Data Protection Policy

1. Introduction

RLA DIGITAL LTD ("we," "our," or "the Company") is committed to protecting and respecting the privacy of individuals whose personal data we process. This Data Protection Policy outlines how we comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection laws.

2. Scope

This policy applies to all employees, contractors, and third-party service providers working on behalf of RLA DIGITAL LTD. It governs all personal data processed by the Company, whether stored electronically, on paper, or in any other format.

3. Definitions

Personal Data: Any information relating to an identified or identifiable individual ("Data Subject").Processing: Any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.Data Controller: The entity that determines the purposes and means of processing personal data. RLA DIGITAL LTD is the Data Controller for the data we process.Data Processor: Any third party that processes data on behalf of the Data Controller.

4. Principles of Data Protection

We adhere to the following principles when processing personal data:

Lawfulness, Fairness, and Transparency: We process personal data lawfully, fairly, and transparently.Purpose Limitation: Personal data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.Data Minimisation: We only collect and process the data necessary for the purposes identified.Accuracy: Personal data is kept accurate and up-to-date.Storage Limitation: Data is retained only as long as necessary for the purposes for which it is processed.Integrity and Confidentiality: Data is processed securely to protect against unauthorised or unlawful processing, accidental loss, destruction, or damage.Accountability: We are responsible for demonstrating compliance with these principles.

5. Legal Bases for Processing

RLA DIGITAL LTD processes personal data based on one or more of the following legal grounds:

Consent: The Data Subject has given clear consent for processing their personal data for specific purposes.Contract: Processing is necessary for a contract we have with the Data Subject, or because they have asked us to take specific steps before entering into a contract.Legal Obligation: Processing is necessary to comply with a legal obligation.Legitimate Interests: Processing is necessary for our legitimate interests, provided they do not override the Data Subject’s rights and freedoms.

6. Data Subject Rights

Data Subjects have the following rights under the UK GDPR:

The right to be informed about how their data is used.The right to access their personal data.The right to rectification of inaccurate or incomplete data.The right to erasure ("right to be forgotten") under certain circumstances.The right to restrict processing under certain conditions.The right to data portability.The right to object to processing based on legitimate interests or direct marketing.The right not to be subject to automated decision-making and profiling.

7. Data Security

We implement appropriate technical and organisational measures to safeguard personal data, including:

Secure storage and encryption of data.Access controls to limit data access to authorised personnel only.Regular staff training on data protection practices.Incident response plans to handle data breaches promptly.

8. Data Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected or as required by law. We conduct regular reviews of data retention practices.

9. Third-Party Processing

Where we engage third-party service providers to process personal data on our behalf, we ensure that they comply with UK GDPR requirements by signing appropriate data processing agreements.

10. International Data

Transfers If personal data is transferred outside the UK, we ensure that adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) or reliance on an adequacy decision.

11. Data Breach Management

In the event of a personal data breach, we will:

Identify and contain the breach promptly.Assess the risk to individuals and notify the Information Commissioner’s Office (ICO) within 72 hours if required.Inform affected individuals where there is a high risk to their rights and freedoms.Document all breaches and remedial actions taken.

12. Roles and Responsibilities

Data Protection Officer (DPO): RLA DIGITAL LTD does not require a DPO under UK GDPR but designates Adam Rica, Managing Director, to oversee compliance. Data protection queries can be directed to [email protected]: All employees are responsible for adhering to this policy and completing data protection training.

13. Policy Review

This policy will be reviewed annually or whenever significant changes to data protection laws or our processing activities occur.

14. Contact Information

If you have questions about this policy or how we process personal data, please contact us:

RLA DIGITAL LTD | Website: www.rladigital.com | Email: [email protected]

Approved by: Adam Rica, Managing Director

Date: 01/01/2026

2026 RLA Digital . All rights reserved.