dronAccess

Privacy Policy

Last updated: 27 August 2026.

Controller and service provider

ForceFlow Solutions Kamil Grykałowski
Address: ul. Urzędowska 34, 20-727 Lublin
NIP: 5214017791
REGON: 525217440
E-mail: kontakt@dronaccess.pl
Legal form: sole proprietorship registered in Poland

Privacy contact: rodo@dronaccess.pl. No data protection officer has been appointed; the controller handles privacy matters directly.

Data we process

We process operator account data, public profile details, private verification documents, content report data and limited technical data required for security and statistics. Directory visitors do not need an account.

Purposes

Operating the directory, authenticating operators, moderating profiles, handling reports, preventing abuse and measuring general website usage. dronAccess does not broker contracts or payments.

Purposes, data and legal bases

Operator account and profilelogin email, settings, business and contact details, description, services, equipment, photos, videos and file metadata, price-list versions and items, and service areaArticle 6(1)(b) GDPR — account contract; Article 6(1)(f) — security and legal claims
Google sign-inprovider identifier, name, email, email-verification status and optional profile imageArticle 6(1)(b) GDPR — creating a session and managing the selected sign-in method
Moderation and documentsprivate documents, file metadata and the history of profile, document, media and price-list decisionsArticle 6(1)(b) — account and publication; Article 6(1)(f) — directory trust and security
Public locationprivate base address and coordinates; only an optional displaced point is publicArticle 6(1)(b) — requested profile feature; it can be disabled without deleting the profile
Content reportsemail, optional name, report, profile and decisionArticle 6(1)(c) — illegal-content duties; Article 6(1)(f) — moderation and claims
Security and statisticslimited technical data, pseudonymous hashes and eventsArticle 6(1)(f) — protection, abuse prevention and service measurement
DronAccess Brief and Newsroom Enginepublic source URLs and content, titles, excerpts and cleaned text, working AI outputs, provenance and review history, and public professional information such as a person’s name, position, role, business or quotationArticle 6(1)(f) GDPR — legitimate interests in providing an information service, producing original industry coverage and keeping UAS operators informed; the data is not used to profile individuals
Newsletteremail and consent record, only if launched and selectedArticle 6(1)(a); consent may be withdrawn

Data source and requirement

Data comes from operators, reporters, user devices and security providers. DronAccess Brief materials come from public websites, official notices, industry media and manufacturer materials. Required account fields are necessary to operate and moderate a profile. Public contact and approximate location are optional as marked. Visitors may browse without an account.

Publishing contact details

Operators choose the phone number or email intended for publication. Contact details are retrieved only after a visitor action and protected by reveal limits and, when required, Turnstile.

Public and private data

Only approved or operator-selected profile elements may be public: name, declared business or private-operator status, description, services, languages, equipment, photos, videos, the last approved price-list version, website, YouTube channel, voluntarily provided Facebook, Instagram and TikTok profiles, approved credential types and, depending on settings, phone, email and a displaced location. The private base address, exact coordinates, login data, document scans, draft and pending price-list versions, and moderation history are not part of the public profile. Social links can be removed and phone, email or location publication can be disabled without deleting the account.

Cookies and device storage

We do not use advertising cookies. Necessary mechanisms support user-requested functions, security and saved settings. Plausible starts only after analytics consent; it does not store a user identifier in cookies or localStorage, although its script may read a technical measurement opt-out flag from localStorage.

Name or mechanismProvider and purposeRetention
sb-…-auth-token (cookie, may be split)Supabase — signed-in operator or administrator sessionUntil sign-out or session expiry
dronaccess-locale (cookie)dronAccess — remembering the language only after an explicit language choice, sign-in or account preference save; merely opening /pl, /en or /uk does not set it12 months
dronaccess:cookie-notice (localStorage)dronAccess — remembering that the cookie information was shownUntil the notice version changes or the user removes it
dronaccess:theme (localStorage)dronAccess — remembering the selected light or dark themeUntil removed by the user
dronaccess_contact_device (localStorage)dronAccess — contact reveal limits and scraping protection30 days, then automatically rotated
Turnstile technical dataCloudflare — human verification, loaded only when a challenge is requiredAccording to Cloudflare policy
Plausible — consent-based analyticsPlausible Analytics EU — loaded only after consent; aggregate views and events without storing a user identifier in cookies or localStorageAccording to the retention configured in Plausible
Vercel Speed Insights — no app-specific persistent identifierVercel — Web Vitals, loading-time and technical performance measurement; form contents and account identifiers are not sentAccording to Vercel settings and retention

Statistics and security

Public profile views are deduplicated on the server for 30 minutes using a one-way hash of technical data. The deduplication hash expires after 30 minutes, profile statistics are retained for no more than 24 months, and technical contact reveal attempts for no more than 24 hours. Plausible receives no addresses, coordinates, phone numbers, emails or Supabase account identifiers.

Retention

Active account data is held until deletion or termination. Profile data, price-list drafts and versions, and private files are deleted from active systems with the account. A video removed by the operator or with the account is deleted from the active Cloudflare Stream library before its application record is removed; technical data may remain until the end of the provider’s applicable cache, backup or log cycle under the contract. Newsroom discoveries, source content, working AI outputs, provenance, review status and decision history are retained for as long as needed to prepare, verify, document and correct a publication, and then under the editorial retention policy and applicable claims requirements. Default periods are: contact reveal and upload counters 1 day; anti-abuse events 30 days; read notifications 180 days; unread notifications 365 days; profile statistics 730 days; resolved reports, moderation audit and pseudonymous deletion receipts 1095 days. Open reports remain until resolved. Under Supabase Pro, the database is backed up daily; the latest seven backups and project logs are retained for approximately 7 days. Database backups contain Storage metadata, not file contents, which are protected separately. After termination of the provider service, a documented window of up to 30 days may apply for data download and deletion. Deleted data may remain in secured backups until the relevant overwrite cycle ends and is not restored for ordinary use. OVHcloud email and log retention follows the currently applicable plan and confirmed provider rules. Legal proceedings or claims may require longer retention. Application retention periods are centrally configured and enforced by a daily cleanup task.

Providers

We use Supabase for database, authentication and files, Google for optional OAuth sign-in, Vercel for hosting and performance, OVHcloud for email, Mapbox for search and maps, Cloudflare Turnstile and Stream, OpenAI for DronAccess Brief editorial assistance, TradeDoubler for offer feeds and affiliate-link handling after a click, Plausible Analytics EU, Sentry and UptimeRobot. Only public source material and data necessary to prepare a working editorial draft is sent to OpenAI, not operator-account data. Google sign-in supplies an account identifier, name, email, its verification status and a profile image where Google makes it available. We do not request contacts, Drive files or advertising data. Providers receive limited technical data only where necessary for the relevant service.

Recipients and international transfers

Recipients include Supabase Pte. Ltd. for database, authentication and files, with the primary project region in Frankfurt; Google LLC for optional OAuth sign-in, where Google also processes data as an independent controller under its own privacy terms; Vercel for hosting, delivery and performance measurement; OVHcloud for email; Mapbox, Inc. for location search and maps; Cloudflare for Turnstile and Stream direct upload, encoding, thumbnails, storage and adaptive video delivery; OpenAI as the provider assisting with working DronAccess Brief editorial materials; Plausible Analytics OÜ for aggregate analytics stored in the EU; Sentry for error diagnostics; and UptimeRobot for availability monitoring. Only public source material needed for editorial work, not operator-account data, is sent to OpenAI. Google and Cloudflare may process data in and outside the EEA through their global infrastructure using the transfer mechanism applicable to the relevant processing. Public profile data is available to visitors, while verification documents are restricted to authorised administrators and necessary infrastructure providers. Current provider and safeguard details are available from rodo@dronaccess.pl. An assessment in progress is not represented as completed.

Your rights

You have rights of access, rectification, erasure, restriction, portability where applicable, objection to legitimate-interest processing and withdrawal of consent. Contact us; identity verification may be required. You may complain to the Polish UODO. We do not make solely automated legal decisions or advertising profiles.

Children

Operator accounts are intended for adults or persons validly authorised by a business and are not directed at children.