Last updated: 26 August 2026
This policy explains how supadrone.com ("SupaDrone", "we", "us") handles personal data.
It covers two things that are usually kept apart: the ordinary personal data of people who hold accounts with us, and personal data that appears incidentally in aerial imagery captured during missions. The second is the reason this policy is longer than a standard software privacy notice.
1. Who is responsible for what
Account and service data. SupaDrone is the controller for personal data relating to account holders and users of the service.
Mission capture. Where a customer commissions a mission, the customer determines the purpose of the capture and is the controller in respect of personal data appearing in the resulting imagery. SupaDrone acts as processor for that imagery on the customer's behalf.
Operational records. SupaDrone is the controller for the record of what flew, when, under what approvals and conditions, and under whose supervision. We hold this in our own right because we remain accountable for flights we have conducted, and we retain it independently of any customer relationship.
SupaVault listings. Where a site owner opts in to listing capture, SupaDrone is the controller in respect of the listed material.
Where SupaDrone acts as processor, a data processing agreement applies in addition to this policy.
2. Personal data we collect
2.1 From account holders
- identity and contact data: name, business email, telephone number, job title, organisation;
- account data: credentials, authentication events, roles and permissions, account and team membership;
- transaction data: purchases, mission charges, balances, payout details for Hosts, and billing address;
- usage data: pages viewed, features used, requests made, device and browser information, IP address;
- communications: support requests, correspondence and their content.
2.2 From missions
Aerial capture of a real place can include personal data even though the subject of the mission is a site or an asset. In practice this means:
- images of people who happen to be present at or near the site during a flight;
- vehicles, including registration plates;
- property belonging to people other than the customer, including neighbouring land and buildings.
People are never the subject of a mission. We do not offer surveillance of individuals, and we do not accept requests whose purpose is the observation of identified people. Capture of this kind is incidental to photographing a place, and we treat it as personal data rather than as scenery.
2.3 Location data
Missions are flown at fixed, registered sites. We hold the location of those sites, the flight radius approved for each, and the position information associated with capture, which is what makes an image locatable and repeatable.
3. Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Providing the service you asked for: requesting, validating, flying and delivering missions | Performance of a contract |
| Taking payment, invoicing and paying Host fees | Performance of a contract, and legal obligation for tax records |
| Keeping the operational record of flights conducted | Legal obligation under aviation and safety requirements, and legitimate interests in being able to account for our operations |
| Safety, security, fraud prevention and service integrity | Legitimate interests |
| Incidental personal data appearing in mission capture | Legitimate interests of the customer and of SupaDrone in inspecting and surveying sites, balanced against the rights of those captured. See section 4 |
| Listing capture in SupaVault | The opt-in agreement of the site owner, and our legitimate interests in operating the marketplace, subject to the safeguards in section 4 |
| Service communications and support | Performance of a contract |
| Marketing communications | Consent, or legitimate interests where permitted for existing business contacts |
Where we rely on legitimate interests, we have carried out a balancing assessment and can provide a summary on request.
4. Safeguards on mission imagery
Because incidental capture is unavoidable when photographing real places, the controls sit around what happens to it rather than around whether it occurs.
- Missions are planned around the asset they were commissioned to inspect. Capture outside that scope is not the purpose of the flight and is not delivered as a finding.
- Access to delivered capture follows the account that commissioned the mission. Hosting the pod a mission flew from does not grant access to that mission.
- Before capture from an opted-in site is offered for licence, it is reviewed against the rule that listings are of places and never of people.
- We do not use mission imagery to identify individuals, and we do not apply facial recognition or biometric identification to it.
- Customers commissioning missions at their own sites are required to inform people routinely present there that aerial inspection takes place.
5. Who we share it with
Service providers. Hosting and database infrastructure, payment processing, email delivery, error monitoring and analytics. Each is bound by contract to process personal data only on our instructions.
Hosts and site owners. Where sharing or listing is enabled, the limited information necessary to operate that arrangement: that a mission was flown, and what is payable. Not the content of another customer's capture.
Aviation and regulatory authorities. Operational records where required by law or by the terms of an approval.
Professional advisers, insurers and auditors where necessary and subject to confidentiality.
Acquirers in connection with a sale or reorganisation of the business.
We do not sell personal data.
6. International transfers
Where personal data is transferred internationally, we rely on an adequacy decision where one applies, and otherwise on standard contractual clauses together with any additional measures the transfer requires. Details of the safeguards for a specific transfer are available on request.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of the account, and for a limited period after closure |
| Delivered mission capture | For the period agreed with the customer, so that later missions remain comparable. Deletable on request, subject to section 8 |
| Operational flight records | For as long as required to remain accountable for flights conducted |
| Transaction and tax records | For the period required by applicable tax law |
| Support correspondence | For as long as needed to resolve the enquiry and any follow-up |
| Listed SupaVault material | While the listing is active, and thereafter for the duration of licences already granted |
8. Limits on deletion
Two limits apply to deletion requests, and we state them plainly rather than leaving them to be discovered:
- The operational record of a flight is retained separately from delivered capture, because we remain accountable for having conducted it.
- Material already licensed to a third party under an opt-in listing continues under that licence. Withdrawing a listing stops future offers and does not reach back through licences already granted.
9. Your rights
Subject to the conditions in applicable data protection law, you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on it.
If you appear in mission imagery and are not a customer of ours, you can still exercise these rights. Because we usually act as processor for mission capture, we will pass the request to the customer who controls it, and will tell you who that is where we are permitted to. Contact privacy@supadrone.com with enough detail about the location, date and approximate time for the material to be found.
You also have the right to lodge a complaint with your local data protection authority.
10. Security
We maintain technical and organisational measures appropriate to the risk, including access control on a least-privilege basis, encryption in transit and at rest, tenant isolation enforced at the database layer, audit logging of access to mission data, and supervised operator access to flight systems.
11. Automated decision-making
We do not make decisions producing legal or similarly significant effects about individuals by automated means. Automated processing is used to validate missions against availability, weather, equipment health and site operating constraints, which concerns whether a flight can proceed rather than any individual.
12. Children
The service is intended for organisations and is not directed at children. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy. Material changes will be notified before they take effect, and the date at the top of this page always reflects the current version.
14. Contact
Data protection enquiries: privacy@supadrone.com.