Legal Documentation

Privacy Policy

Effective date: 1 March 2026 Last reviewed: 1 March 2026 ICO Reg: ZB826186
Data Controller

MLA Group Ltd (trading as MLA Group)

Unit 1 (Suite 121), Imperial Court, Exchange Street East, Liverpool, L2 3AB

Tel: 0151 558 0162  ·  info@mlagroup.co.uk

Company Registration No: 16117562  ·  ICO Registration No: ZB826186

Section 01

Who We Are

MLA Group Ltd (trading as MLA Group) is an AI governance advisory firm registered in England and Wales. We provide AI governance risk assessments, compliance advisory services, and board-level reporting tools to organisations operating across regulated and professional sectors.

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website at www.mlagroup.co.uk, complete an AI Governance Risk Diagnostic, access your client portal, or otherwise interact with our services.

We are registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZB826186.

Section 02

Data We Collect

We collect personal data in the following categories:

CategoryData CollectedSource
Account DataEmail address, password (hashed), account creation dateProvided by you on registration
Professional DataFull name, job title/role, organisation name, industry sector, organisation sizeProvided by you during diagnostic
Assessment DataResponses to AI governance diagnostic questions, risk scores, governance maturity ratingsGenerated during diagnostic completion
Report DataAI governance risk reports generated from your assessment responses, including domain scores and remediation recommendationsGenerated by our platform
Usage DataPages visited, time on site, browser type, device type, IP addressCollected automatically via cookies

We do not collect special category data (such as health, biometric, or financial data) through our platform. We do not collect payment card data — any future payment processing will be handled by a PCI-compliant third-party provider.

Section 03

Legal Basis for Processing

Under UK GDPR, we rely on the following legal bases for processing your personal data:

Processing ActivityLegal Basis
Creating and managing your accountContract (Art. 6(1)(b)) — necessary to provide the service you have requested
Delivering the AI Governance Risk Diagnostic and reportContract (Art. 6(1)(b)) — core delivery of our service
Storing assessment results and reports in your portalContract (Art. 6(1)(b)) — necessary to provide ongoing access to your results
Sending service communications (account, report notifications)Contract (Art. 6(1)(b))
Analytics and site improvementLegitimate Interests (Art. 6(1)(f)) — improving our platform and user experience
Compliance with legal obligationsLegal Obligation (Art. 6(1)(c))
Marketing communications (where opted in)Consent (Art. 6(1)(a))
Section 04

How We Use Your Data

We use your personal data for the following purposes:

Service Delivery — To create and manage your account, deliver the AI Governance Risk Diagnostic, generate your personalised governance risk report, and provide access to your client portal.

Communication — To send you account confirmations, report notifications, and material updates to our regulatory framework where these affect your risk band or sector obligations.

Platform Improvement — To analyse how users interact with our platform in order to improve the diagnostic tool, reporting quality, and user experience. This analysis is conducted on aggregated, anonymised data where possible.

Legal Compliance — To meet our obligations under applicable law, including responding to lawful requests from regulators or enforcement authorities.

We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects about you. Our diagnostic generates a risk score based on your responses; interpretation and advisory context is provided by our framework and reviewed by our team.

Section 05

Third Parties and Data Sharing

We share personal data with the following third parties only where necessary to deliver our services:

ProcessorPurposeLocation
Supabase Inc.Authentication, secure data storage, and database hosting for your account and assessment resultsEU / USA (SCCs in place)
Netlify Inc.Website hosting and content deliveryUSA (SCCs in place)
Google (Analytics)Anonymous site usage analyticsUSA (SCCs in place)

We do not sell, rent, or otherwise disclose your personal data to third parties for their own marketing purposes. All third-party processors are bound by data processing agreements and are required to process your data only on our instructions.

Where data is transferred outside the UK, we ensure appropriate safeguards are in place including Standard Contractual Clauses (SCCs) approved by the ICO, in compliance with UK GDPR Chapter V.

Section 06

Data Retention

We retain your personal data for the following periods:

Data TypeRetention Period
Account and registration dataDuration of account plus 2 years after account closure
Assessment responses and risk reportsDuration of account plus 3 years after account closure
Usage and analytics data26 months from collection
Communications and correspondence3 years from date of communication

At the end of the applicable retention period, data is securely deleted or anonymised. You may request earlier deletion of your data subject to the conditions set out in Section 07 below.

Section 07

Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

Right of Access (Art. 15)
You have the right to request a copy of the personal data we hold about you and information about how we use it.
Right to Rectification (Art. 16)
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure (Art. 17)
You have the right to request deletion of your personal data in certain circumstances, including where we no longer need it for the purpose it was collected.
Right to Restriction (Art. 18)
You have the right to request that we restrict processing of your data in certain circumstances, for example while a complaint is being resolved.
Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, machine-readable format and to transfer it to another controller.
Right to Object (Art. 21)
You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Art. 7)
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at info@mlagroup.co.uk. We will respond within one calendar month. We may need to verify your identity before processing your request.

If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.

Section 08

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:

Encryption — All data is transmitted over encrypted HTTPS connections. Passwords are hashed and never stored in plain text.

Access Controls — Access to personal data is restricted to authorised personnel only, on a need-to-know basis. Database access is protected by Row Level Security policies.

Authentication — Account access requires secure authentication through our portal.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, in accordance with our obligations under UK GDPR Art. 33–34.

Section 09

Cookies

We use cookies and similar tracking technologies on our website. For full details of the cookies we use, the purposes for which we use them, and how to manage your preferences, please read our Cookie Policy.

Section 10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. Material changes will be communicated to registered users by email. The effective date at the top of this page will always reflect the date of the most recent revision.

Continued use of our services following notification of changes constitutes acceptance of the updated policy.

Section 11

Contact Us

Privacy Enquiries

MLA Group Ltd

Unit 1 (Suite 121), Imperial Court, Exchange Street East, Liverpool, L2 3AB

Tel: 0151 558 0162

Email: info@mlagroup.co.uk