This addendum (hereinafter, the "Addendum") governs the processing of personal data between the Client of the DRONCORE service (hereinafter, the "Controller") and ESDINET SCP, with Spanish tax ID (CIF) J25715848, owner of the website https://www.droncore.com (hereinafter, the "Processor"), under article 28 of Regulation (EU) 2016/679 of 27 April, the General Data Protection Regulation ("GDPR") and of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD").
This Addendum forms an integral part of the Terms of Service and applies automatically whenever, in connection with the use of the Service by the Controller, the Processor processes personal data on its behalf. In the event of any conflict between the Terms of Service and this Addendum regarding data protection, this Addendum shall prevail.
The Controller and the Processor are jointly referred to as the "Parties". The capacity of Controller corresponds to the Client with respect to the personal data that it processes through the Service in relation to its own users, pilots, employees, collaborators, end clients, data subjects or third parties. With respect to the Client's own contact, billing or administrator-user data, the Processor acts as controller in accordance with its Privacy Policy, a matter excluded from this Addendum.
-
SUBJECT MATTER, NATURE AND PURPOSE OF THE PROCESSING.
Through this Addendum the Controller entrusts the Processor with
the processing of personal data necessary for the provision of
the DRONCORE Service, consisting of a cloud platform for
operational management, documentation and traceability of
unmanned aircraft (UAS) operators and related activities. The
processing comprises, by way of example, the operations of
collection, recording, structuring, storage, consultation, use,
disclosure by transmission, matching, interconnection, restriction,
erasure and, where applicable, the making of backup copies and
technical-support tasks. The purpose of the processing is
exclusively the provision of the Service to the Controller in
accordance with the Terms of Service.
The Processor may additionally process the information resulting from the use of the Service in strictly anonymised or aggregated form, such that it does not allow any natural person to be identified directly or indirectly, for its own purposes of internal metrics, operational intelligence, usage study, technical diagnostics, maintenance, security, measurement and improvement of the Service. To the extent that such information is effectively anonymised in accordance with applicable standards (including, where applicable, the AEPD and EDPB guidelines on anonymisation), it shall cease to constitute personal data and its processing shall fall outside the scope of this Addendum. - DURATION. This Addendum shall have the same duration as the Service agreement and shall remain in force for as long as the Processor retains personal data of the Controller in its systems or under its control, until returned, deleted or anonymised as provided below.
- DATA PROCESSED AND CATEGORIES OF DATA SUBJECTS. The detailed types of personal data to be processed and the categories of data subjects affected are set out in Annex I of this document. By using the Service, the Controller may extend or modify, within the Service's functional limits, the types of data uploaded. The Controller shall be solely responsible for such extension or modification and for having a sufficient legal basis for it.
- OBLIGATIONS OF THE CONTROLLER. The Controller is responsible for, by way of example: (i) determining the purposes and means of the processing; (ii) having a sufficient legal basis for each processing in accordance with article 6 GDPR and, where applicable, article 9 GDPR; (iii) complying with the information duties towards data subjects in accordance with articles 13 and 14 GDPR; (iv) handling the exercise of data subject rights; (v) carrying out, where appropriate, the data protection impact assessment (DPIA) and the prior consultation with the supervisory authority; (vi) properly configuring the parameters of the Service, the permissions of its Users and the applicable retention periods; (vii) not uploading to the Service special categories of personal data (article 9 GDPR) or data relating to criminal convictions and offences (article 10 GDPR) unless strictly necessary for the purpose for which it uses the Service and it has a sufficient legal basis, in which case it assumes full responsibility for such processing; (viii) issuing written instructions to the Processor as required, with the instructions contained in this Addendum and in the Terms of Service, as well as those issued through the usual Service administration channels, being considered documented instructions.
-
OBLIGATIONS OF THE PROCESSOR. The Processor
undertakes to:
- Process personal data only on the Controller's documented instructions and exclusively for the provision of the Service, not using them for any other purpose nor disclosing them to third parties except where legally authorised or required by Union or Member State law applicable to the Processor, in which case it shall notify the Controller in advance unless legally prohibited.
- Ensure that persons authorised to process personal data commit, expressly and in writing, to respect confidentiality and to comply with the corresponding security measures.
- Adopt the appropriate technical and organisational measures to ensure a level of security appropriate to the risk in accordance with article 32 GDPR, as set out in Annex II, which measures may evolve in accordance with the state of the art.
- Assist the Controller, as far as possible and by means of appropriate technical and organisational measures, in handling requests to exercise data subject rights (access, rectification, erasure, objection, restriction, portability, automated decisions), making available to the Controller the Service functionalities that allow this. Where data subjects contact the Processor directly, the Processor shall forward the request to the Controller without undue delay.
- Assist the Controller in ensuring compliance with the obligations arising from articles 32 to 36 GDPR (security, breach notification, DPIA and prior consultation), taking into account the nature of the processing and the information available to the Processor.
- At the Controller's choice, delete or return the personal data once the provision of the Service ends, as well as delete existing copies, unless their retention is required by Union or Member State law.
- Make available to the Controller the information necessary to demonstrate compliance with the obligations of article 28 GDPR, as well as allow and contribute to audits as provided below.
- Inform the Controller, as soon as possible, if in its opinion any instruction infringes the GDPR, the LOPDGDD or any other data-protection provision.
- CONFIDENTIALITY. The Processor guarantees that all persons authorised to process personal data are bound by the duty of confidentiality in accordance with article 5.1.f) GDPR. This obligation shall remain in force even after the end of the relationship with the Processor.
- SECURITY MEASURES. The Processor shall apply the technical and organisational measures appropriate to the risk described in Annex II. Such measures may be reviewed and updated by the Processor in accordance with the state of the art, the costs of implementation, the nature and the risks of the processing, always ensuring an equivalent or higher level of protection.
-
SUB-PROCESSORS. GENERAL AUTHORISATION.
The Controller expressly authorises the Processor to subcontract with third parties the processing of personal data necessary for the provision of the Service. The list of authorised sub-processors in place at the time of acceptance of this Addendum is set out, for information purposes, in Annex III.
The Processor may add new sub-processors or replace existing ones, notifying the Controller through the usual Service notification means or by updating the published list, with a minimum of thirty (30) days' advance notice before the effective addition or replacement. The Controller may object, on legitimate grounds, within that period, in which case the Parties shall negotiate in good faith an alternative solution; if none is reached within a reasonable period, the Controller may terminate the Service agreement without penalty.
The Processor shall enter into with each sub-processor a contract imposing data-protection obligations equivalent, as applicable, to those set out in this Addendum. The Processor shall be liable for the sub-processor's compliance with the obligations arising from the processing, as provided in article 28.4 GDPR.
- INTERNATIONAL TRANSFERS. Processing shall preferably take place within the European Economic Area (EEA). However, the Controller acknowledges and accepts that, for the provision of the Service and for operational, infrastructure or Service- evolution reasons, international data transfers to countries outside the EEA may exist or need to be articulated through cloud providers, DJI, other providers of integrated services, sub- processors or future tools. In such cases, the Processor shall ensure that such transfers are carried out under one of the safeguards provided for in articles 44 et seq. of the GDPR, including, where applicable, adequacy decisions of the European Commission, Standard Contractual Clauses (SCCs) approved by the European Commission, binding corporate rules or other valid mechanisms, adopting, where appropriate, the supplementary technical, organisational or contractual measures required by the regulations and by the interpretative criteria of the supervisory authorities.
- SECURITY BREACH NOTIFICATION. The Processor shall notify the Controller, without undue delay and, whenever technically possible, within seventy-two (72) hours of becoming effectively aware, of any personal data breach affecting the data processed on the Controller's behalf, providing, to the extent available: (i) the nature of the breach, including where possible the categories and approximate number of data subjects and records affected; (ii) the contact details for obtaining further information; (iii) the likely consequences; and (iv) the measures adopted or proposed to remedy it and mitigate its possible adverse effects. Notification to the Controller shall not in itself imply any recognition of liability by the Processor. It shall be the Controller's responsibility, where applicable, to notify the supervisory authority and to communicate with data subjects in accordance with articles 33 and 34 GDPR.
- AUDIT. The Controller may verify the Processor's compliance with this Addendum through audits, with a maximum annual frequency, unless a supervisory authority imposes a higher frequency or an incident warrants it. Audits shall be carried out upon prior written notice with a minimum of thirty (30) days' advance notice, during business hours, without disrupting the operation of the Service, respecting the confidentiality and rights of the Processor's other clients and at the Controller's cost, unless they reveal a material breach attributable to the Processor. The Processor may satisfy its obligation to allow audits by providing current certifications, independent third-party audit reports or compliance questionnaires, where these reasonably evidence the matters to be verified.
- FATE OF THE DATA UPON TERMINATION. Upon termination of the Service, the Processor, at the Controller's choice, shall return or delete the personal data processed on its behalf. The Controller shall have a period of no less than thirty (30) calendar days from the effective termination to export its data through the tools made available. After that period, the Processor may proceed to the secure deletion of the data, unless a Union or Member State rule requires its retention, in which case it shall remain blocked until the end of the applicable legal period. Existing backup copies shall be deleted in accordance with the Processor's ordinary backup rotation cycles.
- LIABILITY. The liability of the Parties towards data subjects and supervisory authorities shall be governed by the provisions of articles 82 GDPR and related articles. In the internal relationship between the Parties, each shall be liable for damages caused to the other by breach of its data-protection obligations. The total and aggregate liability of the Processor towards the Controller arising from or related to this Addendum shall be subject to the same quantitative limits and exclusions as those set out in the Terms of Service, unless a mandatory rule provides otherwise.
- EFFECTIVENESS AND AMENDMENT. This Addendum shall take effect upon acceptance of the Terms of Service or upon the effective commencement of processing, whichever occurs first. The Processor may amend this Addendum to adapt it to regulatory changes, decisions of supervisory authorities, industry standards or technical evolution of the Service, notifying the Controller at least thirty (30) days before its entry into force. If the Controller does not accept the amendments, it may terminate the Service agreement without penalty by notifying prior to such date.
- APPLICABLE LAW AND JURISDICTION. This Addendum shall be governed by Spanish law. The Parties, expressly waiving any other jurisdiction, submit to the Courts and Tribunals of the city of Lleida, unless a mandatory rule establishes another jurisdiction, without prejudice to the competence of the Spanish Data Protection Agency (AEPD) in accordance with applicable law.
Annex I. Description of the processing
Subject matter of the processing: provision of the DRONCORE Service in accordance with the Terms of Service.
Nature and purpose: operational management, documentation and traceability of UAS operators and related activities, including storage, consultation, structuring and, where applicable, backup of the information uploaded by the Controller.
Duration: that of the Service agreement and, as necessary, the subsequent statutory retention period.
Categories of data subjects (depending on the data the Controller decides to upload to the Service):
- User, administrator and operator persons of the Controller.
- Pilots, technical, maintenance personnel and collaborators.
- Clients, suppliers and other third parties with whom the Controller has an operational relationship.
- Persons who may appear, incidentally, in images or recordings captured by the aircraft and uploaded to the Service.
Categories of personal data (depending on the Controller's decision):
- Identification and contact data (name, surname, DNI/NIE, email, phone, address).
- Professional and training data (position, pilot licences, certifications, flight hours, qualifications).
- Activity and operation data (operations carried out, aircraft used, incidents, maintenance).
- Image and video data captured with aircraft and uploaded by the Controller.
- Geographic location data associated with operations and flights.
- Technical metadata (access logs, IP addresses, user agent, actions carried out on the platform).
Special categories of data (art. 9 GDPR) and data relating to criminal convictions and offences (art. 10 GDPR): in principle not foreseen. The Controller is responsible, under its exclusive decision and responsibility, for not uploading such data unless it has a sufficient legal basis and does so out of justified necessity for the purpose of the Service.
Annex II. Technical and organisational security measures
The Processor shall apply, on an indicative and evolving basis in accordance with the state of the art, the following categories of security measures, with the detail and under the terms appropriate at any given time:
- Access control: access to the Service by means of individual credentials, password policy, lockout after failed attempts, roles and permissions per User and, where applicable, two-factor authentication on administration interfaces.
- Communications: traffic encryption via TLS/HTTPS on the channels exposed to the Controller and its Users.
- Storage: hosting in data centres with physical and logical security measures, logical segregation between clients, encryption of credentials and of those fields whose sensitivity justifies it.
- Backups: periodic backup copies for operational continuity purposes and rotation in accordance with the cycles established by the Processor, which do not constitute an historical archive service or long-term preservation service.
- Traceability: logging of relevant administration accesses and actions, in the terms technically feasible.
- Vulnerability and update management: periodic application of security patches to the operating system, dependencies and components of the Service.
- Protection against malicious software: reasonable perimeter protection measures and measures for the Processor's systems.
- Incident management: internal procedure for the detection, analysis and response to security incidents and, where applicable, notification to the Controller in accordance with this Addendum.
- Staff training and confidentiality: written confidentiality commitments from authorised personnel and basic training in data protection.
- Secure deletion: procedures for logical deletion and, where appropriate, secure erasure of information upon termination of the contract or when retention periods are met.
The measures listed are of a general and evolving nature; their detail, parameterisation and evolution correspond to the Processor in accordance with the state of the art, the costs of implementation, the nature of the processing and the risks to data subjects. The Processor may replace any of them with others of equivalent or higher level without the need for individualised approval by the Controller.
Annex III. Authorised sub-processors
As of the effective date of this Addendum, the Processor relies, for the provision of the Service, on the following categories of sub-processors:
- Infrastructure and hosting provider in the European Union, for the hosting of the Service, databases and file storage.
- Transactional email provider, for sending notifications, confirmations and alerts associated with the Service.
- Payment gateway provider, when the Service is paid for by card or electronic means.
- Support and development providers contracted by the Processor and subject to the corresponding confidentiality and processing agreements where applicable.
- External integration services contracted by the Controller and activated by it through the Service (for example, synchronisation services with aircraft manufacturers, airspace services or weather services), under the terms and conditions of the relevant third party.
The named and updated list of specific sub-processors and, where applicable, their location, may be provided by the Processor upon written request from the Controller addressed to droncore@droncore.com. Additions, removals and replacements shall be communicated in accordance with clause 8 of this Addendum.