1. Parties and Scope of Agreement
These terms govern the use of UAV-Planner ("the Service"), provided by UAV-Planner ("the Provider"). The terms apply only to business customers (B2B). The Customer must be a legal entity (company/enterprise) and cannot be a consumer.
The Service is offered to customers in Europe/EEA. If the Customer is established outside Norway, these terms still apply unless otherwise agreed in writing.
Provider: UAV-Planner AS, org. no. 933 479 501, address Eidsdalsheia 17, 4634 Kristiansand S, Norway, email thomas.bjornson.larsen@uav-planner.com.
Customer: The legal entity that accepts the terms upon ordering/agreement.
2. Definitions
- Administrator: A user with administrative access in the Customer's organization, who can invite/create users and manage the Customer's account and settings.
- Pilot: A user who has access to register/plan and log flights.
- User: Any person who gains access to the Service through the Customer's account, including employees and approved subcontractors.
- Customer Data: Data that the Customer or Users register, upload, or generate in the Service (e.g., flight logs, flight zones, equipment data, certificates, and messages).
- Personal Data: Any information about an identified or identifiable natural person, cf. GDPR.
3. The Service
UAV-Planner is a cloud-based platform for managing drone operations, including (currently) functionality for maps and flight zones, flight logging, pilot and role administration, certificate and compliance overview, equipment registry, statistics/dashboards, internal messaging, and CSV export.
The Provider may further develop, modify, or remove functionality as part of ongoing product development. If the change is significant and negative for the Customer, the Customer shall be notified with reasonable notice.
Certain features may be marked as "beta" or "preview". Such features are offered "as-is" and may be changed or removed without notice.
4. Account, Creation, and Access
The Customer's Administrator account is created by the Provider. The Administrator then invites Users to create their user profile.
Authentication may occur via email and password, Google OAuth, or both. The Provider may introduce requirements for multi-factor authentication (MFA) and other security measures.
The Customer is responsible for ensuring that Users act in accordance with the terms and that access is revoked when a User should no longer have access.
5. Use of Subcontractors
The Customer may grant access to subcontractors/consultants who perform work on behalf of the Customer (one level). The Customer is responsible for the subcontractor's actions and for ensuring the subcontractor is bound by equivalent confidentiality and security obligations.
6. Customer's Responsibility (Regarding Regulations and Safe Operations)
UAV-Planner provides decision support and administrative support for planning and documenting drone operations. The Service is not legal advice and provides no guarantee that a specific operation is lawful.
The Customer and Users are at all times responsible for: (i) following applicable laws and regulations, (ii) obtaining necessary permits, (iii) performing their own risk and safety assessments, and (iv) ensuring personnel and equipment have necessary approvals/certificates.
The Customer shall have adequate insurance for their drone operations, including liability insurance where required or appropriate.
7. Support and Onboarding
The Provider offers onboarding at no extra cost unless otherwise agreed. Training courses may be offered as an additional service for a fee.
Support is offered via chat and email during business hours. The Provider may prioritize inquiries from the Customer's business managers/administrators. The Service is delivered with "best effort" uptime without a specific SLA unless otherwise agreed in writing.
We normally notify customers of planned maintenance by email to the Customer's Administrator with reasonable notice.
8. Subscription, Fees, and Payment
The Service is typically priced per Pilot license per agreement period (usually annually). Other payment intervals may be agreed in writing.
Subscriptions are invoiced in advance. If the number of Pilots exceeds the agreed number of licenses, the Provider shall notify the Customer to arrange additional licenses.
Price changes are notified at least 3 months before taking effect. Prices may be indexed annually according to Statistics Norway (SSB) Consumer Price Index (CPI).
In case of payment default, the Provider may restrict or suspend access when the Customer is 30 days past the first due date, after notice. Reopening may require that outstanding amounts are paid.
9. Trial Period
A trial period may be agreed in writing. Duration, scope, and any limitations are then specified in the agreement. Upon expiration of the trial period, access ends unless the parties enter into a paid subscription.
10. Data, Ownership, and Privacy
The Customer owns the Customer Data. The Customer grants the Provider a limited, non-exclusive right to store and process Customer Data to the extent necessary to deliver, operate, maintain, and improve the Service.
The Provider may use aggregated and/or anonymized data for analysis, statistics, troubleshooting, product development, and benchmarking, provided that data cannot be linked to identifiable individuals or the Customer where anonymization is required.
The Provider processes Personal Data on behalf of the Customer as a data processor. A Data Processing Agreement (DPA) is included as an appendix and governs the processing.
Upon termination, Customer Data is stored for up to 90 days for export. Thereafter, data is deleted or anonymized in accordance with the DPA. Flight history may be anonymized to preserve statistics and history without linking to identifiable persons.
11. Security
The Provider uses technical and organizational measures to protect Customer Data, including role-based access, Row-Level Security (RLS), audit logging, and password requirements. Accounts may require email verification and multi-factor authentication (MFA).
The Provider performs regular backups. Currently, daily backup with a 7-day recovery window (via Supabase) is used, subject to changes over time.
12. Acceptable Use
The Customer and Users shall not use the Service for illegal purposes, violate third-party rights, attempt to circumvent security measures, or overload/inject malicious code into the system.
Internal messaging is a support function delivered on a "best effort" basis. The Provider does not normally monitor message content but may access content during support inquiries, security incidents, or when necessary to comply with legal obligations. The Provider may remove or block content that is clearly illegal or suspend access in cases of serious misuse.
13. Intellectual Property Rights
The Provider (and any licensors) retains all intellectual property rights to the Service. The Customer receives a limited, non-exclusive, non-transferable right to use the Service during the agreement period.
The Customer shall not reverse engineer, copy, scrape, resell, offer as "white-label," or otherwise exploit the Service in violation of the terms.
Feedback and suggestions from the Customer may be freely used by the Provider to improve the Service without special compensation.
14. Confidentiality
The parties shall treat each other's confidential information as confidential and only use it to fulfill the agreement. This does not apply to information that is publicly known or must be disclosed by law or government order.
15. Liability and Limitation of Liability
The Service is delivered "as-is" and "as-available". The Provider does not guarantee that the Service is error-free or continuously available.
The Provider is not liable for indirect losses, including lost profits, loss of revenue, interruption losses, or losses resulting from the Customer's breach of regulations.
The Provider's total liability during the agreement period is limited to the amount the Customer has actually paid for the Service in the 12 months before the damage occurred, unless otherwise required by mandatory law.
16. Indemnification
The Customer shall indemnify the Provider against third-party claims resulting from the Customer's or Users' unlawful use of the Service, breach of regulations (including aviation regulations), or infringement of third-party rights.
17. Duration, Termination, and Suspension
The agreement runs for the agreed period and renews automatically unless terminated with 3 months' written notice before expiration.
The Provider may suspend or terminate the agreement with immediate effect for material breach, including: (i) payment default, (ii) illegal use, (iii) serious security breaches or circumvention attempts, (iv) use that exposes the Provider or third parties to significant risk, or (v) breach of confidentiality or IP rights.
Where practically possible, the Provider shall notify and give the Customer an opportunity to remedy the situation before suspension/termination. In serious cases, suspension may occur immediately.
Upon termination, the Provider may retain technical logs (e.g., audit logs) for a limited period for security, troubleshooting, and documentation, in accordance with the DPA and applicable regulations.
18. Force Majeure
The parties are not liable for delays or failures to perform due to circumstances beyond the party's control, including government orders, war, strikes, network failures, or failures by subcontractors.
19. Governing Law and Disputes
The agreement is governed by Norwegian law.
The parties shall first attempt to resolve disputes amicably through negotiations. If the parties do not agree within 30 days, either party may bring the matter before the ordinary courts with agreed venue in Kristiansand (Agder District Court), unless otherwise agreed in writing.
Appendix A – Data Processing Agreement (DPA)
This appendix is entered into between the Customer (Data Controller) and the Provider (Data Processor) and governs the processing of Personal Data in connection with the Service.
A1. Purpose, Nature, and Duration of Processing
Purpose: Deliver, operate, and support UAV-Planner, including user management, flight logging, equipment management, certificate management, messaging function, analysis, and troubleshooting.
Duration: During the agreement period and for a limited period after termination for export/deletion according to section A8.
A2. Categories of Data Subjects and Personal Data
Data Subjects: The Customer's employees and hired consultants/subcontractors who gain access to the Service.
Personal Data (typical): name, email, phone, address, role/affiliation, certificate information, flight history linked to pilot, and system logs (e.g., login).
A3. Data Processor's Obligations
The Data Processor shall process Personal Data only according to documented instructions from the Customer and ensure confidentiality, integrity, and availability.
A4. Security Measures
Measures include RLS, access control, logging, backup, and email verification/MFA where implemented. Further description may be attached and updated as needed.
A5. Sub-processors
The Data Processor may use sub-processors to deliver the Service. An updated list is included in Appendix B. The Customer is notified of significant changes.
A6. Assistance to the Customer
The Data Processor assists the Customer in fulfilling obligations related to access, rectification, deletion, restriction, data portability, and security, to the extent relevant to the Service.
A7. Incidents and Security Breaches
In case of a breach of Personal Data security, the Data Processor shall notify the Customer without undue delay and no later than 72 hours after the breach is discovered.
A8. Deletion/Return upon Termination
Customer Data is made available for export for up to 90 days after termination. Thereafter, Personal Data is deleted or anonymized unless storage is required by law. Flight history may be anonymized for statistical purposes.
A9. Audit
The Customer may request relevant documentation demonstrating compliance with this DPA. Audits/reviews are conducted with reasonable notice and in a manner that does not unnecessarily disrupt operations, and may be limited to once per year unless special circumstances exist.
Appendix B – Sub-processors
The Provider uses the following sub-processors as of today:
- Supabase (AWS): Database/storage and authentication (primary data platform). Region: EU.
- Vercel: Hosting/delivery of web application and analytics/speed insights.
- Google (OAuth): Login via Google OAuth (authentication).
- Sentry: Error tracking and monitoring.
- HubSpot: CRM/communication and customer dialogue (outside the core system).
- OpenStreetMap/related map services: Map data and tile servers.
Appendix C – Acceptable Use Policy (AUP)
The Customer and Users shall not:
- violate applicable laws or regulations (including aviation regulations)
- store, share, or send illegal content through the Service
- share sensitive personal data through messages beyond what is necessary for the purpose
- attempt to gain unauthorized access to the Service or other customers' data
- circumvent or attempt to circumvent security mechanisms
- reverse engineer, scrape, or copy the Service
- use the Service in a way that overloads or degrades availability for others
- use the Service contrary to its intended purpose
Contact
For questions about these terms, contact us at: thomas.bjornson.larsen@uav-planner.com