider from the connection, session and request logs, processing-job status and timing, error and crash diagnostics.Your device and browser automatically; our servers and first-party analytics.Operating and securing the Service; measuring reliability and performance; diagnosing errors; understanding feature usage to prioritize development.Cloud hosting providers; crash and diagnostics tooling.Raw logs for up to 13 months; aggregated and de-identified metrics may be kept indefinitely.
Professional and employment informationBusiness name, job title or role, trade or vertical, team membership and permissions within a workspace.You; the tenant that invited you.Provisioning role-based access; configuring the product for your trade; support and account management.Cloud hosting providers; the tenant that administers your workspace.For the life of the account, then deleted or de-identified within 90 days of closure.
Account credentials and security dataHashed passwords, multi-factor authentication enrollment, session tokens, sign-in and authorization events.You; your single sign-on provider; our authentication systems.Authenticating you; protecting accounts; detecting, investigating, and responding to unauthorized access.Cloud hosting providers; security tooling. Never sold, shared, or disclosed for any other purpose.Credentials for the life of the account; security event logs for up to 24 months.
Communications contentSupport requests and correspondence, in-product messages, email and SMS a tenant sends through the Service to its own contacts, consent and opt-out records.You; the tenant; the tenant’s end customers.Delivering the requested communication; providing support; honoring opt-outs and suppression; demonstrating consent and compliance.Email delivery provider; telecommunications carriers for SMS; cloud hosting providers.Support correspondence for 24 months. Opt-out and suppression records are kept indefinitely — deleting them would cause us to contact someone who asked us not to.
InferencesAggregated product-usage patterns and derived reliability and performance metrics.Derived from the categories above.Operating and improving the Service; capacity planning; prioritizing development.Not disclosed in identifiable form.Kept in de-identified or aggregated form only.

We do not knowingly collect personal information from categories we have no business need for. In particular, we do not collect government identification numbers, financial account numbers, health information, or information about race, religion, union membership, sexual orientation, or immigration status, and you should not submit them to the Service.

4. Sensitive personal information

Certain of the information described above is designated “sensitive personal information” under California law and “special category” or similarly protected data under other regimes. We collect the following and no more: precise geolocation, which is inherent to a capture platform and is used for mission planning, flight logging, georeferencing, and airspace and solar-resource lookups; account credentials and authentication data, which are used solely to sign you in and secure your account; and the contents of communications a tenant sends through the Service, which are used solely to deliver, support, and log those communications.

We use and disclose sensitive personal information only for the purposes permitted by Cal. Civ. Code § 1798.121(a) and 11 CCR § 7027(m) — performing the services requested, ensuring security and integrity, detecting and resisting malicious or fraudulent activity, and verifying and maintaining the quality and safety of the Service. We do not use or disclose it to infer characteristics about you.

BECAUSE WE DO NOT USE OR DISCLOSE SENSITIVE PERSONAL INFORMATION FOR ANY PURPOSE BEYOND THOSE PERMITTED BY LAW WITHOUT A SEPARATE PURPOSE-LIMITATION NOTICE, THE CALIFORNIA “RIGHT TO LIMIT THE USE OF MY SENSITIVE PERSONAL INFORMATION” DOES NOT APPLY TO OUR PROCESSING. WE STATE THIS AFFIRMATIVELY RATHER THAN BY OMISSION SO THAT THE BASIS FOR IT IS ON THE RECORD.

You can withdraw device location permission at any time in your operating-system settings, as described in Section 18. Doing so will disable the features that depend on it — mission planning relative to your position, in-flight tracking, and automatic georeferencing of a capture — but will not otherwise prevent you from using the Service.

5. Imagery, 3D reconstructions, and people or property depicted in a capture

A capture is a photograph or video of a real place, and a place may contain people, vehicles, addresses, and the interiors visible through an opening. The reconstruction we generate from it — a Gaussian splat scene, a photogrammetric mesh, a point cloud, an orthomosaic — carries whatever the source frames carried. We treat that material as capable of containing personal information and handle it accordingly.

What we do not do

We commit to the following, and these commitments are enforceable representations rather than aspirations:

  • We do not derive, extract, generate, or store biometric identifiers or biometric information from imagery or reconstructions. We do not compute or retain scans of face geometry, hand geometry, iris or retina patterns, voiceprints, or gait, and we do not create a mathematical template from any of them.
  • We do not perform facial recognition, face matching, face clustering, or any other operation intended to identify, verify, or track an individual person appearing in a capture.
  • We do not use captures, scenes, or the people or property depicted in them to build profiles, to enrich records about individuals, or for advertising of any kind.
  • We do not use one tenant’s captures to serve, benchmark, or enrich another tenant, and we do not disclose a capture outside the tenant’s workspace except as the tenant directs or as Section 8 permits.
  • We do not sell captures or reconstructions, and we do not license them to data brokers, imagery aggregators, or model-training marketplaces.

Where responsibility sits

The tenant chooses what to photograph, when, from what altitude and vantage, and who receives the result. Accordingly, and as the Terms of Service (/terms) provide, the tenant is responsible for obtaining every right, permission, and consent required to capture, process, publish, and retain imagery of a person or of property — including any notice or consent required by state biometric, recording, eavesdropping, two-party consent, trespass, nuisance, or privacy statutes in the jurisdiction of the capture. Updrone hosts and processes what the tenant submits; it is not in a position to know whether a given consent was obtained, and it does not represent that it was.

If you believe you appear in, or your property appears in, a capture hosted on Updrone and you wish to have it addressed, contact us at support@updrone.com. Because the capture belongs to the tenant’s workspace and the tenant is its controller, we will identify and notify the relevant tenant and support them in responding, and we will act directly where the law requires us to.

7. Artificial intelligence features and automated processing

Parts of the Service use machine learning and generative models — for example, the in-product assistant, generated summaries, and automated detection steps in the capture-processing pipeline. When you use one of these features, the prompt and the context needed to produce a response are processed by our AI subprocessor, identified at /subprocessors, and returned to you.

Our commitments regarding these features:

  • We do not train, fine-tune, or otherwise develop models on tenant conversations, captures, customer records, or other tenant data without the tenant’s consent. Where a tenant opts in, the use is limited to the scope agreed and may be withdrawn.
  • We contractually require our AI subprocessor not to train its models on the data we send it for these features.
  • We may use aggregated and de-identified telemetry — information that cannot reasonably be linked back to a tenant or an individual — to operate, evaluate, and improve the Service.
  • Model outputs are generated by statistical prediction and may be incomplete or wrong. They are a drafting and review aid, not a determination, and the Terms of Service (/terms) require human review before reliance.

We do not make decisions producing legal or similarly significant effects concerning an individual through solely automated processing, including profiling, within the meaning of Article 22 of the General Data Protection Regulation and the profiling opt-out provisions of United States state privacy laws. Automated steps in the Service — detecting a roof plane, proposing a measurement, drafting a summary — inform a human decision made by the tenant; they do not substitute for one, and the tenant remains the professional of record for the result.

8. When we disclose personal information

We disclose personal information only in the circumstances below, and only the information the recipient needs for the stated purpose:

  • To subprocessors that help us deliver the Service — cloud compute and object storage, payment processing, email delivery, AI features, mapping and solar-resource lookups — each of which is listed at /subprocessors and bound by written contract to process the data only on our documented instructions and to maintain appropriate safeguards.
  • To the tenant whose workspace a record belongs to, and to the authorized users that tenant has granted access, in accordance with the permissions the tenant configures.
  • To recipients a tenant or user directs us to share with — for example, a scene, proposal, or deliverable sent to an end customer through a share link the tenant creates.
  • To professional advisors — lawyers, auditors, accountants, and insurers — bound by professional or contractual duties of confidentiality, where reasonably necessary.
  • In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business or assets, subject to the acquirer continuing to honor this Policy for the information transferred and to notice where required by law.
  • To comply with applicable law, a subpoena, court order, or other lawful request from a public authority, and to establish, exercise, or defend legal claims. Where we are legally permitted, and unless doing so would risk harm or prejudice an investigation, we will use reasonable efforts to notify the affected tenant before disclosing data we hold on their behalf, so that the tenant has the opportunity to seek protective relief.
  • To protect the rights, property, or safety of Updrone, our customers, or the public, including to detect, prevent, or address fraud, security incidents, or violations of our Acceptable Use Policy (/acceptable-use).

We do not disclose personal information to third parties for their own independent purposes, and our contracts with subprocessors prohibit them from using it for anything other than providing their services to us.

9. We do not sell or share personal information

UPDRONE DOES NOT SELL PERSONAL INFORMATION AND DOES NOT SHARE PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING, AS THOSE TERMS ARE DEFINED IN CAL. CIV. CODE § 1798.140(ad) AND (ah) AND IN THE COMPARABLE PROVISIONS OF OTHER UNITED STATES STATE PRIVACY LAWS. WE HAVE NOT DONE SO IN THE TWELVE MONTHS PRECEDING THE DATE OF THIS POLICY, AND WE DO NOT SELL OR SHARE THE PERSONAL INFORMATION OF ANY INDIVIDUAL WE KNOW TO BE UNDER SIXTEEN YEARS OF AGE.

We also do not process personal information for targeted advertising, we do not serve advertising in the Service, we are not a data broker under California or Vermont law, and we do not buy personal information from data brokers or enrich our records from third-party data vendors.

Because we do not sell or share personal information, we do not offer a “Do Not Sell or Share My Personal Information” mechanism to stop something that does not occur. Our privacy choices page (/privacy-choices) is where you can exercise the rights we do offer, and Section 10 describes how we treat browser opt-out preference signals.

Our disclosures to subprocessors are made under written contracts that meet the “service provider” and “contractor” requirements of Cal. Civ. Code § 1798.140(ag) and (j) — restricting the recipient to the specified purposes, prohibiting retention, use, or disclosure for any other purpose, and prohibiting any combination with data from other sources. Such a disclosure is not a sale or a share.

10. Cookies, analytics, and opt-out preference signals

We use cookies, browser local storage, and similar technologies to keep you signed in, to remember your preferences, and to measure the reliability and performance of the Service. Our Cookie Policy (/cookies) describes each category, what it is for, and how to control it. We use first-party analytics only; we do not use third-party advertising cookies, advertising SDKs, or cross-site tracking pixels.

On updrone.com we also record cookieless first-party page views — path, referring hostname, campaign tags from links we publish, coarse device / browser / OS family, and an approximate city / region / country supplied by the hosting provider. We do not store the IP address or the raw user-agent; a hash of those values plus the UTC date identifies a visitor for that day only and cannot be linked to the next day. This beacon does not set a cookie and does not run if your browser sends Do Not Track or the Global Privacy Control. A separate, consent-gated conversion funnel (scroll depth, which call-to-action was clicked, signup steps) records nothing until you grant the analytics category in our banner.

A tenant’s published marketing website has its own cookieless first-party page-view count, stored only in that tenant’s workspace. Updrone does not read, aggregate, or reuse one tenant’s website analytics for our own purposes or for another tenant.

We honor opt-out preference signals, including the Global Privacy Control (GPC), transmitted by a browser or extension. A GPC or Do Not Track signal disables the cookieless page-view beacon on updrone.com. We also treat GPC as a valid request to opt out of any sale or sharing of personal information and of processing for targeted advertising for the browser or device that sends it, as required by 11 CCR § 7025 and the comparable rules of other states. Because we do not sell or share personal information in the first place, that second effect changes nothing about how we treat you — but the signal is received, respected, and not overridden.

Strictly necessary cookies cannot be switched off in-product; blocking them in your browser will prevent sign-in. Preference and analytics storage can be cleared or blocked at any time without affecting your ability to use the Service.

11. Tenant data ownership and multi-tenant isolation

Tenants own their data. The leads, scenes, customer records, measurements, and deliverables a tenant creates or uploads remain the tenant’s data. Updrone acts as the tenant’s processor for that data and uses it to provide the Service to that tenant, on that tenant’s instructions, and for no independent purpose of our own.

Tenant data is isolated. Each tenant’s records are logically separated and access is scoped so that one tenant cannot read, query, or enumerate another tenant’s data. We do not reuse one tenant’s data to serve, benchmark, train for, or enrich another tenant. There is no cross-tenant reuse.

Aggregated and de-identified information may be used to operate, secure, and improve the Service. Where we hold information in de-identified form, we maintain it in de-identified form, we publicly commit to processing it only in that form, we do not attempt to reidentify it, and we contractually obligate any recipient to the same, consistent with Cal. Civ. Code § 1798.140(m).

12. Subprocessors

We engage a deliberately short list of vetted vendors to deliver the Service, and we disclose to each only the data it needs for its function. Our current subprocessors, the purpose of each engagement, and the categories of data involved are published at /subprocessors.

Each subprocessor is bound by written contract to confidentiality obligations and to data-protection commitments substantially equivalent to our own, including processing only on our documented instructions and maintaining appropriate technical and organizational measures. Engaging a subprocessor does not relieve Updrone of its obligations: we remain responsible to our customers for each subprocessor’s performance to the same extent as if we performed the service ourselves.

Where a tenant uses the Service to process personal data about its own end customers, our Data Processing Addendum (/dpa) governs that processing and sets out how we give notice of a new subprocessor and how a tenant may object.

13. Security

We maintain a security program with administrative, technical, and physical safeguards appropriate to the nature of the data we hold. These include encryption of data in transit and at rest, role-based and least-privilege access controls, logical isolation of each tenant’s data, multi-factor authentication for administrative access, logging and monitoring of access to production systems, secure development and code-review practices, background-appropriate personnel controls with confidentiality obligations, and vendor security review before engagement.

Access to production systems and to tenant data is restricted to personnel whose role requires it, is logged, and is reviewed periodically. We test and update these practices on an ongoing basis as the Service and the threat landscape change.

No system is perfectly secure, and we do not and cannot guarantee absolute security. Tenants are responsible for safeguarding their own credentials, enabling available account-protection features, managing who on their team has access and promptly removing those who should not, and configuring the sharing settings for the scenes and deliverables they distribute.

To report a suspected vulnerability, unauthorized access, or data exposure, contact support@updrone.com. We investigate every report we receive and will not pursue a good-faith security researcher who reports a finding responsibly and does not access, alter, or exfiltrate data beyond what is necessary to demonstrate the issue.

14. Data retention and deletion

We retain personal information for as long as needed for the purposes described in this Policy. The specific periods and the criteria that determine them are set out per category in the table in Section 3. In general, we retain tenant data for as long as the account is active and for a limited period afterward, and we retain records of a completed transaction for as long as tax, accounting, and audit obligations require.

Where we keep information longer than the period stated in Section 3, it is for one of the following reasons and no others:

  • To comply with a legal, tax, accounting, or regulatory obligation that applies to us.
  • To establish, exercise, or defend a legal claim, including where litigation is pending or reasonably anticipated and a legal hold applies.
  • To detect, investigate, or prevent security incidents, fraud, or abuse, and to maintain the integrity of the Service.
  • To honor an opt-out, suppression, or deletion request — a record that someone asked not to be contacted must outlive the record it suppresses, or the request would defeat itself.

Tenants can delete individual records within the platform at any time. On account closure, we delete or de-identify tenant data within 90 days, subject to the exceptions above. Deletion from live systems is immediate or near-immediate; encrypted backups are not purged on demand but age out and are overwritten on a rolling schedule not exceeding 35 days, and data in a backup is not restored to live systems except as part of a disaster-recovery event.

To request deletion, or to ask what we hold, contact support@updrone.com or use the process in Section 15.

15. Your privacy rights — United States

Depending on your state of residence, you may have some or all of the rights below. We extend these rights to residents of every state with a comprehensive consumer privacy law in force, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, and we apply the same process to a request from anyone else who asks.

Subject to verification and to the exceptions the applicable statute provides, you may request to:

  • Know and access — confirm whether we process personal information about you and obtain the categories and specific pieces we hold, the categories of sources, the purposes, and the categories of recipients.
  • Correct — have inaccurate personal information about you corrected, taking into account the nature of the information and the purpose of the processing.
  • Delete — have personal information we collected from you deleted, subject to the retention exceptions in Section 14.
  • Obtain a portable copy — receive personal information you provided to us in a portable and, to the extent technically feasible, readily usable format.
  • Opt out of sale, sharing, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects. As Sections 7 and 9 state, we do none of these, so there is nothing to opt out of — the right is stated because you are entitled to know its status.
  • Limit the use of sensitive personal information, as described and qualified in Section 4.
  • Not be discriminated against or retaliated against for exercising any of these rights. We will not deny you the Service, charge you a different price, or provide a different level or quality of service because you exercised a right.

How to submit a request

Submit a request at /privacy-choices, or by email to support@updrone.com. Please tell us which right you are exercising and give us enough information to locate your records. If you need to reach us by another means, ask at that address and we will arrange one.

Verification, agents, and timing

We must verify that a request comes from you before we act on it — acting on an unverified request would itself be a disclosure to a stranger. We verify by matching the information in the request against the information already in our records, and for a request seeking specific pieces of personal information we apply a correspondingly higher standard, which may include asking you to confirm the request from the email address on the account. We do not ask for more information than verification requires, and we use anything you provide for verification only for that purpose and then delete it.

An authorized agent may submit a request on your behalf if the agent provides written permission signed by you, or a valid power of attorney. We may contact you directly to confirm the authorization and to verify your own identity.

We acknowledge a request within 10 business days and respond within 45 days. Where reasonably necessary, we may extend once by a further 45 days and will tell you why within the initial period. There is no charge for a request unless it is manifestly unfounded or excessive, in which case we will explain the reason and any fee before proceeding.

Appeals

If we decline to act on your request, we will tell you why. You may appeal that decision within a reasonable period by replying to our decision or writing to support@updrone.com with the subject line “Privacy Appeal.” We will review the appeal and inform you in writing of the outcome, and of our reasoning, within 45 days (or 60 days where the applicable state statute provides for it). If we deny the appeal, we will provide a method by which you may contact your state attorney general to submit a complaint.

California “Shine the Light”

California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for those parties’ own direct-marketing purposes. We make no such disclosures. To request confirmation, write to support@updrone.com.

If your request concerns data held by a tenant

Where Updrone holds personal information as a processor on a tenant’s behalf — the position described in Section 2 — requests from that tenant’s end customers belong with the tenant as the controller of that data. We will forward such a request to the tenant where we are permitted to do so and will support the tenant in responding within the statutory period.

16. Your privacy rights — EEA, United Kingdom, and Switzerland

If you are in the European Economic Area, the United Kingdom, or Switzerland, and Updrone acts as a controller of your personal data as described in Section 2, you have the rights set out in Articles 15 to 22 of the General Data Protection Regulation and the corresponding provisions of the UK GDPR and the Swiss Federal Act on Data Protection.

Those rights are:

  • Access — to obtain confirmation of whether we process your personal data and a copy of it, together with the information set out in Article 15.
  • Rectification — to have inaccurate personal data corrected and incomplete data completed.
  • Erasure — to have your personal data erased where one of the grounds in Article 17 applies.
  • Restriction — to have processing restricted where one of the grounds in Article 18 applies.
  • Portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, including profiling; and to object at any time and without justification to processing for direct-marketing purposes, which we will stop on request without exception.
  • Withdrawal of consent — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • Not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. As Section 7 states, we make no such decisions.

To exercise any of these rights, contact support@updrone.com. We will respond within one month, extendable by two further months where the request is complex or numerous, and we will tell you within the first month if we need the extension.

You also have the right to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement; with the Information Commissioner’s Office in the United Kingdom; or with the Federal Data Protection and Information Commissioner in Switzerland. We would welcome the opportunity to address your concern first, but that is your right and nothing here conditions it.

Where a tenant established in these territories uses the Service to process personal data about its own end customers, the tenant is the controller, Updrone is its processor, and our Data Processing Addendum (/dpa) — including the Standard Contractual Clauses where they apply — governs that processing.

17. International data transfers

Updrone is established in the United States, and the infrastructure that runs the Service is located there. Personal information we process may therefore be stored and handled in the United States and in other countries where we or our subprocessors operate. These countries may have data-protection rules different from those where you live, and may permit access by public authorities in circumstances that differ from those in your jurisdiction.

Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on an appropriate safeguard recognized under applicable law — principally the Standard Contractual Clauses adopted by the European Commission, together with the UK International Data Transfer Addendum and the Swiss adaptations where those apply. We conduct transfer impact assessments where required and apply supplementary technical measures, including encryption in transit and at rest and access controls, to the transferred data.

To request a copy of the safeguards we rely on for a particular transfer, contact support@updrone.com.

18. Mobile applications

Our mobile applications collect certain information that the web portal does not, because a capture happens in the field and on a device. Each of the following is gated behind an operating-system permission that you grant and can revoke at any time in your device settings.

PermissionWhat it is used forIf you decline
Location — while in usePlanning a mission relative to your position, logging flights, and airspace-class lookups for the site.Mission planning and flight logging that depend on your position are unavailable; you can still use the rest of the app.
Location — backgroundContinuing to track a mission in progress while the app is not in the foreground.Tracking stops when the app is backgrounded during a mission.
CameraScanning a pairing code on drone hardware. Frames are processed in the moment and are not stored for this purpose.Hardware pairing by code scan is unavailable; you can pair by other supported means.
Photo libraryImporting captures already on your device into a mission. We access only the items you select.You cannot import existing media; captures made through the app are unaffected.
MicrophoneRecording an optional voice note against a mission. Audio is uploaded only if you record one.Voice notes are unavailable. Nothing else changes. We never record ambient audio in the background.
NotificationsAlerting you to processing completion, messages, and account or security events.You will not receive push alerts; the same information remains available in the app and by email.

The applications also collect device identifiers, crash reports, and diagnostics for reliability and for targeting over-the-air updates. Crash reports are scrubbed of personal information before transmission where technically possible.

We do not use the Advertising Identifier (IDFA), we implement no attribution or ad-network framework, we include no advertising or third-party marketing SDK, and we do not track you across other companies’ apps or websites. Our app-store data-safety filings say the same thing, and are intended to be read consistently with this Policy.

Deleting the app removes locally cached data from your device. It does not delete your account or the data held in the Service — to do that, follow Section 14 or Section 15.

19. Email and text-message communications

We send transactional and service messages about your account, security, billing, and the operation of the Service. These are not marketing, they are part of the Service, and they cannot be unsubscribed from while your account is open — a security alert you have opted out of is a security alert that does not arrive. We also send marketing email to business contacts, and every marketing message carries a working unsubscribe link that we honor promptly.

The Service also lets a tenant send email and text messages to the tenant’s own contacts. In that flow the tenant is the sender and the party responsible for having a lawful basis and any consent required, and Updrone provides the transport. Our Terms of Service (/terms) place that obligation on the tenant expressly.

For text messaging specifically, and consistent with telecommunications-industry requirements:

  • Message and data rates may apply, and message frequency varies with your account activity and the tenant you are corresponding with.
  • Reply STOP to any message to opt out, and HELP for assistance. We honor an opt-out expressed by any reasonable means, not only the exact keyword, consistent with 47 C.F.R. § 64.1200(a)(10).
  • We maintain suppression records so that an opt-out persists. As Section 14 notes, those records are kept indefinitely by design.
  • No mobile information — phone numbers, opt-in status, or consent records — is sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. Sharing is limited to the subprocessors that carry the message on our behalf, and those parties are prohibited from any other use.

20. Children’s privacy

Updrone is a business-to-business platform. It is not directed to children, and we do not knowingly collect personal information from anyone under 18 in the ordinary operation of the Service. Our Terms of Service require every account holder and authorized user to be at least 18 years old.

We do not knowingly collect personal information from a child under 13 within the meaning of the Children’s Online Privacy Protection Act, and we do not sell or share the personal information of any individual under 16 as those terms are used in United States state privacy law. Where the General Data Protection Regulation applies, we do not knowingly process the personal data of a child below the age at which consent is valid in the relevant Member State.

If you believe a child has provided us personal information, contact support@updrone.com and we will delete it promptly. If a tenant’s capture incidentally depicts a minor, Section 5 governs and the tenant remains responsible for the permissions required for that capture.

21. Third-party websites and services

The Service links to and integrates with services operated by others — a payment processor’s checkout, map tiles, a tenant’s own website, a share link a tenant sends. This Policy does not apply to them. Their operators handle any information you provide under their own privacy notices, and we encourage you to read those notices before providing information.

Updrone is not responsible for the privacy practices, security, or content of a third-party service, and the inclusion of a link or an integration is not an endorsement.

22. Data-breach notification

If we determine that a security incident has resulted in the unauthorized acquisition of or access to personal information we hold, we will notify affected individuals and, where Updrone acts as a processor, the affected tenant, without undue delay and within the timeframes required by applicable law. Where we act as a processor, the tenant as controller decides whether and how its own end customers and any supervisory authority are notified, and we will provide the information the tenant reasonably needs to make and act on that decision.

Our notification will describe, to the extent then known, what happened, the categories of information involved, what we have done in response, and the steps you can take. Notifying you of an incident, or responding to one, is not an admission of fault or liability by Updrone.

Our incident-response and notification obligations to tenants are set out in more detail in our Data Processing Addendum (/dpa).

23. Accessibility of this notice

We are committed to making this Policy usable by people with disabilities. If you use assistive technology and have difficulty accessing any part of this Policy, contact support@updrone.com and we will provide the information in an alternative format at no charge.

24. Changes to this Policy

We may update this Policy as the Service, our practices, or the law changes. Every version carries a version identifier and a “Last updated” date at the top of this page, and the current version identifier is the one shown there.

When we make a material change — one that expands the categories of personal information we collect, adds a materially different purpose, or changes the categories of recipients — we will provide notice before it takes effect, by posting notice in the Service, by email to the address on the account, or by both, and where the law requires consent for the change we will obtain it. Continued use of the Service after a change takes effect constitutes acceptance of the revised Policy, except where applicable law requires otherwise.

Changes are not applied retroactively to information already collected in a way that would be materially inconsistent with the Policy in force when it was collected, without your consent where such consent is required.

25. How to contact us

Updrone, Inc. is the entity responsible for the personal information described in this Policy where we act as a controller.

EVERYTHING IN THIS POLICY REACHES US AT ONE ADDRESS: support@updrone.com. THAT IS THE ONLY EMAIL ADDRESS UPDRONE PUBLISHES, AND IT IS MONITORED. USE IT FOR PRIVACY QUESTIONS, RIGHTS REQUESTS AND APPEALS, SECURITY REPORTS, DATA-TRANSFER SAFEGUARDS, AND ANYTHING ELSE THIS POLICY REFERS TO. RIGHTS REQUESTS CAN ALSO BE SUBMITTED AT /privacy-choices.

We deliberately publish a single address rather than a directory of departmental ones. A published address that nobody monitors is worse than no address at all — it starts a statutory clock that no one is answering — so the address above is the one that receives mail, and everything routes from there.

Tell us in your message what you are writing about — a rights request, an appeal, a security report — and we will route it. If you need to reach us by post, or if you are in the European Economic Area or the United Kingdom and require the contact details of a representative appointed under Article 27 of the General Data Protection Regulation or the UK GDPR, ask at support@updrone.com and we will provide them.