Last updated: 2026
This notice applies to all websites and applications developed and delivered by DLR Group and its Affiliates, and explains how we collect, use and protect your personal data.
This notice applies to all websites & applications developed and delivered by DLR Group and its Affiliates.
DLR Media, along with DLR Retail, are Affiliates of the DLR Group (Scotland) Limited, which is a registered company incorporated in Scotland under company number 600110 and has a registered office at 10 Abbey Park Place, Dunfermline, Fife, Scotland, KY12 7NZ. All significant decisions about data processing and policy implementation will be made using UK GDPR and EU GDPR (General Data Protection Regulation). This notice is set out to help you understand the types of data that we collect from you, and/or your business, and how that data is used and managed.
DLR Group are committed to protecting the privacy and security of your personal data. We continually monitor compliance through implementing policies & procedures to safeguard data and by setting regular reviews to manage these policies and procedures.
In accordance with ICO (Information Commissioners Office) requirements of Data Controllers, DLR Group & affiliates are registered with the Information Commissioners Office DLR Group (ZB628857) DLR Retail Limited (ZB641902) & DLR Media Limited (ZB641897) We act as a data controller and in many cases also act as a data processor depending on the processing being performed. We continue to use the ICO guidance and self-assessment toolkits when evaluating if we are a processor or controller.
At DLR Group, we offer a comprehensive range of marketing and communications advice, strategy, and services for individuals and businesses and serve local, national, and international clients. We offer a full digital service to our clients to help their business grow.
As part of our services, we may design, develop, deploy and host websites, applications, automations and AI-assisted systems using third-party platforms, infrastructure providers and integrated services.
Some applications or websites developed by us may be operated by our clients, who independently determine the data collected and the purposes for which it is processed.
In such cases, the client is responsible for ensuring compliance with applicable privacy and data protection laws.
Personal data is information about you and from which you can be identified. We will collect and process personal data about you depending on our relationship with you. Most of the personal information we process is provided to us directly by you. Data collection can be through a variety of channels, including by telephone, email, via our website or on site and via third parties.
Clients & Customers b2b & b2c, job applicants, Investors, Training Delegates, Suppliers & Service Providers, Regulatory Bodies & Compliance Authorities, Employees & Contractors. Collaborative Partners and Alliances, Competitors, Legal & Financial Advisors, Media services, Industry Associations & Communities.
DLR group will only process personal data where we have a lawful basis for doing so. The legal grounds for processing data will depend on the purpose of the data collected and its processing requirements. Under UK GDPR, there are six available lawful basis, namely: Consent, Contract, Legal Obligation, Vital Interests, Public Task, and Legitimate Interests.
We want to give you the best possible customer experience. One way to achieve that is to get the richest picture we can of who you are by combining the data we have about you. The data privacy law allows this as part of our legitimate interest in understanding our customers and providing the highest levels of service. Of course, if you wish to change how we use your data, you will find details in the 'Your data protection rights' section below.
We collect, process and store personal data for the following purposes as we are a small organisation with minimal processing, we may also occasionally process data not listed below: -
To carry out our obligations arising from any contracts entered into by clients and us.
To respond, provide support, make assessments and recommendations around products and services we provide.
Provide reporting statistical analysis, identify customer trends and measuring effectiveness of marketing campaigns. Service quality, improvements & identify training requirements.
To process payments including verification, invoicing, payments & regulatory submissions.
To advertise, create, monitor & support attendance at Business-to-Business networking events.
To introduce, signpost, & promote businesses and their brand products through media interactions.
To host events on behalf of stakeholder(s), collect feedback on events and services we provide & to sign post similar future events.
To send you relevant, personalised email communications about services and products.
Use data analytics to improve our website, products/services, marketing, customer, member & volunteer relationships, and experiences.
Profiling - we may analyse your personal information to create a profile of your interests and preferences so that we can contact you with information relevant to you. We may make use of additional information about you when it is available from external sources to help us do this effectively.
Job Application form part of our recruitment process to validate and evaluate and review potential and existing staff.
Customise our websites according to your interests and ensure that content is presented in the most effective manner for your computer, tablet, or mobile device.
To carry out Identity verification checks in order to comply with contractual and legal obligations.
We may also use your personal information to detect crimes such as fraud.
Administer purchases, confirm your purchases, and otherwise communicate with you about your purchase.
Address any claims made against us; for example, we may share details of our accident logs with our insurers in connection with any claim made or likely to be made against us in connection with legal proceedings (i.e., the establishment, exercise, or defence of legal claims)
To protect our rights, & safety of our clients, contractors, and other third parties
When you visit our offices, we will collect information required to identity you and the organisation you represent. We will also collect the dates and times of attendance.
Some of our services may involve the use of artificial intelligence, automated systems or machine-assisted development tools.
Such systems may process prompts, instructions, content, configuration data or usage information in order to generate functionality, content, workflows or application features.
We take reasonable steps to ensure that AI-assisted services are implemented responsibly, however customers remain responsible for reviewing and approving outputs and ensuring that any data entered into such systems is appropriate and lawful.
We know how much data security matters to all our clients. With this in mind we will treat your data with the utmost care and take all appropriate steps to protect it. We secure access to all transactional areas of our website using 'https' technology. Access to your personal data (such as email and phone number) is password-protected, and sensitive data (payment information) is secured and encrypted to ensure it is protected. All significant decisions about data processing and policy implementation will be made using UK GDPR. we take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this notice.
DLR Media collects personal data from web forms submitted by customers requesting information in the form of general enquiries or to register for the events and services provided by DLR Media. This comprises the name, email address, company name, subject & message of the person making the enquiry.
Some applications or websites developed by us may include login systems, user accounts, authentication providers or restricted-access areas.
Where applicable, personal information such as names, email addresses, account identifiers, login activity and user-generated content may be processed in connection with these features.
DLR Media can be found on social media platforms such as Facebook, Twitter, Instagram, and LinkedIn. Social Media is an important part of our awareness effort, so you may be presented with a retargeting ads & emails in future following a visit to our website. We may target ads at audiences that we believe match the profile of our target audience and would therefore be interested in our services. We will also regularly tag or mention you where we are carrying out business promotion on your behalf or to raise your professional profile.
These platforms are run by commercial companies and DLR Media is not the Data Controller or Data Processor of your social media profile. You should contact these social media platforms directly if you have concerns over how your personal data is being used and stored by them.
Our websites & information we share around events & involving stakeholders may contain links to other websites run by other organisations. This privacy policy applies only to our website, so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website. In addition, if you linked to our website from a third-party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and recommend that you check the policy of that third party site.
We use software to collect analytic information on how website visitors engage with our website pages and content. We do this to understand how our website visitors use a website in order to provide an efficient user experience along with relevant information. This information is only processed in a way which does not identify individuals.
We use Google Analytics to collect standard internet log information on visitor behaviour patterns. We do this to understand how our website visitors use a website in order to provide an efficient user experience along with relevant information. This information is only processed in a way which does not identify individuals. For more information about Google Analytics terms and conditions, visit https://www.google.com/analytics/terms/. To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.
We may also collect personal data from the website using Google Analytics to anonymously track how users interact with our site. This involves installing Google Analytics code on our website in the form of a 'cookie.' Cookies contain an ID number which is assigned to a user and provides us with the following information:
Your IP address (An IP address does not provide identifiable personal information)
The time of your visits and the length of time you spent on our website.
Your location (although this might be influenced by the location of your server)
Referral source (how you arrived on our site, e.g. search engine, direct URL, social media, or third-party website).
Whether we are acting as a data controller or processor we continue to apply the UK GDPR principles to all personal & sensitive data that we hold or process and these principles lie at the heart of our approach to processing personal data.
1) Processed lawfully, fairly and in a transparent manner in relation to individuals.
2) Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be incompatible with the initial purposes.
3) Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
4) Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased, or rectified without delay.
5) Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the UK GDPR in order to safeguard the rights and freedoms of individuals.
6) Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
We use third parties who provide elements of our services for us. We have contracts in place with these 3rd parties who are data processors (the people who process personal information on our behalf). This means they cannot do anything with your personal information unless we have instructed them to do it. We will apply the following considerations at all times: -
They will not share your personal information with any organisation apart from us.
They will hold it securely and retain it for the period we instruct them to.
They may only use your data for the exact purposes we specify in our contract with them.
If we stop using their services, any of your data held by them will either be deleted or rendered anonymous.
We will not share your information with any third parties for the purposes of direct marketing.
Some of our 3rd parties host, process and/or store data in the US,
We may be required to transfer your information to a third party as part of a division/merger/sale of some or all of our business assets as part of any restructuring or reorganisation of the business.
We may also be required to disclose or share your personal data to comply with any legal obligation or to enforce or apply our terms of use or to protect the rights, property or safety of our trustees, members, volunteers, supporters, contractors, and customers. However, we will take steps with the aim of ensuring that your privacy rights continue to be protected.
We may share names, email addresses, pictures, job roles and organisational information as part of business-to-business networking events & with organisations & contractors commissioned to assist & co-ordinate these events.
Pre & post event/webinar management may include grouped online communications such as meeting invites in meeting chats and document sharing. Others attending may see your name and email address and may see conversation responses and questions you may ask.
Where we have been commissioned by an organisation to host a webinar or event, your registration & attendance information & any feedback you provide will be shared with this organisation.
We work closely with organisations to ensure that your privacy is respected and protected at all times.
We do not anticipate providing services directly to children, however we do understand that if this change occurs, we will make provisions to verify age. We will also make further provisions to gain parental or guardian consent for data processing activity where required.
We will continue to look for new ways to protect data. We have effective processes and procedures in place to be able to detect, investigate, risk assess and record incidents and breaches. However, in the event of a data breach we will notify the ICO (Information Commissioners Office) within 72 hours of becoming aware of the breach as well as take steps to inform any individuals affected. Where we do not yet have all the relevant details, we will notify the ICO, if required, when we expect to have the results of the investigation..
All significant decisions about data processing by DLR will be made using UK GDPR & EU GDPR as part of the services offered to you. Some of our processors systems & resources are hosted and process and store data in the US which will contain categories deemed low risk such as Personal, Professional & in some cases Sensitive (pseudonymized financial data as part of a blockchain) However special category data which the Processor collects on behalf of the Controller will not be transferred to countries outside the UK without explicit consent. We will take steps to ensure that appropriate security measures are taken to ensure that the rights of individuals will continue to be protected as outlined in this notice.
If you use our services while you are outside the UK, your information may be transferred outside the UK in order to provide you with those services.
Under data protection law, you have rights we need to make you aware of. The rights available to you depend on our reason for processing your information.
Your right of access - You have the right to ask us for copies of your personal information. This right always applies. There are some exemptions, which means you may not always receive all the information we process.
Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. This right always applies.
Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.
Your right to object to processing - You have the right to object to processing if we are able to process your information because the process forms part of our public tasks or is in our legitimate interests.
Your right to data portability - This only applies to information you have given us. You have the right to ask that we transfer the information you gave us from one organisation to another or give it to you. The right only applies if we are processing information based on your consent or under, or in talks about entering into a contract and the processing is automated.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
The Privacy and Electronic Communication Regulations (PECR) sits alongside the Data Protection Act and the UK GDPR and gives individuals specific rights around electronic communication. This means if we send electronic marketing or use cookies or similar technologies, we must comply with both PECR and UK GDPR
Although PECR covers a number of areas which provide public electronic communication network or services, PECR applies to DLR for
You have the right to stop the use of your personal data for direct marketing activity through all channels, or selected channels. We must always comply with your request unless an exemption applies. There are various ways you can stop direct marketing communications from us.
Click the "unsubscribe" link in any direct marketing email communication that we send you. We will then stop any further direct marketing emails.
You can also email, call, or write to us to ask us to add you to our suppression list.
If you unsubscribe from our marketing mailing lists, you will still receive service and support communications from us where you are an existing customer, supplier or have a relationship with us that requires us to process your information as part of a contract or where the law requires us to do so.
Cookies are small pieces of information sent by an organisation to your computer and stored on your hard drive to allow that website to recognise you when you visit. They collect statistical data about your browsing actions and patterns and do not identify you as an individual. For example, we use cookies to store your country preference. This helps us to improve our website and deliver a better more personalised service. It is possible to switch off cookies by setting your browser preferences. Turning cookies off may result in a loss of functionality when using our website.
Further information around your rights can be found at https://ico.org.uk/your-data-matters