Privacy Notice
1. Who we are
This notice is issued by The RLK Group, a private limited company incorporated in Scotland under company number SC781391, with its registered office at Unit 4 Strathclyde Business Centre, Cambuslang, United Kingdom, G72 7XR ("RLK", "we", "us"). We are the data controller for personal data processed in connection with our counter-UAS mission analysis platform, UAVSimNet (the "Platform"), and the public website that describes it (the "Site").
For privacy enquiries, to exercise your rights under UK GDPR, or to contact our data protection function, write to The RLK Group in writing at its registered office: Unit 4 Strathclyde Business Centre, Cambuslang, United Kingdom, G72 7XR. We will respond within the time limits set out in §10.
2. Scope
This notice applies to personal data we process about three categories of individual: (a) people who submit an access request through the public contact form on the Site; (b) Authorised Users of the Platform — individuals who hold credentials issued by us to access UAVSimNet on behalf of a customer organisation; and (c) general visitors to the Site. It supplements, and should be read alongside, our Terms of Service (/terms) and Acceptable Use Policy (/aup).
3. Personal data we collect
3.1 From access-request submissions
- Full name and organisation name.
- Work email address.
- Country of operation (ISO-3166 alpha-2 code).
- Role or job title.
- Free-form description of the intended use case and the problem you are trying to solve.
- The four compliance and consent attestations captured at submission, each with its own timestamp: compliance attestation, Terms acceptance, AUP acceptance, and training-mirror participation consent.
3.2 From Authorised User accounts
- Authentication data — username (derived from the email local-part), password stored as a salted hash, session tokens, session issue and expiry timestamps.
- Authentication events — login success, login failure, password change, invite-link redemption, and the originating IP address and user-agent string for each.
- Platform interaction data — scenarios submitted, run history, artefact downloads, and actions taken inside the operator console.
3.3 From general Site visitors
- IP address (in transit; not retained beyond short-term operational logs), browser type, user-agent string, and the page path requested.
- We do not place advertising trackers on the Site. We do not use third-party analytics such as Google Analytics on the public marketing pages.
4. Lawful bases for processing
We rely on the following lawful bases under Article 6 of the UK GDPR, depending on the processing activity:
- Performance of a contract (Article 6(1)(b)) — account provisioning, user authentication, run execution, artefact storage, and support.
- Legitimate interests (Article 6(1)(f)) — security monitoring, fraud prevention, audit logging, service improvement, and internal analytics on platform usage. Our legitimate interests are balanced against the rights and freedoms of data subjects; we have conducted legitimate interests assessments for each such activity.
- Consent (Article 6(1)(a)) — optional participation in the training-data mirror described in §5, and any other non-essential processing offered to Authorised Users. Consent can be withdrawn at any time by writing to us at the registered office address in §1; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Legal obligation (Article 6(1)(c)) — export-control screening, compliance record-keeping, retention of audit logs and financial records for the periods required by UK law.
5. Training-data mirror — explicit disclosure
Where Customer has opted in at access-request time, we duplicate a defined, narrow set of run artefacts into an internal training mirror used to improve future releases of the Platform. The artefact set is limited to:
scenario.json— the compiled scenario configuration that was executed.run_results.csv— per-sample engagement outcomes (miss distance, time to intercept, failure mode).trajectories.csv— time-series state samples captured during the run.aggregate.json— summary statistics for the run as a whole.
Each mirror entry is labelled with a one-way SHA-256 hash of the originating tenant identifier (the "tenant_hash"), truncated to sixteen hexadecimal characters. Direct personal identifiers — usernames, real names, email addresses, IP addresses, and any other field that could identify an individual — are stripped before data enters the mirror. The mirror is not shared with any third party, is not sold, and is not used for advertising.
You may withdraw from training-mirror participation at any time by writing to us at the registered office address in §1. Withdrawal applies to future runs only; mirror entries created while consent was in force can be deleted on request by the tenant_hash associated with Customer's tenant. Deletion is irreversible. Retention of mirror entries, while consent is active, is indefinite.
6. How we use personal data
- Provisioning and operating Customer tenants; authenticating Authorised Users; executing runs; producing and storing artefacts.
- Providing support in response to Customer requests, and proactively where an incident requires contact.
- Security monitoring, detection of abuse and unauthorised access, incident response, and post-incident forensics.
- Invoicing, billing, and maintenance of the commercial records required by UK tax and company law.
- Compliance verification — including sanctions screening and export-control review — at access-request time and during the Subscription Term.
- Sales and relationship management in response to inbound access requests and during active customer relationships.
- Internal analytics on aggregate platform usage, to inform product priorities and capacity planning.
7. Third-party recipients (sub-processors)
We use a small number of sub-processors to deliver the Services. Each is bound by a written data-processing agreement and is subject to security and confidentiality obligations consistent with UK GDPR. Our current sub-processors are:
- Capsule CRM (Zestia Ltd) — customer relationship management system used to manage inbound access requests and active customer accounts. Categories of data processed: name, work email, organisation name, country, role or job title, use-case description. Purpose: inbound enquiry triage, sales pipeline management, account notes. Processing location: United Kingdom / European Union.
- Hosting and platform infrastructure — the Platform is hosted on cloud infrastructure operated by emergent.sh and the underlying cloud provider on which the emergent.sh service runs. Categories of data processed: all data at rest and in transit, including Customer Data. Purpose: operational hosting and delivery of the Services.
We do not use advertising networks, third-party analytics services, or social-media trackers on the Site or inside the operator console. If this changes in future we will update this notice and notify active customers by email.
8. International transfers
Where personal data is transferred outside the United Kingdom we apply the transfer mechanism appropriate to the destination: UK-to-EEA transfers are treated as adequate under the UK Government's adequacy determination for the EEA; any UK-to-US transfers are covered by the UK Addendum to the EU Standard Contractual Clauses, the International Data Transfer Agreement (IDTA), or the EU–US / UK–US Data Privacy Framework, as applicable to the recipient; and transfers to other jurisdictions are covered by the IDTA or equivalent safeguards.
9. Retention
- Active account data — retained for the Subscription Term and for seven (7) years after termination, to comply with commercial and tax record-keeping obligations.
- Authentication logs — retained for twelve (12) months.
- Run artefacts — retained for the Subscription Term plus seven (7) years, unless the Customer requests earlier deletion.
- Training-mirror entries (anonymised) — retained indefinitely while consent is active, and deleted on request as described in §5.
- Access-request submissions that are declined — retained for twelve (12) months to support sanctions-screening audit requirements, then deleted.
10. Your rights under UK GDPR
Subject to the conditions set out in UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your personal data ("right to be forgotten"), where the conditions in Article 17 are met.
- Restriction of processing in the circumstances described in Article 18.
- Data portability — to receive your data in a structured, commonly used, machine-readable format, where processing is based on consent or on contract and is carried out by automated means.
- Object to processing carried out under legitimate interests, including profiling.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with the UK Information Commissioner's Office — see §16.
To exercise any of these rights, write to The RLK Group in writing at its registered office: Unit 4 Strathclyde Business Centre, Cambuslang, United Kingdom, G72 7XR. We will respond within one month of receiving a verified request; that period may be extended by up to two further months where the request is complex or numerous, in which case we will tell you and explain why.
11. Children's data
The Platform is intended for professional use by defence, government, law-enforcement, licensed-industry, and academic research teams. It is not directed at persons under eighteen (18). We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, write to us at the registered office address in §1 and we will delete it promptly.
12. Cookies and tracking
The public Site uses only strictly necessary cookies — for session continuity inside the operator console and for remembering UI preferences. We do not use advertising cookies, social-media tracking pixels, or cross-site third-party analytics on the Site. Where a cookie exists purely for security or session management, we rely on the "strictly necessary" exemption in the UK PECR; we will display a cookie notice if we ever add a non-essential cookie.
13. Security
We apply technical and organisational measures proportionate to the nature of the data we process and to the counter-UAS customer profile we serve. Our security posture is summarised on the public Security page and is covered in more detail under NDA during procurement evaluation. Key controls include encryption of data in transit and at rest, strict per-customer tenant isolation, role-based access controls, and an auditable access trail for all authentication and run-lifecycle events.
14. Data breaches
If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, in line with UK GDPR Article 33. Where the breach is likely to result in a high risk to rights and freedoms, we will also communicate the breach directly to affected individuals in line with Article 34.
15. Changes to this notice
We may update this notice from time to time. The current version is always available at /privacy, with the effective date shown at the top. Where a change is material, we will notify active customers by email at least thirty (30) days before the change takes effect.
16. Contact and complaints
For privacy enquiries or to exercise your rights, write to The RLK Group in writing at its registered office: Unit 4 Strathclyde Business Centre, Cambuslang, United Kingdom, G72 7XR. You also have the right to lodge a complaint about our handling of your personal data with the UK Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: https://ico.org.uk
We would appreciate the opportunity to resolve any concern before you approach the ICO; please give us a reasonable opportunity to respond by writing to our registered office first.