Last updated: 15 August 2026
This notice describes how Dronetrake processes personal data — on the website, on the platform and in the apps — under Regulation (EU) 2016/679 ("GDPR"). It is written to be read: if something doesn't add up, write to us.
Bluix Group Ltd, a company registered in England and Wales. For any request about your data: privacy@dronetrake.com.
For your account and billing data, we are the controller. For the data your organisation uploads and collects with the platform — flights, footage, volunteers' contacts, customers, people filmed by the cameras — the controller is the organisation, and we process that data as a processor on its behalf (Art. 28 GDPR; data processing agreement available on request). Decisions about what to film, whom to invite and how long to keep things rest with the organisation.
Account: name, email, phone number (optional), language, credentials (the password is stored only as a hash). Operations: missions, fleet, flights with tracks and telemetry, logbook, documents. Media and recordings: photos, videos and recordings of live streams — the latter encrypted with a key dedicated to each organisation. Safety from the field: bodycam positions, SOS alerts (including via SMS or satellite, with position and message). People without an account: contacts in the operational address book (name and phone number, for SMS invitations), requests sent from /rilievi or from pilots' public pages (name, contact details, location of the requested job), signers of contracts (name, IP address and device, as a guarantee of the signature), "drone found" reports. Support: tickets and emails. Technical logs: IP addresses and security events.
To provide the service you signed up for (Art. 6.1.b). For legal obligations: the flight log is kept for the period required by European UAS regulation (Art. 6.1.c). For legitimate interest: platform security, abuse prevention, defence of rights (Art. 6.1.f). With your consent, where needed: newsletter, forwarding a survey request to other operators — always off until you switch it on (Art. 6.1.a). No profiling, no selling of data.
Payments are handled by Creem as merchant of record: it is Creem that collects payment data, issues the receipt and applies VAT — we neither see nor store card numbers. For that data Creem is an independent controller, with its own privacy notice.
Infrastructure: netcup GmbH (servers, datacentre in Vienna, EU) and Hetzner Online GmbH (encrypted backup copies, Nuremberg, EU). SMS delivery: the message and the number pass through the sending provider and the recipient's telephone networks. Optional AI features: Anthropic (see the transfers section). Satellite devices, only if the organisation connects them: Ground Control/RockBLOCK (modem identifier and messages). The up-to-date list is available by writing to privacy@dronetrake.com.
The infrastructure that runs the platform is in the European Union, and operational data does not leave it for the provision of the service. The one exception, stated openly: the artificial-intelligence features — analysis of photos and frames, report drafts, ticket assistance — send the strictly necessary content to Anthropic (United States), with the Art. 46 GDPR safeguards provided by its data processing agreement and with no model training on your data. AI features are optional: if you don't use them, that content never leaves.
Encrypted connections (TLS). Live-stream recordings are encrypted with a key dedicated to each organisation. Backups are encrypted and replicated to an offsite copy in a separate datacentre. The logbook is an append-only ledger with an integrity chain. Support staff access to customer data is logged.
The flight log: for the period required by UAS regulation (currently three years), even after the account is closed. Recordings and media: for the time the organisation declares in its own retention policy — without an explicit choice, we delete nothing. Every deletion leaves a signed record (what, when, under which rule): that is certified deletion. Backups: local copies for 7 days plus the encrypted offsite copy. On account closure: you export your data, then we delete or anonymise what we are not required to keep.
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent: write to privacy@dronetrake.com and we reply within the GDPR time limits. If the data belongs to processing for which your organisation is the controller (for example, footage taken by its drone), the request goes to the organisation — and we help it respond. You always have the right to lodge a complaint with your national supervisory authority.
Only a technical session cookie (CSRF protection and language preference). No profiling cookies, no third-party trackers.
The Android app for flight synchronisation has a dedicated privacy page, with the exact list of what it processes: dronetrake.com/sync/privacy.