Legal

Privacy Notice

This Privacy Notice describes how Argoisten LLC handles personal information across argoisten.com, the AXR internal platform, and D510 UAV Operations.

Effective May 2, 2026

1. Introduction and data controller

Argoisten LLC ("Argoisten," "we," "us," or "our") operates the public website at argoisten.com, the internal AXR platform at axr.argoisten.com, and the D510 UAV Operations division. This Privacy Notice explains how we collect, use, disclose, retain, and safeguard personal information, and describes the rights available to individuals whose information we process. The data controller for personal information processed under this notice is Argoisten LLC, a limited liability company organized under the laws of the State of Texas, with a principal office in Midland, Texas.

2. Scope and applicability

This notice applies to personal information collected through the public website argoisten.com, the D510 quote request and intake forms, the contact form, the careers inquiry process, the AXR internal platform, internal communication systems including Relay, and any related Argoisten-operated digital services. It does not apply to third-party websites, services, or platforms that may be linked from our properties; those are governed by the privacy practices of their respective operators.

3. Categories of personal information we collect

Depending on your interaction with Argoisten, we may collect the following categories of personal information: identifiers (name, email address, telephone number, mailing address, account identifier, IP address); commercial information (services requested, project location, transaction records); professional or employment information (employer name, role, division assignment, time and shift records); geolocation information (project site coordinates and area geometries that you submit through the D510 mapping tool); internet or network activity (server logs, browser type, device identifiers, pages visited, referrer, timestamps); user-generated content (messages, attachments, quote details, project notes, news drafts); authentication and security information (hashed passwords, MFA enrollment, session tokens, recovery codes, fingerprinted session metadata); and inferences drawn from the categories above where reasonably necessary to operate the platform.

4. Sources of personal information

We collect personal information directly from you when you complete a form, sign in, send a message, or otherwise interact with our services. We collect information automatically through your device and browser when you access our properties, including server-side logs and security telemetry. For internal AXR users, we collect information from your employer of record (Argoisten) and from designated administrators who issue access codes and configure roles. We do not purchase personal information from data brokers.

5. Purposes of processing and legal bases

We process personal information for the following purposes: (a) to provide, operate, and secure argoisten.com, AXR, and D510 services; (b) to respond to and fulfill quote requests, contact requests, and other inquiries; (c) to schedule, mobilize, and document UAV operations, including airspace authorization filings and engagement records; (d) to administer accounts, authenticate users, and enforce role-based access; (e) to maintain operational records, time tracking, project history, communications, and audit trails; (f) to detect, investigate, and prevent fraud, abuse, security incidents, and policy violations; (g) to comply with applicable legal, regulatory, tax, accounting, and recordkeeping obligations, including Federal Aviation Administration ("FAA") Part 107 requirements; (h) to improve and develop our services; and (i) to enforce our agreements and protect the rights, property, or safety of Argoisten, our personnel, our clients, or others. Where required by law, our legal bases for processing include the performance of a contract, our legitimate interests in operating and securing our business, compliance with legal obligations, and, where applicable, your consent.

6. D510 quote-form and site geometry data

When you submit a D510 quote request, we collect the form fields you complete (such as name, company, email, phone, service requested, project location, site details, and message) and any optional geographic information you provide through the on-page satellite map (such as polygon vertices, dropped pins, computed acreage, and the centroid of your selection). This information is used solely to scope, schedule, price, and respond to that drone-services request, and to maintain a record of the engagement. Submission metadata, including IP address, user agent, and timestamp, is retained for fraud prevention, abuse detection, and security review. Quote-form geometry is not used for unrelated marketing or sold to third parties.

7. Cookies and similar technologies

We use a small number of strictly necessary cookies and similar technologies to operate our services. These include an authentication session cookie used by AXR to keep you signed in, which is HttpOnly, Secure, and SameSite-controlled. We do not use third-party advertising cookies, behavioral tracking pixels, or cross-site retargeting technologies. We do not knowingly serve content that loads ad-tech trackers. The public site may use locally stored preferences (such as theme selection) which are kept on your device only.

8. How we share personal information

We share personal information only as reasonably necessary to operate Argoisten and to deliver the services you request. Recipients may include: (a) authorized Argoisten personnel and contractors with a legitimate business need; (b) infrastructure and software service providers acting under our instructions, including hosting, transactional email delivery, secure storage, and security monitoring; (c) professional advisors such as legal counsel, auditors, and insurance carriers; (d) governmental, regulatory, or law-enforcement authorities where required by law, court order, lawful subpoena, or to respond to a verifiable legal request; and (e) successors in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to confidentiality and continued protection of personal information. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

9. Service providers and processors

We rely on a limited number of vetted third-party processors to operate our services, including transactional email delivery for internal notifications, satellite imagery tile providers used by the D510 site map, and infrastructure operators that host our application and database. These processors operate under written agreements that limit their use of information to the purposes for which we engaged them, require appropriate technical and organizational safeguards, and prohibit unauthorized further processing.

10. International data transfers

Argoisten is based in the United States. If you access our services from outside the United States, you understand that personal information may be transferred to, processed, and stored in the United States, where data-protection laws may differ from those of your jurisdiction. Where required by applicable law, we implement appropriate safeguards for cross-border transfers, including contractual measures with our service providers.

11. Data retention

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to provide our services, comply with our legal, regulatory, tax, and accounting obligations, resolve disputes, and enforce our agreements. Quote-request records and engagement records are retained for at least the period required to support invoicing, regulatory compliance, and dispute resolution, and may be retained longer where business or legal requirements warrant. Security logs, authentication events, and audit trails are retained as needed for incident response and fraud prevention. When personal information is no longer needed, we delete, anonymize, or de-identify it in a manner consistent with our retention policies and applicable law.

12. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction. Controls include enforced HTTPS and HSTS, server-side password hashing with peppering, mandatory multi-factor authentication for AXR accounts, recovery-code policies, session fingerprinting, role-based access scoping, audit logging, content security policy headers, and ongoing review of dependencies and infrastructure. No method of transmission or storage is fully secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting personal information, we will respond in accordance with applicable law.

13. Your privacy rights

Depending on your jurisdiction, you may have the right to (a) request access to the personal information we hold about you; (b) request correction of inaccurate or incomplete information; (c) request deletion of personal information, subject to legal and operational retention requirements; (d) request a portable copy of your information in a structured, commonly used format where applicable; (e) object to or request restriction of certain processing; (f) withdraw consent where our processing is based on consent; and (g) lodge a complaint with a competent supervisory authority. We will respond to verifiable rights requests within the timeframes required by applicable law. Some requests may be limited by legal obligations, the rights of others, the integrity of operational records, or active dispute, security, or compliance investigations.

14. Notice to California residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), California residents have the rights described in Section 13 above, plus the right to know the specific pieces of personal information we have collected, the right to opt out of sales or sharing for cross-context behavioral advertising, the right to limit the use of sensitive personal information, and the right to non-discrimination for exercising privacy rights. Argoisten does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not use sensitive personal information for purposes beyond those that are reasonably necessary and proportionate to provide our services and to detect and prevent security and integrity incidents.

15. Children's information

Our services are not directed to, and we do not knowingly collect personal information from, individuals under 16 years of age. If we learn that we have collected personal information from a child under 16 without verifiable parental consent, we will delete that information promptly.

16. Automated decision-making

We do not engage in automated decision-making that produces legal or similarly significant effects on individuals. D510 quote submissions may include service scope, site geometry, acreage, pin counts, and project details, but pricing, scheduling, and contracting decisions are reviewed by Argoisten operations before any Engagement is accepted.

17. Changes to this notice

We may update this Privacy Notice from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will revise the effective date at the top of this notice and, where appropriate, provide additional notice. Your continued use of our services after the effective date of an updated notice constitutes acceptance of the changes.

18. How to contact us

For privacy questions, rights requests, or to provide notice under this Privacy Notice, please contact Argoisten LLC, Attn: Operations / Privacy, Midland, Texas, United States, or use the contact form at argoisten.com/contact. We will respond within a reasonable period and within any timeframes required by applicable law.

Questions or rights requests

For privacy questions, data-subject rights requests, or to report a possible incident, contact our operations team through the channels listed in Section 18.