Privacy Policy — Drone Ops Consultants
Version 1.0 · Effective 21 September 2026
Who we are
Drone Ops Consultants ("DOC", "we") is a trading name of Grey Rock Innovations Ltd, company number 11621288, registered in England and Wales at Orchard House, Clyst St Mary, Exeter, Devon, EX5 1BR. We run a paid directory that lists independent drone operations consultants so commercial drone operators can find and contact them. We are the data controller for the processing described here.
- Privacy contact: privacy@droneopsconsultants.com
- Data Protection Officer: Athlex Limited (contact via the privacy address, marked for the DPO)
- ICO registration: ZA891345
We are an introducer, not a party. We help an operator reach a consultant. We are not part of the engagement they go on to agree, and we do not provide consultancy ourselves. When we pass an operator's enquiry to a consultant, that consultant becomes an independent controller of the operator's data for their own purposes, and their privacy policy applies from that point.
Dronedesk and Drone Ops Consultants are both operated by Grey Rock Innovations Ltd. They are separate services run by the same company; listing with us does not create a Dronedesk account, and vetting and ranking are the same for everyone.
We offer the service in the UK, the US and the EEA. Because Grey Rock Innovations Ltd is UK-based, UK GDPR governs everything we do; where we serve people in the EEA, EU GDPR applies too. Our EU representative under Article 27 is DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Ireland (dronedesk@datarep.com). We do not offer the service in Switzerland.
The personal data we collect
Consultants (our paying customers, who hold accounts)
- Account: name, email, hashed password, company name, website, country.
- Business entity: entity type, registration number, VAT number.
- Identity verification: a verification session reference only. We do not store your ID document or selfie (see Identity checks below).
- Vetting evidence (private): insurance certificates and jurisdiction authorisation evidence, which may contain personal and business details. Held in a private store, never publicly served.
- Sanctions vetting: our own listing decision (approved or declined), plus a provider reference and the date screened. We do not store the screening result itself.
- Payment: Stripe customer and subscription identifiers. Card data is held by Stripe, never by us.
- Profile content you publish: bio, tagline, pricing, jurisdictions, services, images, and (Pro, optional) a link to your Google Business Profile, from which we show only its overall Google rating and review count.
- Communications and analytics: your enquiry-routing email, verification state, listing impressions and views, enquiry counts, and email delivery and open status.
Operators (enquirers, anonymous, no accounts)
When you send an enquiry we collect only what you submit: your name, organisation, email, your free-text requirement, and the jurisdiction and service you selected. We email this to the consultant you chose. We do not create an account for you, we do not run an on-platform relay, and we hold no identity data about you beyond the enquiry itself. Our enquiry form also uses bot-detection signals and your request carries an IP address in server logs.
Website visitors
Analytics events, bot-detection signals, and an IP address in server logs.
Why we use your data, and our lawful basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Provide the consultant account and subscription | Account, billing | Contract |
| Vet consultants before listing (identity, entity, sanctions, insurance) and evidence the "vetted before listing" claim | Vetting records and evidence | Legitimate interests |
| Pass an operator's enquiry to the chosen consultant | Enquiry data | Legitimate interests / the operator's own initiation of contact |
| Send service email (sign-in, enquiry alerts, insurance reminders, enquiry-count digest) | Consultant email, communications log | Contract / legitimate interests |
| Keep the service secure and prevent abuse | Enquiry signals, IP, hashed identifiers | Legitimate interests |
| Take payment and keep tax and accounting records | Billing | Contract / legal obligation |
| Product and funnel analytics | Analytics events (cookieless) | Legitimate interests |
| Marketing nurture to consultants | Email, name, company, lifecycle tags | Consent, captured at signup |
We only send marketing (our nurture emails to consultants) where you have given consent at signup, and you can withdraw it at any time using the unsubscribe link or by emailing us. Service emails, such as sign-in links and enquiry notifications, are separate and are not marketing.
Special-category and criminal-offence data
Sanctions screening. We screen consultant names against sanctions and PEP watchlists through a screening provider (OpenSanctions) as a vetting gate. By design we store only our own listing decision (approved or declined) and a neutral provider reference, never a result about the person.
Identity and biometric checks. Identity verification uses a third-party provider (Didit) that checks an ID document and a selfie. The selfie means biometric data is processed during that check. Didit carries out the processing; we store only a session reference, never the document or the biometric data. We rely on your explicit consent, captured at the point of the check, and Didit acts as our processor, processing this data in the EU.
Sub-processors and international transfers
We use the vendors below to run the service. Each is bound by a written contract and acts as our processor or, where marked, as an independent controller for its own regulated purposes.
| Sub-processor | What it does | Location |
|---|---|---|
| Supabase | Authentication, database, and private file storage | UK (London) |
| Vercel | Application hosting, edge and scheduled tasks | UK (London) |
| Stripe (independent controller for payments) | Payments, subscriptions, tax | US and global |
| Resend | Transactional email, including sign-in and enquiry notifications | US |
| UploadThing | Hosting of public profile images only | US (moving to EU, Dublin) |
| Cloudflare (Turnstile) | Bot protection on the enquiry form | Global |
| OpenPanel | Cookieless product analytics (internal) | EU (Germany) |
| Didit | Identity verification | EU |
| OpenSanctions | Sanctions and PEP screening | EU |
| Companies House (statutory) | UK company verification | UK |
| VIES (EU Commission) (statutory) | EU VAT number validation | EU |
| Google (Places API) | Fetches the overall rating and review count for a Google Business Profile a Pro consultant links (no review text) | US |
| Anthropic | AI extraction of insurance certificate details (human-reviewed; zero-retention, no-training terms) | US |
| Encharge | Marketing automation (consent-based) | US |
Our core data stays in the UK (Supabase, London). Some vendors process data in the EU, which UK adequacy regulations cover. Some are in the US, and those transfers rely on UK adequacy where it applies, or on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. Because we also serve the EEA, EEA-to-US transfers additionally rely on the EU Standard Contractual Clauses.
To ask about any sub-processor or a specific transfer, email privacy@droneopsconsultants.com.
How long we keep data
We keep personal data only as long as we need it:
| What | Kept for |
|---|---|
| Operator enquiry personal data | 12 months from the enquiry |
| Consultant vetting decision record | 24 months after cancellation |
| Consultant evidence and badge files | 24 months after cancellation |
| Insurance certificate files | 24 months after cancellation |
| Insurance record (insurer, policy reference, cover dates) | 24 months after cancellation |
| Email bodies | 90 days from sending |
| Email delivery metadata | 12 months from sending |
| Billing and accounting records | 6 years (retained by Stripe, HMRC) |
| Verification audit log | For as long as we run the directory, reviewed every 3 years |
When a period ends we delete the files, redact the enquiry and email personal data, and keep only stripped rows that identify no one (such as counts and badge or insurance status). Before we delete operator enquiry data we remind the consultant so they can export anything they still need. Our verification audit log is kept for accountability and is not deleted on the ordinary cycle (see Your rights).
How we keep data safe
Core data is held in the UK. Sensitive vetting files sit in a private store reachable only by server-side credentials, never publicly served. We enforce access control server-side with a default-deny backstop, encrypt data in transit (HTTPS/HSTS), use a strict nonce-based content security policy, verify the signature on every webhook, redact secrets and tokens before writing to our communications log, and protect the public enquiry form against bots and malformed input. No system is perfectly secure, but we take these measures seriously and review them as the service changes.
Your rights
You can ask us to give you a copy of your data, correct it, erase it, restrict or object to how we use it, or provide it in a portable form. Email privacy@droneopsconsultants.com. We respond within one month.
Erasure has limits, and we will explain what survives and why:
- Our verification audit log is not purged. It records who took which vetting action and when, and it is our accountability record. On an erasure request we restrict it to that purpose rather than deleting it.
- Vetting evidence kept to defend our "vetted before listing" claim is retained until its retention period ends, then deleted.
- Payment records are retained by Stripe under its own legal obligations.
Complaints. Please raise concerns with us first, at /privacy/complaint or the privacy address. We acknowledge within 30 days and tell you the outcome. You can also complain to the ICO (ico.org.uk, 0303 123 1113). If you are in the EEA, you can complain to your local supervisory authority at any time.
Cookies and tracking
We use very little, and nothing for advertising:
- Sign-in and session cookies (Supabase Auth): strictly necessary.
- Product analytics (OpenPanel): cookieless. It uses a salted-hash device identifier and IP-derived data rather than cookies, and attributes logged-in consultants by their account ID. It is processed in the EU (Germany). We use it for our own internal product analysis; operators and visitors stay anonymous.
- Bot protection (Cloudflare Turnstile, invisible mode): assesses browser and device signals for security only, never advertising. Because it runs invisibly there is no on-screen notice, so we point you to Cloudflare's Turnstile Privacy Addendum.
The listing statistics we show consultants (impressions and profile views) come from our own first-party counter, not from OpenPanel, and are aggregated. We do not use advertising or cross-site tracking cookies.
Automated processing
We do not make solely automated decisions that significantly affect you.
- Vetting is decided by a person. Automated checks gather information, but a human reviews the evidence and decides. If you are declined you can ask for the reason and ask a different person to review it.
- Insurance extraction uses AI with human review. To speed up the insurance gate, the content of an uploaded insurance certificate (such as the insured name, cover amounts and dates) is sent to an AI provider (Anthropic) to pre-fill the details. A person reviews and approves the result, so this is assisted automation, not an automated decision. We use Anthropic's API on zero-retention, no-training terms.
Children
This is a business service, not directed at children. We do not knowingly collect data from anyone under 18.
Changes
We may update this policy as the service or the law changes. The version and date at the top show which version you are reading. If a change materially affects how we use your data, we will tell affected consultants by email before it takes effect.