Data Handling & Compliance

Effective date: July 3, 2026

Last updated: July 3, 2026

1. Overview

DroneIt360 (JKautomatic Inc.) provides a property-inspection platform that captures, organizes, and delivers photo evidence and standardized forms to insurance carriers, MGAs, and their inspectors. This statement summarizes the data we handle, where it lives, who processes it, and the safeguards and compliance practices we follow.

2. Categories of data we process

  • Account data: name, email, role, company, phone.
  • Inspection data: property address, insured/owner name, insurance company, policy and claim numbers (when provided by the customer), inspection form answers.
  • Media: property photos and imported drone imagery.
  • Evidence metadata: precise GPS coordinates and accuracy, capture and server-receipt timestamps, and an append-only audit trail of capture and edit events.
  • Technical data: device and OS details, app version, IP address, and diagnostic logs.

3. Data residency and storage

All production data is stored and processed in the United States. Core data (accounts, inspection records, photos) is held in our cloud backend (Supabase: managed PostgreSQL, authentication, and object storage). Our web and marketing site runs on a dedicated, hardened server. On the web app, image bytes may be cached in the user’s browser (IndexedDB) to support offline use.

4. Subprocessors

Subprocessor Purpose Data involved
Supabase Database, authentication, file/photo storage Account, inspection, media, metadata
Cloud hosting provider Web app and website hosting Web/site traffic, logs
Brevo (Sendinblue) Transactional and contact email Name, email, message contents
Apple App Store / Google Play App distribution and any in-app purchases Distribution and purchase data (per their policies)

We maintain a current list of subprocessors and will provide reasonable notice of material changes to business customers under contract.

5. Security controls

  • Encryption: TLS for data in transit; encryption at rest for stored data and backups.
  • Access control: database row-level security (RLS) enforcing role-based access (inspector vs. client); least-privilege administrative access; key-based SSH only for infrastructure.
  • Integrity: append-only audit logging of who captured and edited each piece of evidence; server-side receipt timestamps.
  • Network hardening: firewalling, brute-force protection (fail2ban), security headers (HSTS and related), and restricted service exposure.
  • Secrets management: service-role and infrastructure keys are never embedded in the client app; the app uses scoped, RLS-protected credentials.
  • Monitoring and patching: routine OS and dependency updates and log review.

6. Insurance data and GLBA

Certain inspection data may constitute nonpublic personal information (NPI) under the Gramm-Leach-Bliley Act (GLBA). When we process such information on behalf of an insurance carrier or MGA, we act as that customer’s service provider and handle NPI consistent with the GLBA Safeguards Rule and our contract with the customer, including maintaining reasonable administrative, technical, and physical safeguards and restricting use to the purposes the customer authorizes. A Data Processing Agreement (DPA) is available for business customers on request.

7. Consumer privacy laws

We support compliance with U.S. state consumer-privacy laws, including the California Consumer Privacy Act as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, and other states. We do not sell personal information or share it for cross-context behavioral advertising. Consumer rights requests are handled as described in our Privacy Policy; where a business customer controls the data, we assist and, where appropriate, refer the request to that customer.

8. Data subject / consumer rights handling

Requests to access, correct, delete, or port personal information can be submitted to droneit360@outlook.com. We verify the requester’s identity or authority before acting, respond within the timeframes required by applicable law, and coordinate with the relevant business customer when the data was collected on their behalf.

9. Retention and deletion

We retain data for as long as needed to provide the Services and to meet evidentiary, audit, legal, and contractual obligations, then delete or de-identify it. Business customers may direct retention and deletion of records they control. Users may request account deletion in-app or by email.

10. Incident response and breach notification

We maintain an incident-response process to detect, contain, investigate, and remediate security incidents. In the event of a data breach affecting personal information, we will notify affected business customers and, where required, individuals and regulators, within the timeframes required by applicable law and contract.

11. Business continuity and backups

Production data is backed up on a regular schedule, with backups encrypted and retained to support recovery.

12. Contact

Security and compliance inquiries: droneit360@outlook.com

JKautomatic Inc. (DroneIt360), 4904 202nd St, Lubbock, TX 79424