Portland Heliport · EGDP
How this service handles your data
To decide whether a drone may fly inside the Portland Flight Restriction Zone, HeliOperations has to know who is flying, what they are flying, and where. This page says exactly what that means in practice.
What an application records
- Your account: name, email address, telephone number, organisation, and your CAA Operator ID and Flyer ID with their expiry dates.
- Each application: the remote pilot’s name and email, the purpose of the operation, the aircraft you intend to fly including its make and model, serial number, broadcast Remote ID, weight and colour, and the area, dates, times and maximum height you have asked for.
- Documents you upload as evidence, such as an Operational Authorisation or insurance certificate.
- A record of what happened to the application: when it was submitted, what was decided, who decided it and any conditions imposed.
Why
To assess the risk to aircraft using Portland Heliport, to issue or refuse a permission, and to hold a record of why a flight was authorised. Nothing collected here is used for marketing, and none of it is sold or shared for advertising.
Who can see it
Operations staff at HeliOperations who assess applications, and you. Other operators cannot see your applications or your documents.
The public verification page, which a permit’s QR code links to, deliberately shows no personal data at all: no name, organisation, email, telephone number or address. It confirms only whether a permission is live, for what area and to what height. Anyone who needs to know who is flying is asked to telephone the heliport.
Where it is held
In a private database and private document storage in the United Kingdom. Uploaded documents are not public: they can only be retrieved by you or by a reviewing member of operations staff.
How long it is kept, and when it is deleted
Nothing here is kept indefinitely. A sweep runs every night and deletes, automatically, without anybody having to ask:
- Expired documents, the day after they expire. An Operational Authorisation or insurance certificate that has run out cannot support a future application, so there is no reason to keep it.
- Applications and their documents, twelve months on. Measured from the later of the last change to the application and the end of its operating window. Your account survives this, so you do not have to register again.
- Your whole account, after twelve months without signing in. Everything goes with it: your details, your aircraft and any documents still held.
The effect is that what is held is either current or gone. That is deliberate: a permit desk assessing a flight should be reading a live Operational Authorisation, not one that lapsed last spring.
The database is backed up daily so that records are not lost to a fault. A deletion takes effect immediately in the service itself, and the deleted record then falls out of the backups as those rotate.
Asking for your data, or its deletion
You do not have to wait for any of the above. You can ask at any time for a copy of what is held about you, for anything inaccurate to be corrected, or for your data to be deleted outright. Write to info@helioperations.co.uk or telephone 01305 700001, and say which you want.
One thing to know before asking for deletion: a permission HeliOperations has issued is the record of why a flight into controlled airspace was authorised. Deleting it removes that record, and any permit you are still holding will no longer verify.
If you are not satisfied with the response you can complain to the Information Commissioner’s Office at ico.org.uk.
Who is responsible
The data controller is Developing Assets (UK) Limited, trading as HeliOperations, of The HeliPort, Osprey Quay, Portland, Dorset, DT5 1BL, company number 04411666. That is the same controller named in their main privacy policy: it decides why and how your data is processed.
This page covers the permit service specifically. The HeliOperations privacy policy covers their website, and where the two differ about this service, this page is the one that describes what actually happens to an application.