Privacy
This explains what we collect, why, and what you can do about it. It is written to be read rather than to be survived.
The short version
We collect what the service needs, we send marketing only if you tick the box, we sell nothing to anyone, and your documents are yours.
Who is responsible
Drone Imagery Services Ltd, trading as Four Drills, is the data controller for your own account: the address you sign in with, what you pay, and how you use the service. Data questions go to hello@fourdrills.co.uk.
For the people you name in your pack, you are the controller and we are the processor. Your roster, the role who decides on a lockdown, anyone you record as needing help getting out: you entered them, you decide what your procedures say, and we process it on your instructions. That half is set out in full in our data processing agreement, which is a contract rather than a notice.
What we collect
| Your account | Your email address, and your name and organisation details if you give them. There is no password, ever: signing in is a six-digit code sent to your inbox, so there is no password for us to hold or to lose. |
|---|---|
| Your venue | The answers you give about your building: its exits, safer areas, entry points, assembly points, capacity assessment and the procedures generated from them. |
| Your staff | The name and role you enter for each person on your roster, and the record of which version of your procedures each of them confirmed reading, and when. A roster line holds those two fields and nothing else: we do not ask for your staff's email addresses or phone numbers and there is nowhere to put them. This is information about your employees and volunteers, entered by you, and you are its controller. |
| Activity | When a document was generated, downloaded or amended, who by, and from what address; when you signed in; and the checklist items you have marked as done. This is the evidence trail the product exists to produce. |
| Consent records | If you ask to hear from us, we record the address, what you agreed to, the page you agreed on, the date, and the date you withdrew if you do. Keeping the record is how we can show the agreement was real. |
| Payment | Handled by Stripe. Card details never reach our servers. We hold the customer and subscription references Stripe gives us, and what you paid. |
| What you ask the assistant | The question you type into the assistant, the answer it gives and the page you asked from. It is never tied to your account: there is no user id, no session id and no IP address on that record, and both halves are passed through a redactor that strips email addresses and phone numbers before the row is written. We keep it to find out what people actually ask, so the site can answer it before they have to. |
| The free scope check | The use category and capacity figure you entered, and the outcome, with no name attached. It tells us how many venues we turn away and why. The free record you can download from that screen creates no account and stores nothing else. |
Why, and on what basis
| To provide the service |
Running your walkthrough, generating your documents, keeping your
attestation trail and letting you download it. Basis: performance of
our contract with you.
Staff attestation is not live yet: it launches before duties commence (expected spring 2027) and is included in the price you pay today. |
|---|---|
| Service messages | Your sign-in codes, your download links, confirmation that your walkthrough is saved, notice that your review is due or your renewal is coming. Basis: performance of the contract. These are part of the service and are not marketing. If you start a walkthrough, give us your email address and then leave it unfinished, we send one reminder after three days and never a second. If you would rather we did not hold your answers, reply to it and we will delete them. |
| Marketing | Only if you ticked a box asking for it. Basis: consent. Every marketing email carries a one-click unsubscribe, and you can turn it off in your account at any time. |
| Keeping the service working and honest | Security logs, rate limiting, fraud prevention, and the counts that tell us where people get stuck. Basis: our legitimate interests in running a service that stays up and does what it says. |
Cookies
We set four cookies, all of them first-party, all of them strictly necessary, and none of them readable by JavaScript:
- fd_session keeps you signed in.
- fd_intake is how a walkthrough you have not finished is still there when you come back.
- fd_chat is the assistant's conversation, so it can follow what you asked a moment ago. It is a sitting rather than an identity: it expires when you close the browser, and after thirty minutes the conversation behind it is gone.
- fd_sent lasts two minutes and exists so the next page can tell you an email went out.
Because every one of them is needed to provide something you asked for, no consent banner is required by law and we do not show one. We set no advertising, analytics or tracking cookies, and there is no third-party origin in this site's content security policy, so one could not load even if somebody added it by accident. If that changes, this policy changes first.
We do not sell your data
Not to anyone, for any purpose, including anonymised or aggregated onward sale. Your venue's layout, your exits and your staff list are not a product.
Who else touches it
A small number of suppliers process data so the service can run. They act on our instructions and cannot use it for their own purposes:
- Hostinger, which runs the server and the database, in the United Kingdom (Manchester).
- Google Workspace (Google Ireland Limited), which delivers sign-in codes, service email and any documents we email you, and which holds the mailbox those messages are sent from and replied to. Google may process this outside the UK under its standard data protection terms.
- Stripe, which takes payments.
-
Anthropic (United States), which provides the automated
check of your walkthrough answers before your documents are made, and the
assistant on this site. For the check it receives your answers about your
building. It is not sent your staff roster: it is given
how many people are on it and what roles they hold, and told that we
withheld the names. It receives no email address, no account details, no
payment details and no contact details for anybody. It does not use any
of it to train its models.
The one thing we cannot control is what you type: an answer box asking for the job that decides on a lockdown will be sent as you wrote it, so if you put a person's name there rather than a role, that name goes with it. The help text on every one of those boxes asks for a role, for this reason among others.
Where it lives, and for how long
The application, its database and its nightly backups are held in the United Kingdom, on a Hostinger server in Manchester. The offsite copies go to Google Drive encrypted before they leave that server, so what reaches Google is ciphertext it has no key for.
Two things do leave the UK, and here is what covers them. Your answers are checked by a model that runs in the United States, and our mailbox is Google Ireland, which may process email elsewhere. Both transfers are made under each provider's data processing terms, which incorporate the Standard Contractual Clauses together with the UK International Data Transfer Addendum issued by the Information Commissioner. That is the legal mechanism, in the words the regulator uses, so you can check it rather than take our word for it. Nothing about your staff roster is in either transfer.
While your account is open we keep your data so the service works.
How long we keep it depends on whether you have ever paid. If you have, we keep your venue records for twelve months after you close your account, because compliance evidence that vanishes the moment you stop paying is not evidence. If you have never paid, we delete your account and its venue records six months after you last used it, and we email you thirty days before that happens so you can sign in and stop it. Signing in is enough, it costs nothing, and the six months start again from that day.
The two numbers are one rule: we keep what somebody is relying on, and we do not sit on a building's exit routes and staff details for years because an account was opened once and never used again.
Two things outlive that, and we would rather say so than be found out. Records of what you paid are kept for six years after the end of the accounting period they fall in, because UK tax law requires it. That is a legal obligation rather than a choice, and an erasure request cannot remove them.
And our backups are not instant. When we delete something it goes from the live service straight away, and it cannot be restored into service after that. It then ages out of our encrypted backups within seven months. Anyone who tells you their backups delete on request either has no backups worth having or has not thought about it.
There is a third thing to say about deletion, and it is the one most privacy notices leave out. Where a record proves something happened, we remove the name and keep the record. "Somebody confirmed version 3 on 4 March" survives; "Jane Smith" is replaced with a marker saying it was redacted, when, and on whose request. We cannot delete the row itself without destroying your own evidence that your staff were briefed, which is the thing you bought. A member of staff who never confirmed anything is deleted outright, because nothing depends on them.
Your organisation's own compliance records are kept and disposed of on your instruction: you can export everything at any time, including after you cancel, and ask us to delete it sooner.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable form. Withdraw marketing consent at any time without affecting anything else.
One caveat we would rather state than hide: where a record exists because your staff attested to a document, deleting it destroys your own evidence that they did. We will confirm before acting on that.
Staff attestation is not live yet: it launches before duties commence (expected spring 2027) and is included in the price you pay today.
If you are not happy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first, but you do not have to.
Last updated . We will change the date here whenever the substance of this page changes, and not for a wording tidy.
This page is not legal advice and not security advice. It describes what this service does and what we undertake to do. Decisions about your premises, and about how the Act applies to them, remain yours to take and are worth taking with someone qualified where the answer is not obvious.