This notice explains what personal data Layer400 receives, why it is used, who it is shared with and the choices available to you.
Last updated
1. Who is responsible
The operator of the Layer400 service is the controller of personal data described in this notice. Formal controller and supplier details applicable to a paid service will be provided before purchase. Privacy questions and rights requests can be sent to [email protected].
2. The data we receive
Account data
Username, email address, verification state, profile fields, organisation, unit and display preferences, account role, plan, security settings and a record of important account events. Passwords are handled by the identity service and are not available to the map.
Receiver and contributor data
Private station name, account relationship, declared capabilities, approximate or precise receiver position supplied during enrolment, software and hardware status, uptime, diagnostics, credential identifiers and contribution statistics.
Remote ID observations
Time-stamped radio reports can contain a broadcast identifier, aircraft serial or session identifier, position, height, speed, direction, status and—where a broadcast standard includes it—the position of the remote pilot or take-off point. We also record which station reported an event and quality or confidence information.
Website and security data
IP address, request time, browser or app information, pages and actions, session identifiers, error reports, rate-limit events and records needed to detect abuse or investigate security incidents.
Location you request on the map
The live map can ask the browser for your location after you press the locate control. Layer400 does not save that precise one-off fix to your account or send it as a dedicated location field. Centring the map requests map tiles and live data for the viewed area, so OpenFreeMap and Layer400 receive ordinary network information and the requested vicinity. The Forget control removes the on-map location display; receiver enrolment is separate and submits the fixed station position you confirm.
Messages and support
Information you include in an enquiry, correction, security report, survey or application, together with the response and any evidence reasonably needed to handle it.
3. Why we use it
to create accounts, authenticate users and provide requested features;
to enrol receivers, route credentials, measure coverage and attribute contribution statistics;
to receive, reconcile, quality-check and display Remote ID observations;
to preserve useful history, investigate integrity and improve network performance;
to prevent fraud, misuse, unauthorised extraction and attacks;
to respond to support, correction, rights and security requests;
to meet legal, regulatory, accounting and safeguarding obligations; and
to communicate material service information and, where permitted, optional news.
4. Our lawful bases
Depending on the activity, we rely on performance of a contract, our legitimate interests in operating and securing a useful receiver network, compliance with legal obligations, or consent. We use consent for optional marketing and for device permissions such as browser geolocation where required. You can withdraw consent, but that does not affect earlier lawful processing.
Our legitimate interests include service delivery, data integrity, security, network planning, proportionate research and protecting legal rights. We consider the likely impact on people and apply access controls, field reduction, rate limits and public-display safeguards where appropriate.
5. Public and restricted information
The public map is designed to show a limited observation view, not an account directory or registry lookup. Some received fields may be shortened, delayed, grouped, withheld or limited to authorised roles. Exact receiver locations are restricted operational data and are not exposed through ordinary map use.
A broadcast identifier is not necessarily a person’s name, but it may still relate to an identifiable operator when combined with other information. Do not attempt to re-identify, target or publish a person from Layer400 data.
6. Retention
Account and receiver records are kept while the relationship is active and for a period afterwards where needed for security, disputes, fraud prevention and legal obligations. Security-log periods are set according to the risk and will be recorded in the retention schedule before public account launch.
Restricted raw receiver messages and decoded observations have a hard technical maximum of 30 days, except that encrypted backups and a documented legal or incident hold may persist for their separate controlled period. Derived, minimised history may be retained for longer to provide replay, measure coverage and investigate integrity. The approved retention schedule will state the period or decision criteria for each dataset before public ingestion launch. A paid entitlement changes access; it does not determine underlying retention.
7. Sharing and processors
We use providers for hosting, database, authentication, email, monitoring and support where those services are enabled. OpenFreeMap supplies the public map style and tiles; visiting a map sends it network request information and the map area requested by your browser. Before public account launch, this notice will link the current subprocessor list and identify each provider’s role and processing location. Access is limited to what each provider needs.
We may disclose data to professional advisers, a buyer of the service, or a competent authority where required by law or necessary to protect people and legal rights. We do not sell personal data or provide an unrestricted public API containing raw observations or exact receiver locations.
8. International processing
Some service providers may process data outside the United Kingdom. Where data-protection law requires it, we use an adequacy decision, recognised contractual safeguards or another lawful transfer mechanism, and assess additional protections where appropriate.
9. Security
We use measures intended to reduce risk, including separate receiver credentials, access controls, encryption in transit, restricted administration, logging, backups and credential revocation. No online system is risk-free. Please follow the security reporting process instead of publishing a vulnerability before it can be addressed.
10. Your rights
Depending on the circumstances, UK data-protection law gives you rights to access, correct, erase or restrict personal data; object to processing; receive certain data in a portable form; and withdraw consent. You can also complain to the UK Information Commissioner’s Office. We may need to verify identity and may lawfully retain or withhold some information.
Because Remote ID is received from radio broadcasts rather than collected from an account holder, we may need the time, location, identifier and supporting evidence to locate a record and assess a request safely.
11. Children
Layer400 is not designed to collect children’s personal information. A person who is not legally able to manage an account or receiver agreement should use the service through a responsible adult. Please tell us if you believe a child’s personal data has been submitted inappropriately.
12. Changes and contact
We will update the date and, for material changes, provide an appropriate notice. Contact [email protected] for a privacy question or rights request. Use the corrections route for a specific observation.