This Privacy Policy describes how ESDINET SCP, with Spanish tax ID (CIF) J25715848 and registered office in Spain (hereinafter, "DRONCORE" or the "Provider"), processes the personal data collected through the website https://www.droncore.com, the DRONCORE platform (hereinafter, the "Service") and the Provider's other communication channels.
This Policy shall be interpreted and applied in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), with Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD") and with Ley 34/2002 on Services of the Information Society and E-Commerce ("LSSICE").
1. Two roles of DRONCORE in data protection
DRONCORE acts, depending on the context, in two distinct roles:
- As controller, with respect to the personal data it collects and processes for its own management: contact data, data of the Client's administrator users, billing data, commercial communications, support, security and browsing on the website. This Policy describes such processing.
- As processor, with respect to the personal data that the Client uploads, generates or processes through the Service in relation to its own pilots, employees, collaborators, End Clients and third parties. Such processing is governed by the Data Processing Addendum and not by this Policy.
2. Controller
- Identity: ESDINET SCP
- Spanish tax ID (CIF): J25715848
- Email: droncore@droncore.com
- Website: https://www.droncore.com
Data Protection Officer (DPO): none has been appointed, as the circumstances set out in article 37 GDPR do not apply; nevertheless, any data-protection enquiry may be sent to the email address above.
3. Categories of data processed
DRONCORE may process, depending on the channel and the purpose, the following categories of personal data:
- Identification and contact data: name, surname, job title, company, email, phone.
- Account data: access credentials (passwords stored exclusively by means of an irreversible derivation function —hashing—), user identifier, role, permissions, preferences.
- Billing and payment data: company name, Spanish tax ID (CIF/NIF), tax address, payment-method data processed through certified payment gateways.
- Usage and browsing data: technical access logs, IP address, browser and device type, operating system, pages visited, time of access, actions carried out on the platform.
- Communications data: content of communications, enquiries, support requests, surveys, tickets.
No special categories of data within the meaning of article 9 GDPR or data relating to criminal convictions and offences (article 10 GDPR) are collected through the Provider's channels.
4. Purposes and legal bases for processing
| Purpose | Legal basis (art. 6 GDPR) | Retention |
|---|---|---|
| Management of sign-up, account and provision of the contracted Service | Performance of the contract (art. 6.1.b) | For the duration of the contract and applicable statutory limitation periods |
| Billing and tax management | Legal obligation (art. 6.1.c) | Up to 6 years (Spanish Commercial Code) or longer in accordance with tax regulations |
| Handling of information requests and commercial contact | Consent (art. 6.1.a) or pre-contractual measures (art. 6.1.b) | 1 year from last contact or until consent is withdrawn |
| Sending of commercial communications and newsletter | Consent (art. 6.1.a) or legitimate interest in communications to clients regarding similar products (art. 21.2 LSSICE) | Until consent is withdrawn or the user unsubscribes |
| Service security, fraud prevention and incident response | Legitimate interest (art. 6.1.f) in the protection of the Service and its users | Up to 12 months unless a specific incident is under investigation |
| Compliance with legal obligations (authority requests, commercial obligations, etc.) | Legal obligation (art. 6.1.c) | The period required by the applicable rule |
| Internal metrics, operational intelligence and Service improvement based on anonymised or aggregated information | Legitimate interest (art. 6.1.f) over personal data prior to anonymisation; no legal basis required once anonymised | For as long as it remains useful for the purpose, with no specific period after anonymisation |
With respect to platform usage data, the Provider may process the information resulting from the use of the Service in strictly anonymised or aggregated form, such that it does not allow any natural person to be identified directly or indirectly, for the purposes of internal metrics, operational intelligence, technical diagnostics, maintenance, security, measurement and improvement of the Service. To the extent that such information is effectively anonymised in accordance with applicable standards, it ceases to constitute personal data.
5. Recipients of the data. Processors
Personal data will be processed by DRONCORE and by its processors, duly bound by contract in accordance with article 28 GDPR. The categories of processors and sub-processors include, by way of example: cloud hosting and infrastructure providers, transactional email providers, payment gateways, support and development providers, and monitoring and security services. The updated list of processors and sub-processors may be requested from the Provider's email address and, with respect to the Service, is detailed in the Data Processing Addendum.
Beyond the foregoing, DRONCORE will not disclose personal data to third parties except (i) by legal obligation, (ii) upon request from competent authorities, or (iii) with the data subject's express consent.
6. International data transfers
Processing will preferably take place within the European Economic Area (EEA). However, for operational reasons, infrastructure reasons or the evolution of the Service itself, international transfers to countries outside the EEA may exist or need to be articulated through cloud providers, DJI, other providers of integrated services, sub-processors or future tools. In such cases, DRONCORE will ensure that such transfers are carried out under one of the safeguards provided for in articles 44 et seq. of the GDPR, including, where applicable, adequacy decisions of the European Commission, Standard Contractual Clauses (SCCs) approved by the Commission, binding corporate rules or other valid mechanisms, adopting, where appropriate, the supplementary technical, organisational or contractual measures required by the regulations and by the criteria of the supervisory authorities.
7. Automated decisions and profiling
DRONCORE does not take decisions based solely on automated processing that produce legal effects or significantly affect data subjects within the meaning of article 22 GDPR.
8. Data subject rights
Data subjects have the right to:
- access their personal data (art. 15 GDPR);
- request its rectification (art. 16);
- request its erasure (art. 17);
- request restriction of processing (art. 18);
- object to processing (art. 21), in particular to processing based on legitimate interest;
- request portability of their data (art. 20);
- withdraw consent at any time, without affecting the lawfulness of prior processing (art. 7.3);
- not be subject to automated decisions with legal effects (art. 22).
To exercise these rights, the data subject may contact the Provider by email at droncore@droncore.com, providing proof of identity. If no satisfactory response is obtained, the data subject may lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es.
9. Source of the data
Personal data processed by DRONCORE as controller originate from the data subject (by filling in forms, contracting the Service, communicating by email, etc.) or from the Client with respect to administrator users designated by the Client. With respect to data processed on behalf of the Client, the source is regulated in the Data Processing Addendum.
10. Data security
DRONCORE applies reasonable technical and organisational measures proportionate to the risk, taking into account the state of the art and the nature of the data processed, including access-control measures, encryption of communications (TLS/HTTPS), irreversible password hashing, logical segregation between clients, periodic backups, security updates and logging of relevant accesses. No security measure guarantees absolute protection against all possible risks.
11. Accuracy of the data
The user is responsible for the truthfulness, accuracy and currency of the data provided. If data of third parties is provided, the user warrants having informed and, where applicable, obtained the consent of such third parties, holding DRONCORE harmless against any claim arising from breach of this obligation.
12. Cookies
The processing of cookies on the website is governed by the Cookie Policy, which forms an integral part of this Policy.
13. Changes to the Policy
DRONCORE may modify this Policy to adapt it to regulatory changes or to the evolution of the Service. Versions are numbered and identified by their effective date. Previous versions are preserved immutably in /legal-archive/. Material changes will be communicated through the usual channels with reasonable advance notice and, where legally required, new acceptance will be requested.
Version 1.1 · effective as of: 2 October 2026.