dronAccess
Privacy Policy
Last updated: 27 August 2026.
Controller and service provider
ForceFlow Solutions Kamil GrykałowskiAddress: ul. Urzędowska 34, 20-727 Lublin
NIP: 5214017791
REGON: 525217440
E-mail: kontakt@dronaccess.pl
Legal form: sole proprietorship registered in Poland
Privacy contact: rodo@dronaccess.pl. No data protection officer has been appointed; the controller handles privacy matters directly.
Data we process
We process operator account data, public profile details, private verification documents, content report data and limited technical data required for security and statistics. Directory visitors do not need an account.
Purposes
Operating the directory, authenticating operators, moderating profiles, handling reports, preventing abuse and measuring general website usage. dronAccess does not broker contracts or payments.
Purposes, data and legal bases
| Operator account and profile | login email, settings, business and contact details, description, services, equipment, photos, videos and file metadata, price-list versions and items, and service area | Article 6(1)(b) GDPR — account contract; Article 6(1)(f) — security and legal claims |
|---|---|---|
| Google sign-in | provider identifier, name, email, email-verification status and optional profile image | Article 6(1)(b) GDPR — creating a session and managing the selected sign-in method |
| Moderation and documents | private documents, file metadata and the history of profile, document, media and price-list decisions | Article 6(1)(b) — account and publication; Article 6(1)(f) — directory trust and security |
| Public location | private base address and coordinates; only an optional displaced point is public | Article 6(1)(b) — requested profile feature; it can be disabled without deleting the profile |
| Content reports | email, optional name, report, profile and decision | Article 6(1)(c) — illegal-content duties; Article 6(1)(f) — moderation and claims |
| Security and statistics | limited technical data, pseudonymous hashes and events | Article 6(1)(f) — protection, abuse prevention and service measurement |
| DronAccess Brief and Newsroom Engine | public source URLs and content, titles, excerpts and cleaned text, working AI outputs, provenance and review history, and public professional information such as a person’s name, position, role, business or quotation | Article 6(1)(f) GDPR — legitimate interests in providing an information service, producing original industry coverage and keeping UAS operators informed; the data is not used to profile individuals |
| Newsletter | email and consent record, only if launched and selected | Article 6(1)(a); consent may be withdrawn |
Data source and requirement
Data comes from operators, reporters, user devices and security providers. DronAccess Brief materials come from public websites, official notices, industry media and manufacturer materials. Required account fields are necessary to operate and moderate a profile. Public contact and approximate location are optional as marked. Visitors may browse without an account.
Publishing contact details
Operators choose the phone number or email intended for publication. Contact details are retrieved only after a visitor action and protected by reveal limits and, when required, Turnstile.
Public and private data
Only approved or operator-selected profile elements may be public: name, declared business or private-operator status, description, services, languages, equipment, photos, videos, the last approved price-list version, website, YouTube channel, voluntarily provided Facebook, Instagram and TikTok profiles, approved credential types and, depending on settings, phone, email and a displaced location. The private base address, exact coordinates, login data, document scans, draft and pending price-list versions, and moderation history are not part of the public profile. Social links can be removed and phone, email or location publication can be disabled without deleting the account.
Statistics and security
Public profile views are deduplicated on the server for 30 minutes using a one-way hash of technical data. The deduplication hash expires after 30 minutes, profile statistics are retained for no more than 24 months, and technical contact reveal attempts for no more than 24 hours. Plausible receives no addresses, coordinates, phone numbers, emails or Supabase account identifiers.
Retention
Active account data is held until deletion or termination. Profile data, price-list drafts and versions, and private files are deleted from active systems with the account. A video removed by the operator or with the account is deleted from the active Cloudflare Stream library before its application record is removed; technical data may remain until the end of the provider’s applicable cache, backup or log cycle under the contract. Newsroom discoveries, source content, working AI outputs, provenance, review status and decision history are retained for as long as needed to prepare, verify, document and correct a publication, and then under the editorial retention policy and applicable claims requirements. Default periods are: contact reveal and upload counters 1 day; anti-abuse events 30 days; read notifications 180 days; unread notifications 365 days; profile statistics 730 days; resolved reports, moderation audit and pseudonymous deletion receipts 1095 days. Open reports remain until resolved. Under Supabase Pro, the database is backed up daily; the latest seven backups and project logs are retained for approximately 7 days. Database backups contain Storage metadata, not file contents, which are protected separately. After termination of the provider service, a documented window of up to 30 days may apply for data download and deletion. Deleted data may remain in secured backups until the relevant overwrite cycle ends and is not restored for ordinary use. OVHcloud email and log retention follows the currently applicable plan and confirmed provider rules. Legal proceedings or claims may require longer retention. Application retention periods are centrally configured and enforced by a daily cleanup task.
Providers
We use Supabase for database, authentication and files, Google for optional OAuth sign-in, Vercel for hosting and performance, OVHcloud for email, Mapbox for search and maps, Cloudflare Turnstile and Stream, OpenAI for DronAccess Brief editorial assistance, TradeDoubler for offer feeds and affiliate-link handling after a click, Plausible Analytics EU, Sentry and UptimeRobot. Only public source material and data necessary to prepare a working editorial draft is sent to OpenAI, not operator-account data. Google sign-in supplies an account identifier, name, email, its verification status and a profile image where Google makes it available. We do not request contacts, Drive files or advertising data. Providers receive limited technical data only where necessary for the relevant service.
Recipients and international transfers
Recipients include Supabase Pte. Ltd. for database, authentication and files, with the primary project region in Frankfurt; Google LLC for optional OAuth sign-in, where Google also processes data as an independent controller under its own privacy terms; Vercel for hosting, delivery and performance measurement; OVHcloud for email; Mapbox, Inc. for location search and maps; Cloudflare for Turnstile and Stream direct upload, encoding, thumbnails, storage and adaptive video delivery; OpenAI as the provider assisting with working DronAccess Brief editorial materials; Plausible Analytics OÜ for aggregate analytics stored in the EU; Sentry for error diagnostics; and UptimeRobot for availability monitoring. Only public source material needed for editorial work, not operator-account data, is sent to OpenAI. Google and Cloudflare may process data in and outside the EEA through their global infrastructure using the transfer mechanism applicable to the relevant processing. Public profile data is available to visitors, while verification documents are restricted to authorised administrators and necessary infrastructure providers. Current provider and safeguard details are available from rodo@dronaccess.pl. An assessment in progress is not represented as completed.
Your rights
You have rights of access, rectification, erasure, restriction, portability where applicable, objection to legitimate-interest processing and withdrawal of consent. Contact us; identity verification may be required. You may complain to the Polish UODO. We do not make solely automated legal decisions or advertising profiles.
Children
Operator accounts are intended for adults or persons validly authorised by a business and are not directed at children.