Privacy Policy
1. Introduction and Commitment to Privacy
The RSA Group (comprising RSA Consulting Ltd and RSA Interims Ltd) is committed to safeguarding the privacy of our website visitors, clients, candidates, and associates. This policy outlines how we collect, store, and process your personal data in accordance with the Data Protection Act 2018, UK GDPR, and other applicable regulatory standards. By using our website and services, you acknowledge the terms of this policy and consent to our processing of cookies as described herein.
2. Categories of Personal Data We Process
We process two general classifications of personal data, applying varying levels of operational protection depending on the sensitivity of the information:
Personally Identifiable Information includes general contact details, usage data (such as IP addresses, geographical locations, browser specifications, and referral pathways), and account communication preferences collected through our online contact forms and analytic tracking systems.
Sensitive and Special Category Data comprises candidate CVs, compensation histories, employment status details, professional references, and interview notes. We treat this information with additional safeguards, ensuring it is only processed when there is a legitimate business requirement and is never distributed externally without your explicit authorisation.
3. Sourcing and Lawful Bases for Processing
We process personal data under distinct legal bases defined by data protection laws:
Service and Account Data: We process your name, contact information, and professional history to administer our executive search services, maintain database backups, and communicate with you. The legal basis for this processing is either our legitimate interest in conducting executive searches on behalf of our clients or the performance of a contract to which you are a party.
Usage and Correspondence Data: We process website usage data and communication metadata to analyse website performance, secure our systems, and manage record-keeping. The legal basis for this is our legitimate interest in monitoring, improving, and securing our digital infrastructure.
4. Providing Your Personal Data to Others
We do not sell personal data, including mailing lists, to any third party. Your personal information is restricted to internal use within our group of companies. We will only disclose candidate identities and dossiers to prospective clients after obtaining your explicit permission. We may disclose your personal data where necessary for compliance with a legal obligation or to protect vital interests.
5. International Data Transfers
We operate global offices and facilities, including in the United States and Singapore. Transfers of personal data to countries outside the United Kingdom and the European Economic Area (EEA) are protected by appropriate safeguards, including standard data protection clauses approved by the European Commission, ensuring your data receives equivalent protection regardless of geography.
6. Data Retention and Erasure
Personal data shall not be kept for longer than is necessary for its stated purposes. We retain candidate profile data for as long as it remains commercially relevant and potentially beneficial to your career development. When your data is deemed no longer relevant to active or future search mandates, it will be securely erased from our systems. We may retain your data where necessary for compliance with a legal obligation or the establishment of legal claims.
7. Your Statutory Rights under UK GDPR
Under data protection laws, you possess the following principal rights regarding your personal information:
The right to access your personal data free of charge.
The right to rectification of any inaccurate or incomplete data.
The right to erasure ("the right to be forgotten") under specific circumstances.
The right to restrict or object to the processing of your data.
The right to data portability to receive your data in a structured, machine-readable format.
The right to withdraw consent at any time for consent-based processing.
The right to complain to the Information Commissioner's Office (ICO) if you believe our processing infringes your statutory rights.
8. Use of Cookies and Web Analytics
Our website uses cookies (both session and persistent) for authentication, security measures, and performance analysis. We use Google Analytics to examine traffic patterns, which collects data via cookies to generate reports on website interactions. You can manage or block cookies through your web browser settings, although blocking all cookies may limit your ability to use certain features on our website.
9. Corporate Registration and Contact Details
This website is owned and operated by The RSA Group.
RSA Consulting Ltd is registered in England and Wales under Company No. 01803896.
RSA Interims Ltd is registered in England and Wales under Company No. 08433229.
Our registered office and principal place of business is at: The Gate House, Fretherne Road
Welwyn Garden City, Hertfordshire, AL8 6NS, United KingdomOur Information Commissioner's Office (ICO) registration number is: Z5582962.
You can contact us by post at our principal address, by telephone at +44 (0) 203 818 8820, or by email at hq@thersagroup.com.
Our designated Data Protection Officer can be reached directly at: gdpr@thersagroup.com.