Privacy

Privacy Policy

How UAV-Planner processes personal data – both as a data controller and as a data processor on behalf of our customers.

Version 0.1 • Last updated: January 25, 2026

1. Who We Are (Data Controller) and Contact Information

This privacy policy applies to UAV-Planner ("the Service"), provided by UAV-Planner ("we", "us").

For personal data that we process as data controller (e.g., on websites, in sales, customer dialogue, support, and invoicing), UAV-Planner is the data controller.

For personal data processed in UAV-Planner on behalf of our customers, the customer is normally the data controller, and UAV-Planner is the data processor. This is further regulated in the Data Processing Agreement (DPA) attached to the terms.

Provider: UAV-Planner AS, org. no. 933 479 501, address Eidsdalsheia 17, 4634 Kristiansand S, Norway, email thomas.bjornson.larsen@uav-planner.com

Contact point for privacy and security incidents: Thomas Bjørnson Larsen, thomas.larsen@assistancesystems.no

2. Who This Policy Applies To

  • Visitors to our websites and marketing platforms.
  • Contact persons at customers and potential customers (B2B).
  • Users of UAV-Planner who gain access through a customer account (for example, pilots and administrators).

UAV-Planner is a B2B service. Users are normally created by invitation from the customer's administrator, and use occurs as part of the customer relationship.

3. What Personal Data We Process

Which data is processed depends on your role (visitor, contact person, or user) and which features are used in UAV-Planner.

  • Identity and contact information: name, email, phone, address (where registered).
  • Account and authentication data: username/email, login history, MFA settings, password reset data, and technical identifiers related to login.
  • Role and organization information: which organization you belong to, roles/access, department, job title, and employment date (if the customer registers this).
  • Operation and flight data: flight zones, coordinates, radius, altitude, time, duration, flight type (VLOS/BLOS), pilot association, and history (may be personal data when linked to a pilot).
  • Certificate and competence information: certificate types, authorizations, issue date, expiry date, and documentation related to certification.
  • Equipment and resource data: registration of drones/equipment and any association with persons (e.g., who is responsible/associated).
  • Communication: support inquiries (chat/email), internal messages in the Service (including recipients, status, and content) when used by the customer.
  • Usage and event logs: audit logs (e.g., administrative changes), error logs, and performance data.
  • Privacy settings in the Service: choices related to anonymization/display (e.g., anonymous ID, full name, or organization name) and sharing of flights (open or within organization only).
  • Website data: cookies and analytics events (e.g., via Vercel Analytics and HubSpot) where enabled.

We ask that users do not enter special categories of personal data (e.g., health information) or other sensitive data in free-text fields or messages unless strictly necessary.

4. Purposes and Legal Basis

4.1 When UAV-Planner is a Data Processor (UAV-Planner)

When you use UAV-Planner through your employer/client, UAV-Planner processes personal data on behalf of the customer to deliver the Service (e.g., flight logging, equipment registry, certificate overview, internal messaging, access control, and reporting).

The customer determines the purpose and legal basis (under GDPR Article 6), and UAV-Planner processes the data in accordance with the customer's instructions and the Data Processing Agreement (DPA).

4.2 When UAV-Planner is a Data Controller

We process personal data as data controller in the following typical cases:

PurposeExamples of DataLegal Basis
Establish and manage customer relationshipsContact data, admin users, support inquiriesContract (b) and/or legitimate interest (f)
Operation, maintenance, and improvement of the ServiceTechnical logs, error logs (Sentry), eventsLegitimate interest (f)
Security, access control, and prevention of misuseLogin history, audit logs, IP addressesLegitimate interest (f) and/or legal obligation (c)
Invoicing, payment, and accountingInvoice and payment data, contact infoContract (b) and legal obligation (c)
Sending operational messages and important noticesEmail, name, customer associationLegitimate interest (f) and/or contract (b)
Marketing to businesses (B2B)Contact data, company, role, history (HubSpot)Legitimate interest (f) and/or consent (a)
Website usage analysisCookie/analytics events, IP addressConsent (a) where required
Enforcement of terms and handling of disputesLogs, communication, contract dataLegitimate interest (f) and/or legal obligation (c)

Where we process personal data based on legitimate interest (GDPR Art. 6(1)(f)), we have conducted a balancing test to ensure that the processing is necessary and that the data subject's privacy does not outweigh our interests.

During troubleshooting, we may process personal data to reproduce errors in production. We try to avoid using personal data in test environments and use anonymized or synthetic data where appropriate.

5. Sources of Personal Data

  • From yourself (for example, when you register profile information, contact support, or consent to cookies/newsletters).
  • From the customer's administrator (for example, when you are invited to UAV-Planner and assigned roles/access).
  • From authentication provider (Google OAuth) if used for login.
  • Automatically from use of the Service or websites (logs, events, cookies).

6. Who We Share Personal Data With

We do not share personal data with third parties unless necessary to deliver the Service, fulfill agreements, comply with legal requirements, or protect our legitimate interests.

6.1 Sharing Within the Customer's Organization

UAV-Planner is a multi-user service. Information may be visible to other users in the customer's organization, depending on roles, settings, and the customer's internal procedures.

6.2 Our Vendors (Data Processors/Sub-processors)

We use vendors for operations, security, and customer dialogue. Examples (as of today):

  • Supabase: Database and authentication
  • AWS: Infrastructure as part of the vendor chain
  • Vercel: Operations/hosting and analytics tools
  • Sentry: Error and event logging
  • HubSpot: CRM and marketing
  • Google: OAuth login if enabled
  • OpenStreetMap: Map data/tiles (IP address may be processed when fetching map tiles)

The list may be updated over time. For UAV-Planner customers, an updated overview of sub-processors will normally be included in the Data Processing Agreement (DPA) or attachment to the agreement.

Access to internal messages: We do not routinely monitor messages. However, when necessary, we may access message content to (i) provide support at the customer's request, (ii) investigate and handle security incidents or misuse, (iii) enforce terms (including removing/restricting illegal content), or (iv) comply with legal orders.

6.3 Authorities and Third Parties

We may disclose personal data if we are legally required to do so (for example, by order from authorities), or if disclosure is necessary to establish, exercise, or defend legal claims.

7. Transfer to Countries Outside the EEA

Core data for UAV-Planner is stored in the EU/EEA by default. Some vendors may nevertheless process limited personal data in or from countries outside the EEA (for example, in connection with support, analytics, or security logging).

Where this involves a transfer to a third country, we ensure a valid transfer mechanism, such as the EU Commission's Standard Contractual Clauses (SCC) and any supplementary measures.

8. Retention Period and Deletion

We retain personal data for as long as necessary for the purposes described in this policy and in accordance with agreements and legal requirements.

  • Customer data in UAV-Planner: stored during the agreement period. After termination, customer data is normally stored for up to 90 days to enable export/handover, then deleted or anonymized. Flight history may be anonymized to preserve statistics and history without direct personal linkage.
  • Audit logs and login history: normally stored for 12 months, unless longer storage is necessary for security, disputes, or legal requirements.
  • Backups: we use daily backups with a seven-day recovery window. Data may therefore exist in backups for a short period after deletion.
  • Invoice and accounting data: stored for as long as we are legally required to retain accounting documentation.

9. Your Rights

You have rights under data protection regulations, including:

  • Access to your personal data.
  • Rectification of incorrect data.
  • Erasure (where the conditions for erasure are met).
  • Restriction of processing in certain cases.
  • Data portability when processing is automated and based on consent or contract (where relevant).
  • To object to processing based on legitimate interest.
  • To withdraw consent where processing is based on consent (without affecting the lawfulness before withdrawal).

If you are a user of UAV-Planner through a customer (e.g., employer), you should primarily contact the customer's administrator for requests regarding access, rectification, or erasure. UAV-Planner will assist the customer as data processor.

You may also contact us directly (see contact information in section 1) if the request concerns personal data we process as data controller.

You have the right to lodge a complaint with the relevant supervisory authority. In Norway, this is the Norwegian Data Protection Authority (Datatilsynet).

10. Cookies and Analytics

We may use cookies and similar technologies on our websites and in connection with marketing tools.

  • Necessary cookies: used for basic functions and security.
  • Analytics: used to understand website usage (e.g., Vercel Analytics).
  • Marketing: may be used to follow up on B2B inquiries and campaigns (e.g., HubSpot).

Where required, we obtain consent before setting analytics/marketing cookies. You can change or withdraw consent at any time via cookie settings (where available).

11. Security

We use technical and organizational measures to protect personal data, including access control, role-based management (including RLS), logging of sensitive events, email verification, password requirements, and multi-factor authentication (MFA).

We limit access to personal data to employees and vendors who have a business need.

12. Changes to the Privacy Policy

We may update this privacy policy as needed, for example, due to changes in the Service or our vendors. For significant changes, we will notify the customer's administrator or publish an updated version on relevant platforms.

13. Contact

Questions about privacy may be directed to:

Thomas Bjørnson Larsen
Email: thomas.larsen@assistancesystems.no

General inquiries: thomas.bjornson.larsen@uav-planner.com