Version 0.1 • Last updated: January 25, 2026
1. Who We Are (Data Controller) and Contact Information
This privacy policy applies to UAV-Planner ("the Service"), provided by UAV-Planner ("we", "us").
For personal data that we process as data controller (e.g., on websites, in sales, customer dialogue, support, and invoicing), UAV-Planner is the data controller.
For personal data processed in UAV-Planner on behalf of our customers, the customer is normally the data controller, and UAV-Planner is the data processor. This is further regulated in the Data Processing Agreement (DPA) attached to the terms.
Provider: UAV-Planner AS, org. no. 933 479 501, address Eidsdalsheia 17, 4634 Kristiansand S, Norway, email thomas.bjornson.larsen@uav-planner.com
Contact point for privacy and security incidents: Thomas Bjørnson Larsen, thomas.larsen@assistancesystems.no
2. Who This Policy Applies To
- Visitors to our websites and marketing platforms.
- Contact persons at customers and potential customers (B2B).
- Users of UAV-Planner who gain access through a customer account (for example, pilots and administrators).
UAV-Planner is a B2B service. Users are normally created by invitation from the customer's administrator, and use occurs as part of the customer relationship.
3. What Personal Data We Process
Which data is processed depends on your role (visitor, contact person, or user) and which features are used in UAV-Planner.
- Identity and contact information: name, email, phone, address (where registered).
- Account and authentication data: username/email, login history, MFA settings, password reset data, and technical identifiers related to login.
- Role and organization information: which organization you belong to, roles/access, department, job title, and employment date (if the customer registers this).
- Operation and flight data: flight zones, coordinates, radius, altitude, time, duration, flight type (VLOS/BLOS), pilot association, and history (may be personal data when linked to a pilot).
- Certificate and competence information: certificate types, authorizations, issue date, expiry date, and documentation related to certification.
- Equipment and resource data: registration of drones/equipment and any association with persons (e.g., who is responsible/associated).
- Communication: support inquiries (chat/email), internal messages in the Service (including recipients, status, and content) when used by the customer.
- Usage and event logs: audit logs (e.g., administrative changes), error logs, and performance data.
- Privacy settings in the Service: choices related to anonymization/display (e.g., anonymous ID, full name, or organization name) and sharing of flights (open or within organization only).
- Website data: cookies and analytics events (e.g., via Vercel Analytics and HubSpot) where enabled.
We ask that users do not enter special categories of personal data (e.g., health information) or other sensitive data in free-text fields or messages unless strictly necessary.
4. Purposes and Legal Basis
4.1 When UAV-Planner is a Data Processor (UAV-Planner)
When you use UAV-Planner through your employer/client, UAV-Planner processes personal data on behalf of the customer to deliver the Service (e.g., flight logging, equipment registry, certificate overview, internal messaging, access control, and reporting).
The customer determines the purpose and legal basis (under GDPR Article 6), and UAV-Planner processes the data in accordance with the customer's instructions and the Data Processing Agreement (DPA).
4.2 When UAV-Planner is a Data Controller
We process personal data as data controller in the following typical cases:
| Purpose | Examples of Data | Legal Basis |
|---|---|---|
| Establish and manage customer relationships | Contact data, admin users, support inquiries | Contract (b) and/or legitimate interest (f) |
| Operation, maintenance, and improvement of the Service | Technical logs, error logs (Sentry), events | Legitimate interest (f) |
| Security, access control, and prevention of misuse | Login history, audit logs, IP addresses | Legitimate interest (f) and/or legal obligation (c) |
| Invoicing, payment, and accounting | Invoice and payment data, contact info | Contract (b) and legal obligation (c) |
| Sending operational messages and important notices | Email, name, customer association | Legitimate interest (f) and/or contract (b) |
| Marketing to businesses (B2B) | Contact data, company, role, history (HubSpot) | Legitimate interest (f) and/or consent (a) |
| Website usage analysis | Cookie/analytics events, IP address | Consent (a) where required |
| Enforcement of terms and handling of disputes | Logs, communication, contract data | Legitimate interest (f) and/or legal obligation (c) |
Where we process personal data based on legitimate interest (GDPR Art. 6(1)(f)), we have conducted a balancing test to ensure that the processing is necessary and that the data subject's privacy does not outweigh our interests.
During troubleshooting, we may process personal data to reproduce errors in production. We try to avoid using personal data in test environments and use anonymized or synthetic data where appropriate.
5. Sources of Personal Data
- From yourself (for example, when you register profile information, contact support, or consent to cookies/newsletters).
- From the customer's administrator (for example, when you are invited to UAV-Planner and assigned roles/access).
- From authentication provider (Google OAuth) if used for login.
- Automatically from use of the Service or websites (logs, events, cookies).
6. Who We Share Personal Data With
We do not share personal data with third parties unless necessary to deliver the Service, fulfill agreements, comply with legal requirements, or protect our legitimate interests.
6.1 Sharing Within the Customer's Organization
UAV-Planner is a multi-user service. Information may be visible to other users in the customer's organization, depending on roles, settings, and the customer's internal procedures.
6.2 Our Vendors (Data Processors/Sub-processors)
We use vendors for operations, security, and customer dialogue. Examples (as of today):
- Supabase: Database and authentication
- AWS: Infrastructure as part of the vendor chain
- Vercel: Operations/hosting and analytics tools
- Sentry: Error and event logging
- HubSpot: CRM and marketing
- Google: OAuth login if enabled
- OpenStreetMap: Map data/tiles (IP address may be processed when fetching map tiles)
The list may be updated over time. For UAV-Planner customers, an updated overview of sub-processors will normally be included in the Data Processing Agreement (DPA) or attachment to the agreement.
Access to internal messages: We do not routinely monitor messages. However, when necessary, we may access message content to (i) provide support at the customer's request, (ii) investigate and handle security incidents or misuse, (iii) enforce terms (including removing/restricting illegal content), or (iv) comply with legal orders.
6.3 Authorities and Third Parties
We may disclose personal data if we are legally required to do so (for example, by order from authorities), or if disclosure is necessary to establish, exercise, or defend legal claims.
7. Transfer to Countries Outside the EEA
Core data for UAV-Planner is stored in the EU/EEA by default. Some vendors may nevertheless process limited personal data in or from countries outside the EEA (for example, in connection with support, analytics, or security logging).
Where this involves a transfer to a third country, we ensure a valid transfer mechanism, such as the EU Commission's Standard Contractual Clauses (SCC) and any supplementary measures.
8. Retention Period and Deletion
We retain personal data for as long as necessary for the purposes described in this policy and in accordance with agreements and legal requirements.
- Customer data in UAV-Planner: stored during the agreement period. After termination, customer data is normally stored for up to 90 days to enable export/handover, then deleted or anonymized. Flight history may be anonymized to preserve statistics and history without direct personal linkage.
- Audit logs and login history: normally stored for 12 months, unless longer storage is necessary for security, disputes, or legal requirements.
- Backups: we use daily backups with a seven-day recovery window. Data may therefore exist in backups for a short period after deletion.
- Invoice and accounting data: stored for as long as we are legally required to retain accounting documentation.
9. Your Rights
You have rights under data protection regulations, including:
- Access to your personal data.
- Rectification of incorrect data.
- Erasure (where the conditions for erasure are met).
- Restriction of processing in certain cases.
- Data portability when processing is automated and based on consent or contract (where relevant).
- To object to processing based on legitimate interest.
- To withdraw consent where processing is based on consent (without affecting the lawfulness before withdrawal).
If you are a user of UAV-Planner through a customer (e.g., employer), you should primarily contact the customer's administrator for requests regarding access, rectification, or erasure. UAV-Planner will assist the customer as data processor.
You may also contact us directly (see contact information in section 1) if the request concerns personal data we process as data controller.
You have the right to lodge a complaint with the relevant supervisory authority. In Norway, this is the Norwegian Data Protection Authority (Datatilsynet).
10. Cookies and Analytics
We may use cookies and similar technologies on our websites and in connection with marketing tools.
- Necessary cookies: used for basic functions and security.
- Analytics: used to understand website usage (e.g., Vercel Analytics).
- Marketing: may be used to follow up on B2B inquiries and campaigns (e.g., HubSpot).
Where required, we obtain consent before setting analytics/marketing cookies. You can change or withdraw consent at any time via cookie settings (where available).
11. Security
We use technical and organizational measures to protect personal data, including access control, role-based management (including RLS), logging of sensitive events, email verification, password requirements, and multi-factor authentication (MFA).
We limit access to personal data to employees and vendors who have a business need.
12. Changes to the Privacy Policy
We may update this privacy policy as needed, for example, due to changes in the Service or our vendors. For significant changes, we will notify the customer's administrator or publish an updated version on relevant platforms.
13. Contact
Questions about privacy may be directed to:
Thomas Bjørnson Larsen
Email: thomas.larsen@assistancesystems.no
General inquiries: thomas.bjornson.larsen@uav-planner.com