This addendum (the «Addendum») governs the processing of personal data between the Client of the DRONCORE service (the «Controller») and ESDINET SCP, with Spanish tax ID (CIF) J25715848, owner of the website https://www.droncore.com (the «Processor»), pursuant to article 28 of Regulation (EU) 2016/679, of 27 April, General Data Protection Regulation («GDPR») and of Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights («LOPDGDD»).
This Addendum forms an integral part of the Terms of Service and applies automatically whenever, in connection with the Client's use of the Service, the Processor processes personal data on behalf of the Client. In the event of a conflict between the Terms of Service and this Addendum on data protection matters, this Addendum shall prevail.
The Controller and the Processor are referred to jointly as the «Parties». The capacity of Controller corresponds to the Client in respect of the personal data that the Client processes through the Service concerning its own users, pilots, employees, collaborators, end clients, data subjects or third parties. As regards the Client's own contact, billing or administrator user data, the Processor acts as controller as described in its Privacy Policy, a matter excluded from this Addendum.
- SUBJECT MATTER, NATURE AND PURPOSE OF THE PROCESSING. By means of this Addendum the Controller instructs the Processor to process the personal data necessary for the provision of the DRONCORE Service, consisting of a cloud platform for the operational, documentary and traceability management of unmanned aircraft (UAS) operators and related activities. The processing includes, on a non-exhaustive basis, the operations of collection, recording, structuring, storage, consultation, use, transmission, cross-referencing, interconnection, restriction, erasure and, where appropriate, backups and technical support tasks. The purpose of the processing is solely the provision of the Service to the Controller in accordance with the Terms of Service.
- DURATION. This Addendum shall have the same duration as the Service contract and shall remain in force for as long as the Processor keeps personal data of the Controller in its systems or under its control, until their return, erasure or anonymisation as set out below.
- DATA PROCESSED AND CATEGORIES OF DATA SUBJECTS. Details of the types of personal data processed and the categories of data subjects affected are set out in Annex I of this document. The Controller may, by using the Service, expand or modify, within the functional limits thereof, the types of data uploaded. The Controller shall be solely responsible for such expansion or modification and for having a sufficient legal basis for it.
- CONTROLLER OBLIGATIONS. The Controller shall, on a non-exhaustive basis: (i) determine the purposes and means of the processing; (ii) have a sufficient legal basis for each processing under article 6 GDPR and, where applicable, article 9 GDPR; (iii) comply with the information duties to data subjects under articles 13 and 14 GDPR; (iv) handle the exercise of data subjects' rights; (v) carry out, where applicable, the data protection impact assessment (DPIA) and prior consultation with the supervisory authority; (vi) correctly configure the Service parameters, the permissions of its Users and the applicable retention periods; (vii) not upload to the Service special categories of personal data (article 9 GDPR) or data relating to criminal convictions and offences (article 10 GDPR) unless this is strictly necessary for the purpose for which the Service is used and the Controller has sufficient legal basis, assuming in such case full responsibility for such processing; (viii) issue to the Processor the written instructions as necessary, with documented instructions being those contained in this Addendum and in the Terms of Service as well as those issued through the usual administration channels of the Service.
-
PROCESSOR OBLIGATIONS. The Processor undertakes to:
- Process the personal data only following the Controller's documented instructions and solely for the provision of the Service, not using them for any other purpose nor communicating them to third parties except where authorised by law or required by Union or Member State law applicable to the Processor, in which case it shall communicate this to the Controller in advance unless prohibited by law.
- Ensure that persons authorised to process personal data commit, expressly and in writing, to respect confidentiality and to comply with the corresponding security measures.
- Adopt the appropriate technical and organisational measures to ensure a level of security appropriate to the risk under article 32 GDPR, in accordance with Annex II, with such measures being able to evolve in line with the state of the art.
- Assist the Controller, insofar as possible and through appropriate technical and organisational measures, in handling data subjects' requests to exercise their rights (access, rectification, erasure, objection, restriction, portability, automated decisions), by making available to the Controller the Service features that enable this. Where data subjects address the Processor directly, the Processor shall forward the request to the Controller without undue delay.
- Assist the Controller to ensure compliance with the obligations arising from articles 32 to 36 GDPR (security, breach notification, DPIA and prior consultation), taking into account the nature of the processing and the information available to the Processor.
- At the Controller's choice, delete or return the personal data once the provision of the Service ends, as well as delete the existing copies, unless retention is required under Union or Member State law.
- Make available to the Controller the information necessary to demonstrate compliance with the obligations under article 28 GDPR, as well as allow and contribute to audits as set out below.
- Inform the Controller as soon as possible if, in its opinion, an instruction infringes the GDPR, the LOPDGDD or any other data protection provision.
- CONFIDENTIALITY. The Processor warrants that all persons authorised to process the personal data are subject to the duty of confidentiality under article 5.1.f) GDPR. This obligation shall continue even after the end of the relationship with the Processor.
- SECURITY MEASURES. The Processor shall apply the appropriate technical and organisational measures to the risk described in Annex II. Such measures may be reviewed and updated by the Processor in line with the state of the art, the costs of implementation, the nature and risks of the processing, always ensuring an equivalent or higher level of protection.
-
SUB-PROCESSORS. GENERAL AUTHORISATION.
The Controller expressly authorises the Processor to subcontract with third parties the processing of personal data necessary for the provision of the Service. The list of sub-processors authorised at the time of acceptance of this Addendum is set out, for information purposes, in Annex III.
The Processor may add new sub-processors or replace existing ones, notifying the Controller through the Service's usual means of communication or by updating the published list, with at least thirty (30) days' prior notice before their effective incorporation or replacement. The Controller may object, on legitimate grounds, within such period, in which case the Parties shall negotiate in good faith an alternative solution; if no agreement is reached within a reasonable time, the Controller may terminate the Service contract without penalty.
The Processor shall enter into a contract with each sub-processor imposing on it data protection obligations equivalent, as applicable, to those set out in this Addendum. The Processor shall be liable for the sub-processor's compliance with the obligations arising from the processing, under article 28.4 GDPR.
- INTERNATIONAL TRANSFERS. Processing shall be carried out preferably within the European Economic Area. If the provision of the Service requires international transfers to countries outside the EEA, the Processor shall ensure that such transfers are carried out subject to one of the safeguards provided for in articles 44 et seq. GDPR, such as adequacy decisions, Standard Contractual Clauses (SCCs) approved by the European Commission or other valid mechanisms, adopting, where applicable, the necessary supplementary measures.
- SECURITY BREACH NOTIFICATION. The Processor shall notify the Controller, without undue delay and, whenever technically feasible, within seventy-two (72) hours of actual knowledge, of any personal data breach affecting data processed on its behalf, providing, insofar as available: (i) the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; (ii) contact details for further information; (iii) the likely consequences; and (iv) the measures taken or proposed to address it and mitigate its possible adverse effects. Notification to the Controller shall not in itself imply any acknowledgment of liability on the part of the Processor. It shall be for the Controller, where applicable, to notify the supervisory authority and communicate to the data subjects under articles 33 and 34 GDPR.
- AUDIT. The Controller may verify the Processor's compliance with this Addendum through audits, with a maximum frequency of once a year, unless a supervisory authority imposes a higher frequency or an incident justifies it. Audits shall be carried out with prior written notice of at least thirty (30) days, during business hours, without disrupting the operation of the Service, respecting confidentiality and the rights of other Processor clients and at the Controller's cost, unless they reveal a material breach attributable to the Processor. The Processor may satisfy its obligation to allow audits by providing current certifications, independent third-party audit reports or compliance questionnaires, where they reasonably evidence the matters to be verified.
- DESTINATION OF THE DATA UPON TERMINATION. Upon termination of the provision of the Service, the Processor shall, at the Controller's choice, return or delete the personal data processed on its behalf. The Controller shall have a period of not less than thirty (30) calendar days from the effective termination to export its data through the tools made available. After that period, the Processor may proceed to the secure deletion of the data, unless a Union or Member State rule requires their retention, in which case they shall be blocked until the end of the corresponding legal period. Existing backups shall be deleted in accordance with the Processor's ordinary backup rotation cycles.
- LIABILITY. The liability of the Parties vis-à-vis data subjects and the supervisory authorities shall be governed by articles 82 GDPR and related provisions. In the internal relationship between the Parties, each shall be liable for damages caused to the other by breach of its data protection obligations. The total and cumulative liability of the Processor to the Controller arising from or in connection with this Addendum shall be subject to the same quantitative limits and exclusions provided for in the Terms of Service, unless a mandatory rule provides otherwise.
- EFFECTIVENESS AND AMENDMENT. This Addendum shall enter into force upon acceptance of the Terms of Service or upon the actual start of the processing, whichever occurs earlier. The Processor may amend this Addendum to adapt it to regulatory changes, supervisory authority decisions, industry standards or technical evolution of the Service, notifying the Controller with at least thirty (30) days' prior notice before its entry into force. If the Controller does not accept the amendments it may terminate the Service contract without penalty by notifying the Processor before such date.
- GOVERNING LAW AND JURISDICTION. This Addendum shall be governed by Spanish law. The Parties, expressly waiving any other jurisdiction, submit to the Courts and Tribunals of the city of Lleida (Spain), unless a mandatory rule establishes another jurisdiction, without prejudice to the competence of the Spanish Data Protection Agency (AEPD) under applicable law.
Annex I. Description of the processing
Subject matter of the processing: provision of the DRONCORE Service in accordance with the Terms of Service.
Nature and purpose: operational, documentary and traceability management of UAS operators and related activities, including storage, consultation, structuring and, where applicable, backup of the information uploaded by the Controller.
Duration: that of the Service contract and, where necessary, the legal retention period thereafter.
Categories of data subjects (depending on the data that the Controller decides to upload to the Service):
- Administrator and operator users of the Controller.
- Pilots, technical and maintenance staff and collaborators.
- Clients, suppliers and other third parties with whom the Controller has an operational relationship.
- Persons who may appear, incidentally, in images or recordings captured with aircraft and uploaded to the Service.
Categories of personal data (as decided by the Controller):
- Identification and contact data (name, surname, national ID number, email, telephone, address).
- Professional and training data (position, pilot licences, certifications, flight hours, qualifications).
- Activity and operational data (operations carried out, aircraft used, incidents, maintenance).
- Image and video data captured with aircraft and uploaded by the Controller.
- Geographic location data associated with operations and flights.
- Technical metadata (access logs, IP addresses, user agent, actions performed on the platform).
Special categories of data (art. 9 GDPR) and data relating to criminal convictions and offences (art. 10 GDPR): in principle not envisaged. The Controller is responsible, under its exclusive decision and liability, for not uploading such data unless it has a sufficient legal basis and does so by justified necessity for the purpose of the Service.
Annex II. Technical and organisational security measures
The Processor shall apply, on an indicative and evolving basis in line with the state of the art, the following categories of security measures, with the detail and in the terms that are appropriate from time to time:
- Access control: access to the Service through individual credentials, password policy, lockout on failed attempts, roles and permissions per User and, where applicable, two-factor authentication on administration interfaces.
- Communications: traffic encryption through TLS/HTTPS on the channels exposed to the Controller and its Users.
- Storage: hosting in data centres with physical and logical security measures, logical segregation between clients, encryption of credentials and of those fields whose sensitivity justifies it.
- Backups: periodic backups for operational continuity purposes with rotation under the cycles established by the Processor, without constituting a historical archive service or long-term preservation service.
- Traceability: logging of access and relevant administration actions, in the terms that are technically feasible.
- Vulnerability management and updates: periodic application of security patches to the operating system, dependencies and components of the Service.
- Protection against malicious software: reasonable perimeter and system protection measures on the Processor's side.
- Incident management: internal procedure for the detection, analysis and response to security incidents and, where appropriate, notification to the Controller as set out in this Addendum.
- Staff training and confidentiality: written confidentiality commitments of authorised staff and basic training in data protection matters.
- Secure deletion: logical deletion procedures and, where applicable, secure erasure of the information at the end of the contract or when retention periods are met.
The measures listed are of a general and evolving nature; their detail, parameterisation and evolution are the responsibility of the Processor, in line with the state of the art, the costs of implementation, the nature of the processing and the risks for data subjects. The Processor may replace any of them with others of equivalent or higher level without the need for individualised approval by the Controller.
Annex III. Authorised sub-processors
As at the effective date of this Addendum, the Processor relies, for the provision of the Service, on the following categories of sub-processors:
- Infrastructure and hosting provider within the European Union, for the hosting of the Service, databases and file storage.
- Transactional email provider, for the delivery of notifications, confirmations and alerts associated with the Service.
- Payment gateway provider, where the Service is paid for by card or electronic means.
- Support and development providers engaged by the Processor and subject to the corresponding confidentiality and, where appropriate, processing agreements.
- External integration services engaged by the Controller and enabled by the Controller through the Service (for example, synchronisation services with aircraft manufacturers, airspace services or weather services), in the terms and under the conditions of the relevant third party.
The nominative and updated list of specific sub-processors and, where applicable, their location, may be provided by the Processor at the written request of the Controller addressed to droncore@droncore.com. Additions, removals and replacements shall be communicated in accordance with clause 8 of this Addendum.