Cordaxis Universal RC Controller

Privacy policy

Version of 17 September 2026. This is the version recorded against your account when you accept it at sign-up. If it changes, we will ask you again.


1 Who handles your data

The controller is the owner of Cordaxis. For anything to do with your data, write to cordaxis.rc@gmail.com.

We have no Data Protection Officer, and given the size and nature of the processing we are not required to have one (GDPR Article 37). A person reads that inbox.

2 What we collect and why

Only what the program needs to work. We do not buy data, we do not sell yours, and there is no advertising or commercial profiling.

WhatWhyLegal basisHow long
Email and passwordTo have an account and sign inContract (Art. 6(1)(b))While the account exists
Name, username, photoSo people recognise you in the communityContractWhile the account exists
CountryProgram language and country rankingsContractWhile the account exists
Year of birthTo check you meet the legal minimum ageLegal obligation (Art. 6(1)(c))While the account exists
Forum, club and wall messages, with their photosSo the community existsContractSee section 5
Private messagesSo you can write to other pilotsContractSee section 5
Flight log, including the place and its coordinates if you enter themTo keep your record of flightsContractWhile the account exists, or until you delete it
Each confirmation of the safety notice before piloting: date and time, notice and terms versions, language, vehicle, output mode and profile nameTo show that you were warned before each sessionLegitimate interest (Art. 6(1)(f)): defence against claimsWhile the account exists
Inventory: batteries, consumables, photos and purchase linksSo you can track your gearContractWhile the account exists
Flight hours, streaks, levelRankings and progressContractWhile the account exists
Reports you file or receiveModerating the communityLegitimate interest (Art. 6(1)(f)): making it liveableSee section 5
Messages you send to support, from the program or from the website formTo answer youContract or, if you have no account yet, your own request (Art. 6(1)(b))2 years after closing
Purchase or donation dataBilling the subscription, receiving the donation and keeping accountsContract and legal obligation6 years, tax law

The flight log coordinates are optional. If you fill them in, they mark where you fly, which is sometimes your home. Only you can see them: the server's row-level rules do not let anyone else read them. Leave the field empty and the log works just the same.

What we do not do: the program sends no usage statistics, no crash reports and no telemetry of any kind. Errors stay written on your computer.

3 What is public and what is not

Photos you upload to the forum, the clubs and the wall live in a publicly readable store: anyone with the exact image address can see it without an account. When you retire a message, its photos are deleted from that store too.

4 Who we share them with

Nobody, except who we need to run this. And they do not all play the same role, which is a distinction that matters:

Who processes data on our behalf (processor, Article 28: may only use it to provide their service to us, under contract):

WhoWhat for
SupabaseDatabase, accounts and photo storage
ResendDelivers to us by email what you write in the website's contact form

Who decides on their own account (independent controller, not our processor):

WhoWhat for
PaddleSells the subscription. Paddle is the merchant of record: the customer buys from them, they issue the invoice, and they handle payment data as their own controller. We never see your card. Their policy: paddle.com/legal/privacy
PayPalTakes donations, on its own page: you enter the amount and your payment details there, and PayPal handles them as its own controller. It shows us your name, your email and the amount, as it does to anyone who receives a payment; the program stores none of it. Their policy: the paypal.com privacy statement for your country

Requests that leave your computer, not ours. In these cases we send them nothing: it is your machine asking for the file, so the other server sees your IP address just as it would if you visited their website.

WhoWhen
GiphyWhen downloading a GIF you picked. The search, by contrast, is done by our server: Giphy receives what you typed, but not your IP address
YouTubeThumbnail for a video linked in the forum
Horizon Hobby, Tamiya, Traxxas, DJI and other manufacturersWhen downloading a model's manual, which is requested from their own server

We will also hand over data to authorities where a legal order requires it.

5 How long we keep them

6 Your rights

You can exercise them from inside the program, under User settings → Privacy and your data, or by writing to cordaxis.rc@gmail.com. We answer within one month at the latest.

7 Where the data lives

Data is stored on Supabase servers in Ireland (region eu-west-1), that is, inside the European Union. Your data is not transferred to countries outside it.

The two exceptions are both on the website. It is hosted on Netlify, a US company, so visiting it sends your IP address to the United States. And what you write in its contact form reaches us by email through Resend, also a US company. Both transfers are covered by the Standard Contractual Clauses approved by the European Commission. The program itself does not go through there.

8 Children

To have an account you must be as old as your country's law requires: between 13 and 16 across the European Union depending on the member state (14 in Spain), 13 in the United States, 18 in India. That is why we ask for a date of birth at sign-up. We store only the year.

If we learn that someone below the minimum age has an account, we close it and delete their data. If you are a parent or guardian and think that is the case, write to cordaxis.rc@gmail.com.

9 Security

Everything travels encrypted to the server. Passwords are stored on the server as a cryptographic hash, never in the clear, and the program does not store your password on your computer: only a derived value used to recognise you when signing in offline, from which the password cannot be recovered. The session stored on your machine is encrypted by Windows with your user account's key.

Who can read what is decided by the server, not by the program, so modifying the program does not let anyone see other people's data.

If there is ever a breach that could affect you, we will tell you, and we will report it to the Spanish Data Protection Agency within 72 hours of becoming aware of it, as GDPR Article 33 requires.

10 Changes

If we change anything important we will tell you inside the program and you will have to accept the new version. Previous versions are archived.